Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

voici mon log hijackthis

 

 

Logfile of HijackThis v1.99.1

Scan saved at 16:49:42, on 21/10/2006

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\WINDOWS\system32\RunDll32.exe

C:\Program Files\Digital Media Reader\shwiconem.exe

C:\WINDOWS\AGRSMMSG.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\CyberLink\PowerCinema\PCMService.exe

C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Messenger\msmsgs.exe

F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe

C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Program Files\AntiVir PersonalEdition Classic\sched.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Program Files\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O1 - Hosts: 67.183.235.156 l2testauthd.lineage2.com

O1 - Hosts: 67.183.235.156 l2authd.lineage2.com

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - F:\PROGRA~1\FlashGet\jccatch.dll

O2 - BHO: Seekmo Search Assistant Helper - {5929CD6E-2062-44a4-B2C5-2C7E78FBAB38} - c:\program files\seekmo\seekmohook.dll (file missing)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - F:\Program Files\Xi\NetTransport 2\NTIEHelper.dll

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - F:\PROGRA~1\FlashGet\fgiebar.dll

O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE

O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"

O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [sunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"

O4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [bDSwitchAgent] "C:\progra~1\softwin\bitdef~1\bdswitch.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\TWINTO~1\MouseElf.EXE

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [bullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe

O4 - HKLM\..\Run: [vmtalk] C:\Program Files\Fichiers communs\Talkway\vmtalk.exe

O4 - HKLM\..\Run: [MNI.UWFX5V_0001_LP1710] "C:\Documents and Settings\pccity\Bureau\Nouveau dossier\WinFixer2005ScannerInstallFRA.exe"

O4 - HKLM\..\Run: [install5G] D:\Install.exe /SI=40

O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [Pando] "F:\Program Files\Pando Networks\Pando\Pando.exe" /Automation

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKCU\..\Run: [steam] "c:\program files\valve\steam\steam.exe" -silent

O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [LDM] F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"

O4 - HKCU\..\Run: [Free Download Manager] F:\Program Files\Free Download Manager\fdm.exe -autorun

O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

O4 - Startup: Eurobarre.lnk = C:\Program Files\eurobarre\eb.exe

O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: FreeventsSchedule.lnk = C:\Philips\FreelineSchedule.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

O4 - Global Startup: Logitech SetPoint.lnk = F:\Program Files\Logitech\SetPoint\SetPoint.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O4 - Global Startup: MioSync.lnk = C:\Program Files\Mio Technology\MioSync\mioSync.exe

O4 - Global Startup: RaConfig2500.lnk = C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe

O8 - Extra context menu item: &Télécharger avec NetTransport - F:\Program Files\Xi\NetTransport 2\NTAddLink.html

O8 - Extra context menu item: Tout t&élécharger avec NetTransport - F:\Program Files\Xi\NetTransport 2\NTAddList.html

O8 - Extra context menu item: Télécharger avec FlashGet - F:\Program Files\FlashGet\jc_link.htm

O8 - Extra context menu item: Télécharger tout avec FlashGet - F:\Program Files\FlashGet\jc_all.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll

O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - F:\PROGRA~1\FlashGet\flashget.exe

O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - F:\PROGRA~1\FlashGet\flashget.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O18 - Protocol: bw+0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw+0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: bwg0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwg0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: offline-8876480 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe

Partager ce message


Lien à poster
Partager sur d’autres sites

Bonjour Palta !

 

Analyse en cours retour dans un instant !

 

Re

 

Fais ceci STP

 

1ére étape :

 

Télécharge AVG Anti-Spyware

  1. Lance AVG Anti-Spyware et clique sur le bouton Update (barre d'outils - au haut). Sous Manual Update clique Start update.
     
  2. Tu verras ceci juste au bas, lorsque la mise à jour sera complétée : "Update successful"
     
  3. Ferme AVG Anti-Spyware. Ne pas le lancer tout de suite.

Télécharger ATF Cleaner par Atribune.

http://www.atribune.org/ccount/click.php?id=1

 

Télécharger SmitfraudFix de S!Ri :P sur http://siri.urz.free.fr/Fix/SmitfraudFix.zip

Dézipper la totalité de l'archive smitfraudfix.zip

-Son tutorial

http://siri.urz.free.fr/Fix/SmitfraudFix.php

 

process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky...) comme étant un RiskTool.

Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.

 

Utilisation ----- option 1 - Recherche :

Double cliquer sur smitfraudfix.cmd

Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

 

Poster le rapport sur le forum et continuer la procédure.

 

2éme étape : Le nettoyage !

 

Redémarrer l'ordinateur en mode sans échec (tapoter F8 au boot pour obtenir le menu de démarrage

ou tuto Symantec).

http://service1.symantec.com/support/inter...020905112131924

 

Double-clique ATF-Cleaner.exe afin de lancer le programme.

Sous l'onglet Main, choisis : Select All

Clique sur le bouton Empty Selected

 

Si tu utilises le navigateur Firefox : Clique Firefox au haut et choisis : Select All

Clique le bouton Empty Selected

NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

Si tu utilises le navigateur Opera : Clique Opera au haut et choisis : Select All

Clique le bouton Empty Selected

NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

Clique Exit, du menu prinicipal, afin de fermer le programme.

Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.

 

Ensuite double cliquer sur smitfraudfix.cmd

Sélectionner 2 pour supprimer les fichiers responsables de l'infection.

A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran

et supprimer les clés de démarrage automatique de l'infection.

Le fix déterminera si le fichier wininet.dll est infecté.

A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

 

A la fin du scan, sauvegarder le rapport (Fichier/Enregistrer sous...) sur le Bureau.

 

N.B.: Cette étape élimine les fichiers infectieux détectés à l'étape #1

Attention : l'option 2 de l'outil supprime le fond d'écran !

 

process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky...) comme étant un RiskTool.

Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.

 

 

Du mode Sans Échec, lance AVG Anti-Spyware et clique sur le bouton Scanner (de la barre d'outils) et ensuite clique sur Complete System Scan. Le scan prendra un certain temps, donc sois patient.

  • AVG Anti-Spyware affichera une liste des fichiers détectés, sur la gauche. En fin de scan, l'outil appliquera les "Actions" à appliquer automatiquement. Clique sur le bouton Apply all actions. AVG Anti-Spyware affichera "All actions have been applied" du côté droit.
     
  • Clique sur "Save Report", puis "Save Report As". Ceci génère un rapport en fichier texte. Assure-toi de le sauvegarder dans un endroit sûr (sur ton Bureau, par exemple).

 

-Redémarrer en mode normal :

 

-Poster une réponse dans le même sujet

(Cliquer sur répondre entre "flash" et "nouveau " tout en bas de page!)

-Mettre le rapport de Smitfraudfix

-Mettre un nouveau rapport HijackThis

-Poster le rapport AVG Anti-Spyware

-Indiquer si le Pc présente encore des dysfonctionnements

 

A plus et bon courage :P !

Partager ce message


Lien à poster
Partager sur d’autres sites

SmitFraudFix v2.112

 

Rapport fait à 16:14:35,84, 22/10/2006

Executé à partir de C:\Documents and Settings\pccity\Bureau\CLEAN\SmitfraudFix

OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT

Fix executé en mode normal

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\pccity

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\pccity\Application Data

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\pccity\Favoris

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Bureau

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]

"Source"="About:Home"

"SubscribedURL"="About:Home"

"FriendlyName"="Ma page d'accueil"

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll

 

 

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~2\\GOEC62~1.DLL"

 

 

»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Fin

Partager ce message


Lien à poster
Partager sur d’autres sites

SmitFraudFix v2.112

 

Rapport fait à 16:51:24,93, 25/10/2006

Executé à partir de C:\Documents and Settings\pccity\Bureau\CLEAN\SmitfraudFix

OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT

Fix executé en mode sans echec

 

»»»»»»»»»»»»»»»»»»»»»»»» Avant SmitFraudFix

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll

 

»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

 

GenericRenosFix by S!Ri

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

 

Nettoyage terminé.

 

»»»»»»»»»»»»»»»»»»»»»»»» Après SmitFraudFix

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Fin

 

 

 

Logfile of HijackThis v1.99.1

Scan saved at 20:38:12, on 25/10/2006

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\WINDOWS\system32\RunDll32.exe

C:\Program Files\Digital Media Reader\shwiconem.exe

C:\WINDOWS\AGRSMMSG.exe

C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe

C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe

C:\Program Files\Fichiers communs\Talkway\vmtalk.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

F:\Program Files\Pando Networks\Pando\Pando.exe

C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe

C:\WINDOWS\System32\svchost.exe

F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Messenger\msmsgs.exe

F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

C:\PROGRA~1\FICHIE~1\Nokia\MPAPI\MPAPI3s.exe

F:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe

C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE

C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe

C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe

C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\Program Files\Nouveau dossier (2)\firefox.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\pccity\Bureau\CLEAN\hijackthis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O1 - Hosts: 67.183.235.156 l2testauthd.lineage2.com

O1 - Hosts: 67.183.235.156 l2authd.lineage2.com

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - F:\PROGRA~1\FlashGet\jccatch.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - F:\Program Files\Xi\NetTransport 2\NTIEHelper.dll

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - F:\PROGRA~1\FlashGet\fgiebar.dll

O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE

O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"

O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [sunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"

O4 - HKLM\..\Run: [share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [bDSwitchAgent] "C:\progra~1\softwin\bitdef~1\bdswitch.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [mouseElf] C:\PROGRA~1\TWINTO~1\MouseElf.EXE

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [bullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe

O4 - HKLM\..\Run: [vmtalk] C:\Program Files\Fichiers communs\Talkway\vmtalk.exe

O4 - HKLM\..\Run: [MNI.UWFX5V_0001_LP1710] "C:\Documents and Settings\pccity\Bureau\Nouveau dossier\WinFixer2005ScannerInstallFRA.exe"

O4 - HKLM\..\Run: [install5G] D:\Install.exe /SI=40

O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [Pando] "F:\Program Files\Pando Networks\Pando\Pando.exe" /Automation

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKCU\..\Run: [steam] "c:\program files\valve\steam\steam.exe" -silent

O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [LDM] F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"

O4 - HKCU\..\Run: [Free Download Manager] F:\Program Files\Free Download Manager\fdm.exe -autorun

O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog

O4 - Startup: Eurobarre.lnk = C:\Program Files\eurobarre\eb.exe

O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: FreeventsSchedule.lnk = C:\Philips\FreelineSchedule.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: HPAiODevice(hp officejet d series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet d series\Bin\hpoojd07.exe

O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = F:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

O4 - Global Startup: Logitech SetPoint.lnk = F:\Program Files\Logitech\SetPoint\SetPoint.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O4 - Global Startup: MioSync.lnk = C:\Program Files\Mio Technology\MioSync\mioSync.exe

O4 - Global Startup: RaConfig2500.lnk = C:\Program Files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe

O8 - Extra context menu item: &Télécharger avec NetTransport - F:\Program Files\Xi\NetTransport 2\NTAddLink.html

O8 - Extra context menu item: Tout t&élécharger avec NetTransport - F:\Program Files\Xi\NetTransport 2\NTAddList.html

O8 - Extra context menu item: Télécharger avec FlashGet - F:\Program Files\FlashGet\jc_link.htm

O8 - Extra context menu item: Télécharger tout avec FlashGet - F:\Program Files\FlashGet\jc_all.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll

O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - F:\PROGRA~1\FlashGet\flashget.exe

O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - F:\PROGRA~1\FlashGet\flashget.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O18 - Protocol: bw+0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw+0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw-0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw00s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw10s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw20s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw30s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw40s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw50s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw60s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw70s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw80s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bw90s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwa0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwb0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwc0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwd0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwe0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwf0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: bwg0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwg0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwh0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwi0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwj0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwk0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwl0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwm0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwn0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwo0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwp0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwq0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwr0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bws0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwt0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwu0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwv0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bww0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwx0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwy0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: bwz0s - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: offline-8876480 - {CB5B0838-EE86-4F8E-8D3A-6C083F270389} - F:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe

 

 

 

 

---------------------------------------------------------

AVG Anti-Spyware - Rapport d'analyse

---------------------------------------------------------

 

+ Créé à: 20:31:34 25/10/2006

 

+ Résultat de l'analyse:

 

 

 

HKLM\SOFTWARE\eXactUtil -> Adware.BargainBuddy : Nettoyé.

HKLM\SOFTWARE\Classes\CLSID\{5929CD6E-2062-44a4-B2C5-2C7E78FBAB38} -> Adware.Generic : Nettoyé.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5929CD6E-2062-44a4-B2C5-2C7E78FBAB38} -> Adware.Generic : Nettoyé.

HKU\S-1-5-21-1628759024-2092540518-1377378048-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} -> Adware.Generic : Nettoyé.

C:\System Volume Information\_restore{CE88A4DA-A8C0-4E4A-B92E-6E2C7120A81F}\RP344\A0111709.exe -> Downloader.Small : Nettoyé.

C:\System Volume Information\_restore{CE88A4DA-A8C0-4E4A-B92E-6E2C7120A81F}\RP344\A0111741.exe -> Downloader.Small : Nettoyé.

C:\System Volume Information\_restore{CE88A4DA-A8C0-4E4A-B92E-6E2C7120A81F}\RP345\A0112241.exe -> Downloader.Small : Nettoyé.

C:\System Volume Information\_restore{CE88A4DA-A8C0-4E4A-B92E-6E2C7120A81F}\RP348\A0112712.exe -> Not-A-Virus.Sniffer.Win32.WpePro.a : Nettoyé.

C:\System Volume Information\_restore{CE88A4DA-A8C0-4E4A-B92E-6E2C7120A81F}\RP348\A0112713.dll -> Not-A-Virus.Sniffer.Win32.WpePro.a : Nettoyé.

 

 

Fin du rapport

 

 

 

 

Mon probleme est résolu.Merci beaucoups!! :P

Partager ce message


Lien à poster
Partager sur d’autres sites

Bonsoir Palta !

 

Fais ceci STP

 

-Faire démarrer/panneau de configuration/ajout-supression de programmes

Regarder dans la liste si présent

FlashGet

BullsEye Network

WinFixer

(désinstaller)

 

Ensuite

 

Télécharge SpySweeper - Télécharge SpySweeper - Aide SpySweeper

- Clic sur sur le lien "Free Trial" pour le télécharger tout à droite

- Installe le et démare le

- Il va te demander de télécharger la dernière définition, accepte

- Ensuite, clic sur le bouton Options à gauche

- Clic sur l'onglet Options

- Assure toi que les options suivantes sont cochées :

o Windows Registery

o Memory Object

o Cookies

o System Restore Folder

o Plus bas :

o Sweep all users accounts

o Sweep for rootkis

 

-- Redémarre en mode sans échec, si tu sais pas comment on fait lis ceci

- Démarre SpySweeper

- Clic sur "Sweep Now" à gauche

- Clic sur le bouton "Start"

- Quand le scan est terminé, clic sur le bouton "Next"

- Assure toi que tout est coché et clic sur le bouton "Next"

- Lorsque tous les éléments trouvés ont été supprimés

- Clic sur "Session Log" en haut à droite, copie tous les élements du log.

- Ferme les fenêtres et colle tout le log ici ainsi qu'un log HijackThis

 

 

Aide : N'hésite pas à consulter l'Aide de SpySweeper

 

A plus.

Partager ce message


Lien à poster
Partager sur d’autres sites

voila ce que j'ai fais:

FlashGet:desinstallé

BullsEye Network:pas dans la liste de suppression de programmes

WinFixer:pas dans la liste de suppression de programmes

 

je continu la procédure

Partager ce message


Lien à poster
Partager sur d’autres sites

10:25: Removal process completed. Elapsed time 00:00:05

10:25: Quarantining All Traces: exact software

10:25: Quarantining All Traces: whenu savenow

10:25: Quarantining All Traces: seekmo search assistant

10:25: Quarantining All Traces: exact bullseye

10:25: Removal process initiated

10:22: Traces Found: 9

10:22: Full Sweep has completed. Elapsed time 00:27:44

10:22: File Sweep Complete, Elapsed Time: 00:26:53

10:22: Warning: Failed to access drive K:

10:22: Warning: Failed to access drive J:

10:22: Warning: Failed to access drive I:

10:22: Warning: Failed to access drive H:

10:22: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\ppjoysetup\pportjoy.cpl". "f:\gabi\ppjoysetup\pportjoy.cpl": File not found

10:22: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\otchaos_client_version_1.2\otchaos client\loader.exe". "f:\gabi\otchaos_client_version_1.2\otchaos client\loader.exe": File not found

10:22: Warning: Failed to open file "f:\gabi\naruto manga\nct-303 hq.rar". Opération réussie

10:22: Warning: Failed to open file "f:\gabi\naruto manga\naruto_305.zip". Opération réussie

10:22: Warning: Failed to open file "f:\gabi\naruto manga\chap_306_mq-hq__nct_.rar". Opération réussie

10:22: Warning: Failed to open file "f:\gabi\naruto manga\chap_302_hq.zip". Opération réussie

10:22: Warning: Failed to open file "f:\gabi\naruto manga\304 mq-hq nct.zip". Opération réussie

10:22: Warning: Failed to open file "f:\gabi\naruto manga\301_mq-hq.zip". Opération réussie

10:22: Warning: Failed to open file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\271\flash1\net\http\auth.dat". Opération réussie

10:22: Warning: Failed to open file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\271\ipl\psp_ipl.bin_p3". Opération réussie

10:22: Warning: Failed to open file "f:\gabi\psp frimware 5\thumbs.db:encryptable". Opération réussie

10:21: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\ppjoysetup\ppjoymouse.exe". "f:\gabi\ppjoysetup\ppjoymouse.exe": File not found

10:21: Warning: Failed to read file "f:\gabi\ppjoysetup\setup.exe". "f:\gabi\ppjoysetup\setup.exe": File not found

10:21: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\epsxe160\plugins\gpupeteopengl.dll". "f:\gabi\epsxe160\plugins\gpupeteopengl.dll": File not found

10:21: Warning: Failed to read file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\thumbs.db". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\thumbs.db": File not found

10:21: Warning: Failed to read file "f:\gabi\otchaos_client_version_1.2\otchaos client\00000007.map". "f:\gabi\otchaos_client_version_1.2\otchaos client\00000007.map": File not found

10:21: Warning: Failed to read file "f:\gabi\downgradeur 1.50 à 1.00\downdater\dump\font\shadow.pgf". "f:\gabi\downgradeur 1.50 à 1.00\downdater\dump\font\shadow.pgf": File not found

10:20: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\ppjoysetup\ppjoydll.exe". "f:\gabi\ppjoysetup\ppjoydll.exe": File not found

10:19: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\epsxe160\plugins\spueternall.dll". "f:\gabi\epsxe160\plugins\spueternall.dll": File not found

10:19: Warning: Failed to read file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\bootselect\thumbs.db". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\bootselect\thumbs.db": File not found

10:19: Warning: Failed to read file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\cpuclock\thumbs.db". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\cpuclock\thumbs.db": File not found

10:19: Warning: Failed to read file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\currentgame\thumbs.db". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\currentgame\thumbs.db": File not found

10:19: Warning: Failed to read file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\firmware\thumbs.db". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\firmware\thumbs.db": File not found

10:19: Warning: Failed to read file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\preloadaddress\thumbs.db". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\preloadaddress\thumbs.db": File not found

10:19: Warning: Failed to read file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\statusbar\thumbs.db". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\statusbar\thumbs.db": File not found

10:19: Warning: Failed to read file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\umdselect\thumbs.db". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\umdselect\thumbs.db": File not found

10:19: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\ignore this if you dont want to use usb mode\pc files\driver\libusb0.dll". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\ignore this if you dont want to use usb mode\pc files\driver\libusb0.dll": File not found

10:19: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\epsxe160\plugins\gpupeted3d.dll". "f:\gabi\epsxe160\plugins\gpupeted3d.dll": File not found

10:19: Warning: Failed to read file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\autorunoption\thumbs.db". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\autorunoption\thumbs.db": File not found

10:19: Warning: Failed to read file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\remotectrl\thumbs.db". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\remotectrl\thumbs.db": File not found

10:19: Warning: Failed to read file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\umdversion\thumbs.db". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\dh\kd\modfiles\images\umdversion\thumbs.db": File not found

10:19: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\ignore this if you dont want to use usb mode\important system files\vb6fr.dll". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\ignore this if you dont want to use usb mode\important system files\vb6fr.dll": File not found

10:19: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\tibiabot_ng\tibiabot ng\loader.exe". "f:\gabi\tibiabot_ng\tibiabot ng\loader.exe": File not found

10:19: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\ignore this if you dont want to use usb mode\pc files\driver\libusb0.sys". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\ignore this if you dont want to use usb mode\pc files\driver\libusb0.sys": File not found

10:19: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\ppjoysetup\ppjoybus.sys". "f:\gabi\ppjoysetup\ppjoybus.sys": File not found

10:19: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\epsxe160\burutter.dll". "f:\gabi\epsxe160\burutter.dll": File not found

10:19: Warning: Failed to read file "f:\gabi\otchaos_client_version_1.2\otchaos client\00000010.map". "f:\gabi\otchaos_client_version_1.2\otchaos client\00000010.map": File not found

10:18: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\ignore this if you dont want to use usb mode\important system files\systray.ocx". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\ignore this if you dont want to use usb mode\important system files\systray.ocx": File not found

10:18: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\ppjoysetup\w98ports.sys". "f:\gabi\ppjoysetup\w98ports.sys": File not found

10:18: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\ignore this if you dont want to use usb mode\pc files\usbhostfs.exe". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\ignore this if you dont want to use usb mode\pc files\usbhostfs.exe": File not found

10:18: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\ppjoysetup\pportjoy.sys". "f:\gabi\ppjoysetup\pportjoy.sys": File not found

10:18: Warning: Failed to read file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\iso\umdboot.iso". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\iso\umdboot.iso": File not found

10:18: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\mpa bot v1.9a pl\mpa bot v1.9a pl\packet.dll". "f:\gabi\mpa bot v1.9a pl\mpa bot v1.9a pl\packet.dll": File not found

10:18: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\epsxe160\plugins\spueternal.dll". "f:\gabi\epsxe160\plugins\spueternal.dll": File not found

10:17: Warning: Failed to read file "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\iso\xmbboot.iso". "f:\gabi\ppsp_devhook___custom_firmware\devicehook + custom firmware\put these on your memory stick\iso\xmbboot.iso": File not found

10:17: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\ppjoysetup\jr_ppm.dll". "f:\gabi\ppjoysetup\jr_ppm.dll": File not found

10:17: Warning: PerformFileOffsetMatch Failed to check file "f:\gabi\ppjoysetup\futaba_ppm.dll". "f:\gabi\ppjoysetup\futaba_ppm.dll": File not found

10:13: Warning: Failed to access drive E:

10:13: Warning: Failed to access drive D:

10:06: exclean.exe (ID = 93622)

10:06: Found Adware: exact software

09:56: vvsn (ID = 2147486920)

09:56: Found Adware: whenu savenow

09:55: Starting File Sweep

09:55: Cookie Sweep Complete, Elapsed Time: 00:00:00

09:55: Starting Cookie Sweep

09:55: Registry Sweep Complete, Elapsed Time:00:00:15

09:55: HKLM\software\classes\typelib\{8be3faba-7468-4851-b97c-0750af2b908e}\ (ID = 1042342)

09:55: HKLM\software\classes\seekmohook.sabho.1\ (ID = 1042280)

09:55: HKLM\software\classes\seekmohook.sabho\ (ID = 1042274)

09:55: HKCR\typelib\{8be3faba-7468-4851-b97c-0750af2b908e}\ (ID = 1042241)

09:55: HKCR\seekmohook.sabho.1\ (ID = 1042197)

09:55: HKCR\seekmohook.sabho\ (ID = 1042191)

09:55: Found Adware: seekmo search assistant

09:55: HKLM\software\microsoft\windows\currentversion\run\ || bullseye network (ID = 104028)

09:55: Found Adware: exact bullseye

09:55: Starting Registry Sweep

09:55: Memory Sweep Complete, Elapsed Time: 00:00:31

09:55: Starting Memory Sweep

09:55: Warning: Files are not scanned for viruses because AV engine failed to load.

09:55: Sweep initiated using definitions version 783

09:55: Spy Sweeper 5.2.3.2120 started

09:55: | Start of Session, jeudi 26 octobre 2006 |

********

09:55: | End of Session, jeudi 26 octobre 2006 |

09:54: Traces Found: 0

09:54: Memory Sweep Complete, Elapsed Time: 00:00:12

09:54: Sweep Canceled

09:54: Starting Memory Sweep

09:54: Warning: Files are not scanned for viruses because AV engine failed to load.

09:54: Sweep initiated using definitions version 783

09:54: Spy Sweeper 5.2.3.2120 started

09:54: | Start of Session, jeudi 26 octobre 2006 |

********

09:54: | End of Session, jeudi 26 octobre 2006 |

09:54: Program Version 5.2.3.2120 Using Spyware Definitions 783

09:53: Program Version 5.2.3.2120 Using Spyware Definitions 783

09:53: Warning: Virus definitions files are invalid, please update your virus definitions. 220

09:49: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.

09:49: Your definitions are up to date.

09:46: Access to Hosts file allowed for F:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE

09:43: There is a problem reaching the server. The cause may be in your connection, or on the server. Please try again later.

09:43: Your definitions are up to date.

Keylogger: Off

BHO Shield: On

IE Security Shield: On

Alternate Data Stream (ADS) Execution Shield: On

Startup Shield: On

Common Ad Sites: Off

Hosts File Shield: On

Internet Communication Shield: On

ActiveX Shield: On

Windows Messenger Service Shield: On

IE Favorites Shield: On

Spy Installation Shield: On

Memory Shield: On

IE Hijack Shield: On

IE Tracking Cookies Shield: Off

09:40: Shield States

09:40: Spyware Definitions: 783

09:40: Warning: Virus definitions files are invalid, please update your virus definitions. 220

09:39: Spy Sweeper 5.2.3.2120 started

09:39: Spy Sweeper 5.2.3.2120 started

09:39: | Start of Session, jeudi 26 octobre 2006 |

********

Partager ce message


Lien à poster
Partager sur d’autres sites

Créer un compte ou se connecter pour commenter

Vous devez être membre afin de pouvoir déposer un commentaire

Créer un compte

Créez un compte sur notre communauté. C’est facile !

Créer un nouveau compte

Se connecter

Vous avez déjà un compte ? Connectez-vous ici.

Connectez-vous maintenant

  • En ligne récemment   0 membre est en ligne

    Aucun utilisateur enregistré regarde cette page.

×