Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e) (modifié)



Essayez ceci:

Vérifier les paramètres d'Internet ...


1) Dans Internet Explorer, clique sur Outils > Options Internet... puis, onglet "Sécurité".

2) Choisir la zone Internet puis, clique sur le bouton Niveau par défaut.


Si cela ne fonctionne pas, essayer ceci


1) Clic sur le bouton Personnaliser le niveau...

2) Cocher tous les boutons radio Activer ou Demander.

3) Valider puis, relancer Internet Explorer.

4) Accéder de nouveau à l'onglet "Sécurité".

5) Cocher le bouton radio Niveau par défaut...

6) Valider puis, relancer Internet Explorer.




Télécharger Antivir

NB : le choix d'Antivir comme antivirus à utiliser dans le cadre de cette procédure, a reposé sur les critères suivants :

--- failles de votre antivirus qui a laissé passer des malwares

--- En mode sans échec ,seuls les processus systèmes sont lancés.Il est donc plus facile de supprimer les infections

--- Antivir peut-être installé et désinstallé facilement

--- Antivir est reconnu pour son efficacité en mode sans échec


Paramètres conseillés

Clic droit sur le parapluie->Configure

Cliquer Expert mode->Scan:

Cocher: All files

Additionnal Settings:tout cocher

Clic sur scan +

Action for concerning files:


copie file to quarantine before action

Primary action...................: repair => au cas ou ce serait un fichier système corrompu

Secondary action.................: delete => s'il y a détection, autant supprimer. une sauvegarde sera dans la quarantaine


Désactivez votre antivirus actuel

Redémarrez en mode sans échec.

Lancez le scan

Postez le rapport


Pour Windows XP SP2 il est possible de refaire un reset de Winsock

(dans le cas où un antivirus se charge dans les LSP il sera supprimé aussi),

cela se fait comme ceci :

Menu Démarrer / executer et taper : netsh winsock reset catalog

Redémarrez l'ordinateur.

Modifié par pear


je n'est pas réussi à faire fonctionner IE7 (ça sera pour une prochaine fois et j'ai une question je télécharge lequel d'antivir parce-que j'ai vu qu'ils y en avaient plusieurs?


je vous poste ici le fichier txt de combofix et une fois que j'aurais le logiciel antivir je vous mettrais le rapport...


ComboFix 08-08-12.01 - Laure et Steve 2008-08-14 18:03:55.5 - NTFSx86

Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.1691 [GMT 2:00]

Endroit: C:\Documents and Settings\Laure et Steve\Bureau\ComboFix.exe

Command switches used :: C:\Documents and Settings\Laure et Steve\Bureau\CFScript.txt.txt

* Création d'un nouveau point de restauration









(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))






((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-14 to 2008-08-14 ))))))))))))))))))))))))))))))))))))



2008-08-14 18:00 . 2008-08-14 18:00 <REP> d-------- C:\Combo-Fix

2008-08-14 12:56 . 2008-08-14 18:00 1,374 --a------ C:\WINDOWS\imsins.BAK

2008-08-12 18:16 . 2008-08-12 18:16 <REP> d-------- C:\Muestras

2008-08-09 13:06 . 2008-08-09 13:06 <REP> d-------- C:\Program Files\iPod

2008-08-09 13:06 . 2008-08-09 13:06 <REP> d-------- C:\Program Files\Apple Software Update

2008-08-04 20:38 . 2008-08-04 20:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Mindjet

2008-08-04 20:38 . 2002-12-28 10:26 20,569 --a------ C:\WINDOWS\system32\pxc25pm.dll

2008-08-04 20:35 . 2008-08-04 20:35 <REP> d-------- C:\WINDOWS\Downloaded Installations

2008-08-04 20:03 . 2008-08-04 20:03 <REP> d-------- C:\Documents and Settings\Laure et Steve\Application Data\QXL Ricardo

2008-08-03 09:55 . 2006-10-05 04:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys

2008-08-03 09:55 . 2006-10-05 04:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys

2008-08-02 19:57 . 2008-08-02 19:57 <REP> d-------- C:\Documents and Settings\Laure et Steve\Application Data\TeamViewer

2008-08-02 19:56 . 2008-08-02 19:56 <REP> d-------- C:\Documents and Settings\Laure et Steve\temp

2008-08-02 19:53 . 2008-08-02 19:53 <REP> d-------- C:\Program Files\TGTSoft

2008-07-30 15:46 . 2004-08-19 16:09 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll

2008-07-30 15:46 . 2001-08-23 17:47 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll

2008-07-29 13:09 . 2003-03-16 00:15 90,112 --a------ C:\WINDOWS\unvise32.exe

2008-07-28 10:52 . 2008-08-03 09:55 <REP> d-------- C:\Program Files\Google

2008-07-25 14:43 . 2008-07-25 14:43 <REP> d-------- C:\Documents and Settings\Laure et Steve\Application Data\CD-LabelPrint

2008-07-24 21:25 . 2008-07-24 21:25 <REP> d-------- C:\WINDOWS\system32\XPSViewer

2008-07-24 21:25 . 2008-07-24 21:25 <REP> d-------- C:\Program Files\Reference Assemblies

2008-07-24 21:25 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll

2008-07-20 17:43 . 2008-07-20 17:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage

2008-07-20 17:42 . 2008-02-14 22:50 676,224 --a------ C:\WINDOWS\system32\ogacheckcontrol.dll

2008-07-19 21:36 . 2008-07-19 21:36 <REP> d-------- C:\Documents and Settings\All Users\Application Data\U3

2008-07-17 18:10 . 2006-12-07 10:45 1,163,264 --a------ C:\WINDOWS\system32\u3dapi10.dll

2008-07-15 19:47 . 2008-04-23 06:16 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll

2008-07-15 19:47 . 2007-04-17 11:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat

2008-07-15 19:47 . 2007-03-08 07:10 1,048,576 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui

2008-07-15 19:47 . 2008-04-23 06:16 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll

2008-07-15 19:47 . 2008-04-23 06:16 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll

2008-07-15 19:47 . 2008-04-23 06:16 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll

2008-07-15 19:47 . 2008-04-23 06:16 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll

2008-07-15 19:47 . 2008-04-23 06:16 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll

2008-07-15 19:47 . 2008-04-22 09:39 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe

2008-07-14 23:05 . 2008-07-14 23:05 <REP> d-------- C:\Program Files\MSXML 4.0

2008-07-14 22:03 . 2008-07-14 22:05 <REP> d-------- C:\WINDOWS\NV26802688.TMP

2008-07-14 22:03 . 2007-03-07 08:49 111,171 --a------ C:\WINDOWS\system32\nvapps.nvb

2008-07-14 22:03 . 2005-06-24 17:05 16,958 --a------ C:\WINDOWS\system32\evga.ico

2008-07-14 22:02 . 2008-07-14 22:02 <REP> d-------- C:\WINDOWS\system32\EVGA

2008-07-14 22:01 . 2007-03-07 02:49 225,280 -ra------ C:\WINDOWS\system32\nvrszhc.dll

2008-07-14 22:01 . 2007-03-07 02:49 167,936 -ra------ C:\WINDOWS\system32\nvwrszht.dll

2008-07-14 22:01 . 2007-03-07 02:49 163,840 -ra------ C:\WINDOWS\system32\nvwrszhc.dll

2008-07-14 22:01 . 2007-03-07 02:49 122,880 -ra------ C:\WINDOWS\system32\nvrszht.dll

2008-07-14 22:01 . 2007-03-07 02:49 111,171 -ra------ C:\WINDOWS\system32\nvapps.xml

2008-07-14 21:59 . 2007-03-07 08:49 6,660,096 --a------ C:\WINDOWS\system32\nvoglnt.dll

2008-07-14 21:59 . 2007-03-07 02:49 335,872 --a------ C:\WINDOWS\system32\nvapi.dll

2008-07-14 21:59 . 2007-03-07 02:49 163,908 --a------ C:\WINDOWS\system32\nvsvc32.exe

2008-07-14 21:52 . 2004-08-19 16:09 116,736 --a--c--- C:\WINDOWS\system32\dllcache\xrxwiadr.dll

2008-07-14 21:52 . 2001-08-23 17:47 27,648 --a--c--- C:\WINDOWS\system32\dllcache\xrxftplt.exe

2008-07-14 21:52 . 2001-08-23 17:47 23,040 --a--c--- C:\WINDOWS\system32\dllcache\xrxwbtmp.dll

2008-07-14 21:52 . 2001-08-23 17:47 17,408 --a--c--- C:\WINDOWS\system32\dllcache\xrxscnui.dll

2008-07-14 21:50 . 2001-08-17 21:28 794,654 --a--c--- C:\WINDOWS\system32\dllcache\usr1801.sys

2008-07-14 21:49 . 2001-08-23 17:47 525,568 --a--c--- C:\WINDOWS\system32\dllcache\tridxp.dll

2008-07-14 21:48 . 2001-08-23 16:57 286,848 --a--c--- C:\WINDOWS\system32\dllcache\stlnata.sys

2008-07-14 21:47 . 2004-08-03 22:41 404,990 --a--c--- C:\WINDOWS\system32\dllcache\slntamr.sys

2008-07-14 21:46 . 2001-08-23 17:46 386,560 --a--c--- C:\WINDOWS\system32\dllcache\sgiul50.dll

2008-07-14 21:45 . 2001-08-23 17:47 495,616 --a--c--- C:\WINDOWS\system32\dllcache\sblfx.dll

2008-07-14 21:44 . 2001-08-23 17:18 899,914 --a--c--- C:\WINDOWS\system32\dllcache\r2mdkxga.sys

2008-07-14 21:43 . 2001-08-17 22:05 351,616 --a--c--- C:\WINDOWS\system32\dllcache\ovcodek2.sys

2008-07-14 21:42 . 2007-02-28 18:02 2,059,648 --a--c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe

2008-07-14 21:41 . 2004-08-19 16:09 1,737,856 --a--c--- C:\WINDOWS\system32\dllcache\mtxparhd.dll

2008-07-14 21:40 . 2001-08-17 21:28 802,683 --a--c--- C:\WINDOWS\system32\dllcache\ltsm.sys

2008-07-14 21:39 . 2001-08-23 17:47 372,824 --a--c--- C:\WINDOWS\system32\dllcache\iconf32.dll

2008-07-14 21:38 . 2004-08-03 22:41 1,041,536 --a--c--- C:\WINDOWS\system32\dllcache\hsfdpsp2.sys

2008-07-14 21:37 . 2001-08-23 17:46 1,733,120 --a--c--- C:\WINDOWS\system32\dllcache\g400d.dll

2008-07-14 21:36 . 2001-08-23 17:13 634,166 --a--c--- C:\WINDOWS\system32\dllcache\el656ct5.sys

2008-07-14 21:35 . 2001-08-17 20:14 952,007 --a--c--- C:\WINDOWS\system32\dllcache\diwan.sys

2008-07-14 21:34 . 2001-08-23 17:04 980,034 --a--c--- C:\WINDOWS\system32\dllcache\cicap.sys

2008-07-14 21:33 . 2007-02-28 18:02 2,182,400 --a--c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe

2008-07-14 21:22 . 2008-08-14 15:19 <REP> d-------- C:\WINDOWS\system32\CatRoot2



(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))


2008-08-14 10:47 --------- d-----w C:\Documents and Settings\Laure et Steve\Application Data\Canon

2008-08-13 17:49 --------- d-----w C:\Documents and Settings\Laure et Steve\Application Data\Apple Computer

2008-08-11 16:22 --------- d-----w C:\Documents and Settings\Laure et Steve\Application Data\U3

2008-08-07 16:42 360,320 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL

2008-08-07 16:42 360,320 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS

2008-07-29 10:44 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-07-29 10:43 --------- d-----w C:\Program Files\Fichiers communs\Adobe

2008-07-28 13:18 --------- d-----w C:\Documents and Settings\Laure et Steve\Application Data\LimeWire

2008-07-20 09:56 --------- d-----w C:\Documents and Settings\Laure et Steve\Application Data\Azureus

2008-07-19 14:06 --------- d-----w C:\Program Files\Bonjour

2008-07-07 16:30 --------- d-----w C:\Program Files\CrossLoop

2008-07-06 17:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\TechSmith

2008-07-06 17:45 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard

2008-07-05 17:59 --------- d-----w C:\Program Files\Rapidown

2008-07-05 16:57 --------- d-----w C:\Program Files\Fichiers communs\Java

2008-07-02 16:36 --------- d-----w C:\Program Files\QuickTime

2008-07-02 16:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer

2008-07-02 16:35 --------- d-----w C:\Program Files\Fichiers communs\Apple

2008-07-02 16:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple

2008-06-30 17:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Adobe Systems

2008-06-30 17:11 --------- d-----w C:\Program Files\Fichiers communs\Adobe Systems Shared

2008-06-28 12:59 --------- d-----w C:\Documents and Settings\Laure et Steve\Application Data\ameCache

2008-06-26 18:22 --------- d-----w C:\Program Files\Windows Media Connect 2

2008-06-25 21:32 --------- d-----w C:\Program Files\MSXML 6.0

2008-06-24 16:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft

2008-06-23 20:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Minnetonka Audio Software

2008-06-23 18:55 --------- d-----w C:\Documents and Settings\Laure et Steve\Application Data\Druide

2008-06-23 18:26 --------- d-----w C:\Program Files\Fichiers communs\Ahead

2008-06-23 18:24 --------- d-----w C:\Documents and Settings\Laure et Steve\Application Data\Ahead

2008-06-23 16:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help

2008-06-23 16:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus

2008-06-23 16:14 --------- d-----w C:\Program Files\MSBuild

2008-06-23 16:14 --------- d-----w C:\Program Files\Microsoft Works

2008-06-23 16:12 --------- d-----w C:\Program Files\Microsoft.NET

2008-06-23 16:10 --------- d-----w C:\Program Files\Microsoft Visual Studio 8

2008-06-23 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec

2008-06-23 15:56 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared

2008-06-22 20:47 --------- d-----w C:\Documents and Settings\Laure et Steve\Application Data\Talkback

2008-06-22 20:30 --------- d-----w C:\Documents and Settings\Laure et Steve\Application Data\Symantec

2008-06-22 19:13 --------- d-----w C:\Program Files\Canon

2008-06-22 19:10 --------- d--h--w C:\Documents and Settings\All Users\Application Data\CanonBJ

2008-06-22 18:47 --------- d-----w C:\Program Files\ASUS

2008-06-22 18:46 --------- d-----w C:\Program Files\Fichiers communs\InstallShield

2008-06-22 18:46 --------- d-----w C:\Program Files\Attansic

2008-06-22 18:40 315,392 ----a-w C:\WINDOWS\HideWin.exe

2008-06-22 18:40 --------- d-----w C:\Program Files\Realtek

2008-06-22 18:33 --------- d-----w C:\Program Files\Intel

2008-06-22 18:24 --------- d-----w C:\Program Files\microsoft frontpage

2008-06-22 18:23 --------- d-----w C:\Program Files\Services en ligne

2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys

2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys

2008-06-14 17:59 272,768 ----a-w C:\WINDOWS\system32\drivers\bthport.sys



------- Sigcheck -------


2007-10-30 18:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys

2008-06-20 12:44 360960 744e57c99232201ae98c49168b918f48 C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys

2008-06-20 13:51 361600 9aefa14bd6b182d61e3119fa5f436d3d C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys

2008-06-20 13:59 361600 ad978a1b783b5719720cff204b666c8e C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys

2007-10-29 14:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys

2008-08-07 18:42 360320 3adce4790f591bf160a94f6f08039577 C:\WINDOWS\system32\dllcache\TCPIP.SYS

2008-08-07 18:42 360320 3adce4790f591bf160a94f6f08039577 C:\WINDOWS\system32\drivers\TCPIP.SYS


((((((((((((((((((((((((((((( snapshot@2008-08-13_20.28.14.12 )))))))))))))))))))))))))))))))))))))))))


- 2005-07-26 04:39:57 243,200 -c--a-w C:\WINDOWS\system32\dllcache\es.dll

+ 2008-07-07 20:31:48 253,952 -c--a-w C:\WINDOWS\system32\dllcache\es.dll

- 2007-08-21 06:17:23 683,520 -c--a-w C:\WINDOWS\system32\dllcache\inetcomm.dll

+ 2008-04-11 18:51:06 683,520 -c--a-w C:\WINDOWS\system32\dllcache\inetcomm.dll

- 2007-10-29 12:00:00 331,776 -c--a-w C:\WINDOWS\system32\dllcache\msadce.dll

+ 2008-05-01 14:31:48 331,776 -c--a-w C:\WINDOWS\system32\dllcache\msadce.dll

- 2005-06-29 01:49:41 74,240 -c--a-w C:\WINDOWS\system32\dllcache\mscms.dll

+ 2008-06-24 16:23:56 74,240 -c--a-w C:\WINDOWS\system32\dllcache\mscms.dll

- 2005-07-26 04:39:57 243,200 ----a-w C:\WINDOWS\system32\es.dll

+ 2008-07-07 20:31:48 253,952 ----a-w C:\WINDOWS\system32\es.dll

- 2007-08-21 06:17:23 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll

+ 2008-04-11 18:51:06 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll

- 2005-06-29 01:49:41 74,240 ----a-w C:\WINDOWS\system32\mscms.dll

+ 2008-06-24 16:23:56 74,240 ----a-w C:\WINDOWS\system32\mscms.dll

- 2007-11-30 12:39:29 18,296 ------w C:\WINDOWS\system32\spmsg.dll

+ 2007-11-30 11:19:06 18,296 ------w C:\WINDOWS\system32\spmsg.dll

- 2008-03-27 09:24:20 60,416 ----a-w C:\WINDOWS\system32\tzchange.exe

+ 2008-07-14 11:09:18 62,976 ----a-w C:\WINDOWS\system32\tzchange.exe


((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))




*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s



"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-10-29 14:00 15360]

"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-10-09 11:28 139264]

"pdfSaver3"="D:\mind manager 7 pro\PDF-XChange\pdfSaver\pdfSaver3.exe" [2004-09-05 17:20 380928]



"pccguide.exe"="D:\trend micro ver.14\pccguide.exe" [2008-08-13 19:03 901185]

"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]

"SunJavaUpdateSched"="D:\java\bin\jusched.exe" [2008-03-25 04:28 144784]

"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-03-07 08:49 8425472]

"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-03-07 08:49 81920]

"AppleSyncNotifier"="C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]

"MMReminderService"="D:\mind manager 7 pro\MMReminderService.exe" [2007-07-24 03:40 37136]

"iTunesHelper"="D:\Itunes\iTunesHelper.exe" [2008-07-30 10:47 289064]

"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 16:49 16126464 C:\WINDOWS\RTHDCPL.exe]

"nwiz"="nwiz.exe" [2007-03-07 02:49 1622016 C:\WINDOWS\system32\nwiz.exe]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\iexplore.exe]

"Debugger"=StripMyRights.exe /D /L N


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\outlook.exe]

"Debugger"=StripMyRights.exe /D /L N



"EnableFirewall"= 0 (0x0)




"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=



R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 16:12]



\Shell\AutoRun\command - J:\LaunchU3.exe -a



\Shell\AutoRun\command - J:\LaunchU3.exe -a



\Shell\AutoRun\command - L:\LaunchU3.exe -a


Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'


2008-08-09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job

- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]




catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,

Rootkit scan 2008-08-14 18:06:42

Windows 5.1.2600 Service Pack 2 NTFS


Balayage processus cach‚s ...


Balayage cach‚ autostart entries ...


Balayage des fichiers cach‚s ...


Scan termin‚ avec succŠs

Les fichiers cach‚s: 0




------------------------ Other Running Processes ------------------------


D:\ad aware 2008\prog\aawservice.exe


C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe


C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe

C:\Program Files\iPod\bin\iPodService.exe




Temps d'accomplissement: 2008-08-14 18:08:29 - machine was rebooted [Laure et Steve]

ComboFix-quarantined-files.txt 2008-08-14 16:08:15

ComboFix2.txt 2008-08-14 15:57:19

ComboFix3.txt 2008-08-13 18:29:22


Pre-Run: 15,943,036,928 octets libres

Post-Run: 15,929,532,416 octets libres


247 --- E O F --- 2008-08-14 16:00:47



merci d'avance.


bonjours j'aurais une petite question, vous allez me prendre pour un fou, mais bon je me lance avant que j'ai eu ces problèmes avec ce vers bagle j'avais songé à formater, pour différentes cause (iE7 qui ne fonctionne plus) et autres problème assez agassants, j'attendais de désinfecter mon pc pour pouvoir réparer IE7 et nettoyer un peu mon disque c. mais vu l'ampleur du problème et le temps que ça prend je me pose la question.... ma question c'est est-ce que le formatage pourrait éradiquer le vers ou pas? celà m'ennuie de vous faire perdre votre temps pour rien, si le formatage serait une solution! salutations

ma question c'est est-ce que le formatage pourrait éradiquer le vers ou pas? celà m'ennuie de vous faire perdre votre temps pour rien, si le formatage serait une solution!


Tous vos problèmes viennent de bagle, y compris Internet, Mode sans échec etc...

Le formatage n'est que très rarement une bonne solution.


Installez la version free d'Antivir et gardez là ensuite.C'est l'un des meilleurs antivirus et il est gratuit.

Configurez le comme dit plus haut et postez en le rapport.


bonsoir voici le résultat du scan.



Avira AntiVir Personal

Report file date: vendredi, 15. août 2008 16:46


Scanning for 1556257 virus strains and unwanted programs.


Licensed to: Avira AntiVir PersonalEdition Classic

Serial number: 0000149996-ADJIE-0001

Platform: Windows XP

Windows version: (Service Pack 2) [5.1.2600]

Boot mode: Save mode

Username: Laure et Steve

Computer name: LAUREETSTEVE


Version information:

BUILD.DAT : 16479 Bytes 09/04/2008 16:24:00

AVSCAN.EXE : 311553 Bytes 18/03/2008 09:02:56

AVSCAN.DLL : 53505 Bytes 07/02/2008 08:43:37

LUKE.DLL : 151809 Bytes 28/02/2008 08:41:23

LUKERES.DLL : 12033 Bytes 21/02/2008 08:28:40

ANTIVIR0.VDF : 11030528 Bytes 18/07/2007 10:33:34

ANTIVIR1.VDF : 8182784 Bytes 24/06/2008 14:40:20

ANTIVIR2.VDF : 2587136 Bytes 14/08/2008 14:40:26

ANTIVIR3.VDF : 74240 Bytes 15/08/2008 14:40:27

Engineversion :

AEVDF.DLL : 102772 Bytes 25/02/2008 09:58:21

AESCRIPT.DLL : 311673 Bytes 15/08/2008 14:40:34

AESCN.DLL : 119156 Bytes 15/08/2008 14:40:33

AERDL.DLL : 418165 Bytes 15/08/2008 14:40:33

AEPACK.DLL : 364917 Bytes 15/08/2008 14:40:32

AEOFFICE.DLL : 192891 Bytes 15/08/2008 14:40:32

AEHEUR.DLL : 1368437 Bytes 15/08/2008 14:40:31

AEHELP.DLL : 115063 Bytes 15/08/2008 14:40:30

AEGEN.DLL : 315764 Bytes 15/08/2008 14:40:29

AEEMU.DLL : 430452 Bytes 15/08/2008 14:40:29

AECORE.DLL : 172406 Bytes 15/08/2008 14:40:28

AEBB.DLL : 53617 Bytes 15/08/2008 14:40:28

AVWINLL.DLL : 14593 Bytes 23/01/2008 17:07:53

AVPREF.DLL : 25857 Bytes 18/02/2008 10:37:50

AVREP.DLL : 98344 Bytes 15/08/2008 14:40:27

AVREG.DLL : 30977 Bytes 23/01/2008 17:07:49

AVARKT.DLL : 307457 Bytes 12/02/2008 08:29:23

AVEVTLOG.DLL : 114945 Bytes 28/02/2008 08:31:31

SQLITE3.DLL : 339968 Bytes 22/01/2008 17:28:02

SMTPLIB.DLL : 28929 Bytes 23/01/2008 17:08:39

NETNT.DLL : 7937 Bytes 25/01/2008 12:05:10

RCIMAGE.DLL : 2371841 Bytes 10/03/2008 14:37:25

RCTEXT.DLL : 86273 Bytes 06/03/2008 12:02:11


Configuration settings for the scan:

Jobname..........................: Complete system scan

Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp

Logging..........................: low

Primary action...................: repair

Secondary action.................: delete

Scan master boot sector..........: on

Scan boot sector.................: on

Boot sectors.....................: C:, D:, E:, F:, I:, O:,

Scan memory......................: on

Process scan.....................: on

Scan registry....................: on

Search for rootkits..............: on

Scan all files...................: All files

Scan archives....................: on

Recursion depth..................: 20

Smart extensions.................: on

Macro heuristic..................: on

File heuristic...................: medium


Start of the scan: vendredi, 15. août 2008 16:46


Starting search for hidden objects.

The driver could not be initialized.


The scan of running processes will be started

Scan process 'avscan.exe' - '1' Module(s) have been scanned

Scan process 'avcenter.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'explorer.exe' - '1' Module(s) have been scanned

Scan process 'aawservice.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'lsass.exe' - '1' Module(s) have been scanned

Scan process 'services.exe' - '1' Module(s) have been scanned

Scan process 'winlogon.exe' - '1' Module(s) have been scanned

Scan process 'csrss.exe' - '1' Module(s) have been scanned

Scan process 'smss.exe' - '1' Module(s) have been scanned

12 processes with 12 modules were scanned


Starting master boot sector scan:

Master boot sector HD0

[iNFO] No virus was found!

Master boot sector HD1

[iNFO] No virus was found!

Master boot sector HD2

[iNFO] No virus was found!


Start scanning boot sectors:

Boot sector 'C:\'

[iNFO] No virus was found!

Boot sector 'D:\'

[iNFO] No virus was found!

Boot sector 'E:\'

[iNFO] No virus was found!

Boot sector 'F:\'

[iNFO] No virus was found!

Boot sector 'I:\'

[iNFO] No virus was found!

Boot sector 'O:\'

[iNFO] No virus was found!


Starting to scan the registry.

The registry was scanned ( '35' files ).



Starting the file scan:


Begin scan in 'C:\'


[WARNING] The file could not be opened!

C:\Muestras\HLDRRR.EXE.Muestra EliBagle v11.66

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.XK

[NOTE] A backup was created as '48e998bb.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\data.oct.vir

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199ae4.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\flec006.exe.vir

[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '490a9af0.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenOffice Calc Join (Merge, Combine) Multiple Sheets & Files Into One Software

[0] Archive type: ZIP

--> OpenOffice Calc Join (Merge, Combine) Multiple Sheets & Files Into One Software 7.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9af5.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenOffice Calc Password Recovery

[0] Archive type: ZIP

--> OpenOffice Calc Password Recovery 1.0.4.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9af6.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenOffice Draw Password Recovery

[0] Archive type: ZIP

--> OpenOffice Draw Password Recovery 1.0.3.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '4888c777.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenOffice IFilter

[0] Archive type: ZIP

--> OpenOffice IFilter 1.4.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9af7.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenOffice Password Recovery

[0] Archive type: ZIP

--> OpenOffice Password Recovery 1.0.3.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9af8.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenOffice Writer Extract Email Addresses From Documents Software

[0] Archive type: ZIP

--> OpenOffice Writer Extract Email Addresses From Documents Software 7.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9af9.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenOffice Writer Find and Replace In Multiple Documents Software

[0] Archive type: ZIP

--> OpenOffice Writer Find and Replace In Multiple Documents Software 7.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9afa.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenOffice Writer Import Multiple Word Documents Software

[0] Archive type: ZIP

--> OpenOffice Writer Import Multiple Word Documents Software 7.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9afb.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\ for

[0] Archive type: ZIP

--> for Linux.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9afc.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenPandora

[0] Archive type: ZIP

--> OpenPandora 0.6.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '4888c77d.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenPhotoPod

[0] Archive type: ZIP

--> OpenPhotoPod 0.0.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9afd.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\openPim 1.2

[0] Archive type: ZIP

--> openPim 1.2 beta.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9afe.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenPlsInWM

[0] Archive type: ZIP

--> OpenPlsInWM 1.0.2.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9aff.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenProj

[0] Archive type: ZIP

--> OpenProj 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b01.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenRemind 1.0.7 Build

[0] Archive type: ZIP

--> OpenRemind 1.0.7 Build 1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '4888c682.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenRun

[0] Archive type: ZIP

--> OpenRun 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b02.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opens and Save Files Utility

[0] Archive type: ZIP

--> Opens and Save Files Utility 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b03.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenSearchFox

[0] Archive type: ZIP

--> OpenSearchFox 0.1.5.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b04.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenSebJ

[0] Archive type: ZIP

--> OpenSebJ 0.41.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b05.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenSezMe

[0] Archive type: ZIP

--> OpenSezMe 1.3.4.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b06.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opensisma 1.3 Build

[0] Archive type: ZIP

--> Opensisma 1.3 Build 80208.4.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '4888c687.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenSSL

[0] Archive type: ZIP

--> OpenSSL 0.9.8g.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b07.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenStego

[0] Archive type: ZIP

--> OpenStego 0.3.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b09.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\ search

[0] Archive type: ZIP

--> search 0.2.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b0a.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenTalk

[0] Archive type: ZIP

--> OpenTalk 3.14.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '4888c68b.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenURL Referrer

[0] Archive type: ZIP

--> OpenURL Referrer 2.3.7.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b0b.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenVIP

[0] Archive type: ZIP

--> OpenVIP 1.1.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b0c.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenVPN GUI

[0] Archive type: ZIP

--> OpenVPN GUI 1.0.3.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b0e.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Openwave Location Studio SDK

[0] Archive type: ZIP

--> Openwave Location Studio SDK 2.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b0f.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Openwave MMS SDK

[0] Archive type: ZIP

--> Openwave MMS SDK 3.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b10.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Openwave WAP Push Library

[0] Archive type: ZIP

--> Openwave WAP Push Library 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '4888c691.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenWire

[0] Archive type: ZIP

--> OpenWire 2.6.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b11.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenWithView

[0] Archive type: ZIP

--> OpenWithView 1.01.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b12.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Openworld FlashPresenter

[0] Archive type: ZIP

--> Openworld FlashPresenter

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b14.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenX ASP Edition for MSSQL, Sybase, Oracle, MySQL

[0] Archive type: ZIP

--> OpenX ASP Edition for MSSQL, Sybase, Oracle, MySQL 2.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b15.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenX for MS SQL Server

[0] Archive type: ZIP

--> OpenX for MS SQL Server 2.0.2.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b16.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenX for MySQL

[0] Archive type: ZIP

--> OpenX for MySQL 2.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b17.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenX for Oracle 7i, 8i

[0] Archive type: ZIP

--> OpenX for Oracle 7i, 8i 2.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b19.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenXML Writer

[0] Archive type: ZIP

--> OpenXML Writer 1.2.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '4888c69a.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OPENXTRA Console

[0] Archive type: ZIP

--> OPENXTRA Console 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '48ea9afa.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpenzUp

[0] Archive type: ZIP

--> OpenzUp 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b1c.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera ASA Office Analog Clocks

[0] Archive type: ZIP

--> Opera ASA Office Analog Clocks 1.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b1d.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera BackupX

[0] Archive type: ZIP

--> Opera BackupX 0.4.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '4888c69e.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera Bible

[0] Archive type: ZIP

--> Opera Bible 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b1e.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera Christmas Widget!

[0] Archive type: ZIP

--> Opera Christmas Widget! 0.6.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b1f.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera Clock

[0] Archive type: ZIP

--> Opera Clock 1.3.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b20.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera for Linux

[0] Archive type: ZIP

--> Opera for Linux 7.21.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b21.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera for Windows with Java

[0] Archive type: ZIP

--> Opera for Windows with Java 7.54u2.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b22.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera Forum Search

[0] Archive type: ZIP

--> Opera Forum Search 1.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b23.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera Launcher

[0] Archive type: ZIP

--> Opera Launcher 2.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b24.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera Password Recovery

[0] Archive type: ZIP

--> Opera Password Recovery 3.4.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b25.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera Password Recovery Master

[0] Archive type: ZIP

--> Opera Password Recovery Master

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b26.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera Snow

[0] Archive type: ZIP

--> Opera Snow 0.2.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '4888c6a7.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera Update Checker

[0] Archive type: ZIP

--> Opera Update Checker 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b28.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera Uptime

[0] Archive type: ZIP

--> Opera Uptime 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b29.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera Web Applications Blog

[0] Archive type: ZIP

--> Opera Web Applications Blog 1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b2a.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera Widget Maker

[0] Archive type: ZIP

--> Opera Widget Maker 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b2b.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera's DC++ (oDC)

[0] Archive type: ZIP

--> Opera's DC++ (oDC) 5.31.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b2c.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera's Ruler

[0] Archive type: ZIP

--> Opera's Ruler 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b2e.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\

[0] Archive type: ZIP

--> .9.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b2f.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opera@USB 9.27 Build

[0] Archive type: ZIP

--> Opera@USB 9.27 Build 8841.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b31.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OperaAdFilter

[0] Archive type: ZIP

--> OperaAdFilter 1.01.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '4888c6b2.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Operating System Gadget

[0] Archive type: ZIP

--> Operating System Gadget

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b32.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Operator

[0] Archive type: ZIP

--> Operator 0.8.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b33.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OperaTor

[0] Archive type: ZIP

--> OperaTor 2.6b.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490a9b34.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OperaView

[0] Archive type: ZIP

--> OperaView 0.6.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '4888c6b5.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Ophcrack

[0] Archive type: ZIP

--> Ophcrack 2.4.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490d9b36.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OPI Swapper for InDesign CS2

[0] Archive type: ZIP

--> OPI Swapper for InDesign CS2 6.1r10.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '48ee9b17.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OPI Swapper for QuarkXPress 6.x

[0] Archive type: ZIP

--> OPI Swapper for QuarkXPress 6.x 6.0r8.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '48ee9b18.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\opImage

[0] Archive type: ZIP

--> opImage 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '48ee9b39.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opinio

[0] Archive type: ZIP

--> Opinio 6.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '490e9b3a.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OPML Library for .NET

[0] Archive type: ZIP

--> OPML Library for .NET 2.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '48f29b1b.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OPML Reader

[0] Archive type: ZIP

--> OPML Reader 0.2.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '48f29b1c.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OPML Support

[0] Archive type: ZIP

--> OPML Support 1.4.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '48f29b1d.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opt-In List Extractor

[0] Archive type: ZIP

--> Opt-In List Extractor 1.0b.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b3e.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Opt-In List Manager

[0] Archive type: ZIP

--> Opt-In List Manager 1.0.15.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b40.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OptContact

[0] Archive type: ZIP

--> OptContact 1.0.4.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '489bc6c1.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OptDrvr - Options Calculator

[0] Archive type: ZIP

--> OptDrvr - Options Calculator 10.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b41.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optenet PC Web Filter

[0] Archive type: ZIP

--> Optenet PC Web Filter 9.4.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b42.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optical Illusion Of The Day

[0] Archive type: ZIP

--> Optical Illusion Of The Day 4.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b43.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optical Info

[0] Archive type: ZIP

--> Optical Info 1.02.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b44.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OpticamFX

[0] Archive type: ZIP

--> OpticamFX 1.2.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b46.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optician Information Management

[0] Archive type: ZIP

--> Optician Information Management 1.3.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '489bc6c7.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\optiDesigner

[0] Archive type: ZIP

--> optiDesigner 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b47.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optidraft

[0] Archive type: ZIP

--> Optidraft 2.03.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b48.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\optiGA

[0] Archive type: ZIP

--> optiGA 2.01.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b49.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optilink

[0] Archive type: ZIP

--> Optilink 3.0.24.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b4a.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optima Metrics Group

[0] Archive type: ZIP

--> Optima Metrics Group 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b4b.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OptimAccess Dial

[0] Archive type: ZIP

--> OptimAccess Dial 3.0.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '489bc6cc.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimal Archive 1.1 build

[0] Archive type: ZIP

--> Optimal Archive 1.1 build 138.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b4c.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimal Data Analyses

[0] Archive type: ZIP

--> Optimal Data Analyses 2.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b4d.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimal Desktop - Professional Edition 5.0

[0] Archive type: ZIP

--> Optimal Desktop - Professional Edition 5.0 r220.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b4f.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimal Desktop Standard 5.0

[0] Archive type: ZIP

--> Optimal Desktop Standard 5.0 r222.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b50.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimal File Combination Calculator

[0] Archive type: ZIP

--> Optimal File Combination Calculator 0.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b51.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimal HTML

[0] Archive type: ZIP

--> Optimal HTML v1.2.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b52.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimal Mandelbrot

[0] Archive type: ZIP

--> Optimal Mandelbrot 3.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b53.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimal Password Generator

[0] Archive type: ZIP

--> Optimal Password Generator 2.1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '489bc6d4.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimal Pilot

[0] Archive type: ZIP

--> Optimal Pilot 1.00.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b55.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimal Shopping List Maker

[0] Archive type: ZIP

--> Optimal Shopping List Maker 1.9.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '489bc6d6.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimal Trader

[0] Archive type: ZIP

--> Optimal Trader 2.4.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b57.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimal Weight

[0] Archive type: ZIP

--> Optimal Weight 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b58.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimaze!

[0] Archive type: ZIP

--> Optimaze! 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b59.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OptimFROG

[0] Archive type: ZIP

--> OptimFROG 4.600ex.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b5a.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimik

[0] Archive type: ZIP

--> Optimik 2.36c.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b5b.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimism

[0] Archive type: ZIP

--> Optimism 1.2.6.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b5c.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimization Algorithm Toolkit - OAT

[0] Archive type: ZIP

--> Optimization Algorithm Toolkit - OAT 1.3.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b5d.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimize Computer

[0] Archive type: ZIP

--> Optimize Computer 1.4.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b5f.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimize GUITIDY

[0] Archive type: ZIP

--> Optimize GUITIDY 1.05.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '489bc6e0.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OptimizeBatch

[0] Archive type: ZIP

--> OptimizeBatch 1.0.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b61.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimizer Rx

[0] Archive type: ZIP

--> Optimizer Rx 1.01.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b62.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimizer XP 3.5

[0] Archive type: ZIP

--> Optimizer XP 3.5 XG.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '489bc6e3.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimum Data Recovery for FAT Formatted

[0] Archive type: ZIP

--> Optimum Data Recovery for FAT Formatted 1.0.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b63.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimum Data Recovery for FAT Undelete

[0] Archive type: ZIP

--> Optimum Data Recovery for FAT Undelete 1.0.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b65.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimum Data Recovery for NTFS Formatted

[0] Archive type: ZIP

--> Optimum Data Recovery for NTFS Formatted 1.0.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b66.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimum Data Recovery for NTFS Undelete

[0] Archive type: ZIP

--> Optimum Data Recovery for NTFS Undelete 1.0.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b67.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optimumcut-1D

[0] Archive type: ZIP

--> Optimumcut-1D 1.20.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b68.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OptimumJPEG

[0] Archive type: ZIP

--> OptimumJPEG

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b6a.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\OptiNet 1.2 Build

[0] Archive type: ZIP

--> OptiNet 1.2 Build #1.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '489bc6eb.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Optinlistexploder

[0] Archive type: ZIP

--> Optinlistexploder 2.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b6c.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Option Calculator

[0] Archive type: ZIP

--> Option Calculator 1.42.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '489bc6ed.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Option Position Calculator

[0] Archive type: ZIP

--> Option Position Calculator 1.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b6e.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Option Pricing Calculator

[0] Archive type: ZIP

--> Option Pricing Calculator 1.0.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b6f.qua' ( QUARANTINE )

[NOTE] The file was deleted!

C:\QooBox\Quarantine\C\Documents and Settings\Laure et Steve\Application Data\m\shared\Option Profit Calculator

[0] Archive type: ZIP

--> Option Profit Calculator 1.0.0.exe

[DETECTION] Is the Trojan horse TR/Dldr.Bagle.YB

[NOTE] A backup was created as '49199b70.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '490a9b65.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '49139b6b.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Dldr.Bagle.XK

[NOTE] A backup was created as '49099b6e.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Dldr.Bagle.XK

[NOTE] A backup was created as '490a9b67.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Rootkit.Gen

[NOTE] A backup was created as '49149b75.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48d99b34.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48db9b34.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48dc9b35.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48d79b41.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48d59b39.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48d69b39.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '4957ceda.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48da9b3c.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48dc9b3c.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48d89b3c.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '4959cedd.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48de9b43.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48dd9b3f.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48de9b3f.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48d89b42.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48d59b44.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48da9b44.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48d69b45.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48dc9b47.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48dd9b47.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48d79b49.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48d99b45.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48d69b46.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48d89b47.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48d59b48.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48d89b49.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48de9b4a.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48d79b4f.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48da9b50.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48db9b51.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48db9b52.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48d59b4a.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48d79b4a.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '4956ceab.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48d79b4d.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48dd9b53.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48da9b54.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48dc9b54.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48da9b51.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48d99b54.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Contains detection pattern of the worm WORM/Bagle.Gen

[NOTE] A backup was created as '48dd9b59.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Bagle.Gen.B

[NOTE] A backup was created as '48d69b56.qua' ( QUARANTINE )

[NOTE] The file was deleted!

Begin scan in 'D:\'

Begin scan in 'E:\'


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!

Begin scan in 'F:\'

Begin scan in 'I:\' <disque dur n°2 >

I:\Azureus\fichiers télécharger\EncoreCS3 Activation.rar

[0] Archive type: RAR


[DETECTION] Is the Trojan horse TR/Agent.55481

[NOTE] A backup was created as '4908aaf5.qua' ( QUARANTINE )

[NOTE] The file was deleted!

I:\Azureus(2)\téléchargement\EncoreCS3 Activation.rar

[0] Archive type: RAR


[DETECTION] Is the Trojan horse TR/Agent.55481

[NOTE] A backup was created as '4908addb.qua' ( QUARANTINE )

[NOTE] The file was deleted!

I:\Azureus(2)\téléchargement\Adobe Creative Suite 3 Master Collection\Keygen\Adobe Creative Suite 3 Master Collection GoLive 9.exe

[DETECTION] Is the Trojan horse TR/Packed.7703

[NOTE] A backup was created as '4914b03d.qua' ( QUARANTINE )

[NOTE] The file was deleted!

I:\E-mule\0.48A\eMule\Incoming\Adobe Encore Cs3 Keygen.rar

[0] Archive type: RAR

--> Adobe Encore CS3 Keygen\Encore DVD 2.0 keygen.exe

[DETECTION] Is the Trojan horse TR/PSWeric5.AFKE

[NOTE] A backup was created as '4914b0f2.qua' ( QUARANTINE )

[NOTE] The file was deleted!


[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen

[NOTE] A backup was created as '4913b33b.qua' ( QUARANTINE )

[NOTE] The file was deleted!

Begin scan in 'O:\' <film et photos>



End of the scan: vendredi, 15. août 2008 18:53

Used time: 2:07:55 min


The scan has been done completely.


11312 Scanning directories

1000211 Files were scanned

178 viruses and/or unwanted programs were found

0 Files were classified as suspicious:

178 files were deleted

0 files were repaired

178 files were moved to quarantine

0 files were renamed

56 Files cannot be scanned

1000033 Files not concerned

6375 Archives were scanned

56 Warnings

178 Notes




Comme vous avez pu le voir dans le rapport Antivir,votre infection Bagle désormais nettoyée était due à l'utilisation de cracks et keygen.

Cela a failli détruire votre système.

Il vous faut donc éviter cela à l'avenir , sous peine d'encourir les mêmes inconvénients ou de pires comme Virut qui tue tous les .exe.

Emule et consorts, ce n'est pas anodin.


Comprenez bien que je ne vous fait pas de leçon de morale, je n'ai aucune qualification pour cela, c'est seulement une mise en garde.


Pour enlever les programmes utilisés pendant la procédure.

Télécharger ToolsCleaner2 de A.Rothstein

* Enregistrer ToolsCleaner2.exe sur le Bureau.

Sous Vista,Clic-droit > Exécuter en tant que Administrateur

* Double-cliquer dessus, puis cliquer sur Recherche --> Le programme va chercher les utilitaires installés

------> Il se peut que la fenêtre devienne blanche pendant le scan, c'est normal !

L'outil supprimera sans que vous ayez à intervenir.

* Copier-coller le contenu du rapport qui apparait dans la fenêtre blanche.


Ie 7 ne fonctionnant plus, désinstallez et réinstallez le via Windows Update.

Il en va de même de vos protections (Parefeu, Antivirus, antispyware.

Si vous gardez Antivir, comme je vous l'ai conseillé, ne réinstallez pas l'ancien, il y aurait conflit.


En suite de quoi, avec vos commentaires sur l'état du pc, postez un rapport Hijackthis.


bonjour je vais faire le nécessaire pour me débarrasser de tout ce petit voilà pour les deux rapport :


-->- Recherche:


C:\Combofix: trouvé !

C:\Qoobox: trouvé !

C:\Documents and Settings\Laure et Steve\Bureau\ComboFix.exe: trouvé !

C:\Documents and Settings\Laure et Steve\Recent\HijackThis.lnk: trouvé !



-->- Suppression:


C:\Documents and Settings\Laure et Steve\Bureau\ComboFix.exe: supprimé !

C:\Documents and Settings\Laure et Steve\Recent\HijackThis.lnk: supprimé !

C:\Combofix: supprimé !

C:\Qoobox: supprimé !


et pour hijackthis


Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:38:42, on 16.08.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Boot mode: Normal


Running processes:







D:\ad aware 2008\prog\aawservice.exe





D:\mind manager 7 pro\MMReminderService.exe


C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe


C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe

C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe

D:\mind manager 7 pro\PDF-XChange\pdfSaver\pdfSaver3.exe

C:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe


C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe



C:\Program Files\iPod\bin\iPodService.exe


D:\firefox 3.0\prog\firefox.exe

C:\Program Files\Canon\CanoScan Toolbox Ver4.5\CSTBox.exe

D:\hijackthis\Laure et Steve.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - D:\snagit\SnagItBHO.dll

O2 - BHO: CmjBrowserHelperObject Object - {07A11D74-9D25-4fea-A833-8B0D76A5577A} - D:\mind manager 7 pro\Mm7InternetExplorer.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\java\bin\ssv.dll

O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll

O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - D:\snagit\SnagItIEAddin.dll

O4 - HKLM\..\Run: [pccguide.exe] "D:\trend micro ver.14\pccguide.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [sunJavaUpdateSched] "D:\java\bin\jusched.exe"


O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [MMReminderService] D:\mind manager 7 pro\MMReminderService.exe

O4 - HKLM\..\Run: [iTunesHelper] "D:\Itunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [pdfSaver3] "D:\mind manager 7 pro\PDF-XChange\pdfSaver\pdfSaver3.exe"

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')

O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: LaunchU3.exe.lnk = ?

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\java\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\java\bin\ssv.dll

O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Envoyer à Mindjet MindManager - {941E1A34-C6AF-4baa-A973-224F9C3E04BF} - D:\mind manager 7 pro\Mm7InternetExplorer.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Correcteur - {F7C8E5F6-B6D1-45db-8D91-2BCFA5DF11A9} - D:\antidote rx7\Internet Explorer\7\Antidote K - IE 7.htm (HKCU)

O9 - Extra button: Dictionnaires - {F9B969E8-58D0-4dd9-AC8A-EE2336FF8F65} - D:\antidote rx7\Internet Explorer\7\Antidote D - IE 7.htm (HKCU)

O9 - Extra button: Guides - {FA089E36-3F1B-4c51-9A1A-C4E7012483AF} - D:\antidote rx7\Internet Explorer\7\Antidote G - IE 7.htm (HKCU)

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

O17 - HKLM\System\CCS\Services\Tcpip\..\{660C3A53-0541-4744-90B6-9A0626FF3D4B}: NameServer =,

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\ad aware 2008\prog\aawservice.exe

O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: NBService - Nero AG - D:\nero 7.5.1\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - D:\TRENDM~1.14\PcCtlCom.exe



End of file - 7710 bytes



j'ai désinstaller IE7, il m'a remis IE6, mais maintenant quand je clic sur l'incône d'internet explorer il me crée un raccourci sur le bureau et je ne peux pas accéder à internet, alors je suis en train de vérifier tout les fichiers système de win avec le vérificateur de win xp et on verra, sinon où pourrais-je m'adresser pour de l'aide au cas oû ?


Bonjour à vous deux ;


Pour lancer IE6, supprime d'abord le(s) raccourci(s) d'Internet Explorer qui se trouve sur le Bureau ainsi que celui dans la barre de lancement rapide (si présent). Ensuite, rends-toi là avec l'Explorateur :


C:\Program Files\Internet Explorer


... fais un clic droit sur Iexplore.exe et choisis "Envoyer vers" >> "Bureau (créer un raccourci)"


Tu devrais maintenant pouvoir lancer IE6.



Pour télécharger IE7, tu pourras le faire via Windows Update, ou bien directement du lien suivant :


Bon succès...


hello alors essayer pas pu, je m'explique je viens d'exécuter la manoeuvre que tu m'as dit mais ça marche pas, il me met une fenêtre avec marquer dedant :

windows ne trouve pas 'C.\program files\internet explorer\iexplore.exe' vérifier que vous avez entré le nom correctement et essayer à nouveau. Pour rechercher un fichier....

quelqu'un aurait-il une idée? merci a+

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
  • Créer...