Jai un pb avec .exe
Dernière réponse : dans Sécurité
Jai un probleme avec mes programmes .exe.
Voici mon hijack. Si quequn pourrait me dire si ou est le probleme sa serait sympas.
Merci davance.
Logfile of HijackThis v1.99.1
Scan saved at 23:24:59, on 14/07/2006
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\LXSUPMON.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVIAGENT.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCTSKSHD.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\FR\MSNAPPAU.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\VETMSG.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVTRAY.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\TRAYMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVRID.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVICLIENT.EXE
C:\PROGRAM FILES\EPSON\EPSON CARDMONITOR\EPSON CARDMONITOR1.2.EXE
C:\PROGRAM FILES\NIKON\PICTUREPROJECT\NKBMONITOR.EXE
C:\PROGRAM FILES\BACKWEB\PROGRAM\BACKWEB.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\BUREAU\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.chello.fr/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=Proxy.chello.fr;ftp=Proxy.chello.fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: CometCursor Class - {1678F7E1-C422-11D0-AD7D-00400515CAAA} - C:\WINDOWS\SYSTEM\COMET.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
O3 - Toolbar: &Kangaroo - {663C7429-E454-11D3-B9AE-0000B4C32B4D} - C:\IDC\WEBKA.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [reminder.exe] C:\Program Files\BackWeb\tuner\reminder.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\SYSTEM\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [navi] "C:\Program Files\VeriSign\NAVI\naviagent.exe" uimode=agentupdate
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\realplay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [OEMCleanup] C:\WINDOWS\OPTIONS\OEMRESET.EXE /O
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [MCTskShd] C:\PROGRA~1\MCAFEE.COM\AGENT\mctskshd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRAM FILES\MOUSEWARE\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /O5 "LPT1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [EPSON Stylus Photo R (Copie 2)] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P30 "EPSON Stylus Photo R (Copie 2)" /O7 "EPUSB1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe"
O4 - HKLM\..\Run: [VetAlert] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VETMSG.EXE
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /M "Stylus Photo RX420" /EF "HKCU"
O4 - Startup: EPSON CardMonitor.lnk = C:\Program Files\epson\EPSON CardMonitor\EPSON CardMonitor1.2.exe
O4 - Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Kangaroo - {06A18DC1-FE86-11d3-B9AF-0000B4C32B4D} - http://knowledge-assistant.com/webka/toolbar/tbie.asp (file missing)
O9 - Extra button: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra 'Tools' menuitem: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra button: (no name) - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O9 - Extra 'Tools' menuitem: Options i-Nav - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://bin.wordsx.cc/yfnYs7ymoJL_Fr5gJ8-5.chm::/on-line...
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdown...
O16 - DPF: {6F6E3A5E-4A75-45F0-BDDE-21B6C4496E2B} (LAInstaller Class) - http://www.cantoche.com/Player/V12/LAinstall.cab
Voici mon hijack. Si quequn pourrait me dire si ou est le probleme sa serait sympas.
Merci davance.
Logfile of HijackThis v1.99.1
Scan saved at 23:24:59, on 14/07/2006
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\LXSUPMON.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVIAGENT.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCTSKSHD.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\FR\MSNAPPAU.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\VETMSG.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVTRAY.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\TRAYMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVRID.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVICLIENT.EXE
C:\PROGRAM FILES\EPSON\EPSON CARDMONITOR\EPSON CARDMONITOR1.2.EXE
C:\PROGRAM FILES\NIKON\PICTUREPROJECT\NKBMONITOR.EXE
C:\PROGRAM FILES\BACKWEB\PROGRAM\BACKWEB.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\BUREAU\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.chello.fr/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=Proxy.chello.fr;ftp=Proxy.chello.fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: CometCursor Class - {1678F7E1-C422-11D0-AD7D-00400515CAAA} - C:\WINDOWS\SYSTEM\COMET.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
O3 - Toolbar: &Kangaroo - {663C7429-E454-11D3-B9AE-0000B4C32B4D} - C:\IDC\WEBKA.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [reminder.exe] C:\Program Files\BackWeb\tuner\reminder.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\SYSTEM\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [navi] "C:\Program Files\VeriSign\NAVI\naviagent.exe" uimode=agentupdate
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\realplay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [OEMCleanup] C:\WINDOWS\OPTIONS\OEMRESET.EXE /O
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [MCTskShd] C:\PROGRA~1\MCAFEE.COM\AGENT\mctskshd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRAM FILES\MOUSEWARE\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /O5 "LPT1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [EPSON Stylus Photo R (Copie 2)] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P30 "EPSON Stylus Photo R (Copie 2)" /O7 "EPUSB1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe"
O4 - HKLM\..\Run: [VetAlert] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VETMSG.EXE
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /M "Stylus Photo RX420" /EF "HKCU"
O4 - Startup: EPSON CardMonitor.lnk = C:\Program Files\epson\EPSON CardMonitor\EPSON CardMonitor1.2.exe
O4 - Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Kangaroo - {06A18DC1-FE86-11d3-B9AF-0000B4C32B4D} - http://knowledge-assistant.com/webka/toolbar/tbie.asp (file missing)
O9 - Extra button: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra 'Tools' menuitem: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra button: (no name) - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O9 - Extra 'Tools' menuitem: Options i-Nav - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://bin.wordsx.cc/yfnYs7ymoJL_Fr5gJ8-5.chm::/on-line...
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdown...
O16 - DPF: {6F6E3A5E-4A75-45F0-BDDE-21B6C4496E2B} (LAInstaller Class) - http://www.cantoche.com/Player/V12/LAinstall.cab
Autres pages sur : jai exe
Lassé par la pub ? Créez un compte
Bonsoir
1 Télécharge
CCleaner.
http://www.filehippo.com/download_ccleaner.html
Installe le dans un répertoire dédié.
SmitRem.zip
http://noahdfear.geekstogo.com/click%20counter/click.ph...
Dézippes le sur le Bureau
Spyware Terminator
http://www.spywareterminator.com/
Installe le dans son répertoire.
Tutorial
http://www.malekal.com/tutorial_SpywareTerminator.html
2 Redémarre en mode sans échec. Attention, tu n'as pas accès à internet dans ce mode, note bien ce que tu as à faire.
Démarre l'ordinateur.
Une fois le chargement du BIOS terminé, il y a un écran noir. Appuye sur la touche F8 ou F5 jusqu'à l'affichage du menu des options avancées de Windows.
En utilisant les touches du curseur, sélectionne le mode sans échec approprié et appuye sur Entrée.
3 Lance le nettoyage avec CCleaner.
4 Ouvre Smitrem
Double clique sur RunThis.bat
Lance le nettoyage. Ecran et icones vont apparaitre et réapparaitre.
Cela peut durer un certain temps.
5 Lances Spyware Terminator
Clique sur Scan, puis Full Spyware scan.
Clique sur Start Scan Now..
6 Redémarre normalement
7 Postes un nouveau rapport HijackThis avec le rapport de Smitrem.
1 Télécharge
CCleaner.
http://www.filehippo.com/download_ccleaner.html
Installe le dans un répertoire dédié.
SmitRem.zip
http://noahdfear.geekstogo.com/click%20counter/click.ph...
Dézippes le sur le Bureau
Spyware Terminator
http://www.spywareterminator.com/
Installe le dans son répertoire.
Tutorial
http://www.malekal.com/tutorial_SpywareTerminator.html
2 Redémarre en mode sans échec. Attention, tu n'as pas accès à internet dans ce mode, note bien ce que tu as à faire.
Démarre l'ordinateur.
Une fois le chargement du BIOS terminé, il y a un écran noir. Appuye sur la touche F8 ou F5 jusqu'à l'affichage du menu des options avancées de Windows.
En utilisant les touches du curseur, sélectionne le mode sans échec approprié et appuye sur Entrée.
3 Lance le nettoyage avec CCleaner.
4 Ouvre Smitrem
Double clique sur RunThis.bat
Lance le nettoyage. Ecran et icones vont apparaitre et réapparaitre.
Cela peut durer un certain temps.
5 Lances Spyware Terminator
Clique sur Scan, puis Full Spyware scan.
Clique sur Start Scan Now..
6 Redémarre normalement
7 Postes un nouveau rapport HijackThis avec le rapport de Smitrem.
Bonjour
Sinon, pour le mode sans echec, va voir là.
http://service1.symantec.com/support/inter/tsgeninfoint...
Sinon, pour le mode sans echec, va voir là.
http://service1.symantec.com/support/inter/tsgeninfoint...
Bonjour,
jai reussi a passer en mode sans echec (sa ma mis 2 jours :-? ).
Jai fait ccleaner, Smitrem par contre j'ai pas pu faireSpyware terminator parceque la souris ne fonctionnait pas et pas moyen d'appuyer sur scan.
En tout cas ca a arrangé les choses puisque mes icones sont redevenues normales et j'ai plus les carre noir.
Voila qund meme mon hijack :
Logfile of HijackThis v1.99.1
Scan saved at 13:44:34, on 25/09/2000
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\PROGRAM FILES\MINDSCAPE\MCF\TGBBOB.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\LXSUPMON.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVIAGENT.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCTSKSHD.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\FR\MSNAPPAU.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\VETMSG.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\TRAYMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVTRAY.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVRID.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVICLIENT.EXE
C:\PROGRAM FILES\EPSON\EPSON CARDMONITOR\EPSON CARDMONITOR1.2.EXE
C:\PROGRAM FILES\NIKON\PICTUREPROJECT\NKBMONITOR.EXE
C:\PROGRAM FILES\BACKWEB\PROGRAM\BACKWEB.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\BUREAU\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.chello.fr/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=Proxy.chello.fr;ftp=Proxy.chello.fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: CometCursor Class - {1678F7E1-C422-11D0-AD7D-00400515CAAA} - C:\WINDOWS\SYSTEM\COMET.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
O3 - Toolbar: &Kangaroo - {663C7429-E454-11D3-B9AE-0000B4C32B4D} - C:\IDC\WEBKA.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [reminder.exe] C:\Program Files\BackWeb\tuner\reminder.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\SYSTEM\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [navi] "C:\Program Files\VeriSign\NAVI\naviagent.exe" uimode=agentupdate
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\realplay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [OEMCleanup] C:\WINDOWS\OPTIONS\OEMRESET.EXE /O
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [MCTskShd] C:\PROGRA~1\MCAFEE.COM\AGENT\mctskshd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRAM FILES\MOUSEWARE\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /O5 "LPT1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [EPSON Stylus Photo R (Copie 2)] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P30 "EPSON Stylus Photo R (Copie 2)" /O7 "EPUSB1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe"
O4 - HKLM\..\Run: [VetAlert] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VETMSG.EXE
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRAM FILES\SPYWARE TERMINATOR\SpywareTerminatorShield.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - HKLM\..\RunServices: [TGB::BOB] C:\Program Files\MINDSCAPE\MCF\TGBBOB.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /M "Stylus Photo RX420" /EF "HKCU"
O4 - Startup: EPSON CardMonitor.lnk = C:\Program Files\epson\EPSON CardMonitor\EPSON CardMonitor1.2.exe
O4 - Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Kangaroo - {06A18DC1-FE86-11d3-B9AF-0000B4C32B4D} - http://knowledge-assistant.com/webka/toolbar/tbie.asp (file missing)
O9 - Extra button: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra 'Tools' menuitem: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra button: (no name) - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O9 - Extra 'Tools' menuitem: Options i-Nav - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://bin.wordsx.cc/yfnYs7ymoJL_Fr5gJ8-5.chm::/on-line...
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdown...
O16 - DPF: {6F6E3A5E-4A75-45F0-BDDE-21B6C4496E2B} (LAInstaller Class) - http://www.cantoche.com/Player/V12/LAinstall.cab
jai reussi a passer en mode sans echec (sa ma mis 2 jours :-? ).
Jai fait ccleaner, Smitrem par contre j'ai pas pu faireSpyware terminator parceque la souris ne fonctionnait pas et pas moyen d'appuyer sur scan.
En tout cas ca a arrangé les choses puisque mes icones sont redevenues normales et j'ai plus les carre noir.
Voila qund meme mon hijack :
Logfile of HijackThis v1.99.1
Scan saved at 13:44:34, on 25/09/2000
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\PROGRAM FILES\MINDSCAPE\MCF\TGBBOB.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\LXSUPMON.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVIAGENT.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCTSKSHD.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\FR\MSNAPPAU.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\VETMSG.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\TRAYMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVTRAY.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVRID.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVICLIENT.EXE
C:\PROGRAM FILES\EPSON\EPSON CARDMONITOR\EPSON CARDMONITOR1.2.EXE
C:\PROGRAM FILES\NIKON\PICTUREPROJECT\NKBMONITOR.EXE
C:\PROGRAM FILES\BACKWEB\PROGRAM\BACKWEB.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\BUREAU\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.chello.fr/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=Proxy.chello.fr;ftp=Proxy.chello.fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: CometCursor Class - {1678F7E1-C422-11D0-AD7D-00400515CAAA} - C:\WINDOWS\SYSTEM\COMET.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
O3 - Toolbar: &Kangaroo - {663C7429-E454-11D3-B9AE-0000B4C32B4D} - C:\IDC\WEBKA.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [reminder.exe] C:\Program Files\BackWeb\tuner\reminder.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\SYSTEM\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [navi] "C:\Program Files\VeriSign\NAVI\naviagent.exe" uimode=agentupdate
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\realplay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [OEMCleanup] C:\WINDOWS\OPTIONS\OEMRESET.EXE /O
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [MCTskShd] C:\PROGRA~1\MCAFEE.COM\AGENT\mctskshd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRAM FILES\MOUSEWARE\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /O5 "LPT1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [EPSON Stylus Photo R (Copie 2)] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P30 "EPSON Stylus Photo R (Copie 2)" /O7 "EPUSB1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe"
O4 - HKLM\..\Run: [VetAlert] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VETMSG.EXE
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRAM FILES\SPYWARE TERMINATOR\SpywareTerminatorShield.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - HKLM\..\RunServices: [TGB::BOB] C:\Program Files\MINDSCAPE\MCF\TGBBOB.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /M "Stylus Photo RX420" /EF "HKCU"
O4 - Startup: EPSON CardMonitor.lnk = C:\Program Files\epson\EPSON CardMonitor\EPSON CardMonitor1.2.exe
O4 - Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Kangaroo - {06A18DC1-FE86-11d3-B9AF-0000B4C32B4D} - http://knowledge-assistant.com/webka/toolbar/tbie.asp (file missing)
O9 - Extra button: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra 'Tools' menuitem: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra button: (no name) - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O9 - Extra 'Tools' menuitem: Options i-Nav - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://bin.wordsx.cc/yfnYs7ymoJL_Fr5gJ8-5.chm::/on-line...
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdown...
O16 - DPF: {6F6E3A5E-4A75-45F0-BDDE-21B6C4496E2B} (LAInstaller Class) - http://www.cantoche.com/Player/V12/LAinstall.cab
On continue le nettoyage.
1 Relance un scan HijackThis et coche les lignes ci-dessous :
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://bin.wordsx.cc/yfnYs7ymoJL_Fr5gJ8-5.chm::/on-line...
Ferme toutes les fenêtres Windows, Internet explorer, Outlook,sauf le logiciel Hijackthis et clique sur « Fix checked »
2 Assure toi d'avoir accés à tous les fichiers.
Démarrer, Poste de travail ou autre dossier, Menu Outils, Option des dossiers, onglet Affichage :
Activer la case : Afficher les fichiers et dossiers cachés
Désactiver la case : Masquer les extensions des fichiers dont le type est connu
Désactiver la case : Masquer les fichiers protégés du système d'exploitation
Puis Appliquer
3 Supprime les fichiers/dossiers incriminés (s'ils existent encore) :
C:\winstall.exe
C:\foo.mht!
Recache les fichiers systeme afin de ne pas faire d'erreur à l'avenir en sélectionnant ne pas afficher les fichiers cachés ou les fichiers système.
4 Lance le nettoyage avec CCleaner.
5 Fais une analyse antivirus en ligne sur Kaspersky
http://webscanner.kaspersky.fr/
Colle son rapport ici avec un nouveau log HijackThis.
1 Relance un scan HijackThis et coche les lignes ci-dessous :
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://bin.wordsx.cc/yfnYs7ymoJL_Fr5gJ8-5.chm::/on-line...
Ferme toutes les fenêtres Windows, Internet explorer, Outlook,sauf le logiciel Hijackthis et clique sur « Fix checked »
2 Assure toi d'avoir accés à tous les fichiers.
Démarrer, Poste de travail ou autre dossier, Menu Outils, Option des dossiers, onglet Affichage :
Activer la case : Afficher les fichiers et dossiers cachés
Désactiver la case : Masquer les extensions des fichiers dont le type est connu
Désactiver la case : Masquer les fichiers protégés du système d'exploitation
Puis Appliquer
3 Supprime les fichiers/dossiers incriminés (s'ils existent encore) :
C:\winstall.exe
C:\foo.mht!
Recache les fichiers systeme afin de ne pas faire d'erreur à l'avenir en sélectionnant ne pas afficher les fichiers cachés ou les fichiers système.
4 Lance le nettoyage avec CCleaner.
5 Fais une analyse antivirus en ligne sur Kaspersky
http://webscanner.kaspersky.fr/
Colle son rapport ici avec un nouveau log HijackThis.
Re bonjour,
Voila le rapport de lanalyse antivirus et du Hijack:
Rapport antivirus:
KASPERSKY ON-LINE SCANNER - RAPPORT
lundi 25 septembre 2000 22:30:41
Système d'exploitation : Microsoft Windows Millennium Edition
Version de Kaspersky On-line Scanner: 5.0.78.0
Dernière mise à jour de la base antivirus Kaspersky : 17/07/2006
Enregistrements dans la base antivirus Kaspersky : 195356
Paramètres d'analyse
Analyser avec la base antivirus suivante standard
Analyser les archives vrai
Analyser les bases de messagerie. vrai
Cible de l'analyse Poste de travail
a:\
c:\
q:\
Statistiques de l'analyse
Total d'objets analysés : 36741
Nombre de virus trouvés 3
Nombre d'objets infectés 4
Nombre d'objets suspects 3
Durée de l'analyse 07:52:04
Nom de l'objet infecté Nom du virus Dernière action
c:\WINDOWS\Bureau\hijackthis.log Suspect : Exploit.HTML.Mht ignoré
c:\WINDOWS\Bureau\backups\backup-20000925-140339-217 Suspect : Exploit.HTML.Mht ignoré
c:\_RESTORE\TEMP\A0481023.CPY Suspect : Exploit.HTML.Mht ignoré
c:\_RESTORE\ARCHIVE\FS277.CAB/A0288431.CPY Infecté: Trojan-Clicker.Win32.LowZones.b ignoré
c:\_RESTORE\ARCHIVE\FS277.CAB CAB: infecté - 1 ignoré
c:\_RESTORE\ARCHIVE\FS426.CAB/A0329902.CPY Infecté: not-virus:Hoax.Win32.Renos.d ignoré
c:\_RESTORE\ARCHIVE\FS426.CAB CAB: infecté - 1 ignoré
Analyse terminée.
Hijack:
Logfile of HijackThis v1.99.1
Scan saved at 22:41:31, on 25/09/2000
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\PROGRAM FILES\MINDSCAPE\MCF\TGBBOB.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\LXSUPMON.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVIAGENT.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCTSKSHD.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\FR\MSNAPPAU.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\TRAYMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVTRAY.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVRID.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVICLIENT.EXE
C:\PROGRAM FILES\EPSON\EPSON CARDMONITOR\EPSON CARDMONITOR1.2.EXE
C:\PROGRAM FILES\NIKON\PICTUREPROJECT\NKBMONITOR.EXE
C:\PROGRAM FILES\BACKWEB\PROGRAM\BACKWEB.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\VETMSG.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\BUREAU\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.chello.fr/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=Proxy.chello.fr;ftp=Proxy.chello.fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: CometCursor Class - {1678F7E1-C422-11D0-AD7D-00400515CAAA} - C:\WINDOWS\SYSTEM\COMET.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
O3 - Toolbar: &Kangaroo - {663C7429-E454-11D3-B9AE-0000B4C32B4D} - C:\IDC\WEBKA.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [reminder.exe] C:\Program Files\BackWeb\tuner\reminder.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\SYSTEM\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [navi] "C:\Program Files\VeriSign\NAVI\naviagent.exe" uimode=agentupdate
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\realplay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [OEMCleanup] C:\WINDOWS\OPTIONS\OEMRESET.EXE /O
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [MCTskShd] C:\PROGRA~1\MCAFEE.COM\AGENT\mctskshd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRAM FILES\MOUSEWARE\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /O5 "LPT1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [EPSON Stylus Photo R (Copie 2)] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P30 "EPSON Stylus Photo R (Copie 2)" /O7 "EPUSB1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe"
O4 - HKLM\..\Run: [VetAlert] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VETMSG.EXE
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRAM FILES\SPYWARE TERMINATOR\SpywareTerminatorShield.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - HKLM\..\RunServices: [TGB::BOB] C:\Program Files\MINDSCAPE\MCF\TGBBOB.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /M "Stylus Photo RX420" /EF "HKCU"
O4 - Startup: EPSON CardMonitor.lnk = C:\Program Files\epson\EPSON CardMonitor\EPSON CardMonitor1.2.exe
O4 - Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O9 - Extra button: Kangaroo - {06A18DC1-FE86-11d3-B9AF-0000B4C32B4D} - http://knowledge-assistant.com/webka/toolbar/tbie.asp (file missing)
O9 - Extra button: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra 'Tools' menuitem: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra button: (no name) - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O9 - Extra 'Tools' menuitem: Options i-Nav - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdown...
O16 - DPF: {6F6E3A5E-4A75-45F0-BDDE-21B6C4496E2B} (LAInstaller Class) - http://www.cantoche.com/Player/V12/LAinstall.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_ansi.cab
Voila le rapport de lanalyse antivirus et du Hijack:
Rapport antivirus:
KASPERSKY ON-LINE SCANNER - RAPPORT
lundi 25 septembre 2000 22:30:41
Système d'exploitation : Microsoft Windows Millennium Edition
Version de Kaspersky On-line Scanner: 5.0.78.0
Dernière mise à jour de la base antivirus Kaspersky : 17/07/2006
Enregistrements dans la base antivirus Kaspersky : 195356
Paramètres d'analyse
Analyser avec la base antivirus suivante standard
Analyser les archives vrai
Analyser les bases de messagerie. vrai
Cible de l'analyse Poste de travail
a:\
c:\
q:\
Statistiques de l'analyse
Total d'objets analysés : 36741
Nombre de virus trouvés 3
Nombre d'objets infectés 4
Nombre d'objets suspects 3
Durée de l'analyse 07:52:04
Nom de l'objet infecté Nom du virus Dernière action
c:\WINDOWS\Bureau\hijackthis.log Suspect : Exploit.HTML.Mht ignoré
c:\WINDOWS\Bureau\backups\backup-20000925-140339-217 Suspect : Exploit.HTML.Mht ignoré
c:\_RESTORE\TEMP\A0481023.CPY Suspect : Exploit.HTML.Mht ignoré
c:\_RESTORE\ARCHIVE\FS277.CAB/A0288431.CPY Infecté: Trojan-Clicker.Win32.LowZones.b ignoré
c:\_RESTORE\ARCHIVE\FS277.CAB CAB: infecté - 1 ignoré
c:\_RESTORE\ARCHIVE\FS426.CAB/A0329902.CPY Infecté: not-virus:Hoax.Win32.Renos.d ignoré
c:\_RESTORE\ARCHIVE\FS426.CAB CAB: infecté - 1 ignoré
Analyse terminée.
Hijack:
Logfile of HijackThis v1.99.1
Scan saved at 22:41:31, on 25/09/2000
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\PROGRAM FILES\MINDSCAPE\MCF\TGBBOB.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\LXSUPMON.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVIAGENT.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCTSKSHD.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\FR\MSNAPPAU.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\TRAYMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVTRAY.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVRID.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVICLIENT.EXE
C:\PROGRAM FILES\EPSON\EPSON CARDMONITOR\EPSON CARDMONITOR1.2.EXE
C:\PROGRAM FILES\NIKON\PICTUREPROJECT\NKBMONITOR.EXE
C:\PROGRAM FILES\BACKWEB\PROGRAM\BACKWEB.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\VETMSG.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\BUREAU\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.chello.fr/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=Proxy.chello.fr;ftp=Proxy.chello.fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: CometCursor Class - {1678F7E1-C422-11D0-AD7D-00400515CAAA} - C:\WINDOWS\SYSTEM\COMET.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
O3 - Toolbar: &Kangaroo - {663C7429-E454-11D3-B9AE-0000B4C32B4D} - C:\IDC\WEBKA.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [reminder.exe] C:\Program Files\BackWeb\tuner\reminder.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\SYSTEM\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [navi] "C:\Program Files\VeriSign\NAVI\naviagent.exe" uimode=agentupdate
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\realplay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [OEMCleanup] C:\WINDOWS\OPTIONS\OEMRESET.EXE /O
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [MCTskShd] C:\PROGRA~1\MCAFEE.COM\AGENT\mctskshd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRAM FILES\MOUSEWARE\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /O5 "LPT1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [EPSON Stylus Photo R (Copie 2)] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P30 "EPSON Stylus Photo R (Copie 2)" /O7 "EPUSB1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe"
O4 - HKLM\..\Run: [VetAlert] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VETMSG.EXE
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRAM FILES\SPYWARE TERMINATOR\SpywareTerminatorShield.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - HKLM\..\RunServices: [TGB::BOB] C:\Program Files\MINDSCAPE\MCF\TGBBOB.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /M "Stylus Photo RX420" /EF "HKCU"
O4 - Startup: EPSON CardMonitor.lnk = C:\Program Files\epson\EPSON CardMonitor\EPSON CardMonitor1.2.exe
O4 - Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O9 - Extra button: Kangaroo - {06A18DC1-FE86-11d3-B9AF-0000B4C32B4D} - http://knowledge-assistant.com/webka/toolbar/tbie.asp (file missing)
O9 - Extra button: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra 'Tools' menuitem: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra button: (no name) - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O9 - Extra 'Tools' menuitem: Options i-Nav - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdown...
O16 - DPF: {6F6E3A5E-4A75-45F0-BDDE-21B6C4496E2B} (LAInstaller Class) - http://www.cantoche.com/Player/V12/LAinstall.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_ansi.cab
Bonjour,
- Désactive ta restauration du systeme :
clik droit sur poste de travail/proprietes/restauration systeme/coche la case desactiver la restauration systeme
- Redemarre ton PC et reactive la restauration du systeme en faisant la manip. inverse
- Refait un scan en ligne chez Kaspersky et poste le rapport ainsi qu'un nouveau rapport HJT
- As-tu encore des problemes ?
- Désactive ta restauration du systeme :
clik droit sur poste de travail/proprietes/restauration systeme/coche la case desactiver la restauration systeme
- Redemarre ton PC et reactive la restauration du systeme en faisant la manip. inverse
- Refait un scan en ligne chez Kaspersky et poste le rapport ainsi qu'un nouveau rapport HJT
- As-tu encore des problemes ?
J'ai fait Spyware terminator et il m'a trouver plein de trucs que j'ai suprimé.
Voila son rapport:
Scan Progress (Full Scan)
Start time: 26/09/2000 11:02:14
Processes Scanning
SSDPSRV : C:\WINDOWS\SYSTEM\SSDPSRV.EXE
StillImageMonitor : C:\WINDOWS\SYSTEM\STIMON.EXE
EPSONWeb-To-Page : C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
CometCursor : C:\WINDOWS\SYSTEM\COMET.DLL
Shdocvw : C:\WINDOWS\SYSTEM\SHDOCVW.DLL
Explorer : C:\WINDOWS\EXPLORER.EXE
PowerProfile : C:\WINDOWS\SYSTEM\POWRPROF.DLL
MltdKeyboard : C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMKEYBD.EXE
LoadQM : C:\WINDOWS\LOADQM.EXE
MCAgent : C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
RealTray : C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
MSNSearchToolbar : MSNAPPAU.EXE
MSNSearchToolbar : C:\WINDOWS\SYSTEM\MSXML3.DLL
Msnappau : C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\FR\MSNAPPAU.EXE
Spyware Terminator : C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE
eTrustEZAntivirus : C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVTRAY.EXE
eTrustEZAntivirus : C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVRID.EXE
Spyware Terminator : C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATOR.EXE
Startup Scanning
MoneyAgent : C:\PROGRAM FILES\MICROSOFT MONEY\SYSTEM\MONEY EXPRESS.EXE
EPSON Stylus Photo RX420 Series : C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
ScanRegistry : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ ScanRegistry
ScanRegistry : C:\WINDOWS\SCANREGW.EXE
TaskMonitor : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ TaskMonitor
TaskMonitor : C:\WINDOWS\TASKMON.EXE
PCHealth : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ PCHealth
PCHealth : C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE
SystemTray : C:\WINDOWS\SYSTEM\SYSTRAY.EXE
Hidserv : C:\WINDOWS\SYSTEM\HIDSERV.EXE
MltdKeyboard : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ MULTIMEDIA KEYBOARD
MltdKeyboard : C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMKEYBD.EXE
reminder.exe : C:\PROGRAM FILES\BACKWEB\TUNER\REMINDER.EXE
LXSUPMON : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ LXSUPMON
LXSUPMON : C:\WINDOWS\SYSTEM\LXSUPMON.EXE
CountrySelection : C:\WINDOWS\PCTPTT.EXE
PCTVOICE : C:\WINDOWS\PCTVOICE.EXE
LoadQM : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ LoadQM
LoadQM : C:\WINDOWS\LOADQM.EXE
MCAgent : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ MCAgentExe
MCAgent : C:\Program Files\McAfee.com\Agent\mcagent.exe
MCUpdate : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ MCUpdateExe
MCUpdate : C:\Program Files\McAfee.com\Agent\mcupdate.exe
navi : C:\PROGRAM FILES\VERISIGN\NAVI\NAVIAGENT.EXE
RealTray : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ RealTray
RealTray : C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
Invalid Startup Items : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ OEMCleanup
PowerProfile : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ LoadPowerProfile
PowerProfile : C:\WINDOWS\SYSTEM\POWRPROF.DLL
MCTskShd : C:\Program Files\McAfee.com\Agent\McTskshd.exe
EM_EXEC : C:\PROGRAM FILES\MOUSEWARE\SYSTEM\EM_EXEC.EXE
EPSON Stylus Photo R (Copie 2) : C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
Msnappau : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ msnappau
Msnappau : C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\FR\MSNAPPAU.EXE
Spyware Terminator : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ SpywareTerminator
Spyware Terminator : C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE
VetAlert : C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
eTrustEZAntivirus : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ CaAvTray
eTrustEZAntivirus : C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVTRAY.EXE
eTrustEZAntivirus : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ CAVRID
eTrustEZAntivirus : C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVRID.EXE
PowerProfile : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ LoadPowerProfile
SchedulingAgent : C:\WINDOWS\SYSTEM\MSTASK.EXE
SSDPSRV : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ SSDPSRV
SSDPSRV : C:\WINDOWS\SYSTEM\SSDPSRV.EXE
StateMgr : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ *StateMgr
StateMgr : C:\WINDOWS\SYSTEM\RESTORE\STATEMGR.EXE
StillImageMonitor : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ StillImageMonitor
StillImageMonitor : C:\WINDOWS\SYSTEM\STIMON.EXE
CAISafe : C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
TGB::BOB : C:\PROGRAM FILES\MINDSCAPE\MCF\TGBBOB.EXE
Toolbars Scanning
&Kangaroo ( Toolbar ) : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ {663C7429-E454-11D3-B9AE-0000B4C32B4D}
&Kangaroo ( Toolbar ) : C:\IDC\WEBKA.DLL
MSDXM : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ {8E718888-423F-11D2-876E-00A0C9082467}
MSDXM : C:\WINDOWS\SYSTEM\MSDXM.OCX
EPSONWeb-To-Page : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ {EE5D279F-081B-4404-994D-C6B60AAEBA6D}
EPSONWeb-To-Page : C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
EPSONWeb-To-Page : C:\WINDOWS\EXPLORER.EXE PID: 4294764777
MSNSearchToolbar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
MSNSearchToolbar : C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
Shdocvw : HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}\
Shdocvw : C:\WINDOWS\SYSTEM\SHDOCVW.DLL
Shdocvw : C:\WINDOWS\EXPLORER.EXE PID: 4294764777
Shdocvw : C:\PROGRAM FILES\BACKWEB\PROGRAM\BACKWEB.EXE PID: 4294417873
Shdocvw : C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATOR.EXE PID: 4294514933
Shdocvw : HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}\
Shdocvw : HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}\
Shdocvw : HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}\
Browser Helper Objects Scanning
i-Nav IDN Resolver ( BHO ) : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CE000992-A58C-4441-8938-744CD72AB27F}\
i-Nav IDN Resolver ( BHO ) : C:\Program Files\VeriSign\i-Nav\i-nav_4_2_1.dll
CometCursor : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1678F7E1-C422-11D0-AD7D-00400515CAAA}\
CometCursor : C:\WINDOWS\SYSTEM\COMET.DLL
CometCursor : C:\WINDOWS\EXPLORER.EXE PID: 4294764777
EPSONWeb-To-Page : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}\
MSNSearchToolbar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\
MSNSearchToolbar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}\
MSNSearchToolbar : C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
IE Explorer Bars
IE Extensions
Services Scanning
Protocol filters Scanning
Protocol handlers Scanning
WinSock2 Scanning
Uninstallers Scanning
C:\WINDOWS\RUNDLL.EXE
C:\PROGRAM FILES\OUTLOOK EXPRESS\SETUP50.EXE
C:\WINDOWS\ISUN040C.EXE
C:\PROGRAM FILES\MICROSOFT MONEY\SETUP\SETUP.EXE
C:\WINDOWS\SYSTEM\MSIEXEC.EXE
C:\PROGRAM FILES\AIRXONIX\UNINS000.EXE
C:\WINDOWS\PTUNINST.EXE
C:\Program Files\McAfee.com\Shared\MCAPPINS.EXE
C:\PROGRAM FILES\KAZAA LITE K++\UNINS000.EXE
C:\WINDOWS\UNVISE32.EXE
C:\WINDOWS\SYSTEM\MACROMED\FLASH\UNINSTFL.EXE
C:\PROGRAM FILES\KAZAA UNLIMITED\UNINSTAL.EXE
C:\WINDOWS\UNVISE32QT.EXE
C:\WINDOWS\W2BNEUNIN.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVIAGENT.EXE
C:\Program Files\Fichiers communs\InstallShield\ENGINE\6\Intel 32\ctor.dll
C:\Program Files\Fichiers communs\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
C:\WINDOWS\INF\AD.INF
C:\WINDOWS\SYSTEM\SETUPWBV.DLL
C:\PROGRAM FILES\SOFTNYX\UNINS001.EXE
C:\PROGRAM FILES\MICROSOFT GAMES\ZOO TYCOON\UNINSTAL.EXE
C:\CCHAMP\UNWISE.EXE
C:\PROGRAM FILES\EPSON\TPMANUAL\ESPRX420\REF_G\DOCUNINS.EXE
C:\WINDOWS\DIIUNIN.EXE
C:\PROGRAM FILES\AXBX\MULTI VIRUS CLEANER 2006\UNINS000.EXE
C:\WINDOWS\INF\WPIE5X86.INF
C:\PROGRAM FILES\EPSON\ESCNDV\SETUP\SETUP.EXE
C:\PROGRAM FILES\EPSON\TPMANUAL\ESPRX420\PQU_G\DOCUNINS.EXE
C:\WINDOWS\SYSTEM\EPUSBUN.EXE
C:\WINDOWS\SYSTEM\EPUPDATE.EXE
C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MTBS.EXE
C:\WINDOWS\BUREAU\HIJACKTHIS.EXE
C:\PROGRAM FILES\CCLEANER\UNINST.EXE
C:\WINDOWS\UNVET32.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\UNINS000.EXE
C:\WINDOWS\SYSTEM\Kaspersky Lab\Kaspersky On-line Scanner\kavuninstall.exe
Start Menu Scanning
Explorer : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Outils système\Tâches planifiées.lnk
Explorer : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Communications\Accès réseau à distance.lnk
Explorer : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Explorateur Windows.lnk
SynchronizationManager : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Synchroniser.lnk
LXSUPMON : C:\WINDOWS\Menu Démarrer\Programmes\Contrôleur de fournitures Lexmark\Contrôleur de fournitures Lexmark.lnk
MCAgent : C:\WINDOWS\Menu Démarrer\Programmes\McAfee\McAfee SecurityCenter.lnk
Ccleaner : C:\WINDOWS\Menu Démarrer\Programmes\CCleaner\CCleaner.lnk
Spyware Terminator : C:\WINDOWS\Menu Démarrer\Programmes\Spyware Terminator\Spyware Terminator.lnk
Desktop Scanning
MCAgent : C:\WINDOWS\Bureau\McAfee SecurityCenter.lnk
MessengerService : C:\WINDOWS\Bureau\MSN Messenger 7.0.lnk
Ccleaner : C:\WINDOWS\Bureau\CCleaner.lnk
PrcRew : C:\WINDOWS\Bureau\smitRem\Process.exe
Spyware Terminator : C:\WINDOWS\Bureau\Spyware Terminator\Spyware Terminator.lnk
Favorites Scanning
Cookies Scanning
Affiliate tracking cookie : C:\WINDOWS\cookies\anyuser@atdmt[2].txt
Affiliate tracking cookie : C:\WINDOWS\cookies\anyuser@advertising[2].txt
Registry Scanning
CometCursor : HKCR\CLSID\{1678F7E1-C422-11D0-AD7D-00400515CAAA}\
CometCursor : C:\WINDOWS\SYSTEM\COMET.DLL
CometCursor : C:\WINDOWS\EXPLORER.EXE PID: 4294764777
MSNSearchToolbar : HKCR\CLSID\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\
MSNSearchToolbar : C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
MSNSearchToolbar : HKCR\CLSID\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}\
MSNSearchToolbar : C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
MSNSearchToolbar : HKCR\CLSID\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\
SchedulingAgent : HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\ SchedulingAgent
SystemTray : HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ SystemTray
MSDXM : HKCR\CLSID\{8E718888-423F-11D2-876E-00A0C9082467}\
MSDXM : C:\WINDOWS\SYSTEM\MSDXM.OCX
EPSONWeb-To-Page : HKCR\CLSID\{EE5D279F-081B-4404-994D-C6B60AAEBA6D}\
EPSONWeb-To-Page : C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
EPSONWeb-To-Page : C:\WINDOWS\EXPLORER.EXE PID: 4294764777
EPSONWeb-To-Page : HKCR\CLSID\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}\
Files Scanning
Spyware Terminator : C:\Program Files\Spyware Terminator\Spywareterminatorshield.exe
Spyware Terminator : C:\Program Files\Spyware Terminator\Spywareterminator.exe
MessengerService : C:\Program Files\MSN Messenger\msnmsgr.exe
SpySheriff : C:\WINDOWS\desktop.html
MCUpdate : C:\Program Files\mcafee.com\agent\McUpdate.exe
MCAgent : C:\Program Files\mcafee.com\agent\mcagent.exe
SSDPSRV : C:\WINDOWS\SYSTEM\ssdpsrv.exe
StateMgr : C:\WINDOWS\System\Restore\StateMgr.exe
TaskMonitor : C:\WINDOWS\taskmon.exe
ScanRegistry : C:\WINDOWS\scanregw.exe
PCHealth : C:\WINDOWS\PCHealth\Support\PCHSchd.exe
SynchronizationManager : C:\WINDOWS\SYSTEM\mobsync.exe
RealTray : C:\Program Files\Real\RealPlayer\RealPlay.exe
McAfeeVirusScan : C:\Program Files\McAfee.com\Agent\McRegWiz.exe
MSDXM : C:\WINDOWS\SYSTEM\msdxm.ocx
eTrustEZAntivirus : C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
LoadQM : C:\WINDOWS\loadqm.exe
StillImageMonitor : C:\WINDOWS\SYSTEM\STIMON.EXE
Internat : C:\WINDOWS\SYSTEM\internat.exe
Wextract : C:\WINDOWS\SYSTEM\advpack.dll
Explorer : C:\WINDOWS\explorer.exe
PowerProfile : C:\WINDOWS\SYSTEM\powrprof.dll
Shdocvw : C:\WINDOWS\SYSTEM\shdocvw.dll
LXSUPMON : C:\WINDOWS\SYSTEM\LXSUPMON.EXE
MltdKeyboard : C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
Ccleaner : C:\Program Files\CCleaner\ccleaner.exe
Navapw32 : C:\Program Files\NORTON~1\navapw32.exe
EPSONWeb-To-Page : C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll
Trojan/IBM-B : C:\WINDOWS\ms3.exe
DeepFiles Scanning
Wextract : C:\WINDOWS\SYSTEM\ADVPACK.DLL
PowerProfile : C:\WINDOWS\SYSTEM\POWRPROF.DLL
StateMgr : C:\WINDOWS\SYSTEM\RESTORE\STATEMGR.EXE
Internat : C:\WINDOWS\SYSTEM\INTERNAT.EXE
StillImageMonitor : C:\WINDOWS\SYSTEM\STIMON.EXE
CometCursor : C:\WINDOWS\SYSTEM\COMET.DLL
LXSUPMON : C:\WINDOWS\SYSTEM\lxsupmon.exe
SynchronizationManager : C:\WINDOWS\SYSTEM\mobsync.exe
MSDXM : C:\WINDOWS\SYSTEM\msdxm.ocx
SSDPSRV : C:\WINDOWS\SYSTEM\SSDPSRV.EXE
Shdocvw : C:\WINDOWS\SYSTEM\SHDOCVW.DLL
PCHealth : C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE
ScanRegistry : C:\WINDOWS\SCANREGW.EXE
Explorer : C:\WINDOWS\EXPLORER.EXE
MCAgent : C:\WINDOWS\Bureau\McAfee SecurityCenter.lnk
MessengerService : C:\WINDOWS\Bureau\MSN Messenger 7.0.lnk
Ccleaner : C:\WINDOWS\Bureau\CCleaner.lnk
PrcRew : C:\WINDOWS\Bureau\smitRem\Process.exe
Spyware Terminator : C:\WINDOWS\Bureau\Spyware Terminator\Spyware Terminator.lnk
MessengerService : C:\WINDOWS\Application Data\Microsoft\Internet Explorer\Quick Launch\MSN Messenger 7.0.lnk
Explorer : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Outils système\Tâches planifiées.lnk
Explorer : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Communications\Accès réseau à distance.lnk
Explorer : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Explorateur Windows.lnk
SynchronizationManager : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Synchroniser.lnk
LXSUPMON : C:\WINDOWS\Menu Démarrer\Programmes\Contrôleur de fournitures Lexmark\Contrôleur de fournitures Lexmark.lnk
MCAgent : C:\WINDOWS\Menu Démarrer\Programmes\McAfee\McAfee SecurityCenter.lnk
Ccleaner : C:\WINDOWS\Menu Démarrer\Programmes\CCleaner\CCleaner.lnk
Spyware Terminator : C:\WINDOWS\Menu Démarrer\Programmes\Spyware Terminator\Spyware Terminator.lnk
SpySheriff : C:\WINDOWS\desktop.html
LoadQM : C:\WINDOWS\LOADQM.EXE
TaskMonitor : C:\WINDOWS\TASKMON.EXE
Trojan/IBM-B : C:\WINDOWS\ms4.exe
Trojan/IBM-B : C:\WINDOWS\ms3.exe
MltdKeyboard : C:\Program Files\NETROPA\Multimedia Keyboard\MMKEYBD.EXE
RealTray : C:\Program Files\REAL\RealPlayer\REALPLAY.EXE
Navapw32 : C:\Program Files\Norton AntiVirus\NAVAPW32.EXE
MessengerService : C:\Program Files\MSN Messenger\msnmsgr.exe
MCAgent : C:\Program Files\McAfee.com\Agent\mcagent.exe
MCUpdate : C:\Program Files\McAfee.com\Agent\mcupdate.exe
McAfeeVirusScan : C:\Program Files\McAfee.com\Agent\mcregwiz.exe
EPSONWeb-To-Page : C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll
eTrustEZAntivirus : C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
eTrustEZAntivirus : C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRid.exe
Msnappau : C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr\msnappau.exe
Msnappau : C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe
MSNSearchToolbar : C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
MSNSearchToolbar : C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
MSNSearchToolbar : C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
Ccleaner : C:\Program Files\CCleaner\ccleaner.exe
Spyware Terminator : C:\Program Files\Spyware Terminator\Spywareterminatorshield.Exe
Spyware Terminator : C:\Program Files\Spyware Terminator\SpywareTerminator.exe
Done
Scan Summary:
Total Scanning Time : 3829,39 s
Objects Scanned : 46 456
Objects Identified : 112
Objects Ignored : 0
Critical Objects : 11
Remove Process:
Preparing structures
Creating System Restore Point
Hard File Remover Disabled
Remove Trojan/IBM-B
Deleted File: C:\WINDOWS\ms3.exe
Deleted File: C:\WINDOWS\ms4.exe
Remove CometCursor
Deleted File: C:\WINDOWS\SYSTEM\COMET.DLL
Deleted Registry : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1678F7E1-C422-11D0-AD7D-00400515CAAA}\
Deleted Registry : HKCR\CLSID\{1678F7E1-C422-11D0-AD7D-00400515CAAA}\
Remove SpySheriff
Deleted File: C:\WINDOWS\desktop.html
Remove Affiliate tracking cookie
Deleted File: C:\WINDOWS\cookies\anyuser@atdmt[2].txt
Deleted File: C:\WINDOWS\cookies\anyuser@advertising[2].txt
Remove PrcRew
Deleted File: C:\WINDOWS\Bureau\smitRem\Process.exe
Remove Invalid Startup Items
Deleted Registry : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ OEMCleanup
Closing System Restore Point
Voila son rapport:
Scan Progress (Full Scan)
Start time: 26/09/2000 11:02:14
Processes Scanning
SSDPSRV : C:\WINDOWS\SYSTEM\SSDPSRV.EXE
StillImageMonitor : C:\WINDOWS\SYSTEM\STIMON.EXE
EPSONWeb-To-Page : C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
CometCursor : C:\WINDOWS\SYSTEM\COMET.DLL
Shdocvw : C:\WINDOWS\SYSTEM\SHDOCVW.DLL
Explorer : C:\WINDOWS\EXPLORER.EXE
PowerProfile : C:\WINDOWS\SYSTEM\POWRPROF.DLL
MltdKeyboard : C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMKEYBD.EXE
LoadQM : C:\WINDOWS\LOADQM.EXE
MCAgent : C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
RealTray : C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
MSNSearchToolbar : MSNAPPAU.EXE
MSNSearchToolbar : C:\WINDOWS\SYSTEM\MSXML3.DLL
Msnappau : C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\FR\MSNAPPAU.EXE
Spyware Terminator : C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE
eTrustEZAntivirus : C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVTRAY.EXE
eTrustEZAntivirus : C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVRID.EXE
Spyware Terminator : C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATOR.EXE
Startup Scanning
MoneyAgent : C:\PROGRAM FILES\MICROSOFT MONEY\SYSTEM\MONEY EXPRESS.EXE
EPSON Stylus Photo RX420 Series : C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
ScanRegistry : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ ScanRegistry
ScanRegistry : C:\WINDOWS\SCANREGW.EXE
TaskMonitor : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ TaskMonitor
TaskMonitor : C:\WINDOWS\TASKMON.EXE
PCHealth : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ PCHealth
PCHealth : C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE
SystemTray : C:\WINDOWS\SYSTEM\SYSTRAY.EXE
Hidserv : C:\WINDOWS\SYSTEM\HIDSERV.EXE
MltdKeyboard : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ MULTIMEDIA KEYBOARD
MltdKeyboard : C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMKEYBD.EXE
reminder.exe : C:\PROGRAM FILES\BACKWEB\TUNER\REMINDER.EXE
LXSUPMON : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ LXSUPMON
LXSUPMON : C:\WINDOWS\SYSTEM\LXSUPMON.EXE
CountrySelection : C:\WINDOWS\PCTPTT.EXE
PCTVOICE : C:\WINDOWS\PCTVOICE.EXE
LoadQM : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ LoadQM
LoadQM : C:\WINDOWS\LOADQM.EXE
MCAgent : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ MCAgentExe
MCAgent : C:\Program Files\McAfee.com\Agent\mcagent.exe
MCUpdate : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ MCUpdateExe
MCUpdate : C:\Program Files\McAfee.com\Agent\mcupdate.exe
navi : C:\PROGRAM FILES\VERISIGN\NAVI\NAVIAGENT.EXE
RealTray : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ RealTray
RealTray : C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
Invalid Startup Items : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ OEMCleanup
PowerProfile : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ LoadPowerProfile
PowerProfile : C:\WINDOWS\SYSTEM\POWRPROF.DLL
MCTskShd : C:\Program Files\McAfee.com\Agent\McTskshd.exe
EM_EXEC : C:\PROGRAM FILES\MOUSEWARE\SYSTEM\EM_EXEC.EXE
EPSON Stylus Photo R (Copie 2) : C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
Msnappau : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ msnappau
Msnappau : C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\FR\MSNAPPAU.EXE
Spyware Terminator : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ SpywareTerminator
Spyware Terminator : C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE
VetAlert : C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
eTrustEZAntivirus : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ CaAvTray
eTrustEZAntivirus : C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVTRAY.EXE
eTrustEZAntivirus : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ CAVRID
eTrustEZAntivirus : C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVRID.EXE
PowerProfile : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ LoadPowerProfile
SchedulingAgent : C:\WINDOWS\SYSTEM\MSTASK.EXE
SSDPSRV : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ SSDPSRV
SSDPSRV : C:\WINDOWS\SYSTEM\SSDPSRV.EXE
StateMgr : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ *StateMgr
StateMgr : C:\WINDOWS\SYSTEM\RESTORE\STATEMGR.EXE
StillImageMonitor : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ StillImageMonitor
StillImageMonitor : C:\WINDOWS\SYSTEM\STIMON.EXE
CAISafe : C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
TGB::BOB : C:\PROGRAM FILES\MINDSCAPE\MCF\TGBBOB.EXE
Toolbars Scanning
&Kangaroo ( Toolbar ) : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ {663C7429-E454-11D3-B9AE-0000B4C32B4D}
&Kangaroo ( Toolbar ) : C:\IDC\WEBKA.DLL
MSDXM : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ {8E718888-423F-11D2-876E-00A0C9082467}
MSDXM : C:\WINDOWS\SYSTEM\MSDXM.OCX
EPSONWeb-To-Page : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ {EE5D279F-081B-4404-994D-C6B60AAEBA6D}
EPSONWeb-To-Page : C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
EPSONWeb-To-Page : C:\WINDOWS\EXPLORER.EXE PID: 4294764777
MSNSearchToolbar : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\ {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
MSNSearchToolbar : C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
Shdocvw : HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}\
Shdocvw : C:\WINDOWS\SYSTEM\SHDOCVW.DLL
Shdocvw : C:\WINDOWS\EXPLORER.EXE PID: 4294764777
Shdocvw : C:\PROGRAM FILES\BACKWEB\PROGRAM\BACKWEB.EXE PID: 4294417873
Shdocvw : C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATOR.EXE PID: 4294514933
Shdocvw : HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}\
Shdocvw : HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}\
Shdocvw : HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}\
Browser Helper Objects Scanning
i-Nav IDN Resolver ( BHO ) : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CE000992-A58C-4441-8938-744CD72AB27F}\
i-Nav IDN Resolver ( BHO ) : C:\Program Files\VeriSign\i-Nav\i-nav_4_2_1.dll
CometCursor : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1678F7E1-C422-11D0-AD7D-00400515CAAA}\
CometCursor : C:\WINDOWS\SYSTEM\COMET.DLL
CometCursor : C:\WINDOWS\EXPLORER.EXE PID: 4294764777
EPSONWeb-To-Page : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}\
MSNSearchToolbar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\
MSNSearchToolbar : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}\
MSNSearchToolbar : C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
IE Explorer Bars
IE Extensions
Services Scanning
Protocol filters Scanning
Protocol handlers Scanning
WinSock2 Scanning
Uninstallers Scanning
C:\WINDOWS\RUNDLL.EXE
C:\PROGRAM FILES\OUTLOOK EXPRESS\SETUP50.EXE
C:\WINDOWS\ISUN040C.EXE
C:\PROGRAM FILES\MICROSOFT MONEY\SETUP\SETUP.EXE
C:\WINDOWS\SYSTEM\MSIEXEC.EXE
C:\PROGRAM FILES\AIRXONIX\UNINS000.EXE
C:\WINDOWS\PTUNINST.EXE
C:\Program Files\McAfee.com\Shared\MCAPPINS.EXE
C:\PROGRAM FILES\KAZAA LITE K++\UNINS000.EXE
C:\WINDOWS\UNVISE32.EXE
C:\WINDOWS\SYSTEM\MACROMED\FLASH\UNINSTFL.EXE
C:\PROGRAM FILES\KAZAA UNLIMITED\UNINSTAL.EXE
C:\WINDOWS\UNVISE32QT.EXE
C:\WINDOWS\W2BNEUNIN.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVIAGENT.EXE
C:\Program Files\Fichiers communs\InstallShield\ENGINE\6\Intel 32\ctor.dll
C:\Program Files\Fichiers communs\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
C:\WINDOWS\INF\AD.INF
C:\WINDOWS\SYSTEM\SETUPWBV.DLL
C:\PROGRAM FILES\SOFTNYX\UNINS001.EXE
C:\PROGRAM FILES\MICROSOFT GAMES\ZOO TYCOON\UNINSTAL.EXE
C:\CCHAMP\UNWISE.EXE
C:\PROGRAM FILES\EPSON\TPMANUAL\ESPRX420\REF_G\DOCUNINS.EXE
C:\WINDOWS\DIIUNIN.EXE
C:\PROGRAM FILES\AXBX\MULTI VIRUS CLEANER 2006\UNINS000.EXE
C:\WINDOWS\INF\WPIE5X86.INF
C:\PROGRAM FILES\EPSON\ESCNDV\SETUP\SETUP.EXE
C:\PROGRAM FILES\EPSON\TPMANUAL\ESPRX420\PQU_G\DOCUNINS.EXE
C:\WINDOWS\SYSTEM\EPUSBUN.EXE
C:\WINDOWS\SYSTEM\EPUPDATE.EXE
C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MTBS.EXE
C:\WINDOWS\BUREAU\HIJACKTHIS.EXE
C:\PROGRAM FILES\CCLEANER\UNINST.EXE
C:\WINDOWS\UNVET32.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\UNINS000.EXE
C:\WINDOWS\SYSTEM\Kaspersky Lab\Kaspersky On-line Scanner\kavuninstall.exe
Start Menu Scanning
Explorer : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Outils système\Tâches planifiées.lnk
Explorer : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Communications\Accès réseau à distance.lnk
Explorer : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Explorateur Windows.lnk
SynchronizationManager : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Synchroniser.lnk
LXSUPMON : C:\WINDOWS\Menu Démarrer\Programmes\Contrôleur de fournitures Lexmark\Contrôleur de fournitures Lexmark.lnk
MCAgent : C:\WINDOWS\Menu Démarrer\Programmes\McAfee\McAfee SecurityCenter.lnk
Ccleaner : C:\WINDOWS\Menu Démarrer\Programmes\CCleaner\CCleaner.lnk
Spyware Terminator : C:\WINDOWS\Menu Démarrer\Programmes\Spyware Terminator\Spyware Terminator.lnk
Desktop Scanning
MCAgent : C:\WINDOWS\Bureau\McAfee SecurityCenter.lnk
MessengerService : C:\WINDOWS\Bureau\MSN Messenger 7.0.lnk
Ccleaner : C:\WINDOWS\Bureau\CCleaner.lnk
PrcRew : C:\WINDOWS\Bureau\smitRem\Process.exe
Spyware Terminator : C:\WINDOWS\Bureau\Spyware Terminator\Spyware Terminator.lnk
Favorites Scanning
Cookies Scanning
Affiliate tracking cookie : C:\WINDOWS\cookies\anyuser@atdmt[2].txt
Affiliate tracking cookie : C:\WINDOWS\cookies\anyuser@advertising[2].txt
Registry Scanning
CometCursor : HKCR\CLSID\{1678F7E1-C422-11D0-AD7D-00400515CAAA}\
CometCursor : C:\WINDOWS\SYSTEM\COMET.DLL
CometCursor : C:\WINDOWS\EXPLORER.EXE PID: 4294764777
MSNSearchToolbar : HKCR\CLSID\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\
MSNSearchToolbar : C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
MSNSearchToolbar : HKCR\CLSID\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}\
MSNSearchToolbar : C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
MSNSearchToolbar : HKCR\CLSID\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\
SchedulingAgent : HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\ SchedulingAgent
SystemTray : HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ SystemTray
MSDXM : HKCR\CLSID\{8E718888-423F-11D2-876E-00A0C9082467}\
MSDXM : C:\WINDOWS\SYSTEM\MSDXM.OCX
EPSONWeb-To-Page : HKCR\CLSID\{EE5D279F-081B-4404-994D-C6B60AAEBA6D}\
EPSONWeb-To-Page : C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
EPSONWeb-To-Page : C:\WINDOWS\EXPLORER.EXE PID: 4294764777
EPSONWeb-To-Page : HKCR\CLSID\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}\
Files Scanning
Spyware Terminator : C:\Program Files\Spyware Terminator\Spywareterminatorshield.exe
Spyware Terminator : C:\Program Files\Spyware Terminator\Spywareterminator.exe
MessengerService : C:\Program Files\MSN Messenger\msnmsgr.exe
SpySheriff : C:\WINDOWS\desktop.html
MCUpdate : C:\Program Files\mcafee.com\agent\McUpdate.exe
MCAgent : C:\Program Files\mcafee.com\agent\mcagent.exe
SSDPSRV : C:\WINDOWS\SYSTEM\ssdpsrv.exe
StateMgr : C:\WINDOWS\System\Restore\StateMgr.exe
TaskMonitor : C:\WINDOWS\taskmon.exe
ScanRegistry : C:\WINDOWS\scanregw.exe
PCHealth : C:\WINDOWS\PCHealth\Support\PCHSchd.exe
SynchronizationManager : C:\WINDOWS\SYSTEM\mobsync.exe
RealTray : C:\Program Files\Real\RealPlayer\RealPlay.exe
McAfeeVirusScan : C:\Program Files\McAfee.com\Agent\McRegWiz.exe
MSDXM : C:\WINDOWS\SYSTEM\msdxm.ocx
eTrustEZAntivirus : C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
LoadQM : C:\WINDOWS\loadqm.exe
StillImageMonitor : C:\WINDOWS\SYSTEM\STIMON.EXE
Internat : C:\WINDOWS\SYSTEM\internat.exe
Wextract : C:\WINDOWS\SYSTEM\advpack.dll
Explorer : C:\WINDOWS\explorer.exe
PowerProfile : C:\WINDOWS\SYSTEM\powrprof.dll
Shdocvw : C:\WINDOWS\SYSTEM\shdocvw.dll
LXSUPMON : C:\WINDOWS\SYSTEM\LXSUPMON.EXE
MltdKeyboard : C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
Ccleaner : C:\Program Files\CCleaner\ccleaner.exe
Navapw32 : C:\Program Files\NORTON~1\navapw32.exe
EPSONWeb-To-Page : C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll
Trojan/IBM-B : C:\WINDOWS\ms3.exe
DeepFiles Scanning
Wextract : C:\WINDOWS\SYSTEM\ADVPACK.DLL
PowerProfile : C:\WINDOWS\SYSTEM\POWRPROF.DLL
StateMgr : C:\WINDOWS\SYSTEM\RESTORE\STATEMGR.EXE
Internat : C:\WINDOWS\SYSTEM\INTERNAT.EXE
StillImageMonitor : C:\WINDOWS\SYSTEM\STIMON.EXE
CometCursor : C:\WINDOWS\SYSTEM\COMET.DLL
LXSUPMON : C:\WINDOWS\SYSTEM\lxsupmon.exe
SynchronizationManager : C:\WINDOWS\SYSTEM\mobsync.exe
MSDXM : C:\WINDOWS\SYSTEM\msdxm.ocx
SSDPSRV : C:\WINDOWS\SYSTEM\SSDPSRV.EXE
Shdocvw : C:\WINDOWS\SYSTEM\SHDOCVW.DLL
PCHealth : C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE
ScanRegistry : C:\WINDOWS\SCANREGW.EXE
Explorer : C:\WINDOWS\EXPLORER.EXE
MCAgent : C:\WINDOWS\Bureau\McAfee SecurityCenter.lnk
MessengerService : C:\WINDOWS\Bureau\MSN Messenger 7.0.lnk
Ccleaner : C:\WINDOWS\Bureau\CCleaner.lnk
PrcRew : C:\WINDOWS\Bureau\smitRem\Process.exe
Spyware Terminator : C:\WINDOWS\Bureau\Spyware Terminator\Spyware Terminator.lnk
MessengerService : C:\WINDOWS\Application Data\Microsoft\Internet Explorer\Quick Launch\MSN Messenger 7.0.lnk
Explorer : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Outils système\Tâches planifiées.lnk
Explorer : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Communications\Accès réseau à distance.lnk
Explorer : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Explorateur Windows.lnk
SynchronizationManager : C:\WINDOWS\Menu Démarrer\Programmes\Accessoires\Synchroniser.lnk
LXSUPMON : C:\WINDOWS\Menu Démarrer\Programmes\Contrôleur de fournitures Lexmark\Contrôleur de fournitures Lexmark.lnk
MCAgent : C:\WINDOWS\Menu Démarrer\Programmes\McAfee\McAfee SecurityCenter.lnk
Ccleaner : C:\WINDOWS\Menu Démarrer\Programmes\CCleaner\CCleaner.lnk
Spyware Terminator : C:\WINDOWS\Menu Démarrer\Programmes\Spyware Terminator\Spyware Terminator.lnk
SpySheriff : C:\WINDOWS\desktop.html
LoadQM : C:\WINDOWS\LOADQM.EXE
TaskMonitor : C:\WINDOWS\TASKMON.EXE
Trojan/IBM-B : C:\WINDOWS\ms4.exe
Trojan/IBM-B : C:\WINDOWS\ms3.exe
MltdKeyboard : C:\Program Files\NETROPA\Multimedia Keyboard\MMKEYBD.EXE
RealTray : C:\Program Files\REAL\RealPlayer\REALPLAY.EXE
Navapw32 : C:\Program Files\Norton AntiVirus\NAVAPW32.EXE
MessengerService : C:\Program Files\MSN Messenger\msnmsgr.exe
MCAgent : C:\Program Files\McAfee.com\Agent\mcagent.exe
MCUpdate : C:\Program Files\McAfee.com\Agent\mcupdate.exe
McAfeeVirusScan : C:\Program Files\McAfee.com\Agent\mcregwiz.exe
EPSONWeb-To-Page : C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll
eTrustEZAntivirus : C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
eTrustEZAntivirus : C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRid.exe
Msnappau : C:\Program Files\MSN Apps\Updater\01.02.3000.1001\fr\msnappau.exe
Msnappau : C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe
MSNSearchToolbar : C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
MSNSearchToolbar : C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
MSNSearchToolbar : C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
Ccleaner : C:\Program Files\CCleaner\ccleaner.exe
Spyware Terminator : C:\Program Files\Spyware Terminator\Spywareterminatorshield.Exe
Spyware Terminator : C:\Program Files\Spyware Terminator\SpywareTerminator.exe
Done
Scan Summary:
Total Scanning Time : 3829,39 s
Objects Scanned : 46 456
Objects Identified : 112
Objects Ignored : 0
Critical Objects : 11
Remove Process:
Preparing structures
Creating System Restore Point
Hard File Remover Disabled
Remove Trojan/IBM-B
Deleted File: C:\WINDOWS\ms3.exe
Deleted File: C:\WINDOWS\ms4.exe
Remove CometCursor
Deleted File: C:\WINDOWS\SYSTEM\COMET.DLL
Deleted Registry : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1678F7E1-C422-11D0-AD7D-00400515CAAA}\
Deleted Registry : HKCR\CLSID\{1678F7E1-C422-11D0-AD7D-00400515CAAA}\
Remove SpySheriff
Deleted File: C:\WINDOWS\desktop.html
Remove Affiliate tracking cookie
Deleted File: C:\WINDOWS\cookies\anyuser@atdmt[2].txt
Deleted File: C:\WINDOWS\cookies\anyuser@advertising[2].txt
Remove PrcRew
Deleted File: C:\WINDOWS\Bureau\smitRem\Process.exe
Remove Invalid Startup Items
Deleted Registry : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ OEMCleanup
Closing System Restore Point
Voici mon nouveau Hijack:
Logfile of HijackThis v1.99.1
Scan saved at 13:03:27, on 26/09/2000
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\PROGRAM FILES\MINDSCAPE\MCF\TGBBOB.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\LXSUPMON.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\TRAYMON.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVIAGENT.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCTSKSHD.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\FR\MSNAPPAU.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\VETMSG.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVTRAY.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVRID.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVICLIENT.EXE
C:\PROGRAM FILES\EPSON\EPSON CARDMONITOR\EPSON CARDMONITOR1.2.EXE
C:\PROGRAM FILES\NIKON\PICTUREPROJECT\NKBMONITOR.EXE
C:\PROGRAM FILES\BACKWEB\PROGRAM\BACKWEB.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\BUREAU\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.chello.fr/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=Proxy.chello.fr;ftp=Proxy.chello.fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
O3 - Toolbar: &Kangaroo - {663C7429-E454-11D3-B9AE-0000B4C32B4D} - C:\IDC\WEBKA.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [reminder.exe] C:\Program Files\BackWeb\tuner\reminder.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\SYSTEM\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [navi] "C:\Program Files\VeriSign\NAVI\naviagent.exe" uimode=agentupdate
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\realplay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [MCTskShd] C:\PROGRA~1\MCAFEE.COM\AGENT\mctskshd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRAM FILES\MOUSEWARE\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /O5 "LPT1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [EPSON Stylus Photo R (Copie 2)] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P30 "EPSON Stylus Photo R (Copie 2)" /O7 "EPUSB1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRAM FILES\SPYWARE TERMINATOR\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [VetAlert] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VETMSG.EXE
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - HKLM\..\RunServices: [TGB::BOB] C:\Program Files\MINDSCAPE\MCF\TGBBOB.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /M "Stylus Photo RX420" /EF "HKCU"
O4 - Startup: EPSON CardMonitor.lnk = C:\Program Files\epson\EPSON CardMonitor\EPSON CardMonitor1.2.exe
O4 - Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O9 - Extra button: Kangaroo - {06A18DC1-FE86-11d3-B9AF-0000B4C32B4D} - http://knowledge-assistant.com/webka/toolbar/tbie.asp (file missing)
O9 - Extra button: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra 'Tools' menuitem: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra button: (no name) - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O9 - Extra 'Tools' menuitem: Options i-Nav - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdown...
O16 - DPF: {6F6E3A5E-4A75-45F0-BDDE-21B6C4496E2B} (LAInstaller Class) - http://www.cantoche.com/Player/V12/LAinstall.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_ansi.cab
Il reste encore queque chose ou c'est bon?
Logfile of HijackThis v1.99.1
Scan saved at 13:03:27, on 26/09/2000
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\ISAFE.EXE
C:\PROGRAM FILES\MINDSCAPE\MCF\TGBBOB.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\MMKEYBD.EXE
C:\WINDOWS\SYSTEM\LXSUPMON.EXE
C:\WINDOWS\PCTVOICE.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\PROGRAM FILES\NETROPA\MULTIMEDIA KEYBOARD\TRAYMON.EXE
C:\PROGRAM FILES\NETROPA\ONSCREEN DISPLAY\OSD.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVIAGENT.EXE
C:\PROGRAM FILES\REAL\REALPLAYER\REALPLAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCTSKSHD.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\WINDOWS\SYSTEM\E_S5I0C1.EXE
C:\PROGRAM FILES\MSN APPS\UPDATER\01.03.0000.1005\FR\MSNAPPAU.EXE
C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\VETMSG.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVTRAY.EXE
C:\PROGRAM FILES\CA\ETRUST EZ ARMOR\ETRUST EZ ANTIVIRUS\CAVRID.EXE
C:\PROGRAM FILES\VERISIGN\NAVI\NAVICLIENT.EXE
C:\PROGRAM FILES\EPSON\EPSON CARDMONITOR\EPSON CARDMONITOR1.2.EXE
C:\PROGRAM FILES\NIKON\PICTUREPROJECT\NKBMONITOR.EXE
C:\PROGRAM FILES\BACKWEB\PROGRAM\BACKWEB.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\WINDOWS\BUREAU\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.chello.fr/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=Proxy.chello.fr;ftp=Proxy.chello.fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.03.0000.1005\EN-XU\STMAIN.DLL
O3 - Toolbar: &Kangaroo - {663C7429-E454-11D3-B9AE-0000B4C32B4D} - C:\IDC\WEBKA.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\PROGRAM FILES\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.5000.1021\FR\MSNTB.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Hidserv] Hidserv.exe run
O4 - HKLM\..\Run: [MULTIMEDIA KEYBOARD] C:\Program Files\Netropa\Multimedia Keyboard\MMKeybd.exe
O4 - HKLM\..\Run: [reminder.exe] C:\Program Files\BackWeb\tuner\reminder.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\SYSTEM\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [PCTVOICE] pctvoice.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [navi] "C:\Program Files\VeriSign\NAVI\naviagent.exe" uimode=agentupdate
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\realplay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [MCTskShd] C:\PROGRA~1\MCAFEE.COM\AGENT\mctskshd.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRAM FILES\MOUSEWARE\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /O5 "LPT1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [EPSON Stylus Photo R (Copie 2)] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P30 "EPSON Stylus Photo R (Copie 2)" /O7 "EPUSB1:" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.03.0000.1005\fr\msnappau.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\PROGRAM FILES\SPYWARE TERMINATOR\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [VetAlert] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VETMSG.EXE
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [CAISafe] C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O4 - HKLM\..\RunServices: [TGB::BOB] C:\Program Files\MINDSCAPE\MCF\TGBBOB.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /M "Stylus Photo RX420" /EF "HKCU"
O4 - Startup: EPSON CardMonitor.lnk = C:\Program Files\epson\EPSON CardMonitor\EPSON CardMonitor1.2.exe
O4 - Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O9 - Extra button: Kangaroo - {06A18DC1-FE86-11d3-B9AF-0000B4C32B4D} - http://knowledge-assistant.com/webka/toolbar/tbie.asp (file missing)
O9 - Extra button: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra 'Tools' menuitem: Aide i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra button: (no name) - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O9 - Extra 'Tools' menuitem: Options i-Nav - {CE000996-A58C-4441-8938-744CD72AB27F} - C:\PROGRAM FILES\VERISIGN\I-NAV\I-NAV_4_2_1.DLL
O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdown...
O16 - DPF: {6F6E3A5E-4A75-45F0-BDDE-21B6C4496E2B} (LAInstaller Class) - http://www.cantoche.com/Player/V12/LAinstall.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_ansi.cab
Il reste encore queque chose ou c'est bon?
Lassé par la pub ? Créez un compte