Bonjour, je suis nouveau ici et je vous demande de l'aide.



1. A chaque lancement de mon navigateur (avant browser), Avast me repere un trojan Win32:Agent-EEW [Trj]. Il se trouve dans le dossier temp. J'ai beau le nettoyer, mettre en 40aine le trojan, il revient a chaque redemarrage et lancement de ma connexion internet.


2. Par ailleurs, j'ai regulierement une page web qui s'ouvre sans que je lui demande avec toujours un site de recherche qui change parfois d'aspect. Le dernier en date est nomme best search. L'adresse est a chaque fois differente.


3. Enfin, j'ai aussi semble-t-il un faux positif que me signale avast depuis une tentative de scan en ligne avec panda. Le nom du trojan est win32 ctx. Meme remarque, chaque fois je le supprime et chaque fois il revient.


Je ne sais plus trop quoi faire et je fais donc appel a vous!

Merci d'avance!

Bonsoir alexandre32123 !


- Télécharge HijackThis de Merijn sur ton bureau.


- Génère un rapport en suivant ces indications :

- Double-clic sur hijackthis.exe

- Exécute le et clique sur Do a scan and save log file.

- Le rapport s'ouvre sur leBloc-Note

- Colle le rapport ici, pour cela :

- Menu Edition / Selectionner Tout

- Menu Edition / copier

- Ici dans un nouveau message : clic droit / coller

Aide : N'hésite pas à consulter l'aide HijackThis -


Ensuite :


Télécharge AVG Anti-Spyware

  1. Lance AVG Anti-Spyware et clique sur le bouton Update (barre d'outils - au haut). Sous Manual Update clique Start update.
  2. Tu verras ceci juste au bas, lorsque la mise à jour sera complétée : "Update successful"
  3. Ferme AVG Anti-Spyware. Ne pas le lancer tout de suite.

Redémarre en mode Sans Échec : au redémarrage, tapote immédiatement la touche F8; tu verras un écran avec choix de démarrages apparaître. Utilisant les flèches du clavier, choisis "Mode Sans Échec" et valide avec "Entrée". Choisis ton compte usuel, et non Administrateur.

  • Du mode Sans Échec, lance AVG Anti-Spyware et clique sur le bouton Scanner (de la barre d'outils) et ensuite clique sur Complete System Scan. Le scan prendra un certain temps, donc sois patient.
  • AVG Anti-Spyware affichera une liste des fichiers détectés, sur la gauche. En fin de scan, l'outil appliquera les "Actions" à appliquer automatiquement. Clique sur le bouton Apply all actions. AVG Anti-Spyware affichera "All actions have been applied" du côté droit.
  • Clique sur "Save Report", puis "Save Report As". Ceci génère un rapport en fichier texte. Assure-toi de le sauvegarder dans un endroit sûr (sur ton Bureau, par exemple).
  • Redémarre ton ordi en mode Normal.



Je te fais passer un autre outil :


Télécharge Blacklight (de F-Secure) et sauvegarde le sur ton Bureau.


Double-clique blbeta.exe et accepte la licence; laisse [X]scan through Windows Explorer activé; clique Scan puis Next


Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).


Copie et colle le contenu de ce rapport dans ta prochaine réponse. NE PAS choisir l'option "Rename" de suite : nous devons analyser le rapport, car des fichiers légitimes peuvent être présents, tel wbemtest.exe



Prière de poster les rapports suivant dans ta prochaine réponse :


1) AVG Anti-Spyware

2) BlackLight

3) Nouveau rapport HijackThis!


Bon courage, et @+

Voila, j'ai fait tout ce que tu m'as dit:

J'espere que vous pourrez m'aider.


Voici par ailleurs l'adresse de pages qui s'ouvrent sans que je les demande:

Mais c'est pas toujours la meme... comment se debarraser de cette salete?





Rapport Hijackthis:


Logfile of HijackThis v1.99.1

Scan saved at 08:51:46, on 15/02/2007

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)


Running processes:









C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe



C:\Program Files\Inventel\Gateway\wlancfg.exe



C:\Program Files\Winamp\Winampa.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe





C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe



C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\SpamPal\spampal.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe



C:\Program Files\Avant Browser\avant.exe

C:\Documents and Settings\Olivier\Bureau\hijackthis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: TMSN Class - {B72549CE-5644-4116-B8A4-A2B042321EC4} - C:\WINDOWS\Policies.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe

O4 - HKLM\..\Run: [Explorer 2238] C:\DOCUME~1\Olivier\LOCALS~1\Temp\30285\explorer.exe

O4 - HKLM\..\Run: [_zlu_zlope04] c:\windows\system32\_zsk_zlu_zlope04cwr_tgawotlcmef_.exe

O4 - HKLM\..\Run: [hp Update 3300C] C:\sj650\hpupdate.exe 3300C+

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKLM\..\RunServices: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe

O4 - HKLM\..\RunServices: [_zlu_zlope04] c:\windows\system32\_zsk_zlu_zlope04cwr_tgawotlcmef_.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [AXVenore] "C:\Program Files\AXVenore\AXVenore.exe"

O4 - HKCU\..\Run: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe

O4 - HKCU\..\Run: [_zlu_zlope04] c:\windows\system32\_zsk_zlu_zlope04cwr_tgawotlcmef_.exe

O4 - Startup: SpamPal.lnk = C:\Program Files\SpamPal\spampal.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: Bloquer ce serveur... - C:\Program Files\Avant Browser\AddAllToADBlackList.htm

O8 - Extra context menu item: Bloquer cette publicité... - C:\Program Files\Avant Browser\AddToADBlackList.htm

O8 - Extra context menu item: Ouvrir dans une nouvelle fenêtre d'Avant Browser - C:\Program Files\Avant Browser\OpenInNewBrowser.htm

O8 - Extra context menu item: Ouvrir tous les liens de la page... - C:\Program Files\Avant Browser\OpenAllLinks.htm

O8 - Extra context menu item: Rechercher sur le Web... - C:\Program Files\Avant Browser\Search.htm

O8 - Extra context menu item: Surligner - C:\Program Files\Avant Browser\Highlight.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -

O17 - HKLM\System\CCS\Services\Tcpip\..\{78000588-DCFE-41C8-B43A-F3E88206B71C}: NameServer =,

O17 - HKLM\System\CCS\Services\Tcpip\..\{D79B7A68-2AF5-402F-9C47-07F55E2199DB}: NameServer =,

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer =

O17 - HKLM\System\CS1\Services\Tcpip\..\{78000588-DCFE-41C8-B43A-F3E88206B71C}: NameServer =,

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer =

O17 - HKLM\System\CS2\Services\Tcpip\..\{78000588-DCFE-41C8-B43A-F3E88206B71C}: NameServer =,

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer =

O20 - AppInit_DLLs: \\?\C:\WINDOWS\System32\com1.xdo

O21 - SSODL: DCOM Server 2238 - {2C1CD3D7-86AC-4068-93BC-A02304BB2238} - C:\DOCUME~1\Olivier\LOCALS~1\Temp\30285\explorer.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe


Rapport blacklight :


02/15/07 08:52:47 [info]: BlackLight Engine 1.0.55 initialized

02/15/07 08:52:47 [info]: OS: 5.1 build 2600 ()

02/15/07 08:52:47 [Note]: 7019 4

02/15/07 08:52:47 [Note]: 7005 0

02/15/07 08:53:00 [Note]: 7006 0

02/15/07 08:53:00 [Note]: 7011 1052

02/15/07 08:53:01 [Note]: 7026 0

02/15/07 08:53:01 [Note]: 7026 0

02/15/07 08:53:06 [Note]: FSRAW library version 1.7.1021

02/15/07 08:54:39 [Note]: 2000 1012

02/15/07 08:54:55 [Note]: 7007 0



Rapport AVG:



AVG Anti-Spyware - Rapport d'analyse



+ Créé à: 10:12:06 15/02/2007


+ Résultat de l'analyse:




D:\System Volume Information\_restore{BB1B914F-52FC-4D07-99E8-943158869A52}\RP36\A0005710.exe -> Adware.BrowsePal : Ignoré.

D:\System Volume Information\_restore{BB1B914F-52FC-4D07-99E8-943158869A52}\RP35\A0003045.exe -> Dialer.Generic : Nettoyé et sauvegardé (mise en quarantaine).

D:\System Volume Information\_restore{BB1B914F-52FC-4D07-99E8-943158869A52}\RP35\A0003058.exe -> Dialer.Generic : Nettoyé et sauvegardé (mise en quarantaine).

D:\System Volume Information\_restore{BB1B914F-52FC-4D07-99E8-943158869A52}\RP35\A0003077.exe -> Dialer.Generic : Nettoyé et sauvegardé (mise en quarantaine).

C:\WINDOWS\system32\dxvwaowd.exe -> Downloader.Small : Nettoyé et sauvegardé (mise en quarantaine).

C:\WINDOWS\system32\dxvwnmlt.exe -> Downloader.Small : Nettoyé et sauvegardé (mise en quarantaine).

C:\WINDOWS\system32\dxvwyedp.exe -> Downloader.Small : Nettoyé et sauvegardé (mise en quarantaine).



Fin du rapport

Voila, j'ai nettoye le pc en mode sans echec avec :

-Ad aware





Rien a signaler, tout est propre... et pourtant!


Et j'ai toujours le trojan Win32:Agent-EEW a chaque nouveau lancement de Avant Browser. Je le supprime. Plus de pb, jusqu'a ce que j'eteigne et rallume le pc: a nouveau Avast detecte le trojan au lancement de Avant. Toujours au meme endroit (dossier temp dans localsetting)


Voici mon dernier hijackthis log:

Logfile of HijackThis v1.99.1

Scan saved at 18:09:15, on 15/02/2007

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)


Running processes:











C:\Program Files\Winamp\Winampa.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe





C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe


C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe



C:\Program Files\Messenger\msmsgs.exe


C:\Program Files\Inventel\Gateway\wlancfg.exe

C:\Program Files\SpamPal\spampal.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe



C:\Program Files\Avant Browser\avant.exe

C:\Documents and Settings\Olivier\Bureau\hijackthis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: TMSN Class - {B72549CE-5644-4116-B8A4-A2B042321EC4} - C:\WINDOWS\Policies.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe

O4 - HKLM\..\Run: [Explorer 2238] C:\DOCUME~1\Olivier\LOCALS~1\Temp\30285\explorer.exe

O4 - HKLM\..\Run: [_zlu_zlope04] c:\windows\system32\_zsk_zlu_zlope04cwr_tgawotlcmef_.exe

O4 - HKLM\..\Run: [hp Update 3300C] C:\sj650\hpupdate.exe 3300C+

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKLM\..\RunServices: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe

O4 - HKLM\..\RunServices: [_zlu_zlope04] c:\windows\system32\_zsk_zlu_zlope04cwr_tgawotlcmef_.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [AXVenore] "C:\Program Files\AXVenore\AXVenore.exe"

O4 - HKCU\..\Run: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe

O4 - HKCU\..\Run: [_zlu_zlope04] c:\windows\system32\_zsk_zlu_zlope04cwr_tgawotlcmef_.exe

O4 - Startup: SpamPal.lnk = C:\Program Files\SpamPal\spampal.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: Bloquer ce serveur... - C:\Program Files\Avant Browser\AddAllToADBlackList.htm

O8 - Extra context menu item: Bloquer cette publicité... - C:\Program Files\Avant Browser\AddToADBlackList.htm

O8 - Extra context menu item: Ouvrir dans une nouvelle fenêtre d'Avant Browser - C:\Program Files\Avant Browser\OpenInNewBrowser.htm

O8 - Extra context menu item: Ouvrir tous les liens de la page... - C:\Program Files\Avant Browser\OpenAllLinks.htm

O8 - Extra context menu item: Rechercher sur le Web... - C:\Program Files\Avant Browser\Search.htm

O8 - Extra context menu item: Surligner - C:\Program Files\Avant Browser\Highlight.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -

O17 - HKLM\System\CCS\Services\Tcpip\..\{78000588-DCFE-41C8-B43A-F3E88206B71C}: NameServer =,

O17 - HKLM\System\CCS\Services\Tcpip\..\{D79B7A68-2AF5-402F-9C47-07F55E2199DB}: NameServer =,

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer =

O17 - HKLM\System\CS1\Services\Tcpip\..\{78000588-DCFE-41C8-B43A-F3E88206B71C}: NameServer =,

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer =

O17 - HKLM\System\CS2\Services\Tcpip\..\{78000588-DCFE-41C8-B43A-F3E88206B71C}: NameServer =,

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer =

O20 - AppInit_DLLs: \\?\C:\WINDOWS\System32\com1.xdo

O21 - SSODL: DCOM Server 2238 - {2C1CD3D7-86AC-4068-93BC-A02304BB2238} - C:\DOCUME~1\Olivier\LOCALS~1\Temp\30285\explorer.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe

Bonjour alexandre32123 !


Woaw ca faisait longtemps que j'avais pas vu un log aussi pourri :P !!


Imprime ces instructions si nécessaire car il va y avoir un redémarrage de l'ordinateur.


Télécharge le FixWareout d'un de ces deux sites sur le bureau:


Lance le fix: clique sur Next, puis Install, puis assure toi que "Run fixit" est activé puis clique sur Finish.

Le fix va commencer, suis les messages à l'écran. Il te sera demandé de redémarrer ton ordinateur, fais le. Ton système mettra un peu plus de temps au démarrage, c'est normal.


Quand ton système aura redémarré, suis les invites des messages. Ensuite lance HijackThis. Clique sur Scan et coche les lignes suivantes:


O17 - HKLM\System\CCS\Services\Tcpip\..\{78000588-DCFE-41C8-B43A-F3E88206B71C}: NameServer =,

O17 - HKLM\System\CCS\Services\Tcpip\..\{D79B7A68-2AF5-402F-9C47-07F55E2199DB}: NameServer =,

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer =

O17 - HKLM\System\CS1\Services\Tcpip\..\{78000588-DCFE-41C8-B43A-F3E88206B71C}: NameServer =,

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer =

O17 - HKLM\System\CS2\Services\Tcpip\..\{78000588-DCFE-41C8-B43A-F3E88206B71C}: NameServer =,

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer =


Clique sur Fix Checked. Ferme HijackThis et clique sur OK pour continuer la procédure.


A la fin du fix, tu auras peut-être encore besoin de redémarrer le PC.


Au final, poste le contenu de C:\fixwareout\report.txt avec un nouveau rapport HijackThis.


Ensuite fais ceci


Télécharge ATF Cleaner par Atribune.



Double-clique ATF-Cleaner.exe afin de lancer le programme.

Sous l'onglet Main, choisis : Select All

Clique sur le bouton Empty Selected


Si tu utilises le navigateur Firefox :

  • Clique Firefox au haut et choisis : Select All
    Clique le bouton Empty Selected
    NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

Si tu utilises le navigateur Opera :

  • Clique Opera au haut et choisis : Select All
    Clique le bouton Empty Selected
    NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

Clique Exit, du menu prinicipal, afin de fermer le programme.

Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.


Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.

Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :

  • Redémarre ton ordinateur
  • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
  • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
  • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
  • Choisis ton compte.

Déroule la liste des instructions ci-dessous :

  • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
  • Appuie sur Y pour commencer le processus de nettoyage.
  • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
  • Appuie sur une touche pour redémarrer le PC.
  • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
  • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
  • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
  • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
  • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !


- Le fichier SDFIX_README.htm (dans le dossier SDFix) contient la liste des malwares pris en compte par l'outil.

- Andy fait plusieurs mises à jour, souvent plus d'une par jour... N'hésitez donc pas à demander de télécharger une nouvelle version lorsque le nettoyage dure et que l'outil ne semble pas tout voir.


Et enfin :


1ére étape :


Télécharger SmitfraudFix de S!Ri :P sur

Dézipper la totalité de l'archive

-Son tutorial


process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky...) comme étant un RiskTool.

Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.


Utilisation ----- option 1 - Recherche :

Double cliquer sur smitfraudfix.cmd

Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.


Poster le rapport sur le forum.


Bon courage !


Voici le rapport de fixwareout:



Fixwareout Last edited 2/11/2007

Post this report in the forums please


»»»»»Prerun check


»»»»» System restarted


»»»»» Postrun check

HKLM\SOFTWARE\~\Winlogon\ "System"=""



»»»»» Misc files.

C:\WINDOWS\System32\kernel32.exe Deleted


»»»»» Checking for older varients.



Search five digit cs, dm, kd, jb, other, files.

The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.




Click browse, find the file then click submit.



»»»»» Other




»»»»» Current runs


"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"

"nwiz"="nwiz.exe /install"

"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"


"WinampAgent"="\"C:\\Program Files\\Winamp\\Winampa.exe\""

"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"

"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"


"Explorer 2238"="C:\\DOCUME~1\\Olivier\\LOCALS~1\\Temp\\30285\\explorer.exe"


"hp Update 3300C"="C:\\sj650\\hpupdate.exe 3300C+"

"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"



"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NVMCTRAY.DLL,NvTaskbarInit"

"WOOKIT"="C:\\PROGRA~1\\Wanadoo\\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM="

"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"

"AXVenore"="\"C:\\Program Files\\AXVenore\\AXVenore.exe\""




Hosts file was reset, If you use a custom hosts file please replace it

»»»»» End report »»»»»



Voici le rapport de hijackthis:


Logfile of HijackThis v1.99.1

Scan saved at 18:44:58, on 15/02/2007

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)


Running processes:









C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe



C:\Program Files\Inventel\Gateway\wlancfg.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe





C:\Program Files\Winamp\Winampa.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe



C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe



C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\SpamPal\spampal.exe


C:\Program Files\Avant Browser\avant.exe

C:\Documents and Settings\Olivier\Bureau\hijackthis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: TMSN Class - {B72549CE-5644-4116-B8A4-A2B042321EC4} - C:\WINDOWS\Policies.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

O4 - HKLM\..\Run: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe

O4 - HKLM\..\Run: [Explorer 2238] C:\DOCUME~1\Olivier\LOCALS~1\Temp\30285\explorer.exe

O4 - HKLM\..\Run: [_zlu_zlope04] c:\windows\system32\_zsk_zlu_zlope04cwr_tgawotlcmef_.exe

O4 - HKLM\..\Run: [hp Update 3300C] C:\sj650\hpupdate.exe 3300C+

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKLM\..\RunServices: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe

O4 - HKLM\..\RunServices: [_zlu_zlope04] c:\windows\system32\_zsk_zlu_zlope04cwr_tgawotlcmef_.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [AXVenore] "C:\Program Files\AXVenore\AXVenore.exe"

O4 - HKCU\..\Run: [_mzu_stonedrv3] c:\windows\system32\_mzu_stonedrv3.exe

O4 - HKCU\..\Run: [_zlu_zlope04] c:\windows\system32\_zsk_zlu_zlope04cwr_tgawotlcmef_.exe

O4 - Startup: SpamPal.lnk = C:\Program Files\SpamPal\spampal.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: Bloquer cette publicité... - C:\Program Files\Avant Browser\AddToADBlackList.htm

O8 - Extra context menu item: Bloquer toutes les publicités de ce site... - C:\Program Files\Avant Browser\AddAllToADBlackList.htm

O8 - Extra context menu item: Ouvrir dans une nouvelle fenêtre... - C:\Program Files\Avant Browser\OpenInNewBrowser.htm

O8 - Extra context menu item: Ouvrir des liens de la page... - C:\Program Files\Avant Browser\OpenAllLinks.htm

O8 - Extra context menu item: Rechercher sur le Web - C:\Program Files\Avant Browser\Search.htm

O8 - Extra context menu item: Surligner toutes les occurrences sur la page - C:\Program Files\Avant Browser\Highlight.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -

O20 - AppInit_DLLs: \\?\C:\WINDOWS\System32\com1.xdo

O21 - SSODL: DCOM Server 2238 - {2C1CD3D7-86AC-4068-93BC-A02304BB2238} - C:\DOCUME~1\Olivier\LOCALS~1\Temp\30285\explorer.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe


Je poursuis...

Voici le rapport de sdfix:


SDFix: Version 1.65


Run by: Olivier - 15/02/2007 @ 20:15:55,68


Microsoft Windows XP [version 5.1.2600]


Running From: C:\SDFix


Safe Mode:

Checking Services:








MZU_RK Deleted


Restoring Windows Registry Entries

Restoring Default Hosts File





Normal Mode:

Checking Files:


Below files will be copied to Backups folder then removed:


C:\WINDOWS\Policies.dll - Deleted

C:\WINDOWS\system32\mini3tone.ini - Deleted

C:\WINDOWS\system32\Policies\Policies.dll - Deleted

C:\WINDOWS\system32\Policies\replace-update-script.bat - Deleted

C:\WINDOWS\system32\Policies\update-script.bat - Deleted

C:\WINDOWS\system32\Policies\version.txt - Deleted




ADS Check:



:bigo.dll 9728

Total size: 9728 bytes.


Removing ADS...


system32: deleted 9728 bytes in 1 streams.


Checking for remaining Streams



No streams found.


Final Check:




Remaining Files:



Backups Folder: - C:\SDFix\backups\



Checking For Files with Hidden Attributes :


C:\Documents and Settings\Olivier\Application Data\Microsoft\Word\~WRL3428.tmp

C:\Documents and Settings\Olivier\Application Data\Microsoft\Word\~WRL3934.tmp






Voici celui de hijackthis:


Logfile of HijackThis v1.99.1

Scan saved at 20:21:25, on 15/02/2007

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)


Running processes:









C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe



C:\Program Files\Inventel\Gateway\wlancfg.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe





C:\Program Files\Winamp\Winampa.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe



C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe



C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\SpamPal\spampal.exe


C:\Program Files\Avant Browser\avant.exe

C:\Documents and Settings\Olivier\Bureau\hijackthis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName


= Liens

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -



O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -


C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: TMSN Class - {B72549CE-5644-4116-B8A4-A2B042321EC4} -


C:\WINDOWS\Policies.dll (file missing)

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -



O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE



O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program


Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program



O4 - HKLM\..\Run: [Explorer 2238]



O4 - HKLM\..\Run: [_zlu_zlope04]



O4 - HKLM\..\Run: [hp Update 3300C] C:\sj650\hpupdate.exe 3300C+

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG


Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKLM\..\RunServices: [_zlu_zlope04]



O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE



O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe



O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"



O4 - HKCU\..\Run: [AXVenore] "C:\Program Files\AXVenore\AXVenore.exe"

O4 - HKCU\..\Run: [_zlu_zlope04]



O4 - Startup: SpamPal.lnk = C:\Program Files\SpamPal\spampal.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft



O8 - Extra context menu item: Bloquer cette publicité... - C:\Program


Files\Avant Browser\AddToADBlackList.htm

O8 - Extra context menu item: Bloquer toutes les publicités de ce


site... - C:\Program Files\Avant Browser\AddAllToADBlackList.htm

O8 - Extra context menu item: Ouvrir dans une nouvelle fenêtre... -


C:\Program Files\Avant Browser\OpenInNewBrowser.htm

O8 - Extra context menu item: Ouvrir des liens de la page... -


C:\Program Files\Avant Browser\OpenAllLinks.htm

O8 - Extra context menu item: Rechercher sur le Web - C:\Program


Files\Avant Browser\Search.htm

O8 - Extra context menu item: Surligner toutes les occurrences sur la


page - C:\Program Files\Avant Browser\Highlight.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -


C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) -


{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program



O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX


Scan Agent 6.6) -



O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)



O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -



O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer


Class) -

O20 - AppInit_DLLs: \\?\C:\WINDOWS\System32\com1.xdo

O21 - SSODL: DCOM Server 2238 - {2C1CD3D7-86AC-4068-93BC-A02304BB2238}


- C:\DOCUME~1\Olivier\LOCALS~1\Temp\30285\explorer.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner


- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Program


Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program


Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program


Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. -


C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision


Corporation - C:\Program Files\Fichiers


communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA


Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel -


C:\Program Files\Inventel\Gateway\wlancfg.exe



Et voici le rapport de:

SmitFraudFix v2.142


Rapport fait à 20:28:21,20, 15/02/2007

Executé à partir de C:\Documents and Settings\Olivier\Bureau\SmitfraudFix\SmitfraudFix

OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT

Le type du système de fichiers est NTFS

Fix executé en mode normal


»»»»»»»»»»»»»»»»»»»»»»»» hosts



»»»»»»»»»»»»»»»»»»»»»»»» C:\



»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS



»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system



»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web



»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32



»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Olivier



»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Olivier\Application Data



»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer



»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Olivier\Favoris



»»»»»»»»»»»»»»»»»»»»»»»» Bureau



»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files



»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues



»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau


[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]



"FriendlyName"="Ma page d'accueil"



»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!


SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll



"{2C1CD3D7-86AC-4068-93BC-A02304BB2238}"="DCOM Server 2238"










»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]




»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]




»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32



»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll



»»»»»»»»»»»»»»»»»»»»»»»» Fin

bonjour alexandre32123 !


Continu comme ceci STP :

Télécharge SpySweeper - Télécharge SpySweeper - Aide SpySweeper

- Clic sur sur le lien "Free Trial" pour le télécharger tout à droite

- Installe le et démare le

- Il va te demander de télécharger la dernière définition, accepte

- Ensuite, clic sur le bouton Options à gauche

- Clic sur l'onglet Options

- Assure toi que les options suivantes sont cochées :

o Windows Registery

o Memory Object

o Cookies

o System Restore Folder

o Plus bas :

o Sweep all users accounts

o Sweep for rootkis


-- Redémarre en mode sans échec, si tu sais pas comment on fait lis ceci

- Démarre SpySweeper

- Clic sur "Sweep Now" à gauche

- Clic sur le bouton "Start"

- Quand le scan est terminé, clic sur le bouton "Next"

- Assure toi que tout est coché et clic sur le bouton "Next"

- Lorsque tous les éléments trouvés ont été supprimés

- Clic sur "Session Log" en haut à droite, copie tous les élements du log.

- Ferme les fenêtres et colle tout le log ici ainsi qu'un log HijackThis



Aide : N'hésite pas à consulter l'Aide de SpySweeper


Ensuite fais un scan en ligne ici (fire fox ou IE)

Et faire celui-ci (IE avec active x seulement)


A la fin du scan, sauvegarder le rapport sur le Bureau.(cliquer sur l'onglet Résultats/ puis cliquer sur Edition/tout sélectionner/copier puis ouvrir un fichier texte et coller la sélection dedans)


-Poster le(s) rapport(s) trendmicro


A plus.


Voila, je suis tes indications, et je te remercie pour ta patience et tes efforts!


Voici le log de spy sweeper:


2 scans ont ete faits dont un hier soir interrompu mais qui a elimie 5 trojans et spywares). Le 2eme ce matin n'a plus rien trouve.


10:10: Traces Found: 0

10:10: Custom Sweep has completed. Elapsed time 01:36:40

10:09: File Sweep Complete, Elapsed Time: 01:35:23

09:45: Warning: SweepDirectories: Cannot find directory "f:". This directory was not added to the list of paths to be scanned.

09:45: Warning: SweepDirectories: Cannot find directory "e:". This directory was not added to the list of paths to be scanned.

09:38: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Corrupted] on [d:\games\starwars - battle grounds with sound (fully working).exe]

09:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Corrupted] on [d:\system volume information\_restore{bb1b914f-52fc-4d07-99e8-943158869a52}\rp35\a0003066.exe]

09:23: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Corrupted] on [d:\system volume information\_restore{7dc9c95e-6295-4f54-b3a1-1430c06bd3dd}\rp437\a0470352.exe]

08:52: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Corrupted] on [c:\program files\emule\temp1.part]

08:51: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [Access Denied] on [c:\pagefile.sys]

08:44: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Corrupted] on [c:\program files\emule\temp7.part]

08:42: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\program files\lavasoft\ad-aware se personal\skins\ad-aware se default.ask]

08:34: Starting File Sweep

08:34: Warning: SweepDirectories: Cannot find directory "a:". This directory was not added to the list of paths to be scanned.

08:34: Cookie Sweep Complete, Elapsed Time: 00:00:00

08:34: Starting Cookie Sweep

08:34: Registry Sweep Complete, Elapsed Time:00:00:10

08:34: Starting Registry Sweep

08:34: Memory Sweep Complete, Elapsed Time: 00:00:52

08:33: Warning: AntiVirus engine for IdentifyMemObject returned [Access Denied] on [C:\WINDOWS\Policies.dll]

08:33: Starting Memory Sweep

08:33: Sweep initiated using definitions version 861

08:33: Spy Sweeper started

08:33: | Start of Session, samedi 17 février 2007 |


08:32: Program Version Using Spyware Definitions 861

08:32: Informational: Loaded AntiVirus Engine: 2.41.0; SDK Version: 4.13; Virus Definitions: 16/02/2007 07:37:56 (GMT)

08:32: Spy Sweeper started

08:32: | Start of Session, samedi 17 février 2007 |


Operation: Terminate

Target: C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe

Source: C:\WINDOWS\system32\csrss.exe

08:29: Tamper Detection

Operation: Terminate

Target: C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe

Source: C:\WINDOWS\system32\csrss.exe

08:29: Tamper Detection

Keylogger: Off

BHO Shield: On

IE Security Shield: On

Alternate Data Stream (ADS) Execution Shield: On

Startup Shield: On

Common Ad Sites: Off

Hosts File Shield: On

Internet Communication Shield: On

ActiveX Shield: On

Windows Messenger Service Shield: On

IE Favorites Shield: On

Spy Installation Shield: On

Memory Shield: Off

IE Hijack Shield: On

IE Tracking Cookies Shield: Off

08:27: Shield States

08:27: Spyware Definitions: 861

08:27: Informational: Loaded AntiVirus Engine: 2.41.0; SDK Version: 4.13; Virus Definitions: 16/02/2007 07:37:56 (GMT)

08:26: Spy Sweeper started

08:26: Spy Sweeper started

08:26: | Start of Session, samedi 17 février 2007 |


08:30: Spy Sweeper started

08:30: Spy Sweeper started

08:30: | Start of Session, samedi 17 février 2007 |


20:04: Spy Installation Shield: found: Virus: Troj/Bckdr-PUX, version

20:03: ApplicationMinimized - EXIT

20:03: ApplicationMinimized - ENTER

20:03: Your virus definitions have been updated.

20:02: Informational: Loaded AntiVirus Engine: 2.41.0; SDK Version: 4.13; Virus Definitions: 16/02/2007 07:37:56 (GMT)

Keylogger: Off

BHO Shield: On

IE Security Shield: On

Alternate Data Stream (ADS) Execution Shield: On

Startup Shield: On

Common Ad Sites: Off

Hosts File Shield: On

Internet Communication Shield: On

20:01: Messenger service has been disabled.

ActiveX Shield: On

Windows Messenger Service Shield: On

IE Favorites Shield: On

Spy Installation Shield: On

Memory Shield: Off

IE Hijack Shield: On

IE Tracking Cookies Shield: Off

20:01: Shield States

20:01: Spyware Definitions: 861

20:01: Informational: Loaded AntiVirus Engine: 2.41.0; SDK Version: 4.13; Virus Definitions: 16/02/2007 07:37:56 (GMT)

20:00: Spy Sweeper started

20:00: Spy Sweeper started

20:00: | Start of Session, vendredi 16 février 2007 |


20:08: Program Version Using Spyware Definitions 861

20:08: Informational: Loaded AntiVirus Engine: 2.41.0; SDK Version: 4.13; Virus Definitions: 16/02/2007 07:37:56 (GMT)

20:07: Spy Sweeper started

20:07: | Start of Session, vendredi 16 février 2007 |


22:07: Removal process completed. Elapsed time 00:00:22

22:07: Quarantining All Traces: Troj/AdClick-DU

22:07: Quarantining All Traces: 180search assistant/zango

22:07: Quarantining All Traces: Troj/SpamTh-Gen

22:07: Quarantining All Traces: fullcontext

22:07: explorer.exe is in use. It will be removed on reboot.

22:07: trojan-backdoor-msdcom32 is in use. It will be removed on reboot.

22:06: Quarantining All Traces: trojan-backdoor-msdcom32

22:06: Removal process initiated

22:06: Traces Found: 12

22:06: File Sweep Complete, Elapsed Time: 01:57:09

22:06: Sweep Canceled

21:31: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:31: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:31: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:31: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:31: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:31: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:31: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:31: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:31: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:31: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:31: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:31: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:30: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:30: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:29: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:29: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:29: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:29: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:28: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:28: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:28: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:28: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:28: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:28: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:28: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:25: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:24: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:23: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:23: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:23: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:23: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:23: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:23: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:23: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:23: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:23: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:23: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:22: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all users\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\documents and settings\all\application data\spybot - search & destroy\recovery\]

21:21: Warning: SweepDirectories: Cannot find directory "f:". This directory was not added to the list of paths to be scanned.

21:21: Warning: SweepDirectories: Cannot find directory "e:". This directory was not added to the list of paths to be scanned.

21:20: a0002697.hta (ID = 0)

21:20: Found Troj/AdClick-DU: Troj/AdClick-DU

21:14: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Corrupted] on [d:\games\starwars - battle grounds with sound (fully working).exe]

21:07: a0006302.ini (ID = 70576)

21:07: Found Adware: 180search assistant/zango

21:01: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Corrupted] on [d:\system volume information\_restore{bb1b914f-52fc-4d07-99e8-943158869a52}\rp35\a0003066.exe]

20:58: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Corrupted] on [d:\system volume information\_restore{7dc9c95e-6295-4f54-b3a1-1430c06bd3dd}\rp437\a0470352.exe]

20:32: pwaq.dll (ID = 0)

20:27: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Corrupted] on [c:\program files\emule\temp1.part]

20:26: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [Access Denied] on [c:\pagefile.sys]

20:19: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Corrupted] on [c:\program files\emule\temp7.part]

20:17: Warning: AntiVirus engine for IdentifyFileObject.ProcessAVResult returned [File Encrypted] on [c:\program files\lavasoft\ad-aware se personal\skins\ad-aware se default.ask]

20:17: fcwol.dll (ID = 0)

20:17: Found Troj/SpamTh-Gen: Troj/SpamTh-Gen

20:09: Starting File Sweep

20:09: Warning: SweepDirectories: Cannot find directory "a:". This directory was not added to the list of paths to be scanned.

20:09: Cookie Sweep Complete, Elapsed Time: 00:00:00

20:09: Starting Cookie Sweep

20:09: Registry Sweep Complete, Elapsed Time:00:00:10

20:09: HKU\S-1-5-21-746137067-920026266-1343024091-1003\software\microsoft\windows\currentversion\run\ || axvenore (ID = 1354027)

20:09: Found Adware: fullcontext

20:09: HKLM\software\microsoft\windows\currentversion\shellserviceobjectdelayload\ || dcom server 2238 (ID = 1589699)

20:09: HKLM\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler\ || {2c1cd3d7-86ac-4068-93bc-a02304bb2238} (ID = 1578070)

20:09: HKLM\software\classes\clsid\{2c1cd3d7-86ac-4068-93bc-a02304bb2238}\ (ID = 1561179)

20:09: HKCR\clsid\{2c1cd3d7-86ac-4068-93bc-a02304bb2238}\ (ID = 1561175)

20:09: Starting Registry Sweep

20:09: Memory Sweep Complete, Elapsed Time: 00:00:48

20:08: Warning: AntiVirus engine for IdentifyMemObject returned [Access Denied] on [C:\WINDOWS\Policies.dll]

20:08: Starting Memory Sweep

20:08: HKCR\clsid\{2c1cd3d7-86ac-4068-93bc-a02304bb2238}\inprocserver32\ (ID = 1604405)

20:08: explorer.exe (ID = 1588150)

20:08: HKLM\software\microsoft\windows\currentversion\run\ || explorer 2238 (ID = 1588150)

20:08: Found Trojan Horse: trojan-backdoor-msdcom32

20:08: Sweep initiated using definitions version 861

20:08: Spy Sweeper started

20:08: | Start of Session, vendredi 16 février 2007 |




Voici le log de hijackthis:


Logfile of HijackThis v1.99.1

Scan saved at 10:15:04, on 17/02/2007

Platform: Windows XP (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 (6.00.2600.0000)


Running processes:











C:\Program Files\Winamp\Winampa.exe

C:\Program Files\QuickTime\qttask.exe

C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe


C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe



C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\Program Files\Messenger\msmsgs.exe


C:\Program Files\SpamPal\spampal.exe


C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

C:\Program Files\Inventel\Gateway\wlancfg.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe


C:\Program Files\Webroot\Spy Sweeper\SSU.EXE


C:\Documents and Settings\Olivier\Bureau\hijackthis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: TMSN Class - {B72549CE-5644-4116-B8A4-A2B042321EC4} - C:\WINDOWS\Policies.dll (file missing)

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx

O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install

O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"

O4 - HKLM\..\Run: [_zlu_zlope04] c:\windows\system32\_zsk_zlu_zlope04cwr_tgawotlcmef_.exe

O4 - HKLM\..\Run: [hp Update 3300C] "C:\sj650\hpupdate.exe" 3300C+

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKLM\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray

O4 - HKLM\..\RunServices: [_zlu_zlope04] c:\windows\system32\_zsk_zlu_zlope04cwr_tgawotlcmef_.exe

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe

O4 - HKCU\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit

O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [_zlu_zlope04] c:\windows\system32\_zsk_zlu_zlope04cwr_tgawotlcmef_.exe

O4 - Startup: SpamPal.lnk = C:\Program Files\SpamPal\spampal.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -

O20 - AppInit_DLLs: \\?\C:\WINDOWS\System32\com1.xdo

O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

O23 - Service: Service de lancement de WlanCfg (Wlancfg) - Inventel - C:\Program Files\Inventel\Gateway\wlancfg.exe



Je poursuis avec les scans en ligne... merci!

