Aller au contenu

xavmal

Membres
  • Compteur de contenus

    10
  • Inscription

  • Dernière visite

Autres informations

  • Mes langues
    Français

xavmal's Achievements

Junior Member

Junior Member (3/12)

0

Réputation sur la communauté

  1. Non apparemment plus de problèmes Merci beaucoup pour l'aide efficace. @ + quote name='bruce lee' date='dimanche 09 décembre 2007 à 11h22' post='1140718'] Re, C'est clean As-tu encore des problemes avec ton PC?
  2. salut j'avais vidé le inbox, apparemment pas suffisant Cette fois ci j'ai tout vidé du compte laposte le nouveau rapport KASPERSKY ONLINE SCANNER REPORT Sunday, December 09, 2007 9:55:04 AM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 9/12/2007 Kaspersky Anti-Virus database records: 477469 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target My Computer C:\ D:\ Scan Statistics Total number of scanned objects 98631 Number of viruses found 0 Number of infected objects 0 Number of suspicious objects 0 Duration of the scan process 01:35:29 Infected Object Name Virus Name Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-09182007-195641.log Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Xavier\Application Data\OpenOffice.org2\user\uno_packages\cache\log.txt Object is locked skipped C:\Documents and Settings\Xavier\Application Data\OpenOffice.org2\user\uno_packages\cache\registry\com.sun.star.comp.deployment.component.PackageRegistryBackend\common_.rdb Object is locked skipped C:\Documents and Settings\Xavier\Application Data\OpenOffice.org2\user\uno_packages\cache\registry\com.sun.star.comp.deployment.component.PackageRegistryBackend\Windows_x86_.rdb Object is locked skipped C:\Documents and Settings\Xavier\Application Data\OpenOffice.org2\user\uno_packages\cache\registry\com.sun.star.comp.deployment.configuration.PackageRegistryBackend\registered_packages.db Object is locked skipped C:\Documents and Settings\Xavier\Application Data\OpenOffice.org2\user\uno_packages\cache\uno_packages.db Object is locked skipped C:\Documents and Settings\Xavier\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{F667AAC2-6A29-41D9-9AEB-8134AB0A1825} Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Historique\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Historique\History.IE5\MSHist012007120920071210\index.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Temp\svc77.tmp\svc95.tmp Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Xavier\Mes documents\Adresses.odb Object is locked skipped C:\Documents and Settings\Xavier\Mes documents\Nouvelle base de données\Table1.dbf Object is locked skipped C:\Documents and Settings\Xavier\Mes documents\Nouvelle base de données.odb Object is locked skipped C:\Documents and Settings\Xavier\ntuser.dat Object is locked skipped C:\Documents and Settings\Xavier\ntuser.dat.LOG Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\WINDOWS\$NtUninstallQ328310$\winsrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ329048$\zipfldr.dll Object is locked skipped C:\WINDOWS\$NtUninstallq329112$\udfs.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ329115$\crypt32.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ329170$\srv.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ329390$\shmedia.dll Object is locked skipped C:\WINDOWS\$NtUninstallq329623$\acgenral.dll Object is locked skipped C:\WINDOWS\$NtUninstallq329623$\sysmain.sdb Object is locked skipped C:\WINDOWS\$NtUninstallQ329692$\duser.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ329834$\raspptp.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\hhctrl.ocx Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\hhsetup.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\itircl.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\itss.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\magnify.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\migwiz.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\narrator.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\osk.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\pchshell.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\shdocvw.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\shell32.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\urlmon.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810577$\mrxsmb.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ810583$\win32k.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ810833$\locator.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ811493$\ntkrnlpa.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ811493$\ntoskrnl.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ814033$\newdev.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ815021$\ntdll.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ817357$\shell32.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ817606$\srv.sys Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed. ca a l'air propre @+ ='bruce lee' date='samedi 08 décembre 2007 à 18h40' post='1140368'] Re, Supprime les messages de ta boite de messagerie laposte.net. Vide le contenu de ta Corbeille puis refais un nouveau scan en ligne avec Kaspersky.
  3. Mon petit rapport K KASPERSKY ONLINE SCANNER REPORT Friday, December 07, 2007 1:15:25 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 7/12/2007 Kaspersky Anti-Virus database records: 475027 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target My Computer C:\ D:\ Scan Statistics Total number of scanned objects 98431 Number of viruses found 1 Number of infected objects 8 Number of suspicious objects 0 Duration of the scan process 02:21:09 Infected Object Name Virus Name Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-09182007-195641.log Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox/[From berardgroupe ][Date Wed, 5 Jan 2005 09:25:01 +0100]/text/[From The SYSTRAN Team ][Date Thu, 3 Mar 2005 23:30:01 -0800]/UNNAMED/[From [email protected]][Date 5 Mar 2005 08:08:39 -0000]/html/[From [email protected]][Date Sat, 12 Mar 2005 12:08:14 +0100]/UNNAMED Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox/[From berardgroupe ][Date Wed, 5 Jan 2005 09:25:01 +0100]/text/[From The SYSTRAN Team ][Date Thu, 3 Mar 2005 23:30:01 -0800]/UNNAMED/[From [email protected]][Date 5 Mar 2005 08:08:39 -0000]/html Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox/[From berardgroupe ][Date Wed, 5 Jan 2005 09:25:01 +0100]/text/[From The SYSTRAN Team ][Date Thu, 3 Mar 2005 23:30:01 -0800]/UNNAMED Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox/[From berardgroupe ][Date Wed, 5 Jan 2005 09:25:01 +0100]/text/[From [email protected]][Date Tuesday 5 April 2005, 8:15]/text/[From "eBay" ][Date Tue, 12 Apr 2005 23:06:51 +0200]/UNNAMED/[From [email protected]][Date Wed, 13 Apr 2005 19:24:52 +0200]/UNNAMED Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox/[From berardgroupe ][Date Wed, 5 Jan 2005 09:25:01 +0100]/text/[From [email protected]][Date Tuesday 5 April 2005, 8:15]/text/[From "eBay" ][Date Tue, 12 Apr 2005 23:06:51 +0200]/UNNAMED Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox/[From berardgroupe ][Date Wed, 5 Jan 2005 09:25:01 +0100]/text/[From [email protected]][Date Tuesday 5 April 2005, 8:15]/text Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox/[From berardgroupe ][Date Wed, 5 Jan 2005 09:25:01 +0100]/text Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox Mail Berkeley mbox: infected - 7 skipped C:\Documents and Settings\Xavier\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{C5DA398E-690B-4ECC-8F53-4275E3943E87} Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Historique\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Historique\History.IE5\MSHist012007120720071208\index.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Xavier\ntuser.dat Object is locked skipped C:\Documents and Settings\Xavier\ntuser.dat.LOG Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\WINDOWS\$NtUninstallQ328310$\winsrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ329048$\zipfldr.dll Object is locked skipped C:\WINDOWS\$NtUninstallq329112$\udfs.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ329115$\crypt32.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ329170$\srv.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ329390$\shmedia.dll Object is locked skipped C:\WINDOWS\$NtUninstallq329623$\acgenral.dll Object is locked skipped C:\WINDOWS\$NtUninstallq329623$\sysmain.sdb Object is locked skipped C:\WINDOWS\$NtUninstallQ329692$\duser.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ329834$\raspptp.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\hhctrl.ocx Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\hhsetup.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\itircl.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\itss.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\magnify.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\migwiz.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\narrator.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\osk.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\pchshell.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\shdocvw.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\shell32.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\urlmon.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810577$\mrxsmb.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ810583$\win32k.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ810833$\locator.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ811493$\ntkrnlpa.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ811493$\ntoskrnl.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ814033$\newdev.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ815021$\ntdll.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ817357$\shell32.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ817606$\srv.sys Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed. @+
  4. Mon nouveau rapport KASPERSKY ONLINE SCANNER REPORT Thursday, December 06, 2007 8:20:56 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 6/12/2007 Kaspersky Anti-Virus database records: 474036 Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true Scan Target My Computer C:\ D:\ Scan Statistics Total number of scanned objects 103385 Number of viruses found 4 Number of infected objects 141 Number of suspicious objects 0 Duration of the scan process 02:37:22 Infected Object Name Virus Name Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-09182007-195641.log Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cert8.db Object is locked skipped C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\history.dat Object is locked skipped C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\key3.db Object is locked skipped C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\parent.lock Object is locked skipped C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\urlclassifier2.sqlite Object is locked skipped C:\Documents and Settings\Xavier\Application Data\OpenOffice.org2\user\uno_packages\cache\log.txt Object is locked skipped C:\Documents and Settings\Xavier\Application Data\OpenOffice.org2\user\uno_packages\cache\registry\com.sun.star.comp.deployment.component.PackageRegistryBackend\common.rdb Object is locked skipped C:\Documents and Settings\Xavier\Application Data\OpenOffice.org2\user\uno_packages\cache\registry\com.sun.star.comp.deployment.component.PackageRegistryBackend\Windows_x86.rdb Object is locked skipped C:\Documents and Settings\Xavier\Application Data\OpenOffice.org2\user\uno_packages\cache\registry\com.sun.star.comp.deployment.configuration.PackageRegistryBackend\registered_packages.db Object is locked skipped C:\Documents and Settings\Xavier\Application Data\OpenOffice.org2\user\uno_packages\cache\uno_packages.db Object is locked skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox/[From berardgroupe ][Date Wed, 5 Jan 2005 09:25:01 +0100]/text/[From The SYSTRAN Team ][Date Thu, 3 Mar 2005 23:30:01 -0800]/UNNAMED/[From [email protected]][Date 5 Mar 2005 08:08:39 -0000]/html/[From [email protected]][Date Sat, 12 Mar 2005 12:08:14 +0100]/UNNAMED Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox/[From berardgroupe ][Date Wed, 5 Jan 2005 09:25:01 +0100]/text/[From The SYSTRAN Team ][Date Thu, 3 Mar 2005 23:30:01 -0800]/UNNAMED/[From [email protected]][Date 5 Mar 2005 08:08:39 -0000]/html Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox/[From berardgroupe ][Date Wed, 5 Jan 2005 09:25:01 +0100]/text/[From The SYSTRAN Team ][Date Thu, 3 Mar 2005 23:30:01 -0800]/UNNAMED Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox/[From berardgroupe ][Date Wed, 5 Jan 2005 09:25:01 +0100]/text/[From [email protected]][Date Tuesday 5 April 2005, 8:15]/text/[From "eBay" ][Date Tue, 12 Apr 2005 23:06:51 +0200]/UNNAMED/[From [email protected]][Date Wed, 13 Apr 2005 19:24:52 +0200]/UNNAMED Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox/[From berardgroupe ][Date Wed, 5 Jan 2005 09:25:01 +0100]/text/[From [email protected]][Date Tuesday 5 April 2005, 8:15]/text/[From "eBay" ][Date Tue, 12 Apr 2005 23:06:51 +0200]/UNNAMED Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox/[From berardgroupe ][Date Wed, 5 Jan 2005 09:25:01 +0100]/text/[From [email protected]][Date Tuesday 5 April 2005, 8:15]/text Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox/[From berardgroupe ][Date Wed, 5 Jan 2005 09:25:01 +0100]/text Infected: Email-Worm.Win32.NetSky.ac skipped C:\Documents and Settings\Xavier\Application Data\Thunderbird\Profiles\hazqrao5.xavier.mallon\Mail\pop.laposte.net\Inbox Mail Berkeley mbox: infected - 7 skipped C:\Documents and Settings\Xavier\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{E0EF5A0D-1A30-4F94-98C2-FBE59D42E03F} Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\Cache\_CACHE_001_ Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\Cache\_CACHE_002_ Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\Cache\_CACHE_003_ Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Historique\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Historique\History.IE5\MSHist012007120620071207\index.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Xavier\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\Navilog1.zip/Navilog1.exe/file7 Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\Navilog1.zip/Navilog1.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\Navilog1.zip ZIP: infected - 2 skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(2).exe/EXE-file/stream/data0007 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(2).exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(2).exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(2).exe Embedded EXE: infected - 3 skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(2).exe UPX: infected - 3 skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(2).exe PE_Patch.UPX: infected - 3 skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(3).exe/EXE-file/stream/data0007 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(3).exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(3).exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(3).exe Embedded EXE: infected - 3 skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(3).exe UPX: infected - 3 skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(3).exe PE_Patch.UPX: infected - 3 skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(4).exe/EXE-file/stream/data0007 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(4).exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(4).exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(4).exe Embedded EXE: infected - 3 skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(4).exe UPX: infected - 3 skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup(4).exe PE_Patch.UPX: infected - 3 skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup.exe/EXE-file/stream/data0007 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup.exe Embedded EXE: infected - 3 skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup.exe UPX: infected - 3 skipped C:\Documents and Settings\Xavier\Mes documents\telechargement\SpywareSecure_trial_setup.exe PE_Patch.UPX: infected - 3 skipped C:\Documents and Settings\Xavier\ntuser.dat Object is locked skipped C:\Documents and Settings\Xavier\ntuser.dat.LOG Object is locked skipped C:\Program Files\Navilog1\reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149527.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149527.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149527.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149527.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149527.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149527.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149527.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149528.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149528.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149528.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149528.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149528.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149528.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149528.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149529.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149529.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149529.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149529.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149529.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149529.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149529.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149530.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149530.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149530.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149530.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149530.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149530.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149530.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149531.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149531.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149531.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149531.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149531.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149531.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149531.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149532.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149532.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149532.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149532.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149532.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149532.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149532.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149533.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149533.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149533.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149533.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149533.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149533.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149533.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149534.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149534.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149534.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149534.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149534.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149534.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149534.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149535.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149535.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149535.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149535.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149535.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149535.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149535.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149536.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149536.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149536.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149536.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149536.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149536.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149536.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149538.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149538.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149538.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149538.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149538.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149538.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149538.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149539.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149539.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149539.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149539.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149539.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149539.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149539.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149540.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149540.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149540.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149540.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149540.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149540.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149540.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149541.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149541.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149541.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149541.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149541.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149541.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149541.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149542.exe/EXE-file/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.bw skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149542.exe/EXE-file/stream/data0009 Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149542.exe/EXE-file/stream Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149542.exe/EXE-file Infected: not-a-virus:FraudTool.Win32.SpywareSecure.a skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149542.exe Embedded EXE: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149542.exe UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP939\A0149542.exe PE_Patch.UPX: infected - 4 skipped C:\System Volume Information\_restore{55317C12-02FA-4961-918D-6F6CCC0C5AE2}\RP994\change.log Object is locked skipped C:\WINDOWS\$NtUninstallQ328310$\winsrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ329048$\zipfldr.dll Object is locked skipped C:\WINDOWS\$NtUninstallq329112$\udfs.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ329115$\crypt32.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ329170$\srv.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ329390$\shmedia.dll Object is locked skipped C:\WINDOWS\$NtUninstallq329623$\acgenral.dll Object is locked skipped C:\WINDOWS\$NtUninstallq329623$\sysmain.sdb Object is locked skipped C:\WINDOWS\$NtUninstallQ329692$\duser.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ329834$\raspptp.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\hhctrl.ocx Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\hhsetup.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\itircl.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\itss.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\magnify.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\migwiz.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\narrator.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\osk.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\pchshell.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\shdocvw.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\shell32.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810565$\urlmon.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ810577$\mrxsmb.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ810583$\win32k.sys Object is locked skipped C:\WINDOWS\$NtUninstallQ810833$\locator.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ811493$\ntkrnlpa.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ811493$\ntoskrnl.exe Object is locked skipped C:\WINDOWS\$NtUninstallQ814033$\newdev.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ815021$\ntdll.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ817357$\shell32.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ817606$\srv.sys Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
  5. Salut j'ai tout fait, ça a l'air nickel Clean Navipromo version 3.3.6 commencé le 05/12/2007 à 16:49:10,19 Outil exécuté depuis C:\Program Files\navilog1 Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO Microsoft Windows XP [version 5.1.2600] Internet Explorer : 7.0.5730.11 Mode suppression automatique Executé en mode sans échec *** fsbl1.txt non trouvé *** (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche) *** Suppression avec sauvegardes résultats GenericNaviSearch *** * Suppression dans C:\WINDOWS\System32 * * Suppression dans C:\DOCUME~1\XAVIER\LOCALS~1\APPLIC~1 * *** Suppression dossiers dans C:\WINDOWS *** *** Suppression dossiers dans C:\Program Files *** *** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data *** *** Suppression dossiers dans C:\Documents and Settings\Xavier\Application Data *** *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 *** *** Suppression fichiers *** C:\WINDOWS\pack.epk supprimé ! *** Suppression fichiers temporaires *** Nettoyage contenu C:\WINDOWS\Temp effectué ! Nettoyage contenu C:\Documents and Settings\Xavier\Local Settings\Temp effectué ! *** Traitement Recherche complémentaire *** (Recherche fichiers spécifiques) 1)Recherche fichiers connus: 2)Recherche, création sauvegardes et suppression Heuristique : C:\WINDOWS\System32\gsywrsaul.dat trouvé ! Copie C:\WINDOWS\system32\gsywrsaul.dat réalisé avec succès ! C:\WINDOWS\system32\gsywrsaul.dat supprimé ! C:\WINDOWS\System32\gsywrsaul_nav.dat trouvé ! Copie C:\WINDOWS\system32\gsywrsaul_nav.dat réalisé avec succès ! C:\WINDOWS\system32\gsywrsaul_nav.dat supprimé ! C:\WINDOWS\System32\gsywrsaul_navps.dat trouvé ! Copie C:\WINDOWS\system32\gsywrsaul_navps.dat réalisé avec succès ! C:\WINDOWS\system32\gsywrsaul_navps.dat supprimé ! C:\WINDOWS\system32\gsywrsaul.exe trouvé ! Copie C:\WINDOWS\system32\gsywrsaul.exe réalisé avec succès ! C:\WINDOWS\system32\gsywrsaul.exe supprimé ! *** Sauvegarde du Registre vers dossier Backupnavi *** sauvegarde du Registre réalisé avec succès ! *** Nettoyage Registre *** Nettoyage Registre Ok *** Certificats *** Certificat Egroup supprimé ! *** Nettoyage terminé le 05/12/2007 à 16:50:36,76 *** --------------------------------------------------------- AVG Anti-Spyware - Rapport d'analyse --------------------------------------------------------- + Créé à: 16:46:10 05/12/2007 + Résultat de l'analyse: C:\Program Files\Fichiers communs\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Nettoyé. :mozilla.79:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Casinotropez : Nettoyé. :mozilla.24:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Com : Nettoyé. C:\Documents and Settings\Xavier\Cookies\xavier@com[1].txt -> TrackingCookie.Com : Nettoyé. :mozilla.17:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé. :mozilla.10:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Netflame : Nettoyé. :mozilla.47:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Overture : Nettoyé. :mozilla.48:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Revsci : Nettoyé. :mozilla.49:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Revsci : Nettoyé. :mozilla.50:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Revsci : Nettoyé. :mozilla.51:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Revsci : Nettoyé. :mozilla.23:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé. :mozilla.52:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé. :mozilla.53:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé. :mozilla.54:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé. :mozilla.55:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé. :mozilla.56:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé. :mozilla.57:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé. :mozilla.18:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé. :mozilla.19:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé. :mozilla.20:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé. :mozilla.21:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé. :mozilla.8:C:\Documents and Settings\Xavier\Application Data\Mozilla\Firefox\Profiles\a0najz40.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé. Fin du rapport Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:03:43, on 05/12/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\S24EvMon.exe C:\WINDOWS\system32\ZCfgSvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\1XConfig.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\WINDOWS\System32\DVDRAMSV.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\RegSrvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\TPSMain.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\WINDOWS\system32\ezSP_Px.exe C:\WINDOWS\system32\TPSBattM.exe C:\WINDOWS\system32\TFNF5.exe C:\WINDOWS\system32THotkey.exe C:\Program Files\Toshiba\Commandes TOSHIBA\TFncKy.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\OpenOffice.org 2.3\program\soffice.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN C:\WINDOWS\system32\rundll32.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://french.icrfast.com/index.php?rvs=hompag R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: GigagetIEHelper Class - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: BHO pour Compagnon Web Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: Compagnon Web Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL O4 - HKLM\..\Run: [TPSMain] TPSMain.exe O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [TFNF5] TFNF5.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32THotkey.exe O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe O4 - HKLM\..\Run: [TFncKy] C:\Program Files\Toshiba\Commandes TOSHIBA\TFncKy.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ZCfgSvc.exe] C:\WINDOWS\system32\ZCfgSvc.exe O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm O8 - Extra context menu item: Easy-WebPrint Ajouter à la Liste à Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{4F712B80-A8D1-466E-9E8B-96CB8C8933B7}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe -- End of file - 10066 bytes J'espère que j'ai rien oublié..... Merci pour tout http://forum.zebulon.fr/style_emoticons/de...con_biggrin.gif
  6. bonjour j'ai utilisé Navilog qui me fournit le rapport suivant Search Navipromo version 3.3.6 commencé le 04/12/2007 à 22:37:53,48 !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!! !!! Postez ce rapport sur le forum pour le faire analyser !!! !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!! Outil exécuté depuis C:\Program Files\navilog1 Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO Microsoft Windows XP [version 5.1.2600] Internet Explorer : 7.0.5730.11 *** Recherche Programmes installés *** *** Recherche dossiers dans C:\WINDOWS *** *** Recherche dossiers dans C:\Program Files *** *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data *** *** Recherche dossiers dans C:\Documents and Settings\Xavier\Application Data *** *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 *** *** Recherche avec Catchme-rootkit/stealth malware detector par gmer *** pour + d'infos : http://www.gmer.net Aucun fichier trouvé dans : - C:\WINDOWS\system32 - C:\DOCUME~1\XAVIER\LOCALS~1\APPLIC~1 *** Recherche avec GenericNaviSearch *** !!! Tous ces résultats peuvent révéler des fichiers légitimes !!! !!! A vérifier impérativement avant toute suppression manuelle !!! * Recherche dans C:\WINDOWS\system32 * * Recherche dans C:\DOCUME~1\XAVIER\LOCALS~1\APPLIC~1 * *** Recherche fichiers *** C:\WINDOWS\pack.epk trouvé ! *** Recherche clés spécifiques dans le Registre *** HKEY_CURRENT_USER\Software\Lanconfig trouvé ! *** Module de Recherche complémentaire *** (Recherche fichiers spécifiques) 1)Recherche fichiers connus: 2)Recherche Heuristique : C:\WINDOWS\system32\gsywrsaul.dat trouvé ! 3)Recherche Certificats : Certificat Egroup trouvé ! *** Analyse terminée le 04/12/2007 à 22:38:44,98 ***
  7. Bonjour; Je crois avoir fait tout ce qui était demandé :j'ai toujours mes indésirables qui m'agressent..... Antivir me signale à chaque demarrage que mon abonnement est terminé depuis juin 2006......... Je vous poste les deux rapports: Username "Xavier" - 03/12/2007 9:29:42 [Fixwareout edited 9/01/2007] ~~~~~ Prerun check HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{8BD86B84-C008-4D59-BF03-43CD5CEBCD96} "nameserver"="85.255.116.52,85.255.112.106" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{AA6D0DA1-1559-4B41-8417-ACF5A7BFBC2D} "nameserver"="85.255.116.52,85.255.112.106" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{BFE54BF4-08F7-4933-A322-6B97ADD6FD89} "nameserver"="85.255.116.52,85.255.112.106" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{E37AF753-7CD0-4F45-AD64-F8F612D94422} "nameserver"="85.255.116.52,85.255.112.106" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{8BD86B84-C008-4D59-BF03-43CD5CEBCD96} "DhcpNameServer"="85.255.116.52,85.255.112.106" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{AA6D0DA1-1559-4B41-8417-ACF5A7BFBC2D} "DhcpNameServer"="85.255.116.52,85.255.112.106" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{E37AF753-7CD0-4F45-AD64-F8F612D94422} "DhcpNameServer"="85.255.116.52,85.255.112.106" <Value cleared. Cache de résolution DNS vidé. System was rebooted successfully. ~~~~~ Postrun check HKLM\SOFTWARE\~\Winlogon\ "System"="lsass.exe" .... .... ~~~~~ Misc files. .... ~~~~~ Checking for older varients. .... ~~~~~ Current runs (hklm hkcu "run" Keys Only) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TPSMain"="TPSMain.exe" "AdaptecDirectCD"="C:\\Program Files\\Adaptec\\Easy CD Creator 5\\DirectCD\\DirectCD.exe" "ezShieldProtector for Px"="C:\\WINDOWS\\system32\\ezSP_Px.exe" "TFNF5"="TFNF5.exe" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "nwiz"="nwiz.exe /installquiet" "00THotkey"="C:\\WINDOWS\\system32\THotkey.exe" "000StTHK"="000StTHK.exe" "TFncKy"="C:\\Program Files\\Toshiba\\Commandes TOSHIBA\\TFncKy.exe" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "ZCfgSvc.exe"="C:\\WINDOWS\\system32\\ZCfgSvc.exe" "PRONoMgr.exe"="C:\\Program Files\\Intel\\NCS\\PROSet\\PRONoMgr.exe" "UserFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,\ 6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,75,00 "Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_03\\bin\\jusched.exe\"" "avgnt"="\"C:\\Program Files\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NVIEW"="rundll32.exe nview.dll,nViewLoadHook" "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" "gsywrsaul"="c:\\windows\\system32\\gsywrsaul.exe gsywrsaul" .... Hosts file was reset, If you use a custom hosts file please replace it... ~~~~~ End report ~~~~~ et Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 09:39:28, on 03/12/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\S24EvMon.exe C:\WINDOWS\system32\ZCfgSvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\1XConfig.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\WINDOWS\System32\DVDRAMSV.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\RegSrvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\TPSMain.exe C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\WINDOWS\system32\ezSP_Px.exe C:\WINDOWS\system32\TFNF5.exe C:\WINDOWS\system32THotkey.exe C:\WINDOWS\system32\TPSBattM.exe C:\Program Files\Toshiba\Commandes TOSHIBA\TFncKy.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\OpenOffice.org 2.3\program\soffice.exe C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://french.icrfast.com/index.php?rvs=hompag R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: GigagetIEHelper Class - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: BHO pour Compagnon Web Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: Compagnon Web Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL O4 - HKLM\..\Run: [TPSMain] TPSMain.exe O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [TFNF5] TFNF5.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32THotkey.exe O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe O4 - HKLM\..\Run: [TFncKy] C:\Program Files\Toshiba\Commandes TOSHIBA\TFncKy.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ZCfgSvc.exe] C:\WINDOWS\system32\ZCfgSvc.exe O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm O8 - Extra context menu item: Easy-WebPrint Ajouter à la Liste à Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{4F712B80-A8D1-466E-9E8B-96CB8C8933B7}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O23 - Service: AntiVir Scheduler (AntiVirScheduler) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe -- End of file - 9815 bytes merci de votre aide;
  8. Merci pour l'aide j'ai obtenu ce rapport : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:17:10, on 02/12/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\S24EvMon.exe C:\WINDOWS\system32\ZCfgSvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\1XConfig.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\WINDOWS\System32\DVDRAMSV.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\RegSrvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Tablet.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\TPSMain.exe C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe C:\WINDOWS\system32\ezSP_Px.exe C:\WINDOWS\system32\TFNF5.exe C:\WINDOWS\system32THotkey.exe C:\Program Files\Toshiba\Commandes TOSHIBA\TFncKy.exe C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\Program Files\Windows Defender\MSASCui.exe C:\WINDOWS\system32\TPSBattM.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\OpenOffice.org 2.3\program\soffice.exe C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Thunderbird\thunderbird.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://french.icrfast.com/index.php?rvs=hompag R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: GigagetIEHelper Class - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: BHO pour Compagnon Web Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: Compagnon Web Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL O4 - HKLM\..\Run: [TPSMain] TPSMain.exe O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [TFNF5] TFNF5.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32THotkey.exe O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe O4 - HKLM\..\Run: [TFncKy] C:\Program Files\Toshiba\Commandes TOSHIBA\TFncKy.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ZCfgSvc.exe] C:\WINDOWS\system32\ZCfgSvc.exe O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe" O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm O8 - Extra context menu item: Easy-WebPrint Ajouter à la Liste à Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{4F712B80-A8D1-466E-9E8B-96CB8C8933B7}: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\..\{8BD86B84-C008-4D59-BF03-43CD5CEBCD96}: NameServer = 85.255.116.52,85.255.112.106 O17 - HKLM\System\CCS\Services\Tcpip\..\{AA6D0DA1-1559-4B41-8417-ACF5A7BFBC2D}: NameServer = 85.255.116.52,85.255.112.106 O17 - HKLM\System\CCS\Services\Tcpip\..\{BFE54BF4-08F7-4933-A322-6B97ADD6FD89}: NameServer = 85.255.116.52,85.255.112.106 O17 - HKLM\System\CCS\Services\Tcpip\..\{E37AF753-7CD0-4F45-AD64-F8F612D94422}: NameServer = 85.255.116.52,85.255.112.106 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 208.67.220.220,208.67.222.222 O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe -- End of file - 10545 bytes Merci encore
  9. Resolu Dans Firefox, je suis pollué par des apparitions non désirées de pages. Après un scan j'ai trouvé ce fichier : 11/28/07 15:57:08 [info]: BlackLight Engine 1.0.67 initialized 11/28/07 15:57:08 [info]: OS: 5.1 build 2600 (Service Pack 2) 11/28/07 15:57:08 [Note]: 7019 4 11/28/07 15:57:08 [Note]: 7005 0 11/28/07 15:57:20 [Note]: 7006 0 11/28/07 15:57:20 [Note]: 7011 1676 11/28/07 15:57:20 [Note]: 7026 0 11/28/07 15:57:20 [Note]: 7026 0 11/28/07 15:57:20 [Note]: 7024 3 11/28/07 15:57:20 [info]: Hidden process: C:\windows\system32\gsywrsaul.exe 11/28/07 15:57:23 [Note]: FSRAW library version 1.7.1024 11/28/07 16:02:47 [info]: Hidden file: c:\WINDOWS\system32\gsywrsaul.dat 11/28/07 16:02:47 [Note]: 10002 1 11/28/07 16:02:48 [info]: Hidden file: C:\windows\system32\gsywrsaul.exe 11/28/07 16:02:48 [Note]: 10002 1 11/28/07 16:02:48 [info]: Hidden file: c:\WINDOWS\system32\gsywrsaul_nav.dat 11/28/07 16:02:48 [Note]: 10002 1 11/28/07 16:02:48 [info]: Hidden file: c:\WINDOWS\system32\gsywrsaul_navps.dat 11/28/07 16:02:48 [Note]: 10002 1 11/28/07 16:36:14 [Note]: 7007 0 Que dois faire pour éradiquer le mal ? Merci pour une réponse.
×
×
  • Créer...