

seroncamille
Membres-
Compteur de contenus
39 -
Inscription
-
Dernière visite
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par seroncamille
-
rapport Hijackthis
seroncamille a répondu à un(e) sujet de seroncamille dans Analyses et éradication malwares
Message reçue 5/5 vais surveiller mes deux enfants. Vais également supprimer ces deux lignes. Je ne sais comment vous remercier Amicalement -
rapport Hijackthis
seroncamille a répondu à un(e) sujet de seroncamille dans Analyses et éradication malwares
Bonjour pear, IBM internet et blackice je ne les trouve pas ni dans prog files ni à partir du panneau de config,,,,,, pour le reste voici, voilà: JavaRa 1.11 Removal Log.Report follows after line.------------------------------------The JavaRa removal process was started on Sat Nov 22 11:05:52 2008 Found and removed: C:\Program Files\Java\jre1.5.0_04Could not delete: C:\Program Files\Java\jre1.5.0_06Found and removed: Software\JavaSoft\Java2D\1.5.0_04Found and removed: Software\JavaSoft\Java2D\1.5.0_06Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510004Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510006Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510004Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510006Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510004Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510006Found and removed: SOFTWARE\Classes\JavaPlugin.150_04Found and removed: SOFTWARE\Classes\JavaPlugin.150_06Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_04Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_06Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_04Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_06Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510004Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510006Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510004Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510006Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150040}Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150060}Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_04Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_06Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_04\Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_06\Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}------------------------------------Finished reporting. Logfile of random's system information tool 1.04 (written by random/random) Run by Nordine at 2008-11-22 11:10:43 Microsoft Windows XP Édition familiale Service Pack 2 System drive C: has 33 GB (28%) free of 119 GB Total RAM: 1022 MB (44% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:10:46, on 22/11/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe C:\Program Files\Eset\nod32krn.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\oodag.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\msiexec.exe C:\Documents and Settings\Nordine\Bureau\RSIT(2).exe C:\Program Files\Trend Micro\HijackThis\Nordine.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = : R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: (no name) - {06663B56-0D73-4f9f-BCC5-4AA941470AFD} - C:\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL O2 - BHO: Pando Search Assistant BHO - {06663B51-0D73-4f9f-BCC5-4AA941470AFD} - C:\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.3558\swg.dll O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" /minimized O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user') O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Tout Télécharger avec Net Transport - C:\PROGRA~1\Xi\NETTRA~1\NTAddList.html O8 - Extra context menu item: Télécharger avec Net Transport - C:\PROGRA~1\Xi\NETTRA~1\NTAddLink.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1129731383765 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1131096353671 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: BlackICE - Unknown owner - C:\Program Files\ISS\BlackICE\blackd.exe (file missing) O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTServ.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe (file missing) O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe O23 - Service: RapApp - Unknown owner - C:\Program Files\ISS\BlackICE\rapapp.exe (file missing) O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: V2i Protector - PowerQuest Corporation - C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe O24 - Desktop Component 0: (no name) - http://www.gtdesktop.com/gtripple/screen01small.jpg -- End of file - 10054 bytes ======Scheduled tasks folder====== C:\WINDOWS\tasks\AppleSoftwareUpdate.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06663B51-0D73-4f9f-BCC5-4AA941470AFD}] Pando Search Assistant BHO - C:\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL [2008-11-10 61440] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{38D3FE60-3D53-4F37-BB0E-C7A97A26A156}] CInterceptor Object - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll [2008-02-14 569344] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}] C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 853672] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - c:\program files\google\googletoolbar2.dll [2007-03-27 2436160] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.3558\swg.dll [2007-03-27 324536] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "!AVG Anti-Spyware"=C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe [2007-11-03 6731312] "nod32kui"=C:\Program Files\Eset\nod32kui.exe [2007-07-27 949376] "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-09-22 7282688] "iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576] "SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-05 15360] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware] C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe [2007-11-03 6731312] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\.nvsvc] C:\WINDOWS\system\smss.exe /w [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-10-10 39792] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater] C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe [2008-11-20 2356088] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] C:\WINDOWS\ALCMTR.EXE [2005-05-04 69632] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe [2008-03-20 217544] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt] C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe /min [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent] C:\Program Files\BitTorrent\bittorrent.exe [2008-09-27 634672] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CHotkey] C:\WINDOWS\mHotkey.exe [2004-06-03 549376] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray] C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe [2005-05-19 57344] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CMS_RSChecker] [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CmUCRRun] C:\WINDOWS\system32\CmUCReye.exe [2005-10-12 241664] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [2004-08-05 15360] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\devenv] C:\WINDOWS\system\smvss.exe /w [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Internet Download Accelerator] C:\Program Files\IDA\ida.exe -autorun [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe [2005-02-16 81920] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.EXE [2007-09-21 55824] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MedionVFD] C:\Program Files\Medion Info Display\MdionLCM.exe [2005-10-11 126976] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] C:\Program Files\MSN Messenger\MsnMsgr.Exe /background [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe [2008-06-17 1249280] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe [2007-09-07 3100672] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] C:\WINDOWS\system32\NvCpl.dll [2005-09-22 7282688] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] C:\WINDOWS\system32\NvMCTray.dll [2005-09-22 86016] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] nwiz.exe /install [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando] C:\Program Files\Pando Networks\Pando\Pando.exe [2008-06-02 6210888] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe [2008-06-18 1122816] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] C:\WINDOWS\RTHDCPL.EXE [2005-08-18 14820864] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite] C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe /startoptions [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-03-27 68856] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe] C:\Program Files\TomTom HOME 2\HOMERunner.exe [2008-09-26 206184] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vdlDeamon] C:\Program Files\Vidal\Communs\Vidal.exe [2006-08-24 980480] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] C:\Program Files\Winamp\winampa.exe [2006-11-21 35328] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [2006-11-03 204288] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BlueSoleil.lnk] C:\PROGRA~1\IVTCOR~1\BLUESO~1\BLUESO~1.EXE [2004-12-21 1044480] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk] C:\PROGRA~1\MICROS~4\Office10\OSA.EXE [2001-02-13 83360] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Outil de mise à jour Google.lnk] C:\PROGRA~1\Google\GOOGLE~1\GOOGLE~1.EXE [2007-03-27 124152] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Nordine^Menu Démarrer^Programmes^Démarrage^RocketDock.lnk] C:\WINDOWS\BRICOP~1\CRYSTA~1\ROCKET~1\ROCKET~1.EXE [2006-05-14 344064] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn] c:\program files\fichiers communs\logitech\bluetooth\LBTWlgn.dll [2007-11-15 72208] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] C:\WINDOWS\system32\WgaLogon.dll [2006-06-27 3584] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"=C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll [2007-05-30 79408] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Driver] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AVG Anti-Spyware Driver] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AVG Anti-Spyware Guard] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WdfLoadGroup] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:enabled:Assistance à distance" "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:enabled:Windows Messenger" "C:\WINDOWS\system32\fxsclnt.exe"="C:\WINDOWS\system32\fxsclnt.exe:*:enabled:Microsoft Fax Console" "C:\Program Files\AOL 9.0\WAOL.exe"="C:\Program Files\AOL 9.0\WAOL.exe:*:Disabled:AOL 9.0" "C:\Program Files\AOL 9.0\AOL.exe"="C:\Program Files\AOL 9.0\AOL.exe:*:Disabled:AOL 9.0" "C:\Program Files\Fichiers communs\AOL\ACS\AOLDIAL.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDIAL.exe:*:Disabled:AOL 9.0 (Connectivity Service Dialer)" "C:\Program Files\Fichiers communs\AOL\ACS\AOLACSD.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLACSD.exe:*:Disabled:AOL 9.0 (Connectivity Service)" "C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule" "C:\Program Files\MaxTV Online\maxtv.exe"="C:\Program Files\MaxTV Online\maxtv.exe:*:Enabled:maxtv" "C:\MAGIX\music_manager\MusicManager.exe"="C:\MAGIX\music_manager\MusicManager.exe:*:Enabled:MAGIX Music Manager 2005" "C:\Program Files\MaxTV Online\plugins\PeerCast.exe"="C:\Program Files\MaxTV Online\plugins\PeerCast.exe:*:Enabled:PeerCast" "C:\Program Files\VIDAL\Communs\HmkIp32.exe"="C:\Program Files\VIDAL\Communs\HmkIp32.exe:*:Enabled:HmkIp32" "C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe"="C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:*:Enabled:BlueSoleil" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\Program Files\adslTV\adslTV.exe"="C:\Program Files\adslTV\adslTV.exe:*:Enabled:adslTV" "C:\Program Files\uTorrent\utorrent.exe"="C:\Program Files\uTorrent\utorrent.exe:*:Enabled:µTorrent" "C:\mcoinstall.exe"="C:\mcoinstall.exe:*:Enabled:mcoinstall" "C:\Program Files\MSN Messenger\mcoinstall.exe"="C:\Program Files\MSN Messenger\mcoinstall.exe:*:Enabled:mcoinstall" "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger" "C:\Program Files\BitTorrent_DNA\dna.exe"="C:\Program Files\BitTorrent_DNA\dna.exe:*:Enabled:DNA" "C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent" "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" "C:\Program Files\IncrediMail\bin\ImApp.exe"="C:\Program Files\IncrediMail\bin\ImApp.exe:*:Enabled:IncrediMail" "C:\Program Files\IncrediMail\bin\IncMail.exe"="C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail" "C:\Program Files\IncrediMail\bin\ImpCnt.exe"="C:\Program Files\IncrediMail\bin\ImpCnt.exe:*:Enabled:IncrediMail" "C:\Documents and Settings\Nordine\Local Settings\Temp\FlashGet Portable\flashget.exe"="C:\Documents and Settings\Nordine\Local Settings\Temp\FlashGet Portable\flashget.exe:*:Enabled:Flashget" "C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe"="C:\Program Files\Nokia\Nokia Software Updater\nsu_ui_client.exe:*:Enabled:Nokia Software Updater" "C:\Program Files\Fichiers communs\Nokia\Service Layer\A\nsl_host_process.exe"="C:\Program Files\Fichiers communs\Nokia\Service Layer\A\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process " "C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Enabled:DNA" "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Program Files\Pando Networks\Pando\pando.exe"="C:\Program Files\Pando Networks\Pando\pando.exe:*:Enabled:Pando Application" "C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:enabled:Assistance à distance" "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:enabled:Windows Messenger" "C:\Program Files\AOL 9.0\AOL.exe"="C:\Program Files\AOL 9.0\AOL.exe:*:enabled:AOL 9.0" "C:\Program Files\AOL 9.0\WAOL.exe"="C:\Program Files\AOL 9.0\WAOL.exe:*:enabled:AOL 9.0" "C:\Program Files\Fichiers communs\AOL\ACS\AOLACSD.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLACSD.exe:*:enabled:AOL 9.0 (Connectivity Service)" "C:\Program Files\Fichiers communs\AOL\ACS\AOLDIAL.exe"="C:\Program Files\Fichiers communs\AOL\ACS\AOLDIAL.exe:*:enabled:AOL 9.0 (Connectivity Service Dialer)" "C:\WINDOWS\system32\fxsclnt.exe"="C:\WINDOWS\system32\fxsclnt.exe:*:enabled:Microsoft Fax Console" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger" "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1d24b8da-9c3d-11dc-9f79-0012bf528247}] shell\AutoRun\command - H:\InstallTomTomHOME.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79d3b904-e158-11dc-9fd5-0012bf528247}] shell\AutoRun\command - H:\InstallTomTomHOME.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{884cb014-ebdf-11da-9d1e-0012bf528247}] shell\AutoRun\command - J:\setupSNK.exe ======List of files/folders created in the last 1 months====== 2008-11-22 11:05:01 ----A---- C:\WINDOWS\system32\javaws.exe 2008-11-22 11:05:01 ----A---- C:\WINDOWS\system32\javaw.exe 2008-11-22 11:05:01 ----A---- C:\WINDOWS\system32\java.exe 2008-11-21 18:11:57 ----D---- C:\rsit 2008-11-21 17:46:11 ----D---- C:\_OTMoveIt 2008-11-21 17:22:18 ----D---- C:\Program Files\Trend Micro 2008-11-21 17:14:38 ----A---- C:\TB.txt 2008-11-21 17:07:18 ----D---- C:\ToolBar SD 2008-11-21 12:17:25 ----D---- C:\Program Files\iPod 2008-11-21 12:17:23 ----D---- C:\Program Files\iTunes 2008-11-21 12:17:23 ----D---- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2008-11-20 12:57:51 ----A---- C:\WINDOWS\system32\msvcr80.dll 2008-11-20 12:57:50 ----A---- C:\WINDOWS\system32\msvcp80.dll 2008-11-20 12:57:49 ----A---- C:\WINDOWS\system32\eEmpty.exe 2008-11-20 12:57:44 ----A---- C:\WINDOWS\system32\TASKMGR.COM 2008-11-20 12:57:44 ----A---- C:\WINDOWS\system32\T.COM 2008-11-20 12:57:44 ----A---- C:\WINDOWS\R.COM 2008-11-20 12:57:43 ----A---- C:\WINDOWS\REGEDIT.COM 2008-11-20 12:57:29 ----D---- C:\Documents and Settings\All Users\Application Data\MicroWorld 2008-11-20 12:14:53 ----D---- C:\Bases 2008-11-20 12:13:15 ----D---- C:\Kaspersky 2008-11-19 14:59:46 ----D---- C:\WINDOWS\system32\Kaspersky Lab 2008-11-18 12:46:27 ----D---- C:\Documents and Settings\Nordine\Application Data\Malwarebytes 2008-11-18 12:46:07 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-11-18 12:46:03 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2008-11-18 11:50:30 ----D---- C:\Documents and Settings\Nordine\Application Data\WinRAR 2008-11-18 11:17:42 ----D---- C:\WINDOWS\ERUNT 2008-11-18 11:07:23 ----D---- C:\SDFix 2008-11-17 15:32:06 ----A---- C:\WINDOWS\ntbtlog.txt 2008-11-17 12:35:51 ----D---- C:\Program Files\TeaTimer (Spybot - Search & Destroy) 2008-11-17 12:35:51 ----D---- C:\Program Files\SDHelper (Spybot - Search & Destroy) 2008-11-17 12:35:51 ----D---- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy) 2008-11-17 12:35:50 ----D---- C:\Program Files\File Scanner Library (Spybot - Search & Destroy) 2008-11-16 19:12:28 ----A---- C:\WINDOWS\system32\wpa.bak 2008-11-16 19:06:29 ----D---- C:\WINDOWS\Prefetch 2008-11-16 18:57:11 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest 2008-11-16 18:57:00 ----HD---- C:\Program Files\WindowsUpdate 2008-11-16 18:40:10 ----A---- C:\WINDOWS\pnplog.txt 2008-11-16 18:35:06 ----A---- C:\WINDOWS\system32\spxcoins.dll 2008-11-16 18:35:06 ----A---- C:\WINDOWS\system32\irclass.dll 2008-11-16 18:34:54 ----RA---- C:\WINDOWS\SET1A3.tmp 2008-11-16 18:34:52 ----RA---- C:\WINDOWS\SET197.tmp 2008-11-16 18:34:50 ----RA---- C:\WINDOWS\SET194.tmp 2008-11-15 22:34:58 ----RD---- C:\~001 2008-11-15 17:50:31 ----A---- C:\WINDOWS\system32\Drive Image 7.0.log.txt 2008-11-14 14:11:42 ----D---- C:\Program Files\AVSMedia 2008-11-13 17:57:29 ----D---- C:\SAMY YOUSSEF 2008-11-13 13:23:02 ----D---- C:\Downloads 2008-11-13 13:22:57 ----D---- C:\Documents and Settings\Nordine\Application Data\Internet Download Accelerator 2008-11-13 13:22:44 ----D---- C:\Program Files\IDA 2008-11-12 15:37:26 ----D---- C:\Program Files\ImgBurn 2008-11-11 20:38:46 ----D---- C:\Program Files\IsoBuster 2008-11-11 13:00:40 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-11-10 14:54:48 ----D---- C:\Program Files\PandoBar 2008-11-10 14:54:21 ----D---- C:\Program Files\Pando Networks 2008-11-08 20:22:02 ----D---- C:\Program Files\DAEMON Tools Lite 2008-11-08 20:17:16 ----D---- C:\Documents and Settings\Nordine\Application Data\DAEMON Tools 2008-11-05 10:37:31 ----D---- C:\WINDOWS\system32\fr 2008-11-05 10:37:31 ----D---- C:\WINDOWS\l2schemas 2008-11-05 10:37:30 ----D---- C:\WINDOWS\system32\bits 2008-11-05 10:34:25 ----D---- C:\WINDOWS\ServicePackFiles 2008-11-05 10:27:02 ----D---- C:\WINDOWS\EHome 2008-11-04 18:38:04 ----D---- C:\Program Files\Microsoft Silverlight 2008-11-04 18:37:24 ----D---- C:\Program Files\Microsoft.NET 2008-11-04 18:36:12 ----D---- C:\a53ff022083ba783e3f2a53c520b 2008-11-04 18:04:30 ----D---- C:\Program Files\Microsoft Synchronization Services 2008-11-04 18:04:29 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition 2008-11-04 18:00:44 ----D---- C:\Program Files\Microsoft Visual Studio 9.0 2008-11-04 18:00:44 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help 2008-11-04 18:00:13 ----D---- C:\Program Files\Microsoft SDKs 2008-11-04 16:43:31 ----HDC---- C:\WINDOWS\$NtUninstallXPSEPSCLP$ 2008-10-31 18:38:58 ----D---- C:\Program Files\Bonjour 2008-10-31 18:38:09 ----D---- C:\Program Files\QuickTime 2008-10-31 18:36:23 ----D---- C:\Program Files\Apple Software Update 2008-10-29 16:04:06 ----D---- C:\Documents and Settings\Nordine\Application Data\Dynamique 2008-10-29 16:04:05 ----D---- C:\Documents and Settings\Nordine\Application Data\Sites 2008-10-29 16:04:05 ----D---- C:\Documents and Settings\Nordine\Application Data\Classes de site 2008-10-29 16:03:34 ----D---- C:\Program Files\Visicom Media 2008-10-28 18:11:33 ----D---- C:\Program Files\MP3Gain 2008-10-25 00:02:25 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$ 2008-10-24 18:54:50 ----A---- C:\WINDOWS\oodcnt.INI 2008-10-24 18:50:08 ----D---- C:\WINDOWS\system32\oodag 2008-10-24 18:45:52 ----D---- C:\Program Files\OO Software ======List of files/folders modified in the last 1 months====== 2008-11-22 11:10:20 ----D---- C:\WINDOWS\Temp 2008-11-22 11:05:54 ----D---- C:\Program Files\Java 2008-11-22 11:05:21 ----SHD---- C:\WINDOWS\Installer 2008-11-22 11:05:15 ----D---- C:\Config.Msi 2008-11-22 11:05:01 ----D---- C:\WINDOWS\system32 2008-11-22 10:54:55 ----D---- C:\Program Files\Mozilla Firefox 2008-11-22 10:31:08 ----A---- C:\WINDOWS\ModemLog_Modem standard.txt 2008-11-22 10:31:08 ----A---- C:\WINDOWS\ModemLog_Bluetooth DUN Modem.txt 2008-11-22 10:31:02 ----A---- C:\WINDOWS\ModemLog_Creatix V.92 Data Fax Modem.txt 2008-11-22 00:31:06 ----A---- C:\WINDOWS\SchedLgU.Txt 2008-11-21 21:25:04 ----SHD---- C:\System Volume Information 2008-11-21 21:25:04 ----D---- C:\WINDOWS\system32\Restore 2008-11-21 18:05:05 ----A---- C:\WINDOWS\NeroDigital.ini 2008-11-21 17:46:13 ----D---- C:\Program Files\ESET 2008-11-21 17:22:18 ----SD---- C:\Program Files 2008-11-21 17:21:57 ----D---- C:\Program Files\Logitech 2008-11-21 11:08:58 ----D---- C:\WINDOWS\system32\CatRoot2 2008-11-20 12:57:44 ----D---- C:\WINDOWS 2008-11-19 22:53:27 ----SH---- C:\boot.ini 2008-11-19 22:53:27 ----A---- C:\WINDOWS\win.ini 2008-11-19 22:53:27 ----A---- C:\WINDOWS\system.ini 2008-11-19 14:59:47 ----SD---- C:\WINDOWS\Downloaded Program Files 2008-11-19 14:59:45 ----HD---- C:\WINDOWS\inf 2008-11-18 18:45:22 ----D---- C:\WINDOWS\system32\drivers 2008-11-17 19:55:56 ----D---- C:\Program Files\PFConfig 2008-11-17 16:27:55 ----D---- C:\WINDOWS\system 2008-11-17 16:16:15 ----D---- C:\WINDOWS\security 2008-11-17 09:49:08 ----D---- C:\WINDOWS\system32\Lang 2008-11-16 19:26:48 ----D---- C:\WINDOWS\system32\Setup 2008-11-16 19:26:40 ----D---- C:\WINDOWS\system32\usmt 2008-11-16 19:26:32 ----D---- C:\WINDOWS\AppPatch 2008-11-16 19:26:30 ----D---- C:\WINDOWS\ime 2008-11-16 19:26:29 ----RSD---- C:\WINDOWS\Fonts 2008-11-16 19:26:28 ----D---- C:\WINDOWS\Media 2008-11-16 19:26:16 ----D---- C:\WINDOWS\PeerNet 2008-11-16 19:26:01 ----D---- C:\WINDOWS\system32\npp 2008-11-16 19:25:54 ----D---- C:\WINDOWS\msagent 2008-11-16 19:23:10 ----D---- C:\WINDOWS\system32\1036 2008-11-16 19:22:41 ----D---- C:\WINDOWS\twain_32 2008-11-16 19:21:52 ----D---- C:\WINDOWS\system32\icsxml 2008-11-16 19:21:14 ----D---- C:\WINDOWS\system32\1033 2008-11-16 19:20:06 ----D---- C:\WINDOWS\WinSxS 2008-11-16 19:20:06 ----D---- C:\WINDOWS\Driver Cache 2008-11-16 19:16:43 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2008-11-16 19:12:32 ----A---- C:\WINDOWS\setuplog.txt 2008-11-16 19:09:47 ----D---- C:\WINDOWS\Registration 2008-11-16 19:05:42 ----D---- C:\WINDOWS\system32\config 2008-11-16 19:05:41 ----D---- C:\WINDOWS\nview 2008-11-16 19:05:41 ----D---- C:\WINDOWS\Help 2008-11-16 19:01:36 ----RSHDC---- C:\WINDOWS\system32\dllcache 2008-11-16 18:58:33 ----D---- C:\Program Files\Windows Media Player 2008-11-16 18:58:05 ----A---- C:\WINDOWS\OEWABLog.txt 2008-11-16 18:58:00 ----A---- C:\WINDOWS\ODBCINST.INI 2008-11-16 18:57:39 ----D---- C:\WINDOWS\system32\ias 2008-11-16 18:57:13 ----SD---- C:\WINDOWS\Web 2008-11-16 18:57:11 ----SD---- C:\WINDOWS\occache 2008-11-16 18:57:05 ----RAHC---- C:\WINDOWS\system32\cdplayer.exe.manifest 2008-11-16 18:56:50 ----D---- C:\WINDOWS\system32\oobe 2008-11-16 18:56:48 ----D---- C:\WINDOWS\srchasst 2008-11-16 18:56:44 ----D---- C:\Program Files\Movie Maker 2008-11-16 18:56:37 ----D---- C:\Program Files\NetMeeting 2008-11-16 18:56:35 ----D---- C:\Program Files\Outlook Express 2008-11-16 18:56:35 ----D---- C:\Program Files\Fichiers communs\System 2008-11-16 18:56:27 ----D---- C:\Program Files\Internet Explorer 2008-11-16 18:56:15 ----D---- C:\WINDOWS\system32\Com 2008-11-16 18:55:10 ----D---- C:\Program Files\Windows NT 2008-11-16 18:55:04 ----D---- C:\WINDOWS\system32\wbem 2008-11-16 18:41:02 ----D---- C:\WINDOWS\system32\ReinstallBackups 2008-11-16 18:36:21 ----D---- C:\WINDOWS\system32\CatRoot 2008-11-16 18:35:00 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini 2008-11-15 21:10:32 ----D---- C:\Program Files\X10 Hardware 2008-11-15 20:58:00 ----SHD---- C:\RECYCLER 2008-11-15 17:24:02 ----D---- C:\Documents and Settings\Nordine\Application Data\BitTorrent 2008-11-15 17:21:04 ----D---- C:\Program Files\eMule 2008-11-15 12:23:18 ----A---- C:\WINDOWS\ModemLog_Bluetooth Fax Modem.txt 2008-11-13 08:01:32 ----A---- C:\WINDOWS\imsins.BAK 2008-11-13 08:01:26 ----HD---- C:\WINDOWS\$hf_mig$ 2008-11-12 15:40:58 ----D---- C:\Documents and Settings\Nordine\Application Data\DNA 2008-11-12 11:44:30 ----D---- C:\Program Files\DNA 2008-11-11 13:00:41 ----D---- C:\Program Files\Lavasoft 2008-11-11 13:00:14 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard 2008-11-05 10:41:22 ----D---- C:\Program Files\Messenger 2008-11-05 10:37:48 ----D---- C:\WINDOWS\network diagnostic 2008-11-05 10:37:33 ----D---- C:\WINDOWS\system32\fr-fr 2008-11-04 19:09:33 ----RSD---- C:\WINDOWS\assembly 2008-11-04 19:09:33 ----D---- C:\WINDOWS\Microsoft.NET 2008-11-04 18:37:24 ----D---- C:\Program Files\Fichiers communs\Microsoft Shared 2008-11-04 18:36:24 ----D---- C:\WINDOWS\system32\XPSViewer 2008-11-04 18:35:44 ----HD---- C:\Program Files\InstallShield Installation Information 2008-11-04 18:35:42 ----D---- C:\crack 2008-11-04 18:35:39 ----D---- C:\Program Files\TomTom HOME 2 2008-11-04 18:35:38 ----D---- C:\Documents and Settings\All Users\Application Data\TomTom 2008-11-04 18:35:15 ----DC---- C:\WINDOWS\system32\DRVSTORE 2008-11-04 18:04:34 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft 2008-11-04 18:03:15 ----SD---- C:\Documents and Settings\Nordine\Application Data\Microsoft 2008-11-04 16:45:36 ----D---- C:\WINDOWS\SxsCaPendDel 2008-11-04 16:40:06 ----D---- C:\WINDOWS\system32\en-us 2008-11-04 01:10:25 ----A---- C:\WINDOWS\system32\MRT.exe 2008-10-31 18:38:13 ----D---- C:\Program Files\Fichiers communs\Apple 2008-10-31 18:36:25 ----SD---- C:\WINDOWS\Tasks 2008-10-24 22:20:20 ----D---- C:\WINDOWS\Debug ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 AVG Anti-Spyware Driver;AVG Anti-Spyware Driver; \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys [] R1 AvgAsCln;AVG Anti-Spyware Clean Driver; C:\WINDOWS\System32\DRIVERS\AvgAsCln.sys [2007-05-30 10872] R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-05 40320] R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-05 14848] R1 nod32drv;nod32drv; C:\WINDOWS\system32\drivers\nod32drv.sys [2007-07-27 15424] R1 PQIMount;PQIMount; C:\WINDOWS\system32\drivers\PQIMount.sys [2003-06-03 46900] R1 StarOpen;StarOpen; C:\WINDOWS\system32\drivers\StarOpen.sys [2007-04-27 5632] R1 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-05 12032] R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.0.1; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2005-10-19 19915] R2 AMON;AMON; C:\WINDOWS\system32\drivers\amon.sys [2007-07-27 512096] R2 DLPortIO;DriverLINX Port I/O Driver; \??\C:\WINDOWS\system32\DRIVERS\DLPortIO.SYS [] R2 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2005-04-21 10624] R2 LBeepKE;LBeepKE; C:\WINDOWS\System32\Drivers\LBeepKE.sys [2006-06-29 3712] R3 3xHybrid;3xHybrid service; C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-10-17 826112] R3 AgereSoftModem;Creatix V.92 Data Fax Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2005-06-30 1094848] R3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-05 60800] R3 BT;Bluetooth PAN Network Adapter; C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [2004-09-21 10804] R3 BTHidEnum;Bluetooth HID Enumerator; C:\WINDOWS\system32\DRIVERS\vbtenum.sys [2004-09-21 11604] R3 CMISTOR;CMIUCR.SYS CM220 Card Reader Driver; C:\WINDOWS\system32\DRIVERS\cmiucr.SYS [2005-10-04 72320] R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2005-05-03 27392] R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464] R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384] R3 HidUsb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-05 9600] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2005-08-18 3856896] R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys [2007-09-21 35088] R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys [2007-09-21 36240] R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-05 12288] R3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-05 61824] R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-09-22 3524640] R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-05 5888] R3 RT2500USB;RT2500 USB Wireless LAN Driver; C:\WINDOWS\system32\DRIVERS\rt2500usb.sys [2005-07-14 241536] R3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992] R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-05 31616] R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-05 26624] R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-05 57600] R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-05 20480] R3 VComm;Virtual Serial port driver; C:\WINDOWS\system32\DRIVERS\VComm.sys [2004-10-19 61312] R3 VcommMgr;Bluetooth VComm Manager Service; C:\WINDOWS\System32\Drivers\VcommMgr.sys [2004-11-05 82148] R3 Wdf01000;Wdf01000; C:\WINDOWS\system32\DRIVERS\Wdf01000.sys [2006-11-02 492000] R3 XUIF;X10 USB Wireless Transceiver; C:\WINDOWS\System32\Drivers\x10ufx2.sys [2004-01-16 17408] S2 giveio;IC-Prog Driver; \??\C:\Documents and Settings\Nordine\Bureau\philips\OSLINK_15C\oslink.sys [] S2 MobiCap;fix8 Virtual Webcam, WDM Video Capture; C:\WINDOWS\system32\DRIVERS\MobiCap.sys [2007-04-02 217600] S3 BlueletAudio;Bluetooth Audio Service; C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [2004-10-19 20096] S3 Btcsrusb;Bluetooth USB For Bluetooth Service; C:\WINDOWS\System32\Drivers\btcusb.sys [2004-12-01 22488] S3 catchme;catchme; \??\C:\DOCUME~1\Nordine\LOCALS~1\Temp\catchme.sys [] S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024] S3 HWIONT;HWIONT; \??\C:\Documents and Settings\Nordine\Bureau\C+\MoreTV 3.53 + Wilma 2.10 + key.txt [Catala] per Cepheus(2)\MoreTV 3.53\HWIONT.sys [] S3 LHidKe;Logitech SetPoint HID Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LHidKE.Sys [2006-05-10 27264] S3 LHidUsbK;Logitech SetPoint USB Receiver device driver; C:\WINDOWS\System32\Drivers\LHidUsbK.Sys [2006-05-10 36736] S3 LMouKE;Logitech SetPoint Mouse Filter Driver; C:\WINDOWS\system32\DRIVERS\LMouKE.Sys [2006-05-10 71680] S3 MPE;Filtre BDA MPE; C:\WINDOWS\system32\DRIVERS\MPE.sys [2004-08-05 15360] S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504] S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376] S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-05 10880] S3 nmwcd;Nokia USB Phone Parent; C:\WINDOWS\system32\drivers\ccdcmb.sys [2008-05-07 17536] S3 nmwcdc;Nokia USB Generic; C:\WINDOWS\system32\drivers\ccdcmbo.sys [2008-05-07 20864] S3 nmwcdnsu;Nokia USB Flashing Phone Parent; C:\WINDOWS\system32\drivers\nmwcdnsu.sys [2008-02-01 138112] S3 nmwcdnsuc;Nokia USB Flashing Generic; C:\WINDOWS\system32\drivers\nmwcdnsuc.sys [2008-02-01 8320] S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632] S3 RapDrv;RapDrv; \??\C:\WINDOWS\system32\drivers\RapDrv.sys [] S3 RapFile;RapFile; \??\C:\WINDOWS\system32\drivers\RapFile.sys [] S3 RapNet;RapNet; \??\C:\WINDOWS\system32\drivers\RapNet.sys [] S3 SE27bus;Sony Ericsson Device 039 Driver driver (WDM); C:\WINDOWS\system32\DRIVERS\SE27bus.sys [2006-09-18 61600] S3 SE27mdfl;Sony Ericsson Device 039 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\SE27mdfl.sys [2006-09-18 9360] S3 SE27mdm;Sony Ericsson Device 039 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\SE27mdm.sys [2006-09-18 97184] S3 SE27mgmt;Sony Ericsson Device 039 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\SE27mgmt.sys [2006-09-18 88688] S3 se27nd5;Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (NDIS); C:\WINDOWS\system32\DRIVERS\se27nd5.sys [2006-09-18 18704] S3 SE27obex;Sony Ericsson Device 039 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\SE27obex.sys [2006-09-18 86560] S3 se27unic;Sony Ericsson Device 039 USB Ethernet Emulation SEMC39 (WDM); C:\WINDOWS\system32\DRIVERS\se27unic.sys [2006-09-18 90800] S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-05 11136] S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 58320] S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 8304] S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 94000] S3 ssm_bus;SAMSUNG Mobile USB Device II 1.0 driver (WDM); C:\WINDOWS\system32\DRIVERS\ssm_bus.sys [2005-08-30 58320] S3 ssm_mdfl;SAMSUNG Mobile USB Modem II 1.0 Filter; C:\WINDOWS\system32\DRIVERS\ssm_mdfl.sys [2005-08-30 8336] S3 ssm_mdm;SAMSUNG Mobile USB Modem II 1.0 Drivers; C:\WINDOWS\system32\DRIVERS\ssm_mdm.sys [2005-08-30 94000] S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-05 15360] S3 upperdev;upperdev; C:\WINDOWS\system32\DRIVERS\usbser_lowerflt.sys [2008-06-06 8064] S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856] S3 usbser;USB Modem Driver; C:\WINDOWS\system32\drivers\usbser.sys [2004-08-05 25600] S3 UsbserFilt;UsbserFilt; C:\WINDOWS\system32\DRIVERS\usbser_lowerfltj.sys [2008-05-07 8064] S3 usbsermpt;Motorola USB Modem Driver for MPT; C:\WINDOWS\system32\DRIVERS\usbsermpt.sys [2006-11-01 22768] S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-05 26496] S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [] S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2005-01-28 18944] S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328] S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-15 82688] S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-11-11 611664] R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040] R2 AVG Anti-Spyware Guard;AVG Anti-Spyware Guard; C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe [2007-05-30 312880] R2 BlueSoleil Hid Service;BlueSoleil Hid Service; C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe [2004-12-13 106496] R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888] R2 CLCapSvc;CyberLink Background Capture Service (CBCS); C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe [2005-11-01 258146] R2 CLSched;CyberLink Task Scheduler (CTS); C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe [2005-11-01 114784] R2 CyberLink Media Library Service;CyberLink Media Library Service; C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe [2005-11-01 1073152] R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe [2005-07-24 53248] R2 NOD32krn;NOD32 Kernel Service; C:\Program Files\Eset\nod32krn.exe [2007-07-27 552064] R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-09-22 131139] R2 O&O Defrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2007-06-28 1049856] R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2005-10-28 167936] R2 StarWindServiceAE;StarWind AE Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2007-05-28 275968] R2 V2i Protector;V2i Protector; C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe [2003-06-03 1200128] R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-05 14336] R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2008-10-01 536872] S2 BlackICE;BlackICE; C:\Program Files\ISS\BlackICE\blackd.exe [] S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-05 268800] S2 GEARSecurity;GEARSecurity; C:\WINDOWS\System32\GEARSec.exe [2002-11-25 49152] S2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-03-27 136952] S2 RapApp;RapApp; C:\Program Files\ISS\BlackICE\rapapp.exe [] S2 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016] S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632] S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728] S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664] S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTServ.exe [2007-11-15 121360] S3 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe [] S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-05-30 572416] S3 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912] S3 x10nets;X10 Device Network Service; C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe [2001-11-12 20480] S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096] -----------------EOF----------------- -
rapport Hijackthis
seroncamille a répondu à un(e) sujet de seroncamille dans Analyses et éradication malwares
Rebonsoir, pour compréhension, les deux rapports que j'ai collées ont été effectués avant le fix des lignes 18. Aprés ce que vous m'avez conseillé de faire, j'ai fixé toutes les lignes en question sans vous en avoir transmis le rapport dont ci-dessous. J'espère que c'est bien de cela dont il est question. Amicalement. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:23:49, on 22/11/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe C:\Program Files\Eset\nod32krn.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\oodag.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = : R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: (no name) - {06663B56-0D73-4f9f-BCC5-4AA941470AFD} - C:\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL O2 - BHO: Pando Search Assistant BHO - {06663B51-0D73-4f9f-BCC5-4AA941470AFD} - C:\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.3558\swg.dll O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" /minimized O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user') O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Tout Télécharger avec Net Transport - C:\PROGRA~1\Xi\NETTRA~1\NTAddList.html O8 - Extra context menu item: Télécharger avec Net Transport - C:\PROGRA~1\Xi\NETTRA~1\NTAddLink.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1129731383765 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1131096353671 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: BlackICE - Unknown owner - C:\Program Files\ISS\BlackICE\blackd.exe (file missing) O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTServ.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe (file missing) O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe O23 - Service: RapApp - Unknown owner - C:\Program Files\ISS\BlackICE\rapapp.exe (file missing) O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: V2i Protector - PowerQuest Corporation - C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe O24 - Desktop Component 0: (no name) - http://www.gtdesktop.com/gtripple/screen01small.jpg -- End of file - 9878 bytes -
rapport Hijackthis
seroncamille a répondu à un(e) sujet de seroncamille dans Analyses et éradication malwares
Oups désolé je reviens de chez le médecin. J'ai du faire une groose co*****e. info.txt logfile of random's system information tool 1.04 2008-11-21 18:12:12 ======Uninstall list====== -->C:\Program Files\DivX\DivXConverterUninstall .exe /CONVERTER -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst. exe RealNetworks|RealPlayer|6.0 -->C:\WINDOWS\IsUn040c.exe - fC:\WINDOWS\orun32.isu -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf µTorrent-->"C:\Program Files\uTorrent\uninstall.exe" AC3Filter (remove only)-- >C:\Program Files\AC3Filter\uninstall.exe Ad-aware 6 Professional-- >C:\PROGRA~1\Lavasoft\AD-AWA~1 \UNWISE.EXE C:\PROGRA~1 \Lavasoft\AD-AWA~1\INSTALL.LOG Ad-Aware-->MsiExec.exe /I {DED53B0B-B67C-4244-AE6A- D6FD3C28D1EF} Adobe Acrobat 5.0-- >C:\WINDOWS\ISUN040C.EXE - f"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0 \NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0 \NT\Uninst.dll" Adobe Flash Player ActiveX-- >C:\WINDOWS\system32 \Macromed\Flash\uninstall_activeX .exe Adobe Flash Player Plugin-- >C:\WINDOWS\system32 \Macromed\Flash\uninstall_plugin. exe Adobe Reader 8.1.1 - Français-- >MsiExec.exe /I{AC76BA86-7AD7- 1036-7B44-A81000000003} Adobe® Photoshop® Album Edition Découverte 3.0-->MsiExec.exe /I {4BDFD2CE-6329-42E4-9801- 9B3D1F10D79B} AIDA32 v3.93-->"C:\Program Files\AIDA32 - Enterprise System Information\unins000.exe" Apple Mobile Device Support-- >MsiExec.exe /I{976C2B2A-CE59- 4AB3-83FB-BF895E28F2E6} Apple Software Update-- >MsiExec.exe /I{6956856F-B6B3- 4BE0-BA0B-8F495BE32033} Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe Ask Toolbar-->rundll32 C:\PROGRA~1 \AskTBar\bar\1.bin\AskTBar.dll,O AVG Anti-Spyware 7.5-->C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe AVS Video Converter 3.4.3.183-- >"C:\Program Files\AVSMedia\VideoConverter3 \unins000.exe" BlueSoleil-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1 \engine\6\INTEL3~1 \Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B9F499B8-D1F0-42FC- 84BE-CC552123CCCB}\Setup.exe" - l0x40c Bonjour-->MsiExec.exe /I {8A25392D-C5D2-4E79-A2BD- C15DDC5B0959} CDDRV_Installer-->MsiExec.exe /I {0C826C5B-B131-423A-A229- C71B3CACCD6A} CloneCD-->"C:\Program Files\SlySoft\CloneCD\ccd- uninst.exe" /D="C:\Program Files\SlySoft\CloneCD" C-Media Card Reader Driver USB2.0-->C:\WINDOWS\system32 \CmUCRRm.exe C-Media USB2.0 Card Reader-- >C:\WINDOWS\CmiUCRUninstall.exe C:\Program Files\C-Media USB2.0 Card Reader Complément Microsoft Word pour Microsoft Works Suite-- >MsiExec.exe /I{D9DAF1AF-D9B7- 4397-A3B6-AFA27D329DAB} Composant Hmk-- >C:\WINDOWS\IsUn040c.exe - f"C:\Program Files\Vidal\Communs\Hmk.isu" Creatix V.92 Data Fax Modem-- >agrsmdel Crux Calculator v5-->"C:\Program Files\Crux Calculator v5 \uninst.exe" dBpowerAMP WMA V9.1 Codec-- >"C:\WINDOWS\system32 \SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32 \SpoonUninstall-dBpowerAMP WMA V9.1 Codec.dat DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC DivX Content Uploader-- >C:\Program Files\DivX\DivXContentUploaderUni nstall.exe /CUPLOADER DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall .exe /CONVERTER DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.ex e /PLAYER DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall .exe /PLUGIN EMUKreator-->C:\Program Files\EMUKreator\Uninstal.exe eMule-->"C:\Program Files\eMule\Uninstall.exe" Extension HighMAT pour l'Assistant Graver un CD de Microsoft Windows XP-- >MsiExec.exe /X{FCE65C4E-B0E8- 4FBD-AD16-EDCBE6CD591F} FlashCvt-->MsiExec.exe /X {849A0004-14D7-4045-AB30- 39662A07FD2E} FTP Expert 3-->"C:\Program Files\Visicom Media\FTP Expert 3 \uninst-ftp.exe" Garmin City Navigator Europe NT v9-->MsiExec.exe /X{200B415D- 7CC6-4818-8624-9E43EDF19D9C} GBA Media Version 1.3-- >C:\PROGRA~1\GBAMED~1\UNWISE.EXE C:\PROGRA~1\GBAMED~1\INSTALL.LOG Google Toolbar for Internet Explorer-->MsiExec.exe /I {DBEA1034-5882-4A88-8033- 81C4EF0CFA29} Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar2.dll" GSpot 2.21 Fr-->"C:\Program Files\GSpot221\unins000.exe" GT Ripple-->"C:\Program Files\GTDesktop\unins000.exe" HijackThis 2.0.2-->"C:\Documents and Settings\Nordine\Bureau\HiJackThi s\HijackThis.exe" /uninstall Home Media Server 4.1.4.0067-- >C:\Program Files\SimpleCenter\uninstall.exe Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-- >C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA- 84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT="" iCF Skin Pack-- >C:\WINDOWS\BricoPacks\Crystal Clear\iColorFolder\Uninstall Skin Pack.exe iColorFolder-- >C:\WINDOWS\BricoPacks\Crystal Clear\iColorFolder\uninstall.exe ImgBurn 2.3.2.0 Fr-->"C:\Program Files\ImgBurn\unins000.exe" Information sur votre PC-- >MsiExec.exe /I{36D6F663-DF15- 45BD-B0C6-4B909308E3B6} iTunes-->MsiExec.exe /I{DDDE0BE3 -0CBE-4BF6-B75A-E3F69C947843} J2SE Runtime Environment 5.0 Update 4-->MsiExec.exe /I {3248F0A8-6813-11D6-A77B- 00B0D0150040} J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I {3248F0A8-6813-11D6-A77B- 00B0D0150060} jetAudio-->RunDll32 C:\PROGRA~1 \FICHIE~1\INSTAL~1\PROFES~1 \RunTime\0701\Intel32 \Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DF8195AF-8E6F-4487- A0EE-196F7E3F4B8A}\Setup.exe" - l0x9 Kaspersky Online Scanner-- >C:\WINDOWS\system32\KASPER~1 \KASPER~1\kavuninstall.exe KhalInstallWrapper-->MsiExec.exe /I{3101CB58-3482-4D21-AF1A- 7057FC935355} Kit Runtime VB6.0-- >C:\WINDOWS\st6unst.exe -n "C:\WINDOWS\system32\ST6UNST.LOG" Konvertor-->c:\Program Files\Konvertor\uninst.exe Language Pack for Ad-aware 6-- >C:\PROGRA~1\Lavasoft\AD-AWA~1 \Lang\LANGUA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1 \Lang\LANGUA~1\INSTALL.LOG Learn2 Player (Uninstall Only)-- >C:\Program Files\Learn2.com\StRunner\stunins t.exe Lecteur Windows Media 10-- >"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall Logitech Desktop Messenger-- >RunDll32 C:\PROGRA~1\FICHIE~1 \INSTAL~1\PROFES~1\RunTime\10\00 \Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46- A882-2CFFFE2EEDCB}\SETUP.exe" - l0x40c UNINSTALL -removeonly Logitech SetPoint-->C:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F- 8EF7-A7E2B9D8B14E}\setup.exe - runfromtemp -l0x040c -removeonly Macromedia Flash Player 8-- >C:\WINDOWS\system32 \Macromed\Flash\UninstFl.exe Macromedia Shockwave Player-- >C:\WINDOWS\system32 \Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32 \Macromed\SHOCKW~1\Install.log Magic Flare 1.0-- >C:\WINDOWS\iun506.exe C:\Program Files\Magic Flare\irunin.ini MAGIX Music Manager (F)-- >C:\MAGIX\music_manager\instslct. exe MAGIX music studio 2006 deLuxe (F)-- >C:\MAGIX\ms2006_deLuxe\instslct. exe MAGIX Photo Manager (F)-- >C:\MAGIX\Photo_Manager\instslct. exe Malwarebytes' Anti-Malware-- >"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe" Matrox Imaging Products-- >C:\WINDOWS\UnInstallMIP.exe MediaShow 3.0-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1 \engine\6\INTEL3~1 \Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D5A9B7C0-8751-11D8- 9D75-000129760D75}\setup.exe" - uninstall Medion Info Display-- >C:\WINDOWS\UnInst32.exe VFDUtil.uni Microsoft .NET Framework 1.1 French Language Pack-- >MsiExec.exe /X{9A394342-4A68- 4EBA-85A6-55B559F4E700} Microsoft .NET Framework 1.1 Hotfix (KB928366)-- >"C:\WINDOWS\Microsoft.NET\Framew ork\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framewo rk\v1.1.4322\Updates\M928366 \M928366Uninstall.msp" Microsoft .NET Framework 1.1-- >msiexec.exe /X {CB2F7EDD-9D1F- 43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 1.1-- >MsiExec.exe /X{CB2F7EDD-9D1F- 43C1-90FC-4F52EAE172A1} Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC- CCC0-3757-8480-9EE176866A7C} Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I {C09FB3CD-3D0C-3F2D-899A- 6A1D67F2073F} Microsoft .NET Framework 2.0-- >C:\WINDOWS\Microsoft.NET\Framewo rk\v2.0.50727\Microsoft .NET Framework 2.0\install.exe Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{0BD83598- C2EF-3343-847B-7D2E84599128} Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I {A3051CD0-2F64-3813-A88D- B8DCCDE8F8C7} Microsoft .NET Framework 3.5 Language Pack SP1 - fra-- >MsiExec.exe /I{3E31821C-7917- 367E-938E-E65FC413EA31} Microsoft .NET Framework 3.5 SP1 -- >C:\WINDOWS\Microsoft.NET\Framewo rk\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe Microsoft .NET Framework 3.5 SP1 -->MsiExec.exe /I{CE2CDD62-0124- 36CA-84D3-9F4DCF5C5BD9} Microsoft AutoRoute 2006-- >MsiExec.exe /I{83ED1E80-A1B7- 4236-BCF1-AC4A88151A6B} Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-- >"C:\WINDOWS\$NtUninstallWdf01005 $\spuninst\spuninst.exe" Microsoft Money-->C:\Program Files\Microsoft Money 2005 \MNYCoreFiles\Setup\uninst.exe /s:120 Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I {9028040C-6000-11D3-8CFE- 0050048383C9} Microsoft Photo 2006 Standard Edition-->"C:\Program Files\Fichiers communs\Microsoft Shared\Picture It!\RmvSuite.exe" ADDREMOVE=1 SKU=PREM VERSION=11 Microsoft Silverlight-- >MsiExec.exe /I{89F4137D-6C26- 4A84-BDB8-2E5A4BB71E00} Microsoft SQL Server Compact 3.5 Design Tools FRA-->MsiExec.exe /X{043ECF7B-4724-4F7B-8A9D- BC22719E95F7} Microsoft SQL Server Compact 3.5 FRA-->MsiExec.exe /I{BE361597- 42AC-4513-9BA6-FFAB310038FB} Microsoft Visual Basic 2008 Express - Français-->C:\Program Files\Microsoft Visual Studio 9.0\Microsoft Visual Basic 2008 Express Edition - FRA\setup.exe Microsoft Visual Basic 2008 Express Edition - FRA-- >MsiExec.exe /X{ACC61C04-48C5- 3F6F-977B-AD33E94E5F40} Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X {7299052b-02a4-4627-81f2- 1818da5d550d} Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X {A49F249F-0C91-497F-86DF- B2585E8E76B7} Microsoft Windows SDK for Visual Studio 2008 Express Tools for .NET Framework-->MsiExec.exe /X {AB47EEE8-507B-331F-AA28- B7C7257F014C} Microsoft Windows SDK for Visual Studio 2008 Express Tools for Win32-->MsiExec.exe /X{07FCBED5- 94C3-4F94-B9D3-360FA27C7B06} Microsoft Word 2002-->MsiExec.exe /I{911B040C-6000-11D3-8CFE- 0050048383C9} Microsoft Works-->MsiExec.exe /I {6B1CB38D-E2E4-4A30-933D- EFDEBA76AD9C} MIKSOFT Mobile 3GP converter-- >"C:\Program Files\MIKSOFT\Mobile 3GP converter\unins000.exe" Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-- >"C:\WINDOWS\$NtUninstallKB898458 $\spuninst\spuninst.exe" Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-- >"C:\WINDOWS\$NtUninstallKB923723 $\spuninst\spuninst.exe" Mobile Music Polyphonic-- >C:\WINDOWS\IsUninst.exe - f"C:\Program Files\MobileMusic\Mobile Music Polyphonic\Uninst.isu" Module linguistique Microsoft .NET Framework 3.5 SP1- fra-- >c:\WINDOWS\Microsoft.NET\Framewo rk\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe Mozilla Firefox (3.0.4)-- >C:\Program Files\Mozilla Firefox\uninstall\helper.exe MP3 Player Utilities 3.68-- >MsiExec.exe /I{7784A172-61F1- 445E-8368-601607E0DD22} MSVC80_x86-->MsiExec.exe /I {212748BB-0DA5-46DE-82A1- 403736DC9F27} MSXML 4.0 SP2 (KB927978)-- >MsiExec.exe /I{37477865-A3F1- 4772-AD43-AAFC6BCFF99F} MSXML 4.0 SP2 (KB936181)-- >MsiExec.exe /I{C04E32E0-0416- 434D-AFB9-6969D703A9EF} MSXML 4.0 SP2 (KB954430)-- >MsiExec.exe /I{86493ADD-824D- 4B8E-BD72-8C5DCDC52A71} MSXML 6.0 Parser (KB933579)-- >MsiExec.exe /I{0A869A65-8C94- 4F7C-A5C7-972D3C8CED9E} Multi Media France Toolbar-- >C:\PROGRA~1\MULTI_~1\UNWISE.EXE C:\PROGRA~1\MULTI_~1\INSTALL.LOG Nero 6 Ultra Edition-->C:\Program Files\Ahead\nero\uninstall\UNNERO .exe /UNINSTALL neroxml-->MsiExec.exe /I {56C049BE-79E9-4502-BEA7- 9754A3E60F9B} Niagara Screensaver-- >C:\WINDOWS\system32\Niagara.scr /U NOD32 Antivirus System-- >C:\Program Files\Eset\Setup\setup.exe /UNINSTALL Nokia Connectivity Cable Driver- ->MsiExec.exe /X{C3F19A5F-35A8- 4FDB-A6ED-0F4CE398DA48} Nokia Flashing Cable Driver-- >MsiExec.exe /X{2A0A6470-FD0F- 4F45-9B11-85F3167DB943} Nokia Lifeblog 2.5-->MsiExec.exe /I{E94603CA-2996-4154-8EE2- A5FCD4BFB500} Nokia NSeries Application Installer-->MsiExec.exe /I {FD349381-D79C-4E5C-8980- 015DFFB962D5} Nokia NSeries Content Copier-- >MsiExec.exe /X{F779EC8D-6703- 4C4A-817C-37B07898E647} Nokia NSeries Multimedia Player- ->MsiExec.exe /I{FA25FAF6-3097- 43C9-BBB2-A77CE8AF1881} Nokia NSeries Music Manager-- >MsiExec.exe /I{F89E5AD8-AE47- 49B5-B9F9-C498791E6255} Nokia NSeries One Touch Access-- >MsiExec.exe /I{F4EE8763-EAA8- 4BC1-8594-8501F5F00414} Nokia NSeries System Utilities-- >MsiExec.exe /X{96E94E18-54D6- 42C1-8FC4-24DACEDC3395} Nokia Nseries Video Manager-- >MsiExec.exe /X{2D21ECE3-8EC1- 4315-AE4E-1970FB3AF17A} Nokia PC Suite-->C:\Documents and Settings\All Users\Application Data\Installations\{2B8BEBBF- 73A0-497D-9900-8474D022AB3F} \Nokia_PC_Suite_rel_7_0_7_0_eng_w eb.exe Nokia PC Suite-->MsiExec.exe /I {2B8BEBBF-73A0-497D-9900- 8474D022AB3F} Nokia Software Launcher-- >MsiExec.exe /I{A8C856AD-63CD- 4613-AA29-E6C85607EA06} Nokia Software Updater-- >MsiExec.exe /X{17BD85F9-3B88- 4C85-BB47-4AB8DD68F8BB} Notepad++-->C:\Program Files\Notepad++\uninstall.exe NSS (remove only)-->C:\Program Files\NSS\uninstall.exe NVIDIA Drivers-- >C:\WINDOWS\system32\nvudisp.exe UninstallGUI O&O Defrag Professional Edition- ->MsiExec.exe /I{53480330-E1D1- 41CA-B8F8-7F78644F7F50} Outil de mise à jour Google-- >"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" - uninstall Pack Crystal Clear 1.0-- >C:\WINDOWS\BricoPacks\Crystal Clear\Remove.exe Package de pilotes Windows - Nokia Modem (02/15/2007 3.1)-- >C:\PROGRA~1 \DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32 \DRVSTORE\pccs_bluet_8B37DC72918C CD58A6EC20373AF6242B037A293B\pccs _bluetooth.inf Package de pilotes Windows - Nokia Modem (05/22/2008 3.-- >C:\PROGRA~1 \DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32 \DRVSTORE\nokia_blue_6F90B0F4A73A 2F780A1010B5D6CB5DDFB098181E\noki a_bluetooth.inf Package de pilotes Windows - Nokia Modem (05/22/2008 7.00.0.1)-->C:\PROGRA~1 \DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32 \DRVSTORE\nokbtmdm_E68D50F7E25BFE 399D47C864C3B52557346242A9 \nokbtmdm.inf Package de pilotes Windows - Nokia pccsmcfd (10/12/2007 6.85.4.0)-->C:\PROGRA~1 \DIFX\270581355A767BF1\dpinst.exe /u C:\WINDOWS\system32 \DRVSTORE\pccsmcfd_4A1E30386F4D0D EC8F5DF262CFBD8845EEBAB175 \pccsmcfd.inf Pando-->MsiExec.exe /I{C0B0FA55- D4E9-4374-9871-BBFBF2AEF0D1} PC Connectivity Solution-- >MsiExec.exe /I{9C7C8898-DC29- 4E8B-9E77-55A77C3250F6} Pcsx2 0.9.1 Watermoose-- >"C:\Program Files\Pcsx2 \unins000.exe" PhotoNow! 1.0-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1 \engine\6\INTEL3~1 \Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D36DD326-7280-11D8- 97C8-000129760CBE}\setup.exe" - uninstall PoiEdit-->C:\PROGRA~1\DNOTES~1 \POIEDI~1\UNWISE.EXE C:\PROGRA~1 \DNOTES~1\POIEDI~1\INSTALL.LOG PowerCinema-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1 \engine\6\INTEL3~1 \Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6- 9EA2-00055D0CA761}\setup.exe" - uninstall PowerDirector-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1 \engine\6\INTEL3~1 \Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB099890-1D5F-11D5- 9EA9-0050BAE317E1}\setup.exe" - uninstall PowerDVD-->RunDll32 C:\PROGRA~1 \FICHIE~1\INSTAL~1\engine\6 \INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4- 9EA1-0050BAE317E1}\setup.exe" - uninstall PowerProducer-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1 \engine\6\INTEL3~1 \Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B7A0CE06-068E-11D6- 97FD-0050BACBF861}\setup.exe" - uninstall PowerQuest Drive Image 7.0-- >MsiExec.exe /X{8D538DFC-1E7A- 45F0-9C7B-D8B6629CC2DC} PSP ISO Compressor-->MsiExec.exe /X{D47087E7-AA15-4D1D-8C0A- 60F7E446D597} QuickPar 0.9-->C:\Program Files\QuickPar\uninst.exe QuickTime-->MsiExec.exe /I {8DC42D05-680B-41B0-8878- 6C14D24602DB} RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst. exe RealNetworks|RealPlayer|6.0 Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1 \FICHIE~1\INSTAL~1\PROFES~1 \RunTime\11\00\Intel32 \Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE- 8A7C-958108FE7DBC}\Setup.exe" - l0x40c -removeonly RT2500 USB Wireless LAN Card-- >RunDll32 C:\PROGRA~1\FICHIE~1 \INSTAL~1\PROFES~1\RunTime\11\00 \Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5490B6EF-5A48-40B7- A9E0-D3B886D17A29}\setup.exe" - l0x40c -removeonly SAMSUNG CDMA Modem Driver Set-- >C:\WINDOWS\system32 \Samsung_USB_Drivers\3 \SSCDUninstall.exe SAMSUNG Mobile USB Modem ^^-- >C:\WINDOWS\system32 \Samsung_USB_Drivers\4 \SSVDUninstall.exe SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32 \Samsung_USB_Drivers\1 \SS_Uninstall.exe SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32 \Samsung_USB_Drivers\2 \SSM_Uninstall.exe Samsung PC Studio 3 USB Driver Installer-->RunDll32 C:\PROGRA~1 \FICHIE~1\INSTAL~1\PROFES~1 \RunTime\10\50\Intel32 \Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EBA29752-DDD2-4B62- B2E3-9841F92A3E3A}\setup.exe" - l0x40c -removeonly SC Ver 2.65-->"C:\Program Files\SC\unins000.exe" Sélecteur d'installation de Microsoft Works 2006-->C:\Program Files\Microsoft Works Suite 2006 \Setup\Launcher.exe /ARP G:\ SigmaTel MSCN Audio Player-- >RunDll32 C:\PROGRA~1\FICHIE~1 \INSTAL~1\PROFES~1\RunTime\0701 \Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8E240C1C-25D0-4248- BC6C-ACC3472E35CE}\setup.exe" - l0x40c -remove Sony Ericsson PC Suite-- >MsiExec.exe /I{52809086-618D- 4F0B-8BF1-B75A5BB817A4} Spybot - Search & Destroy 1.4-- >"C:\Program Files\Spybot - Search & Destroy\unins000.exe" Super Utilities Pro 7.63-- >"C:\Program Files\SuperLogix\Super Utilities\unins000.exe" Symbian Developer Certificate Request-->RunDll32 C:\PROGRA~1 \FICHIE~1\INSTAL~1\PROFES~1 \RunTime\11\00\Intel32 \Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA6C1A80-D188-427C- 8102-226CF9E35AF4}\setup.exe" - l0x9 -removeonly System Security Suite 1.04-- >C:\Program Files\System Security Suite 1.04\uninstal.exe TomTom HOME-->C:\Program Files\TomTom HOME 2\Uninstall TomTom HOME.exe Usb to Serial Driver 1.12.25-- >RunDll32 C:\PROGRA~1\FICHIE~1 \INSTAL~1\PROFES~1\RunTime\09\00 \Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F46E168-E0F4-45EA- 81F5-80488334B609}\Setup.exe" - l0x40c USB Wireless Keyboard Driver-- >RunDll32 C:\PROGRA~1\FICHIE~1 \INSTAL~1\engine\6\INTEL3~1 \Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B338EA45-9F18-4FE4- A079-89668D1F6519}\Setup.exe" - l0x40c Utilitaire de sauvegarde Windows -->MsiExec.exe /I{76EFFC7C-17A6- 479D-9E47-8E658C1695AE} VC_MergeModuleToMSI-->MsiExec.exe /I{900A92BA-19EF-4A34-86CF- 7B6C85BDD971} VCRedistSetup-->MsiExec.exe /I {3921A67A-5AB1-4E48-9444- C71814CF3027} VIDALexpert-- >C:\WINDOWS\ISUN040C.EXE - f"C:\Program Files\VIDAL\VIDALexpert\Uninst.is u" -c"C:\Program Files\VIDAL\VIDALexpert\Bin\UnIns tTVS.dll" VideoLAN VLC media player 0.8.5- ->C:\Program Files\VideoLAN\VLC\uninstall.exe videon-->RunDll32 C:\PROGRA~1 \FICHIE~1\INSTAL~1\PROFES~1 \RunTime\0701\Intel32 \Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{261D0486-9127-4071- BA1D-FE784310752E}\Setup.exe" - l0x40c Videora iPod Converter 2.25-- >C:\Program Files\Red Kawa\Video Converter\uninstaller.exe Viewpoint Media Player-- >C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u Visionneuse Journal Windows Microsoft-->MsiExec.exe /X {43DCF766-6838-4F9A-8C91- D92DA586DFA7} VMN Toolbar-->C:\Program Files\vmntoolbar\uninstall.exe Winamp (remove only)-- >"C:\Program Files\Winamp\UninstWA.exe" Winamp 5 Media Liabrary Import/Export (remove only)-- >"C:\Program Files\Winamp\uninstall.exe" Windows Genuine Advantage v1.3.0254.0-->MsiExec.exe /I {63569CE9-FA00-469C-AF5C- E5D4D93ACF91} Windows Media Format 11 runtime- - >"C:\WINDOWS\$NtUninstallWMFDist1 1$\spuninst\spuninst.exe" Windows Media Format Runtime-- >"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll Windows Media Player 11-- >"C:\WINDOWS\$NtUninstallwmp11 $\spuninst\spuninst.exe" Windows Presentation Foundation- ->MsiExec.exe /X{BAF78226-3200- 4DB4-BE33-4D922A799840} Windows XP Service Pack 3-- >"C:\WINDOWS\$NtServicePackUninst all$\spuninst\spuninst.exe" X10 Hardware-- >C:\WINDOWS\UNWISE.EXE C:\PROGRA~1\X10HAR~1\Install.log XML Paper Specification Shared Components Language Pack 1.0-- >"C:\WINDOWS\$NtUninstallXPSEPSCL P$\spuninst\spuninst.exe" XnView 1.91.3-->"C:\Program Files\XnView\unins000.exe" =====HijackThis Backups===== R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01? FORM=TOOLBR O2 - BHO: (no name) - {02478D38- C3F9-4efb-9B51-7695ECA05670} - (no file) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7- 2C66DA43AC6C} - (no file) O18 - Protocol: bwt0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwm0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwa0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw80s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwb0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwf0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw70 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw80 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwq0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: offline-8876480 - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw10 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwn0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwu0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw00 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwi0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwt0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwb0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwz0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwd0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwe0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw90 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bws0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwm0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw20s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwc0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw90s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwv0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwe0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw50s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw30s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw10s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bww0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwc0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwj0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw40 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwj0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw-0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwh0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwp0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwx0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwo0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwq0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw70s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwv0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwr0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwl0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwu0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwo0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwk0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwa0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwd0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwx0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwh0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwi0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwk0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw-0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwp0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw30 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw+0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwz0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwf0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw60s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw20 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw50 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwl0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw00s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw60 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw40s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwr0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bw+0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bws0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwy0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwg0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bww0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80- C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\GAPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwg0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwy0 - {DF18A746 -F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) O18 - Protocol: bwn0s - {DF18A746-F60E-41C0-B4C5- 41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480 \Program\BWPlugProtocol- 8876480.dll (file missing) ======Hosts File====== 127.0.0.1 localhost ======Security center information====== AV: ESET NOD32 antivirus system 2.70 ======Environment variables====== "ComSpec"=%SystemRoot%\system32 \cmd.exe "Path"=%SystemRoot%\system32;% SystemRoot%;%SystemRoot% \system32\WBEM;C:\Program Files\PC Connectivity Solution\;C:\Program Files\Fichiers communs\Teleca Shared;C:\Program Files\Samsung\Samsung PC Studio 3\;C:\Program Files\QuickTime\QTSystem\;C:\Prog ram Files\Smart Projects\IsoBuster "windir"=%SystemRoot% "FP_NO_HOST_CHECK"=NO "OS"=Windows_NT "PROCESSOR_ARCHITECTURE"=x86 "PROCESSOR_LEVEL"=15 "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 4, GenuineIntel "PROCESSOR_REVISION"=0404 "NUMBER_OF_PROCESSORS"=2 "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VB S;.VBE;.JS;.JSE;.WSF;.WSH "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "VGAVCF"=c:\Program Files\Matrox Imaging\drivers\vga\vcf "CLASSPATH"=.;C:\Program Files\Java\jre1.5.0_06 \lib\ext\QTJava.zip "QTJAVA"=C:\Program Files\Java\jre1.5.0_06 \lib\ext\QTJava.zip -----------------EOF------------ ----- -----------\\ ToolBar S&D 1.2.5 XP/Vista Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2 X86-based PC ( Multiprocessor Free : Intel® Pentium® D CPU 3.00GHz ) BIOS : Phoenix - AwardBIOS v6.00PG USER : Nordine ( Administrator ) BOOT : Fail-safe boot Antivirus : ESET NOD32 antivirus system 2.70 2.70 (Activated) C:\ (Local Disk) - NTFS - Total:116 Go (Free:33 Go) D:\ (Local Disk) - NTFS - Total:110 Go (Free:5 Go) E:\ (Local Disk) - FAT32 - Total:5 Go (Free:1 Go) F:\ (CD or DVD) G:\ (CD or DVD) I:\ (USB) K:\ (USB) L:\ (USB) "C:\ToolBar SD" ( MAJ : 20-11-2008|20:25 ) Option : [2] ( 21/11/2008|17:17 ) -----------\\ SUPPRESSION Supprime! - C:\Program Files\DAEMON Tools Toolbar\FirefoxDTT Supprime! - C:\Program Files\DAEMON Tools Toolbar\_DTLite.xml Supprime! - C:\Program Files\Multi_Media_France\INSTALL.LOG Supprime! - C:\Program Files\Multi_Media_France\LanguagePack.xml Supprime! - C:\Program Files\Multi_Media_France\LocalSettings.txt Supprime! - C:\Program Files\Multi_Media_France\RadioPlayer Supprime! - C:\Program Files\Multi_Media_France\tbMul0.dll Supprime! - C:\Program Files\Multi_Media_France\tbMult.dll Supprime! - C:\Program Files\Multi_Media_France\ThirdPartyComponents.xml Supprime! - C:\Program Files\Multi_Media_France\toolbar.cfg Supprime! - C:\Program Files\Multi_Media_France\UNWISE.EXE Supprime! - C:\Program Files\Multi_Media_France\UNWISE.INI Supprime! - C:\Program Files\Multi_Media_France\update.xml Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\---Yahoo.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\01net.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\1px_dark.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\1px_green.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\1px_white.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\a.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\amazon.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\an.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrowB.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrowT.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrow_down.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrow_red.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrow_red2.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrow_up.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\autofill.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\avstate.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\b.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\background2.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bgmeteo_results.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bg_pub.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bg_ttl.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bottom.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bottom_left.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bottom_right.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\btn_close.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\btn_minus.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\btn_moreforecast.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\c.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\canalblog.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\cn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\d.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\dictionary2.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\dn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\downfile Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\DownloadCOM.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\dropdown.css Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\ErrorLog.txt Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\ErrorPageTemplate.css Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\f.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_argentine.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_australia.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_brazil.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_canada.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_china.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_france.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_germany.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_greece.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_hongkong.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_india.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_indonesia.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_italy.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_japan.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_korea.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_mexico.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_netherlands.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_spain.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_sweeden.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_taiwan.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_uk.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_usa.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\fn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\g.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\gaming.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\gn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\gograph.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred0.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred0_5.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred1.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred1_5.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred2.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred2_5.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred3.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred3_5.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred4.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred4_5.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred5.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\help.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\hideremove.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\highlight.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\hn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_aquarius.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_aries.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_cancer.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_capricorn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_gemini.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_leo.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_libra.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_pisces.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_sagittarius.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_scorpio.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_taurus.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_virgo.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\i.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\icotemp_placeholder.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\IEtab1_7d.zip Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\in.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\ipsearch.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\j.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\jn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\k.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\kn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\l.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\left.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\ln.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\loading.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\login.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\logo.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\n.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\New York_NY_weather.txt Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\new02.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\NewCfg Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\news.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\news.html Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\nn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\o.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\on.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\p.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\pestscanimg.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\pixsy.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\pn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\popup_off.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\popup_on.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\popup_ona.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\p_yahoo.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\p_yahoo_fr.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\q.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\qn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\r.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\relatedlinks.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\report.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\right.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rss.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rss.xsl Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rss1.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rsslib.js Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rssmenu1_7a.zip Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\s.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\search.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\search_fr.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\security.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\sinfo.txt Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\siteinfo.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\slider.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\sn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\spacer.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red1.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red2.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red3.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red4.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red5.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\storage.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\t.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tabdataV3.js Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tablib.js Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tabwelcome_en.html Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tabwelcome_fr.html Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tab_icon.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\technorati.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\thes_search.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tools.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\top.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\top_left.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\top_right.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\translate.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\u.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\un.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\utf8.js Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\v.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\vmlib.js Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\vmntoolbartb1501.cfg Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\vn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\w.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\web.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\web_fr.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\wikipedia.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\wn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\x.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\xp_close_small.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\yahoo.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\yahoo_search.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\YouTube.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\z.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\zn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\zoom.bmp Supprime! - C:\Program Files\VMNToolbar\install.ico Supprime! - C:\Program Files\VMNToolbar\tbuninstall.exe Supprime! - C:\Program Files\VMNToolbar\toolbar.ini Supprime! - C:\Program Files\VMNToolbar\uninstall.exe Supprime! - C:\Program Files\DAEMON Tools Toolbar Supprime! - C:\Program Files\Multi_Media_France Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar Supprime! - C:\Program Files\VMNToolbar -----------\\ Recherche de Fichiers / Dossiers ... -----------\\ Extensions (Nordine) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} => freecorder (Nordine) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar (Nordine) - {c4dc572a-3295-40eb-b30f-b54aa4cdc4b7} => wmlbrowser -----------\\ [..\Internet Explorer\Main] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.fr/" "Search Page"="http://www.google.com" "Search Bar"="http://www.google.com/ie" "SearchMigratedDefaultURL"="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"'>http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://www.msn.com/" --------------------\\ Recherche d'autres infections --------------------\\ Cracks & Keygens .. C:\DOCUME~1\Nordine\Application Data\IDM\DwnlData\Nordine\Crack et s‚rial jeux soft e_71 C:\DOCUME~1\Nordine\Application Data\IDM\DwnlData\Nordine\Crack et s‚rial jeux soft e_72 C:\DOCUME~1\Nordine\Application Data\IDM\DwnlData\Nordine\Crack et s‚rial jeux soft e_71\log_71.log C:\DOCUME~1\Nordine\Application Data\IDM\DwnlData\Nordine\Crack et s‚rial jeux soft e_72\log_72.log C:\DOCUME~1\Nordine\Application Data\Microsoft\Office\Fichiers r‚cents\crack pour europe V7.lnk C:\DOCUME~1\Nordine\Application Data\Microsoft\Office\Fichiers r‚cents\Crack tomtom map version 7.doc.lnk C:\DOCUME~1\Nordine\Bureau\ttn_6.032_elrincondedey_crackeada.cab C:\DOCUME~1\Nordine\Bureau\Ad aware 2008 pro 7.0.1.11\Ad aware 2008 pro 7.0.1.11\CRACK a mettre dans le dossier d'installation a la fin de l'installation C:\DOCUME~1\Nordine\Bureau\Ad aware 2008 pro 7.0.1.11\Ad aware 2008 pro 7.0.1.11\CRACK a mettre dans le dossier d'installation a la fin de l'installation\lavalicense.dll C:\DOCUME~1\Nordine\Bureau\DOSSIERS\O&O Defrag 10.0.1670.Francais+keygen C:\DOCUME~1\Nordine\Bureau\DOSSIERS\aide et astuce divers\ASTUCE RECHERCHE CRACK.txt C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\Nero-8.1.1.0+keygen.zip C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack\AudStu.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack\midi studio 11.Key C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack\MusicManager.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack\PhotoManager.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\DIVX_6.8_upbyzeus\DIVX_6.8_upbyzeus\Keygen DivX AIO.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_ C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_.rar C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_\Crack Fruity Loops 7 rc6b - fixato il problema del key scaduto(by SimoDj).reg C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_\FLEngine.dll C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_\Readme.txt C:\DOCUME~1\Nordine\Bureau\DOSSIERS\O&O Defrag 10.0.1670.Francais+keygen\O&O Defrag 10.0.1670.Francais+keygen C:\DOCUME~1\Nordine\Bureau\DOSSIERS\O&O Defrag 10.0.1670.Francais+keygen\O&O Defrag 10.0.1670.Francais+keygen\o-o-defrag_o_o_defrag_10.0.1670_anglais_11995.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\O&O Defrag 10.0.1670.Francais+keygen\O&O Defrag 10.0.1670.Francais+keygen\OO Defrag 10 Keygen.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\vidal3006\Crack C:\DOCUME~1\Nordine\Bureau\DOSSIERS\vidal3006\Crack\Crack 3006 Vidal Expert.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\vidal3006\Crack\… lire!!!!.txt C:\DOCUME~1\Nordine\Favoris\Bienvenue sur FranceCrack.com.url C:\DOCUME~1\Nordine\Favoris\DreamDDL.com - Full Version Download Crack Serial Keygen Torrent Rapidshare Free Warez.url C:\DOCUME~1\Nordine\Favoris\Fruity loops 7 problem du crack enfin r‚solu 2.url C:\DOCUME~1\Nordine\Favoris\Full Version Download with Crack Serial Keygen or Torrent from Rapidshare-Free Warez.url 1 - "C:\ToolBar SD\TB_1.txt" - 21/11/2008|17:16 - Option : [1] 2 - "C:\ToolBar SD\TB_2.txt" - 21/11/2008|17:18 - Option : [2] -----------\\ Fin du rapport a 17:18:56,20 Avec l'espoir que cette fois ci pas de bléme. amicalement. -
rapport Hijackthis
seroncamille a répondu à un(e) sujet de seroncamille dans Analyses et éradication malwares
-
rapport Hijackthis
seroncamille a répondu à un(e) sujet de seroncamille dans Analyses et éradication malwares
Bonsoir pear, donc voici les rapports demadés dans l'ordre: -----------\\ ToolBar S&D 1.2.5 XP/Vista Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2 X86-based PC ( Multiprocessor Free : Intel® Pentium® D CPU 3.00GHz ) BIOS : Phoenix - AwardBIOS v6.00PG USER : Nordine ( Administrator ) BOOT : Fail-safe boot Antivirus : ESET NOD32 antivirus system 2.70 2.70 (Activated) C:\ (Local Disk) - NTFS - Total:116 Go (Free:33 Go) D:\ (Local Disk) - NTFS - Total:110 Go (Free:5 Go) E:\ (Local Disk) - FAT32 - Total:5 Go (Free:1 Go) F:\ (CD or DVD) G:\ (CD or DVD) I:\ (USB) K:\ (USB) L:\ (USB) "C:\ToolBar SD" ( MAJ : 20-11-2008|20:25 ) Option : [1] ( 21/11/2008|17:14 ) -----------\\ Recherche de Fichiers / Dossiers ... C:\Program Files\DAEMON Tools Toolbar C:\Program Files\DAEMON Tools Toolbar\FirefoxDTT C:\Program Files\DAEMON Tools Toolbar\_DTLite.xml C:\Program Files\DAEMON Tools Toolbar\FirefoxDTT\chrome C:\Program Files\DAEMON Tools Toolbar\FirefoxDTT\components C:\Program Files\DAEMON Tools Toolbar\FirefoxDTT\chrome\dttoolbar.jar C:\Program Files\DAEMON Tools Toolbar\FirefoxDTT\components\DTToolbarFF.dll C:\Program Files\Multi_Media_France C:\Program Files\Multi_Media_France\INSTALL.LOG C:\Program Files\Multi_Media_France\LanguagePack.xml C:\Program Files\Multi_Media_France\LocalSettings.txt C:\Program Files\Multi_Media_France\RadioPlayer C:\Program Files\Multi_Media_France\tbMul0.dll C:\Program Files\Multi_Media_France\tbMult.dll C:\Program Files\Multi_Media_France\ThirdPartyComponents.xml C:\Program Files\Multi_Media_France\toolbar.cfg C:\Program Files\Multi_Media_France\UNWISE.EXE C:\Program Files\Multi_Media_France\UNWISE.INI C:\Program Files\Multi_Media_France\update.xml C:\Program Files\Multi_Media_France\RadioPlayer\Predefined_Media_List.xml C:\Program Files\Multi_Media_France\RadioPlayer\User_Media_List.xml C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\---Yahoo.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\01net.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\1px_dark.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\1px_green.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\1px_white.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\a.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\amazon.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\an.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrowB.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrowT.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrow_down.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrow_red.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrow_red2.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrow_up.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\autofill.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\avstate.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\b.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\background2.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bgmeteo_results.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bg_pub.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bg_ttl.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bottom.png C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bottom_left.png C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bottom_right.png C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\btn_close.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\btn_minus.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\btn_moreforecast.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\c.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\canalblog.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\cn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\d.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\dictionary2.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\dn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\downfile C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\DownloadCOM.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\dropdown.css C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\ErrorLog.txt C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\ErrorPageTemplate.css C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\f.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_argentine.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_australia.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_brazil.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_canada.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_china.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_france.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_germany.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_greece.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_hongkong.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_india.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_indonesia.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_italy.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_japan.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_korea.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_mexico.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_netherlands.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_spain.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_sweeden.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_taiwan.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_uk.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_usa.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\fn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\g.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\gaming.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\gn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\gograph.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred0.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred0_5.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred1.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred1_5.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred2.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred2_5.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred3.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred3_5.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred4.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred4_5.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred5.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\help.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\hideremove.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\highlight.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\hn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_aquarius.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_aries.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_cancer.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_capricorn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_gemini.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_leo.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_libra.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_pisces.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_sagittarius.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_scorpio.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_taurus.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_virgo.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\i.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\icotemp_placeholder.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\IEtab1_7d.zip C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\in.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\ipsearch.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\j.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\jn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\k.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\kn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\l.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\left.png C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\ln.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\loading.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\login.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\logo.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\n.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\New York_NY_weather.txt C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\new02.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\NewCfg C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\news.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\news.html C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\nn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\o.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\on.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\p.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\pestscanimg.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\pixsy.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\pn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\popup_off.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\popup_on.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\popup_ona.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\p_yahoo.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\p_yahoo_fr.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\q.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\qn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\r.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\relatedlinks.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\report.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\right.png C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rss.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rss.xsl C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rss1.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rsslib.js C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rssmenu1_7a.zip C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\s.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\search.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\search_fr.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\security.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\sinfo.txt C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\siteinfo.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\slider.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\sn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\spacer.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red1.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red2.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red3.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red4.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red5.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\storage.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\t.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tabdataV3.js C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tablib.js C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tabwelcome_en.html C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tabwelcome_fr.html C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tab_icon.png C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\technorati.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\thes_search.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tools.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\top.png C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\top_left.png C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\top_right.png C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\translate.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\u.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\un.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\utf8.js C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\v.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\vmlib.js C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\vmntoolbartb1501.cfg C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\vn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\w.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\web.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\web_fr.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\wikipedia.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\wn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\x.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\xp_close_small.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\yahoo.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\yahoo_search.gif C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\YouTube.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\z.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\zn.bmp C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\zoom.bmp C:\Program Files\VMNToolbar C:\Program Files\VMNToolbar\install.ico C:\Program Files\VMNToolbar\tbuninstall.exe C:\Program Files\VMNToolbar\toolbar.ini C:\Program Files\VMNToolbar\uninstall.exe -----------\\ Extensions (Nordine) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} => freecorder (Nordine) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar (Nordine) - {c4dc572a-3295-40eb-b30f-b54aa4cdc4b7} => wmlbrowser -----------\\ [..\Internet Explorer\Main] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.fr/"'>http://www.google.fr/" "Search Page"="http://www.google.com"'>http://www.google.com" "Search Bar"="http://www.google.com/ie"'>http://www.google.com/ie" "SearchMigratedDefaultURL"="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"'>http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"'>http://go.microsoft.com/fwlink/?LinkId=69157"'>http://go.microsoft.com/fwlink/?LinkId=69157" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"'>http://go.microsoft.com/fwlink/?LinkId=54896"'>http://go.microsoft.com/fwlink/?LinkId=54896"'>http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157" --------------------\\ Recherche d'autres infections --------------------\\ Cracks & Keygens .. C:\DOCUME~1\Nordine\Application Data\IDM\DwnlData\Nordine\Crack et s‚rial jeux soft e_71 C:\DOCUME~1\Nordine\Application Data\IDM\DwnlData\Nordine\Crack et s‚rial jeux soft e_72 C:\DOCUME~1\Nordine\Application Data\IDM\DwnlData\Nordine\Crack et s‚rial jeux soft e_71\log_71.log C:\DOCUME~1\Nordine\Application Data\IDM\DwnlData\Nordine\Crack et s‚rial jeux soft e_72\log_72.log C:\DOCUME~1\Nordine\Application Data\Microsoft\Office\Fichiers r‚cents\crack pour europe V7.lnk C:\DOCUME~1\Nordine\Application Data\Microsoft\Office\Fichiers r‚cents\Crack tomtom map version 7.doc.lnk C:\DOCUME~1\Nordine\Bureau\ttn_6.032_elrincondedey_crackeada.cab C:\DOCUME~1\Nordine\Bureau\Ad aware 2008 pro 7.0.1.11\Ad aware 2008 pro 7.0.1.11\CRACK a mettre dans le dossier d'installation a la fin de l'installation C:\DOCUME~1\Nordine\Bureau\Ad aware 2008 pro 7.0.1.11\Ad aware 2008 pro 7.0.1.11\CRACK a mettre dans le dossier d'installation a la fin de l'installation\lavalicense.dll C:\DOCUME~1\Nordine\Bureau\DOSSIERS\O&O Defrag 10.0.1670.Francais+keygen C:\DOCUME~1\Nordine\Bureau\DOSSIERS\aide et astuce divers\ASTUCE RECHERCHE CRACK.txt C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\Nero-8.1.1.0+keygen.zip C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack\AudStu.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack\midi studio 11.Key C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack\MusicManager.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack\PhotoManager.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\DIVX_6.8_upbyzeus\DIVX_6.8_upbyzeus\Keygen DivX AIO.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_ C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_.rar C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_\Crack Fruity Loops 7 rc6b - fixato il problema del key scaduto(by SimoDj).reg C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_\FLEngine.dll C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_\Readme.txt C:\DOCUME~1\Nordine\Bureau\DOSSIERS\O&O Defrag 10.0.1670.Francais+keygen\O&O Defrag 10.0.1670.Francais+keygen C:\DOCUME~1\Nordine\Bureau\DOSSIERS\O&O Defrag 10.0.1670.Francais+keygen\O&O Defrag 10.0.1670.Francais+keygen\o-o-defrag_o_o_defrag_10.0.1670_anglais_11995.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\O&O Defrag 10.0.1670.Francais+keygen\O&O Defrag 10.0.1670.Francais+keygen\OO Defrag 10 Keygen.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\vidal3006\Crack C:\DOCUME~1\Nordine\Bureau\DOSSIERS\vidal3006\Crack\Crack 3006 Vidal Expert.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\vidal3006\Crack\… lire!!!!.txt C:\DOCUME~1\Nordine\Favoris\Bienvenue sur FranceCrack.com.url C:\DOCUME~1\Nordine\Favoris\DreamDDL.com - Full Version Download Crack Serial Keygen Torrent Rapidshare Free Warez.url C:\DOCUME~1\Nordine\Favoris\Fruity loops 7 problem du crack enfin r‚solu 2.url C:\DOCUME~1\Nordine\Favoris\Full Version Download with Crack Serial Keygen or Torrent from Rapidshare-Free Warez.url 1 - "C:\ToolBar SD\TB_1.txt" - 21/11/2008|17:16 - Option : [1] -----------\\ Fin du rapport a 17:16:06,70 -----------\\ ToolBar S&D 1.2.5 XP/Vista Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2 X86-based PC ( Multiprocessor Free : Intel® Pentium® D CPU 3.00GHz ) BIOS : Phoenix - AwardBIOS v6.00PG USER : Nordine ( Administrator ) BOOT : Fail-safe boot Antivirus : ESET NOD32 antivirus system 2.70 2.70 (Activated) C:\ (Local Disk) - NTFS - Total:116 Go (Free:33 Go) D:\ (Local Disk) - NTFS - Total:110 Go (Free:5 Go) E:\ (Local Disk) - FAT32 - Total:5 Go (Free:1 Go) F:\ (CD or DVD) G:\ (CD or DVD) I:\ (USB) K:\ (USB) L:\ (USB) "C:\ToolBar SD" ( MAJ : 20-11-2008|20:25 ) Option : [2] ( 21/11/2008|17:17 ) -----------\\ SUPPRESSION Supprime! - C:\Program Files\DAEMON Tools Toolbar\FirefoxDTT Supprime! - C:\Program Files\DAEMON Tools Toolbar\_DTLite.xml Supprime! - C:\Program Files\Multi_Media_France\INSTALL.LOG Supprime! - C:\Program Files\Multi_Media_France\LanguagePack.xml Supprime! - C:\Program Files\Multi_Media_France\LocalSettings.txt Supprime! - C:\Program Files\Multi_Media_France\RadioPlayer Supprime! - C:\Program Files\Multi_Media_France\tbMul0.dll Supprime! - C:\Program Files\Multi_Media_France\tbMult.dll Supprime! - C:\Program Files\Multi_Media_France\ThirdPartyComponents.xml Supprime! - C:\Program Files\Multi_Media_France\toolbar.cfg Supprime! - C:\Program Files\Multi_Media_France\UNWISE.EXE Supprime! - C:\Program Files\Multi_Media_France\UNWISE.INI Supprime! - C:\Program Files\Multi_Media_France\update.xml Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\---Yahoo.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\01net.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\1px_dark.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\1px_green.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\1px_white.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\a.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\amazon.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\an.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrowB.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrowT.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrow_down.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrow_red.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrow_red2.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\arrow_up.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\autofill.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\avstate.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\b.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\background2.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bgmeteo_results.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bg_pub.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bg_ttl.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bottom.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bottom_left.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\bottom_right.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\btn_close.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\btn_minus.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\btn_moreforecast.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\c.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\canalblog.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\cn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\d.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\dictionary2.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\dn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\downfile Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\DownloadCOM.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\dropdown.css Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\ErrorLog.txt Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\ErrorPageTemplate.css Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\f.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_argentine.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_australia.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_brazil.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_canada.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_china.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_france.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_germany.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_greece.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_hongkong.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_india.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_indonesia.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_italy.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_japan.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_korea.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_mexico.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_netherlands.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_spain.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_sweeden.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_taiwan.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_uk.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\flag_usa.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\fn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\g.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\gaming.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\gn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\gograph.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred0.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred0_5.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred1.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred1_5.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred2.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred2_5.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred3.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred3_5.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred4.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred4_5.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\graphred5.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\help.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\hideremove.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\highlight.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\hn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_aquarius.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_aries.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_cancer.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_capricorn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_gemini.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_leo.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_libra.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_pisces.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_sagittarius.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_scorpio.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_taurus.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\h_virgo.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\i.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\icotemp_placeholder.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\IEtab1_7d.zip Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\in.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\ipsearch.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\j.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\jn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\k.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\kn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\l.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\left.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\ln.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\loading.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\login.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\logo.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\n.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\New York_NY_weather.txt Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\new02.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\NewCfg Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\news.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\news.html Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\nn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\o.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\on.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\p.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\pestscanimg.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\pixsy.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\pn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\popup_off.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\popup_on.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\popup_ona.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\p_yahoo.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\p_yahoo_fr.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\q.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\qn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\r.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\relatedlinks.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\report.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\right.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rss.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rss.xsl Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rss1.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rsslib.js Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\rssmenu1_7a.zip Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\s.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\search.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\search_fr.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\security.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\sinfo.txt Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\siteinfo.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\slider.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\sn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\spacer.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red1.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red2.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red3.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red4.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\stars-red5.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\storage.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\t.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tabdataV3.js Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tablib.js Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tabwelcome_en.html Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tabwelcome_fr.html Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tab_icon.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\technorati.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\thes_search.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\tools.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\top.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\top_left.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\top_right.png Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\translate.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\u.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\un.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\utf8.js Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\v.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\vmlib.js Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\vmntoolbartb1501.cfg Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\vn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\w.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\web.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\web_fr.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\wikipedia.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\wn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\x.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\xp_close_small.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\yahoo.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\yahoo_search.gif Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\YouTube.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\z.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\zn.bmp Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar\zoom.bmp Supprime! - C:\Program Files\VMNToolbar\install.ico Supprime! - C:\Program Files\VMNToolbar\tbuninstall.exe Supprime! - C:\Program Files\VMNToolbar\toolbar.ini Supprime! - C:\Program Files\VMNToolbar\uninstall.exe Supprime! - C:\Program Files\DAEMON Tools Toolbar Supprime! - C:\Program Files\Multi_Media_France Supprime! - C:\DOCUME~1\Nordine\APPLIC~1\VMNToolbar Supprime! - C:\Program Files\VMNToolbar -----------\\ Recherche de Fichiers / Dossiers ... -----------\\ Extensions (Nordine) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} => freecorder (Nordine) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar (Nordine) - {c4dc572a-3295-40eb-b30f-b54aa4cdc4b7} => wmlbrowser -----------\\ [..\Internet Explorer\Main] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://www.google.fr/" "Search Page"="http://www.google.com" "Search Bar"="http://www.google.com/ie" "SearchMigratedDefaultURL"="http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8" [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main] "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157" "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896" "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896" "Start Page"="http://www.msn.com/" --------------------\\ Recherche d'autres infections --------------------\\ Cracks & Keygens .. C:\DOCUME~1\Nordine\Application Data\IDM\DwnlData\Nordine\Crack et s‚rial jeux soft e_71 C:\DOCUME~1\Nordine\Application Data\IDM\DwnlData\Nordine\Crack et s‚rial jeux soft e_72 C:\DOCUME~1\Nordine\Application Data\IDM\DwnlData\Nordine\Crack et s‚rial jeux soft e_71\log_71.log C:\DOCUME~1\Nordine\Application Data\IDM\DwnlData\Nordine\Crack et s‚rial jeux soft e_72\log_72.log C:\DOCUME~1\Nordine\Application Data\Microsoft\Office\Fichiers r‚cents\crack pour europe V7.lnk C:\DOCUME~1\Nordine\Application Data\Microsoft\Office\Fichiers r‚cents\Crack tomtom map version 7.doc.lnk C:\DOCUME~1\Nordine\Bureau\ttn_6.032_elrincondedey_crackeada.cab C:\DOCUME~1\Nordine\Bureau\Ad aware 2008 pro 7.0.1.11\Ad aware 2008 pro 7.0.1.11\CRACK a mettre dans le dossier d'installation a la fin de l'installation C:\DOCUME~1\Nordine\Bureau\Ad aware 2008 pro 7.0.1.11\Ad aware 2008 pro 7.0.1.11\CRACK a mettre dans le dossier d'installation a la fin de l'installation\lavalicense.dll C:\DOCUME~1\Nordine\Bureau\DOSSIERS\O&O Defrag 10.0.1670.Francais+keygen C:\DOCUME~1\Nordine\Bureau\DOSSIERS\aide et astuce divers\ASTUCE RECHERCHE CRACK.txt C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\Nero-8.1.1.0+keygen.zip C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack\AudStu.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack\midi studio 11.Key C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack\MusicManager.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\cle USB\magix music studio 2006 deluxe\Crack\PhotoManager.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\DIVX_6.8_upbyzeus\DIVX_6.8_upbyzeus\Keygen DivX AIO.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_ C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_.rar C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_\Crack Fruity Loops 7 rc6b - fixato il problema del key scaduto(by SimoDj).reg C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_\FLEngine.dll C:\DOCUME~1\Nordine\Bureau\DOSSIERS\NON UTILISER\Crack_Fruity_Loops_7_rc6b_-_fixato_il_problema_del_key_scaduto_by_SimoDj_\Readme.txt C:\DOCUME~1\Nordine\Bureau\DOSSIERS\O&O Defrag 10.0.1670.Francais+keygen\O&O Defrag 10.0.1670.Francais+keygen C:\DOCUME~1\Nordine\Bureau\DOSSIERS\O&O Defrag 10.0.1670.Francais+keygen\O&O Defrag 10.0.1670.Francais+keygen\o-o-defrag_o_o_defrag_10.0.1670_anglais_11995.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\O&O Defrag 10.0.1670.Francais+keygen\O&O Defrag 10.0.1670.Francais+keygen\OO Defrag 10 Keygen.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\vidal3006\Crack C:\DOCUME~1\Nordine\Bureau\DOSSIERS\vidal3006\Crack\Crack 3006 Vidal Expert.exe C:\DOCUME~1\Nordine\Bureau\DOSSIERS\vidal3006\Crack\… lire!!!!.txt C:\DOCUME~1\Nordine\Favoris\Bienvenue sur FranceCrack.com.url C:\DOCUME~1\Nordine\Favoris\DreamDDL.com - Full Version Download Crack Serial Keygen Torrent Rapidshare Free Warez.url C:\DOCUME~1\Nordine\Favoris\Fruity loops 7 problem du crack enfin r‚solu 2.url C:\DOCUME~1\Nordine\Favoris\Full Version Download with Crack Serial Keygen or Torrent from Rapidshare-Free Warez.url 1 - "C:\ToolBar SD\TB_1.txt" - 21/11/2008|17:16 - Option : [1] 2 - "C:\ToolBar SD\TB_2.txt" - 21/11/2008|17:18 - Option : [2] -----------\\ Fin du rapport a 17:18:56,20 ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== FILES ========== C:\Documents and Settings\Nordine\Bureau\DOSSIERS\NON UTILISER\telecherger vidéo youtube\VDownloader.exe moved successfully. C:\Documents and Settings\Nordine\Bureau\DOSSIERS\NON UTILISER\uploud\uploud moved successfully. File/Folder C:\Documents and Settings\Nordine\Favoris\sat\F.U.C - Najlepszy Upload TV Sat !! Nowa odslona !! not found. C:\Program Files\ESET\infected moved successfully. D:\utilitaires\ultravnc.zip moved successfully. File/Folder J:\Logiciels divers\keyfinder\keyfinder.exe not found. File/Folder J:\Logiciels divers\la petite mosquée dans la prairie Share Accelerator\ShareAcceleratorMM_SS07.EXE not found. File/Folder J:\Logiciels divers\Vista Activation Dual Boot Method.rar not found. File/Folder J:\MEDION\Progamme files\Visicom Media\FTP Expert 3\vmntoolbar\vmntoolbarsetup1.7_en.exe not found. File/Folder J:\MEDION\Bureau\DOSSIERS\NON UTILISER\incredimail_install.exe not found. File/Folder J:\MEDION\Bureau\DOSSIERS\NON UTILISER\telecherger vidéo youtube\VDownloader.exe not found. File/Folder J:\MEDION\Progamme files\ESET\infected not found. ========== REGISTRY ========== ========== COMMANDS ========== File delete failed. C:\DOCUME~1\Nordine\LOCALS~1\Temp\etilqs_ewkaZsXIOLrLNNHuwGid scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\CLML_AGENT_LOG1.txt scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\sqlite_7y4UV9TbqBXqR3G scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Nordine\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Nordine\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Nordine\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Nordine\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Nordine\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\urlclassifier3.sqlite scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11212008_174611 Merci beaucoup Dans l'attente Amicalement -
rapport Hijackthis
seroncamille a répondu à un(e) sujet de seroncamille dans Analyses et éradication malwares
Bonjour pear, voici enfin le rapport suite à ta prescription en espérant cette fois ci que c'est la bonne. en l'attente de te lire. amicalement. File C:\WINDOWS\system32\mswinsck.ocx infected by "Backdoor.Win32.VB.fnl" Virus. Action Taken: File Deleted. File C:\Documents and Settings\Nordine\Bureau\DOSSIERS\NON UTILISER\telecherger vidéo youtube\VDownloader.exe tagged as not-a-virus:Downloader.Win32.VDown.a. No Action Taken. File C:\Documents and Settings\Nordine\Bureau\DOSSIERS\NON UTILISER\uploud\uploud\DVHK UPLOAD strona glówna.url infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\Documents and Settings\Nordine\Bureau\DOSSIERS\NON UTILISER\uploud\uploud\F.U.C - Najlepszy Upload TV Sat !! Nowa odslona !!.url infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\Documents and Settings\Nordine\Favoris\sat\F.U.C - Najlepszy Upload TV Sat !! Nowa odslona !!.url infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\Program Files\ESET\infected\FH5QRNBA.NQF tagged as not-a-virus:WebToolbar.Win32.MyWebSearch.aw. No Action Taken. File C:\Program Files\ESET\infected\MHZIA0BA.NQF tagged as not-a-virus:WebToolbar.Win32.MyWebSearch.az. No Action Taken. File C:\Program Files\ESET\infected\VJV02XCA.NQF infected by "Trojan.Win32.Zapchast.fa" Virus. Action Taken: File Deleted. File C:\Program Files\ESET\infected\XHNECMBA.NQF infected by "Trojan.Win32.Zapchast.ez" Virus. Action Taken: File Deleted. File C:\RECYCLER\S-1-5-18\Dc1.rar infected by "Rootkit.Win32.Agent.eii" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Favoris\sat\F.U.C - Najlepszy Upload TV Sat !! Nowa odslona !!.url infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File D:\Documents and Settings\Nordine\Local Settings\Temp\11exhmrgml_2.exe infected by "Trojan.Win32.Zapchast.kx" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\13exhmreg2.exe infected by "Trojan.Win32.Zapchast.fk" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\15exhmreg2.exe infected by "Trojan.Win32.Zapchast.fk" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\20exhmrgml_2.exe infected by "Trojan.Win32.Zapchast.kx" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\30exhmrgml_2.exe infected by "Trojan.Win32.Zapchast.kx" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\40exhmrgml_5.exe infected by "Trojan.Win32.Zapchast.me" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\42exhmrgml_2.exe infected by "Trojan.Win32.Zapchast.kx" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\54exhmreg2.exe infected by "Trojan.Win32.Zapchast.fk" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\57exhmreg2.exe infected by "Trojan.Win32.Zapchast.fk" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\60exhmrgml_2.exe infected by "Trojan.Win32.Zapchast.kx" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\64exhmrgml_5.exe infected by "Trojan.Win32.Zapchast.me" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\65exhmrgml_2.exe infected by "Trojan.Win32.Zapchast.kx" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\75exhmrgml_2.exe infected by "Trojan.Win32.Zapchast.kx" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\80exhmreg2.exe infected by "Trojan.Win32.Zapchast.fk" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\86exhmrgml_5.exe infected by "Trojan.Win32.Zapchast.me" Virus. Action Taken: File Deleted. File D:\Documents and Settings\Nordine\Local Settings\Temp\89exhmreg2.exe infected by "Trojan.Win32.Zapchast.fk" Virus. Action Taken: File Deleted. File D:\mes documents\uploud\uploud\DVHK UPLOAD strona glówna.url infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File D:\mes documents\uploud\uploud\F.U.C - Najlepszy Upload TV Sat !! Nowa odslona !!.url infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File D:\utilitaires\DivXPro5GAINBundle.exe tagged as not-a-virus:AdWare.Win32.Gator.3102. No Action Taken. File D:\utilitaires\ultravnc.zip tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.c. No Action Taken. File J:\Logiciels divers\keyfinder\keyfinder.exe tagged as not-a-virus:PSWTool.Win32.RAS.a. No Action Taken. File J:\Logiciels divers\Driver Detective 6.0.6.5\Driver Detective 6.0.6.5.exe infected by "Trojan-Proxy.Win32.Mitglieder.ei" Virus. Action Taken: File Deleted. File J:\Logiciels divers\la petite mosquée dans la prairie Share Accelerator\ShareAcceleratorMM_SS07.EXE tagged as not-a-virus:AdWare.Win32.Shopper.k. No Action Taken. File J:\Logiciels divers\animation sony ericsson_fastest_BitTorrent_downloader.zip infected by "Trojan.Win32.Inject.ba" Virus. Action Taken: File Deleted. File J:\Logiciels divers\Driver Detective 6.0.6.5.zip infected by "Trojan-Proxy.Win32.Mitglieder.ei" Virus. Action Taken: File Deleted. File J:\Logiciels divers\Vista Activation Dual Boot Method.rar tagged as not-a-virus:PSWTool.Win32.RAS.g. No Action Taken. File J:\mur\Ma musique\France Gall\France Gall - Diego libre dans sa tzte.mp3 infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File J:\MEDION\Disque dur C\System Volume Information\_restore{E6C9CA23-D5A3-401C-B9B0-7C9F09E5F657}\RP799\A0145072.exe tagged as not-a-virus:AdWare.Win32.MegaSearch.n. No Action Taken. File J:\MEDION\Disque dur C\System Volume Information\_restore{E6C9CA23-D5A3-401C-B9B0-7C9F09E5F657}\RP798\A0142315.exe tagged as not-a-virus:AdWare.Win32.MegaSearch.n. No Action Taken. File J:\MEDION\Disque dur C\System Volume Information\_restore{E6C9CA23-D5A3-401C-B9B0-7C9F09E5F657}\RP794\A0139391.exe tagged as not-a-virus:AdWare.Win32.MegaSearch.n. No Action Taken. File J:\MEDION\Disque dur C\System Volume Information\_restore{E6C9CA23-D5A3-401C-B9B0-7C9F09E5F657}\RP791\A0137163.dll tagged as not-a-virus:AdWare.Win32.MegaSearch.n. No Action Taken. File J:\MEDION\Emule\Avs video converter v2.7 serial keygen.zip infected by "Trojan.Win32.Agent.bnj" Virus. Action Taken: File Deleted. File J:\MEDION\Emule\Blackice Firewall v3.6 by FFF serial keygen.zip infected by "Trojan.Win32.Agent.bnj" Virus. Action Taken: File Deleted. File J:\MEDION\Progamme files\eMule\Incoming\Avs video converter v2.7 serial keygen.zip infected by "Trojan.Win32.Agent.bnj" Virus. Action Taken: File Deleted. File J:\MEDION\Progamme files\eMule\Incoming\Blackice Firewall v3.6 by FFF serial keygen.zip infected by "Trojan.Win32.Agent.bnj" Virus. Action Taken: File Deleted. File J:\MEDION\Progamme files\ESET\infected\00NFGACA.NQF infected by "Backdoor.Win32.Agent.afj" Virus. Action Taken: File Renamed. File J:\MEDION\Progamme files\ESET\infected\3R1LGHDA.NQF infected by "Trojan-Downloader.Win32.LoadAdv.gen" Virus. Action Taken: File Deleted. File J:\MEDION\Progamme files\ESET\infected\4N4ZHVBA.NQF infected by "Trojan-Downloader.Win32.Agent.fbe" Virus. Action Taken: File Deleted. File J:\MEDION\Progamme files\ESET\infected\DVQHHOAA.NQF infected by "Trojan-Dropper.Win32.Small.ayg" Virus. Action Taken: File Deleted. File J:\MEDION\Progamme files\ESET\infected\FH5QRNBA.NQF tagged as not-a-virus:WebToolbar.Win32.MyWebSearch.aw. No Action Taken. File J:\MEDION\Progamme files\ESET\infected\MHZIA0BA.NQF tagged as not-a-virus:WebToolbar.Win32.MyWebSearch.az. No Action Taken. File J:\MEDION\Progamme files\ESET\infected\NLFVXCCA.NQF infected by "Trojan-Proxy.Win32.Horst.sv" Virus. Action Taken: File Deleted. File J:\MEDION\Progamme files\ESET\infected\QG42AODA.NQF infected by "P2P-Worm.Win32.Kapucen.b" Virus. Action Taken: File Deleted. File J:\MEDION\Progamme files\ESET\infected\TK4LULCA.NQF infected by "Trojan-Spy.Win32.BZub.buz" Virus. Action Taken: File Deleted. File J:\MEDION\Progamme files\ESET\infected\ZPT2HGAA.NQF tagged as not-a-virus:AdWare.Win32.Agent.bm. No Action Taken. File J:\MEDION\Progamme files\Visicom Media\FTP Expert 3\vmntoolbar\vmntoolbarsetup1.7_en.exe tagged as not-a-virus:AdWare.Win32.MegaSearch.n. No Action Taken. File J:\MEDION\Bureau\DOSSIERS\NON UTILISER\incredimail_install.exe tagged as not-a-virus:Downloader.Win32.ImLoader.e. No Action Taken. File J:\MEDION\Bureau\DOSSIERS\NON UTILISER\uploud\uploud\DVHK UPLOAD strona glówna.url infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File J:\MEDION\Bureau\DOSSIERS\NON UTILISER\uploud\uploud\F.U.C - Najlepszy Upload TV Sat !! Nowa odslona !!.url infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File J:\MEDION\Bureau\DOSSIERS\NON UTILISER\telecherger vidéo youtube\VDownloader.exe tagged as not-a-virus:Downloader.Win32.VDown.a. No Action Taken. -
rapport Hijackthis
seroncamille a répondu à un(e) sujet de seroncamille dans Analyses et éradication malwares
Autant pour moi j'ai zappé le copier/coller download vers kaspersky. ça suit son cours pour le moment. Merci -
rapport Hijackthis
seroncamille a répondu à un(e) sujet de seroncamille dans Analyses et éradication malwares
Bonjour, je reste bloqué sur la dernière face, à savoir en mode sans échec et en cliquant sur mwavscan.com, il s'affiche " Virus database is older than 30 days. We recommand that you doawnload the lastet .....from http///www.mwti.net. ". A cette adresse il n'y rien ?????? -
rapport Hijackthis
seroncamille a répondu à un(e) sujet de seroncamille dans Analyses et éradication malwares
Bonsoir, Kaspersky vient de terminer et de ce pas je vous colle son rapport que je trouve bizarre mais bon je suis novice. Merci de nouveau pour votre aide. ------------------------------------------------------------------------------- KASPERSKY ON-LINE SCANNER REPORT Wednesday, November 19, 2008 10:47:01 PM Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky On-line Scanner version : 5.0.84.2 Dernière mise à jour de la base antivirus Kaspersky : 19/11/2008 Enregistrements dans la base antivirus Kaspersky : 1250691 ------------------------------------------------------------------------------- Paramètres d'analyse: Analyser avec la base antivirus suivante: standard Analyser les archives: vrai Analyser les bases de messagerie: vrai Cible de l'analyse - Poste de travail: C:\ D:\ E:\ F:\ G:\ I:\ J:\ K:\ L:\ Statistiques de l'analyse: Total d'objets analysés: 258097 Nombre de virus trouvés: 24 Nombre d'objets infectés: 76 / 0 Nombre d'objets suspects: 0 Durée de l'analyse: 07:00:39 Nom de l'objet infecté / Nom du virus / Dernière action C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\0237\0192\values L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\cert8.db L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\content-prefs.sqlite L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\cookies.sqlite L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\downloads.sqlite L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\formhistory.sqlite L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\key3.db L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\parent.lock L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\permissions.sqlite L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\places.sqlite L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\places.sqlite-journal L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\search.sqlite L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Application Data\Sun\Java\Deployment\log\plugin150_06.trace L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Cookies\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\Cache\_CACHE_001_ L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\Cache\_CACHE_002_ L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\Cache\_CACHE_003_ L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\Cache\_CACHE_MAP_ L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Application Data\Mozilla\Firefox\Profiles\8ozqwreg.default\urlclassifier3.sqlite L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Application Data\Pando\Pando Files\cert\cert8.db L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Application Data\Pando\Pando Files\cert\key3.db L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Application Data\Pando\Pando Files\F4\08\F40864B5F607380B0C038CAB1D6AE754ED6968C0.dat L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Application Data\Pando\Pando Files\pando.log L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Historique\History.IE5\MSHist012008111920081120\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Temp\etilqs_ddMgVQVLQMPqTELSqLEp L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Temp\hsperfdata_Nordine\644 L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Temp\~DF2E13.tmp L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Temp\~DFFE84.tmp L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\ntuser.dat L'objet est verrouillé ignoré C:\Documents and Settings\Nordine\ntuser.dat.LOG L'objet est verrouillé ignoré C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\sw_ae-20081119-100756.log L'objet est verrouillé ignoré C:\Program Files\ESET\cache\CACHE.NDB L'objet est verrouillé ignoré C:\Program Files\ESET\infected\VJV02XCA.NQF Infecté : Trojan.Win32.Zapchast.fa ignoré C:\Program Files\ESET\infected\XHNECMBA.NQF Infecté : Trojan.Win32.Zapchast.ez ignoré C:\Program Files\ESET\logs\virlog.dat L'objet est verrouillé ignoré C:\Program Files\ESET\logs\warnlog.dat L'objet est verrouillé ignoré C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLML_MAIN\CLML.db L'objet est verrouillé ignoré C:\RECYCLER\S-1-5-18\Dc1.rar/27_gui_1.exe Infecté : Rootkit.Win32.Agent.eii ignoré C:\RECYCLER\S-1-5-18\Dc1.rar RAR: infecté - 1 ignoré C:\RECYCLER\S-1-5-18\Dc2.exe Infecté : Rootkit.Win32.Agent.eii ignoré C:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré C:\System Volume Information\_restore{E6C9CA23-D5A3-401C-B9B0-7C9F09E5F657}\RP3\change.log L'objet est verrouillé ignoré C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré C:\WINDOWS\SoftwareDistribution\EventCache\{2A021B29-A6E5-4372-8249-8E6A6B3AF92E}.bin L'objet est verrouillé ignoré C:\WINDOWS\SoftwareDistribution\EventCache\{BB8D9899-28FE-4C12-873F-2582CF5C48DF}.bin L'objet est verrouillé ignoré C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl L'objet est verrouillé ignoré C:\WINDOWS\system32\mswinsck.ocx Infecté : Backdoor.Win32.VB.fnl ignoré C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré C:\WINDOWS\Temp\CLML_AGENT_LOG1.txt L'objet est verrouillé ignoré C:\WINDOWS\Temp\sqlite_rf2fxEnzcaDYgM6 L'objet est verrouillé ignoré C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\11exhmrgml_2.exe Infecté : Trojan.Win32.Zapchast.kx ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\13exhmreg2.exe Infecté : Trojan.Win32.Zapchast.fk ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\15exhmreg2.exe Infecté : Trojan.Win32.Zapchast.fk ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\20exhmrgml_2.exe Infecté : Trojan.Win32.Zapchast.kx ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\30exhmrgml_2.exe Infecté : Trojan.Win32.Zapchast.kx ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\40exhmrgml_5.exe Infecté : Trojan.Win32.Zapchast.me ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\42exhmrgml_2.exe Infecté : Trojan.Win32.Zapchast.kx ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\54exhmreg2.exe Infecté : Trojan.Win32.Zapchast.fk ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\57exhmreg2.exe Infecté : Trojan.Win32.Zapchast.fk ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\60exhmrgml_2.exe Infecté : Trojan.Win32.Zapchast.kx ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\64exhmrgml_5.exe Infecté : Trojan.Win32.Zapchast.me ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\65exhmrgml_2.exe Infecté : Trojan.Win32.Zapchast.kx ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\75exhmrgml_2.exe Infecté : Trojan.Win32.Zapchast.kx ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\80exhmreg2.exe Infecté : Trojan.Win32.Zapchast.fk ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\86exhmrgml_5.exe Infecté : Trojan.Win32.Zapchast.me ignoré D:\Documents and Settings\Nordine\Local Settings\Temp\89exhmreg2.exe Infecté : Trojan.Win32.Zapchast.fk ignoré D:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré J:\System Volume Information\_restore{47FD84A0-C019-471C-9970-1F9B8F1B8B5E}\RP417\A0547941.exe/2.exe/run.exe Infecté : Trojan-Downloader.Win32.Agent.ion ignoré J:\System Volume Information\_restore{47FD84A0-C019-471C-9970-1F9B8F1B8B5E}\RP417\A0547941.exe/2.exe Infecté : Trojan-Downloader.Win32.Agent.ion ignoré J:\System Volume Information\_restore{47FD84A0-C019-471C-9970-1F9B8F1B8B5E}\RP417\A0547941.exe RAR: infecté - 2 ignoré J:\Logiciels divers\Driver Detective 6.0.6.5\Driver Detective 6.0.6.5.exe Infecté : Trojan-Proxy.Win32.Mitglieder.ei ignoré J:\Logiciels divers\animation sony ericsson_fastest_BitTorrent_downloader.zip/BitDownload-3.0-setup.exe/file12 Infecté : Trojan.Win32.Inject.ba ignoré J:\Logiciels divers\animation sony ericsson_fastest_BitTorrent_downloader.zip/BitDownload-3.0-setup.exe Infecté : Trojan.Win32.Inject.ba ignoré J:\Logiciels divers\animation sony ericsson_fastest_BitTorrent_downloader.zip ZIP: infecté - 2 ignoré J:\Logiciels divers\Driver Detective 6.0.6.5.zip/Driver Detective 6.0.6.5.exe Infecté : Trojan-Proxy.Win32.Mitglieder.ei ignoré J:\Logiciels divers\Driver Detective 6.0.6.5.zip ZIP: infecté - 1 ignoré J:\Logiciels divers\ESET.NOD32.Antivirus.Business.Edition.v3.0.566.CRACKED.rar/ESET.NOD32.Antivirus.Business.Edition.v3.0.566.CRACKED/setup.exe Infecté : Trojan.Win32.Buzus.vsy ignoré J:\Logiciels divers\ESET.NOD32.Antivirus.Business.Edition.v3.0.566.CRACKED.rar RAR: infecté - 1 ignoré J:\Logiciels divers\entretien PC\avg anti-spyware 7.5.1.43.rar/AVG Anti-Spyware 7.5.1.43.exe/2.exe/run.exe Infecté : Trojan-Downloader.Win32.Agent.ion ignoré J:\Logiciels divers\entretien PC\avg anti-spyware 7.5.1.43.rar/AVG Anti-Spyware 7.5.1.43.exe/2.exe Infecté : Trojan-Downloader.Win32.Agent.ion ignoré J:\Logiciels divers\entretien PC\avg anti-spyware 7.5.1.43.rar/AVG Anti-Spyware 7.5.1.43.exe Infecté : Trojan-Downloader.Win32.Agent.ion ignoré J:\Logiciels divers\entretien PC\avg anti-spyware 7.5.1.43.rar RAR: infecté - 3 ignoré J:\Logiciels divers\entretien PC\avg anti-spyware 7.5.1.43\AVG Anti-Spyware 7.5.1.43.exe/2.exe/run.exe Infecté : Trojan-Downloader.Win32.Agent.ion ignoré J:\Logiciels divers\entretien PC\avg anti-spyware 7.5.1.43\AVG Anti-Spyware 7.5.1.43.exe/2.exe Infecté : Trojan-Downloader.Win32.Agent.ion ignoré J:\Logiciels divers\entretien PC\avg anti-spyware 7.5.1.43\AVG Anti-Spyware 7.5.1.43.exe RAR: infecté - 2 ignoré J:\Logiciels divers\ESET.NOD32.Antivirus.Business.Edition.v3.0.566.CRACKED\ESET.NOD32.Antivirus.Business.Edition.v3.0.566.CRACKED\setup.exe Infecté : Trojan.Win32.Buzus.vsy ignoré J:\C nordine\incoming1\log ps2\_ Comment Graver Les Jeux Playstation® 2 _ ( ps2 gravure jeu video facile logiciel adapté cd-rom 702mo) _ by Fifoune _ 4\CDRWIN.v6.1.1.0.Incl.Keygen-Virility.rar/cdrwin6.exe Infecté : Trojan-Dropper.Win32.Agent.agp ignoré J:\C nordine\incoming1\log ps2\_ Comment Graver Les Jeux Playstation® 2 _ ( ps2 gravure jeu video facile logiciel adapté cd-rom 702mo) _ by Fifoune _ 4\CDRWIN.v6.1.1.0.Incl.Keygen-Virility.rar RAR: infecté - 1 ignoré J:\C nordine\incoming1\log ps2\_ Comment Graver Les Jeux Playstation® 2 _ ( ps2 gravure jeu video facile logiciel adapté cd-rom 702mo) _ by Fifoune _ 4\CDRWIN.v6.1.1.0.Incl.Keygen-Virility\cdrwin6.exe Infecté : Trojan-Dropper.Win32.Agent.agp ignoré J:\MEDION\Disque dur C\System Volume Information\_restore{E6C9CA23-D5A3-401C-B9B0-7C9F09E5F657}\RP755\A0129233.exe Infecté : Trojan-Dropper.Win32.Agent.agp ignoré J:\MEDION\Emule\Avs video converter v2.7 serial keygen.zip/Avs video converter v2.7.exe Infecté : Trojan.Win32.Agent.bnj ignoré J:\MEDION\Emule\Avs video converter v2.7 serial keygen.zip ZIP: infecté - 1 ignoré J:\MEDION\Emule\Blackice Firewall v3.6 by FFF serial keygen.zip/Blackice Firewall v3.6 by FFF.exe Infecté : Trojan.Win32.Agent.bnj ignoré J:\MEDION\Emule\Blackice Firewall v3.6 by FFF serial keygen.zip ZIP: infecté - 1 ignoré J:\MEDION\Emule\Samsung e900 Fonds D Ecran Et Gifs Animes - 240 X 320(1).rar/setup.exe Infecté : P2P-Worm.Win32.Kapucen.b ignoré J:\MEDION\Emule\Samsung e900 Fonds D Ecran Et Gifs Animes - 240 X 320(1).rar RAR: infecté - 1 ignoré J:\MEDION\Progamme files\eMule\Incoming\Avs video converter v2.7 serial keygen.zip/Avs video converter v2.7.exe Infecté : Trojan.Win32.Agent.bnj ignoré J:\MEDION\Progamme files\eMule\Incoming\Avs video converter v2.7 serial keygen.zip ZIP: infecté - 1 ignoré J:\MEDION\Progamme files\eMule\Incoming\Blackice Firewall v3.6 by FFF serial keygen.zip/Blackice Firewall v3.6 by FFF.exe Infecté : Trojan.Win32.Agent.bnj ignoré J:\MEDION\Progamme files\eMule\Incoming\Blackice Firewall v3.6 by FFF serial keygen.zip ZIP: infecté - 1 ignoré J:\MEDION\Progamme files\eMule\Incoming\Samsung e900 Fonds D Ecran Et Gifs Animes - 240 X 320(1).rar/setup.exe Infecté : P2P-Worm.Win32.Kapucen.b ignoré J:\MEDION\Progamme files\eMule\Incoming\Samsung e900 Fonds D Ecran Et Gifs Animes - 240 X 320(1).rar RAR: infecté - 1 ignoré J:\MEDION\Progamme files\ESET\infected\00NFGACA.NQF Infecté : Backdoor.Win32.Agent.afj ignoré J:\MEDION\Progamme files\ESET\infected\3R1LGHDA.NQF/keygen.exe Infecté : Trojan-Downloader.Win32.LoadAdv.gen ignoré J:\MEDION\Progamme files\ESET\infected\3R1LGHDA.NQF/crack.exe Infecté : Trojan.Win32.Agent.apt ignoré J:\MEDION\Progamme files\ESET\infected\3R1LGHDA.NQF/serial.exe Infecté : Trojan.Win32.Dialer.qn ignoré J:\MEDION\Progamme files\ESET\infected\3R1LGHDA.NQF/install.exe Infecté : Trojan-Downloader.Win32.Agent.bls ignoré J:\MEDION\Progamme files\ESET\infected\3R1LGHDA.NQF RAR: infecté - 4 ignoré J:\MEDION\Progamme files\ESET\infected\3R1LGHDA.NQF PE-Crypt.XorPE: infecté - 4 ignoré J:\MEDION\Progamme files\ESET\infected\4N4ZHVBA.NQF Infecté : Trojan-Downloader.Win32.Agent.fbe ignoré J:\MEDION\Progamme files\ESET\infected\DVQHHOAA.NQF/keygen.exe Infecté : Trojan-Dropper.Win32.Small.ayg ignoré J:\MEDION\Progamme files\ESET\infected\DVQHHOAA.NQF/serial.exe Infecté : Trojan.Win32.Dialer.qn ignoré J:\MEDION\Progamme files\ESET\infected\DVQHHOAA.NQF/install.exe Infecté : Trojan-Downloader.Win32.Small.eqn ignoré J:\MEDION\Progamme files\ESET\infected\DVQHHOAA.NQF RAR: infecté - 3 ignoré J:\MEDION\Progamme files\ESET\infected\DVQHHOAA.NQF PE-Crypt.XorPE: infecté - 3 ignoré J:\MEDION\Progamme files\ESET\infected\NLFVXCCA.NQF Infecté : Trojan-Proxy.Win32.Horst.sv ignoré J:\MEDION\Progamme files\ESET\infected\QG42AODA.NQF Infecté : P2P-Worm.Win32.Kapucen.b ignoré J:\MEDION\Progamme files\ESET\infected\TK4LULCA.NQF Infecté : Trojan-Spy.Win32.BZub.buz ignoré J:\MEDION\Bureau\DOSSIERS\NON UTILISER\avg anti-spyware 7.5.1.43\AVG Anti-Spyware 7.5.1.43.exe/2.exe/run.exe Infecté : Trojan-Downloader.Win32.Agent.ion ignoré J:\MEDION\Bureau\DOSSIERS\NON UTILISER\avg anti-spyware 7.5.1.43\AVG Anti-Spyware 7.5.1.43.exe/2.exe Infecté : Trojan-Downloader.Win32.Agent.ion ignoré J:\MEDION\Bureau\DOSSIERS\NON UTILISER\avg anti-spyware 7.5.1.43\AVG Anti-Spyware 7.5.1.43.exe RAR: infecté - 2 ignoré Analyse terminée. -
rapport Hijackthis
seroncamille a répondu à un(e) sujet de seroncamille dans Analyses et éradication malwares
Bonjour, Effectivement le scan précedant a été effectué en mode. Suivant vos conseils, je vous post le dernier scan. Merci pour tout. Malwarebytes' Anti-Malware 1.30 Version de la base de données: 1410 Windows 5.1.2600 Service Pack 2 19/11/2008 12:14:02 mbam-log-2008-11-19 (12-14-02).txt Type de recherche: Examen complet (C:\|D:\|E:\|H:\|J:\|) Eléments examinés: 306341 Temps écoulé: 1 hour(s), 48 minute(s), 36 second(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 0 Valeur(s) du Registre infectée(s): 0 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 0 Fichier(s) infecté(s): 0 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): (Aucun élément nuisible détecté) Clé(s) du Registre infectée(s): (Aucun élément nuisible détecté) Valeur(s) du Registre infectée(s): (Aucun élément nuisible détecté) Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): (Aucun élément nuisible détecté) Fichier(s) infecté(s): (Aucun élément nuisible détecté) -
rapport Hijackthis
seroncamille a répondu à un(e) sujet de seroncamille dans Analyses et éradication malwares
Merci de la réponse. Avant que je ne fasse une autre erreur le scan avec MBAM doit se faire en mode normal ou en mode sans echec? -
rapport Hijackthis
seroncamille a répondu à un(e) sujet de seroncamille dans Analyses et éradication malwares
Bonsoir Pear, Merci de ta réponse qui a était rapide. Le temps d'un scan avec antivir puis Sdfix et Malwarebytes, la journée s'est vite écoulée. Donc voici les deux rapports dans l'ordre d'exécution et merci encore pour tes conseils et ton diag que j'attends avec impatience. SDFix: Version 1.240 Run by Nordine on 18/11/2008 at 11:22 Microsoft Windows XP [version 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : No Trojan Files Found Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-18 12:27:54 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04] "p0"="C:\Program Files\Alcohol Soft\Alcohol 120\" "h0"=dword:00000000 "ujdew"=hex:5a,d1,5b,68,50,b6,3d,5e,37,46,8b,db,bb,3e,c2,ba,bf,a9,ae,c0,c8,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "h0"=dword:00000001 "khjeh"=hex:ac,54,cd,c7,3f,f6,00,18,e1,7d,9f,22,16,2d,9c,41,73,74,b9,cc,89,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04] "p0"="C:\Program Files\Alcohol Soft\Alcohol 120\" "h0"=dword:00000000 "ujdew"=hex:5a,d1,5b,68,50,b6,3d,5e,37,46,8b,db,bb,3e,c2,ba,bf,a9,ae,c0,c8,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04] "p0"="C:\Program Files\Alcohol Soft\Alcohol 120\" "h0"=dword:00000000 "ujdew"=hex:5a,d1,5b,68,50,b6,3d,5e,37,46,8b,db,bb,3e,c2,ba,bf,a9,ae,c0,c8,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "h0"=dword:00000001 "khjeh"=hex:ac,54,cd,c7,3f,f6,00,18,e1,7d,9f,22,16,2d,9c,41,73,74,b9,cc,89,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04] "p0"="C:\Program Files\Alcohol Soft\Alcohol 120\" "h0"=dword:00000000 "ujdew"=hex:5a,d1,5b,68,50,b6,3d,5e,37,46,8b,db,bb,3e,c2,ba,bf,a9,ae,c0,c8,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4] "h0"=dword:00000001 "khjeh"=hex:ac,54,cd,c7,3f,f6,00,18,e1,7d,9f,22,16,2d,9c,41,73,74,b9,cc,89,.. scanning hidden registry entries ... [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System] "OODEFRAG10.00.00.01WORKSTATION"="9C18BB89BCBA78DDC7253A3137010827C3F59A31F3254D656AB821E1891121D529AF5E03E6E 348484ADBBB14CD24E2BF0BAF5B3F0CF9B62507D7C3568E83400AED105958C12F19FB0D8B2F904328 2B67A76A9EC0E05BB387A3BFB757E8819D6A79A8FCBFCB401D8683F36F368A522D549357EABBFBCEC E0DDE33D106D6731EE230EE0A129601B758F6DBCCB8AAADEB239CAC3E5DF8A0C61BAB79DAA828835F BF4ADAB74EC89E01CA858D0AEC3F071C52E2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC 74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC79338EDD5E5BE2F6E6 67A6171C11EC38DE3DFEBC9E127BECC74CF7668377667B1A5872E7BA7118F8786C7256BB2EBDC022F BFE6C796BBEAA5669823F21558B07B97EF6D16FF6CB16740E976A1AF7984D6354A6C6CE304EE5DD33 4C12BA87EB49053BF1B4A424803D2A04BFF01AF0A771BBD1A3CAA7E499CBCD1362CC24A9CC91AA224 38E8A8E1DDA6F66C191E4411257CA355AEDC665A9E1B08BDC52D8EF36E4BB9D50CC735B4B90822471 68C326455E938FB1988FA4CAE37376D0F7F69FF4FB2F69845355477AB4017E2B86A86F6E1980C795A 70BA70C43E6FD5E0740931C43E015CB78CC20DBCFEE8BCBED268180CCDC98756D650742A1412324BE 98B97F5A8C8799861849659F3335B71A75D333F4D91245AC717186D69A38C6D08C14B897567861BE1 ABB521599B75473717482400B95FC212326336FF1E46FE249B8A40245F41E51D9801F57D1A68C5C9A 81AB1169DA1775137CE8A92727CB8F1F5365D6C25DCDE781B90FBE6EE64FA793B0337ED06C14CC00D B0CF9814C8A640621DD861C67F19CE018A7D967338F9EA6C9E0D182A8773AC7C2C58729FA61639774 B935061B8EFD6BE334681998C3FBBD283E0A22434947704280AD2BA788829033E4BB9555AF8F36774 261C0F7E5EF69BD1BD9B7411472A3FE6DFBF820BD2CD3D990A6C547E147FC44A3EE8289F49EDD0F8A A7B1FE692BAEB380B66903C0BEE67332B574F3B6129F4BEDEB6754F421F233E38E5D2BDAD601ABF1D 3B4C5560CF424825FE3B743CD1F257C6CD8B7E902A35542DB72C7014FB0C93D0178AE46584921FE4A BABBA14DA47CEDB5A7E4E04290B8859306AC7860F403A39B37D9DE6057B6E8D30482F0587891A23F8 66267D47D304F6B97035F4B2D5F293954B7EF513641C40C2DE051A90CB5C1390C0910235323884D06 CB5A46D77E159F1A8B4E4B1DB35DB7897FE76FF0D236033587F1091C8E5A58165710F81C8F74CAB56 C52E66C143DCFCE5ADF4E5D622D34E0DEA7D40903B5DF6E4E2D01C1D896EA3A48D92EA37DB7001743 E55C2EF3971552E54F4C6DA34D691EA960EFB53390639A5CC39C6B1E61A9625F2CA461AA2EA2B0458 C28C12B97B094BA5EC9888CB9CAB1" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{633EEBD2-A350-B286-FD31-806F0554F1E2}] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8B7289BA-4A7F-1CB5-578A-D294BC89C994}] "fabegaompjnn"=hex:66,61,68,68,68,64,6e,69,68,63,6b,6c,00,00 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8D99BE76-60C7-111E-BF04-7CD4269C9781}] "abblchjkhgcgemigafjfcclademijkhkkn"=hex:61,61,00,00 "bbblchjkhgcgemigafgfjdkbpnamlgedmohh"=hex:61,61,00,00 scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:enabled:Assistance … distance" "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:enabled:Windows Messenger" "C:\\WINDOWS\\system32\\fxsclnt.exe"="C:\\WINDOWS\\system32\\fxsclnt.exe:*:enabled:Microsoft Fax Console" "C:\\Program Files\\AOL 9.0\\WAOL.exe"="C:\\Program Files\\AOL 9.0\\WAOL.exe:*:Disabled:AOL 9.0" "C:\\Program Files\\AOL 9.0\\AOL.exe"="C:\\Program Files\\AOL 9.0\\AOL.exe:*:Disabled:AOL 9.0" "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDIAL.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDIAL.exe:*:Disabled:AOL 9.0 (Connectivity Service Dialer)" "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLACSD.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLACSD.exe:*:Disabled:AOL 9.0 (Connectivity Service)" "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule" "C:\\Program Files\\MaxTV Online\\maxtv.exe"="C:\\Program Files\\MaxTV Online\\maxtv.exe:*:Enabled:maxtv" "C:\\MAGIX\\music_manager\\MusicManager.exe"="C:\\MAGIX\\music_manager\\MusicManager.exe:*:Enabled:MAGIX Music Manager 2005" "C:\\Program Files\\MaxTV Online\\plugins\\PeerCast.exe"="C:\\Program Files\\MaxTV Online\\plugins\\PeerCast.exe:*:Enabled:PeerCast" "C:\\Program Files\\VIDAL\\Communs\\HmkIp32.exe"="C:\\Program Files\\VIDAL\\Communs\\HmkIp32.exe:*:Enabled:HmkIp32" "C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"="C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe:*:Enabled:BlueSoleil" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\adslTV\\adslTV.exe"="C:\\Program Files\\adslTV\\adslTV.exe:*:Enabled:adslTV" "C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:æTorrent" "C:\\mcoinstall.exe"="C:\\mcoinstall.exe:*:Enabled:mcoinstall" "C:\\Program Files\\MSN Messenger\\mcoinstall.exe"="C:\\Program Files\\MSN Messenger\\mcoinstall.exe:*:Enabled:mcoinstall" "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Disabled:Logitech Desktop Messenger" "C:\\Program Files\\BitTorrent_DNA\\dna.exe"="C:\\Program Files\\BitTorrent_DNA\\dna.exe:*:Enabled:DNA" "C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" "C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"="C:\\Program Files\\IncrediMail\\bin\\ImApp.exe:*:Enabled:IncrediMail" "C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail" "C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail" "C:\\Documents and Settings\\Nordine\\Local Settings\\Temp\\FlashGet Portable\\flashget.exe"="C:\\Documents and Settings\\Nordine\\Local Settings\\Temp\\FlashGet Portable\\flashget.exe:*:Enabled:Flashget" "C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"="C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe:*:Enabled:Nokia Software Updater" "C:\\Program Files\\Fichiers communs\\Nokia\\Service Layer\\A\\nsl_host_process.exe"="C:\\Program Files\\Fichiers communs\\Nokia\\Service Layer\\A\\nsl_host_process.exe:*:Enabled:Nokia Service Layer Host Process " "C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA" "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Pando Networks\\Pando\\pando.exe"="C:\\Program Files\\Pando Networks\\Pando\\pando.exe:*:Enabled:Pando Application" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:enabled:Assistance … distance" "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:enabled:Windows Messenger" "C:\\Program Files\\AOL 9.0\\AOL.exe"="C:\\Program Files\\AOL 9.0\\AOL.exe:*:enabled:AOL 9.0" "C:\\Program Files\\AOL 9.0\\WAOL.exe"="C:\\Program Files\\AOL 9.0\\WAOL.exe:*:enabled:AOL 9.0" "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLACSD.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLACSD.exe:*:enabled:AOL 9.0 (Connectivity Service)" "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDIAL.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDIAL.exe:*:enabled:AOL 9.0 (Connectivity Service Dialer)" "C:\\WINDOWS\\system32\\fxsclnt.exe"="C:\\WINDOWS\\system32\\fxsclnt.exe:*:enabled:Microsoft Fax Console" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" Remaining Files : Files with Hidden Attributes : Wed 22 Oct 2008 949,072 A.SHR --- "C:\Program Files\File Scanner Library (Spybot - Search & Destroy)\advcheck.dll" Wed 22 Oct 2008 962,896 A.SHR --- "C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)\Tools.dll" Mon 15 Sep 2008 1,562,960 A.SHR --- "C:\Program Files\SDHelper (Spybot - Search & Destroy)\SDHelper.dll" Tue 16 Sep 2008 1,833,296 A.SHR --- "C:\Program Files\TeaTimer (Spybot - Search & Destroy)\TeaTimer.exe" Fri 4 Nov 2005 56 A.SHR --- "C:\WINDOWS\system32\07E9BADCB3.sys" Thu 22 Jun 2006 56 A.SHR --- "C:\WINDOWS\system32\53875BDCAC.sys" Wed 19 Oct 2005 8 A.SHR --- "C:\WINDOWS\system32\CFE20AE075.sys" Thu 22 Jun 2006 10,332 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys" Fri 23 Jun 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Mon 19 Sep 2005 1,851,392 A..HR --- "C:\Program Files\Microsoft Works Suite 2006\Setup\launcher.exe" Fri 5 Nov 2004 53,760 A..HR --- "C:\Program Files\Microsoft Works Suite 2006\Setup\mnyinsta.dll" Fri 22 Apr 2005 95,232 A..HR --- "C:\Program Files\Microsoft Works Suite 2006\Setup\RmvSuite.exe" Tue 6 Sep 2005 36,864 A..HR --- "C:\Program Files\Microsoft Works Suite 2006\Setup\setuplng.dll" Thu 7 Jul 2005 20,480 A..HR --- "C:\Program Files\Microsoft Works Suite 2006\Setup\unregwtr.exe" Fri 8 Dec 2006 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp" Sun 10 Sep 2006 96 A..H. --- "C:\Program Files\Common Files\X10\Common\x10prod.sys" Finished! Malwarebytes' Anti-Malware 1.30 Version de la base de données: 1406 Windows 5.1.2600 Service Pack 2 18/11/2008 17:14:08 mbam-log-2008-11-18 (17-13-59).txt Type de recherche: Examen complet (C:\|D:\|E:\|J:\|) Eléments examinés: 309603 Temps écoulé: 3 hour(s), 44 minute(s), 4 second(s) Processus mémoire infecté(s): 0 Module(s) mémoire infecté(s): 0 Clé(s) du Registre infectée(s): 9 Valeur(s) du Registre infectée(s): 4 Elément(s) de données du Registre infecté(s): 0 Dossier(s) infecté(s): 7 Fichier(s) infecté(s): 32 Processus mémoire infecté(s): (Aucun élément nuisible détecté) Module(s) mémoire infecté(s): (Aucun élément nuisible détecté) Clé(s) du Registre infectée(s): HKEY_CLASSES_ROOT\CLSID\{b69a9db4-d0a1-4722-b56b-f20757a29cdf} (Adware.Agent) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b69a9db4-d0a1-4722-b56b-f20757a29cdf} (Adware.Agent) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b69a9db4-d0a1-4722-b56b-f20757a29cdf} (Adware.Agent) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> No action taken. HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000005-0000-0000-0000-100011000004} (Trojan.Downloader) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Live_TV (Adware.Agent) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Live_TV (Adware.Agent) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Live_TV Toolbar (Adware.Agent) -> No action taken. Valeur(s) du Registre infectée(s): HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{b69a9db4-d0a1-4722-b56b-f20757a29cdf} (Adware.Agent) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{b69a9db4-d0a1-4722-b56b-f20757a29cdf} (Adware.Agent) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{b69a9db4-d0a1-4722-b56b-f20757a29cdf} (Adware.Agent) -> No action taken. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{b69a9db4-d0a1-4722-b56b-f20757a29cdf} (Adware.Agent) -> No action taken. Elément(s) de données du Registre infecté(s): (Aucun élément nuisible détecté) Dossier(s) infecté(s): C:\Program Files\Live_TV (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\CacheIcons (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\CacheIcons (Adware.Agent) -> Files: 537 -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\Logs (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\RadioPlayer (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\rss (Adware.Agent) -> No action taken. Fichier(s) infecté(s): C:\Program Files\Live_TV\tbLiv1.dll (Adware.Agent) -> No action taken. C:\Program Files\Live_TV\tbLiv0.dll (Adware.Shopper) -> No action taken. C:\Program Files\Live_TV\tbLive.dll (Adware.Shopper) -> No action taken. C:\Program Files\Multi_Media_France\tbMul1.dll (Adware.Shopper) -> No action taken. D:\ net\TELECHARGER SONNERIE GRATUIT\cr-idm5e\CORE10k.EXE (Trojan.Agent) -> No action taken. J:\Logiciels divers\pour valider xp\Pack validation wga dÚfinitif\Pack validation wga définitif\Windows XP Keygen.exe (Malware.Tool) -> No action taken. J:\Mes documents\cr-idm5e\CORE10k.EXE (Trojan.Agent) -> No action taken. J:\C nordine\incoming1\Apple.QuickTime.Pro.v7.2.0.240.Multilingual.Regged-CORE\cr-qt720\CORE10k.EXE (Trojan.Agent) -> No action taken. J:\MEDION\Disque dur C\System Volume Information\_restore{E6C9CA23-D5A3-401C-B9B0-7C9F09E5F657}\RP755\A0129105.EXE (Trojan.Agent) -> No action taken. J:\MEDION\Progamme files\Live_TV\tbLiv0.dll (Adware.Shopper) -> No action taken. J:\MEDION\Progamme files\Live_TV\tbLive.dll (Adware.Shopper) -> No action taken. J:\MEDION\Progamme files\Multi_Media_France\tbMul1.dll (Adware.Shopper) -> No action taken. C:\Program Files\Live_TV\INSTALL.LOG (Adware.Agent) -> No action taken. C:\Program Files\Live_TV\toolbar.cfg (Adware.Agent) -> No action taken. C:\Program Files\Live_TV\UNWISE.EXE (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\LanguagePack.xml (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\LocalSettings.txt (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\ThirdPartyComponents.xml (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\update.xml (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\RadioPlayer\Predefined_Media_List.xml (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\rss\http___feeds_feedburner_com_metacafe_TYps.xml (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\rss\http___feeds_feedburner_com_metacafe_TYps_history.xml (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\rss\http___feeds_feedburner_com_metacafe_TYps_structured.xml (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\rss\http___video_google_com_videofeed_type=top100new&num=20&output=rss.xml (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\rss\http___video_google_com_videofeed_type=top100new&num=20&output=rss_history.xml (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\rss\http___video_google_com_videofeed_type=top100new&num=20&output=rss_structured.xml (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\rss\http___youtube_com_rss_global_top_viewed_today_rss.xml (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\rss\http___youtube_com_rss_global_top_viewed_today_rss.xml.tmp (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\rss\http___youtube_com_rss_global_top_viewed_today_rss_history.xml (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\rss\http___youtube_com_rss_global_top_viewed_today_rss_structured.xml (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\rss\slc=0&floc=1&sabfmts=2&saprclo=150&sascs=2&saprchi=550&saaff=afepn&ftrv=8&fbfmt=1&ftrt=1&fcl=3&ft=1&frpp=50&customid=&nojspr=y&satitle=new&afmp=&sacat=293&saslop=1&fss=0.xml (Adware.Agent) -> No action taken. C:\Documents and Settings\Nordine\Local Settings\Application Data\Live_TV\rss\slc=0&floc=1&sabfmts=2&saprclo=150&sascs=2&saprchi=550&saaff=afepn&ftrv=8&fbfmt=1&ftrt=1&fcl=3&ft=1&frpp=50&customid=&nojspr=y&satitle=new&afmp=&sacat=293&saslop=1&fss=0.xml.tmp (Adware.Agent) -> No action taken. Amicalement. -
Bonjour, suite à une réparation de windows (gros virus) le pc est extrémement lent, les dossiers ne s'ouvrent pas vite et l'écran se fige souvent. Je vous joint le rapport et merci de vos conseils. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:03:01, on 17/11/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\CmUCReye.exe C:\Program Files\Eset\nod32kui.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe C:\WINDOWS\System32\GEARSec.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe C:\Program Files\Eset\nod32krn.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\oodag.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lavasoft\Ad-aware 6\Ad-watch.exe C:\Documents and Settings\Nordine\Bureau\HiJackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = : R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll R3 - URLSearchHook: Live TV Toolbar - {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - C:\Program Files\Live_TV\tbLiv1.dll R3 - URLSearchHook: (no name) - {06663B56-0D73-4f9f-BCC5-4AA941470AFD} - C:\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: Pando Search Assistant BHO - {06663B51-0D73-4f9f-BCC5-4AA941470AFD} - C:\Program Files\PandoBar\SrchAstt\1.bin\P4SRCHAS.DLL O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.3558\swg.dll O2 - BHO: Live TV Toolbar - {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - C:\Program Files\Live_TV\tbLiv1.dll O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file) O3 - Toolbar: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMul0.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: (no name) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - (no file) O3 - Toolbar: Live TV Toolbar - {b69a9db4-d0a1-4722-b56b-f20757a29cdf} - C:\Program Files\Live_TV\tbLiv1.dll O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - (no file) O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\zyzoom.exe" /minimized O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [CmUCRRun] C:\WINDOWS\system32\CmUCReye.exe O4 - HKLM\..\Run: [CHotkey] mHotkey.exe O4 - HKLM\..\Run: [MedionVFD] "C:\Program Files\Medion Info Display\MdionLCM.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [devenv] C:\WINDOWS\system\smvss.exe /w O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user') O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Tout Télécharger avec Net Transport - C:\PROGRA~1\Xi\NETTRA~1\NTAddList.html O8 - Extra context menu item: Télécharger avec Net Transport - C:\PROGRA~1\Xi\NETTRA~1\NTAddLink.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: (no name) - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - (no file) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1129731383765 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1131096353671 O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O18 - Protocol: bw+0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: offline-8876480 - {DF18A746-F60E-41C0-B4C5-41587258202E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: BlackICE - Unknown owner - C:\Program Files\ISS\BlackICE\blackd.exe (file missing) O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTServ.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe (file missing) O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe O23 - Service: RapApp - Unknown owner - C:\Program Files\ISS\BlackICE\rapapp.exe (file missing) O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe O23 - Service: V2i Protector - PowerQuest Corporation - C:\Program Files\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe O24 - Desktop Component 0: (no name) - http://www.gtdesktop.com/gtripple/screen01small.jpg -- End of file - 24662 bytes