tres UrGent SVP ...merci D'avance
-
- Novice
- Messages : 47
- Enregistré le : 23 nov. 2008, 17:10
- Configuration matérielle : urgent!!!
Re: tres UrGent SVP ...merci D'avance
bon tout d'abord je vous remerci beaucoup pour cette immense aide et la je vous poste le rapport d'ANTIVIR en mode SANS ECHEC
End of the scan: mardi 25 novembre 2008 11:58
Used time: 41:42 Minute(s)
The scan has been done completely.
18835 Scanning directories
291906 Files were scanned
2819 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
2819 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
289086 Files not concerned
1657 Archives were scanned
6 Warnings
2819 Notes
ps (j'ai pa copier coller tout les détails car c'est trop long sa faisait pas place donc ça c'est le résumé d'enbas)
End of the scan: mardi 25 novembre 2008 11:58
Used time: 41:42 Minute(s)
The scan has been done completely.
18835 Scanning directories
291906 Files were scanned
2819 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
2819 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
289086 Files not concerned
1657 Archives were scanned
6 Warnings
2819 Notes
ps (j'ai pa copier coller tout les détails car c'est trop long sa faisait pas place donc ça c'est le résumé d'enbas)
- bernard53
- Support
- Messages : 3516
- Enregistré le : 25 avr. 2008, 22:05
- Configuration matérielle : Processeur intel 2 duo CPU E6750 2.66GHz
3GO mémoire vive
disque dur samsung 160Go
Re: tres UrGent SVP ...merci D'avance
bon très bien.
comment vas ton pc
mets moi un nouveau rapport hijackthis pour contrôle.
Pour Antivir :
Vide la quarantaine

comment vas ton pc

mets moi un nouveau rapport hijackthis pour contrôle.
Pour Antivir :
Vide la quarantaine

Bonne visite sur: http://tuto-b.comli.com/
-
- Novice
- Messages : 47
- Enregistré le : 23 nov. 2008, 17:10
- Configuration matérielle : urgent!!!
Re: tres UrGent SVP ...merci D'avance
oui sayé je l'ai vider la quarantaine 'antivir ' oki je vais fair hijackthis le voici:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:59:24, on 23/11/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16757)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 5400 Series\lxctmon.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.fr.acer.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [lxctmon.exe] "C:\Program Files\Lexmark 5400 Series\lxctmon.exe"
O4 - HKLM\..\Run: [Lexmark 5400 Series Fax Server] "C:\Program Files\Lexmark 5400 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 5400 Series\ezprint.exe"
O4 - HKLM\..\Run: [LXCTCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [c00148FE] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00148FE.mat", sh
O4 - HKCU\..\Run: [c0082240] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0082240.mat", sh
O4 - HKCU\..\Run: [c00A6900] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A6900.mat", sh
O4 - HKCU\..\Run: [c0059A4A] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0059A4A.mat", sh
O4 - HKCU\..\Run: [c0081AA0] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0081AA0.mat", sh
O4 - HKCU\..\Run: [c00CB729] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CB729.mat", sh
O4 - HKCU\..\Run: [c0034D1] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0034D1.mat", sh
O4 - HKCU\..\Run: [c00E52AA] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E52AA.mat", sh
O4 - HKCU\..\Run: [c00D14C4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D14C4.mat", sh
O4 - HKCU\..\Run: [c00D4C8E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D4C8E.mat", sh
O4 - HKCU\..\Run: [c00BEB10] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00BEB10.mat", sh
O4 - HKCU\..\Run: [c00A2690] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A2690.mat", sh
O4 - HKCU\..\Run: [c0099DD8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0099DD8.mat", sh
O4 - HKCU\..\Run: [c004772B] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c004772B.mat", sh
O4 - HKCU\..\Run: [c00EC346] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00EC346.mat", sh
O4 - HKCU\..\Run: [c005F81E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c005F81E.mat", sh
O4 - HKCU\..\Run: [c00A8BE9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A8BE9.mat", sh
O4 - HKCU\..\Run: [c003549C] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c003549C.mat", sh
O4 - HKCU\..\Run: [c00B156A] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00B156A.mat", sh
O4 - HKCU\..\Run: [c0076E64] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0076E64.mat", sh
O4 - HKCU\..\Run: [c0056690] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0056690.mat", sh
O4 - HKCU\..\Run: [c007D70] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c007D70.mat", sh
O4 - HKCU\..\Run: [c0040B99] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0040B99.mat", sh
O4 - HKCU\..\Run: [c00CA368] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CA368.mat", sh
O4 - HKCU\..\Run: [c00992C9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00992C9.mat", sh
O4 - HKCU\..\Run: [c0018157] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0018157.mat", sh
O4 - HKCU\..\Run: [c0065844] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0065844.mat", sh
O4 - HKCU\..\Run: [c009F6E4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c009F6E4.mat", sh
O4 - HKCU\..\Run: [c00E07F8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E07F8.mat", sh
O4 - HKCU\..\Run: [c00DC9C3] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00DC9C3.mat", sh
O4 - HKCU\..\Run: [c006A3F8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c006A3F8.mat", sh
O4 - HKCU\..\Run: [c00F07C9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00F07C9.mat", sh
O4 - HKCU\..\Run: [c00CB411] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CB411.mat", sh
O4 - HKCU\..\Run: [c005E0F4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c005E0F4.mat", sh
O4 - HKCU\..\Run: [c0039AA8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0039AA8.mat", sh
O4 - HKCU\..\Run: [c00C68E2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00C68E2.mat", sh
O4 - HKCU\..\Run: [c0068E3E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0068E3E.mat", sh
O4 - HKCU\..\Run: [c0028CF1] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0028CF1.mat", sh
O4 - HKCU\..\Run: [c003095E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c003095E.mat", sh
O4 - HKCU\..\Run: [c008C650] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c008C650.mat", sh
O4 - HKCU\..\Run: [c00F5900] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00F5900.mat", sh
O4 - HKCU\..\Run: [c009B621] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c009B621.mat", sh
O4 - HKCU\..\Run: [c00E4AB9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E4AB9.mat", sh
O4 - HKCU\..\Run: [c0012D87] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0012D87.mat", sh
O4 - HKCU\..\Run: [c0049B2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0049B2.mat", sh
O4 - HKCU\..\Run: [c0088490] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0088490.mat", sh
O4 - HKCU\..\Run: [c00D62D2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D62D2.mat", sh
O4 - HKCU\..\Run: [c001F6C0] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c001F6C0.mat", sh
O4 - HKCU\..\Run: [c0036694] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0036694.mat", sh
O4 - HKCU\..\Run: [c0059853] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0059853.mat", sh
O4 - HKCU\..\Run: [c008CF04] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c008CF04.mat", sh
O4 - HKCU\..\Run: [c00DA4AC] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00DA4AC.mat", sh
O4 - HKCU\..\Run: [c00237D8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00237D8.mat", sh
O4 - HKCU\..\Run: [c00CC689] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CC689.mat", sh
O4 - HKCU\..\Run: [c00281EE] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00281EE.mat", sh
O4 - HKCU\..\Run: [c00E9624] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E9624.mat", sh
O4 - HKCU\..\Run: [c001676B] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c001676B.mat", sh
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Winamp Toolbar Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.co ... nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2B218E3-51B5-434A-8775-34E10D41BD45}: NameServer = 212.25.53.252,212.27.54.252
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\Windows\system32\c00ADB6B.mat
O20 - Winlogon Notify: c0047749 - C:\Windows\SYSTEM32\c0047749.mat
O20 - Winlogon Notify: c00ADB6B - C:\Windows\SYSTEM32\c00ADB6B.mat
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: lxct_device - - C:\Windows\system32\lxctcoms.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
--
End of file - 17943 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:59:24, on 23/11/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16757)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 5400 Series\lxctmon.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.fr.acer.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [lxctmon.exe] "C:\Program Files\Lexmark 5400 Series\lxctmon.exe"
O4 - HKLM\..\Run: [Lexmark 5400 Series Fax Server] "C:\Program Files\Lexmark 5400 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 5400 Series\ezprint.exe"
O4 - HKLM\..\Run: [LXCTCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [c00148FE] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00148FE.mat", sh
O4 - HKCU\..\Run: [c0082240] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0082240.mat", sh
O4 - HKCU\..\Run: [c00A6900] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A6900.mat", sh
O4 - HKCU\..\Run: [c0059A4A] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0059A4A.mat", sh
O4 - HKCU\..\Run: [c0081AA0] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0081AA0.mat", sh
O4 - HKCU\..\Run: [c00CB729] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CB729.mat", sh
O4 - HKCU\..\Run: [c0034D1] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0034D1.mat", sh
O4 - HKCU\..\Run: [c00E52AA] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E52AA.mat", sh
O4 - HKCU\..\Run: [c00D14C4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D14C4.mat", sh
O4 - HKCU\..\Run: [c00D4C8E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D4C8E.mat", sh
O4 - HKCU\..\Run: [c00BEB10] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00BEB10.mat", sh
O4 - HKCU\..\Run: [c00A2690] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A2690.mat", sh
O4 - HKCU\..\Run: [c0099DD8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0099DD8.mat", sh
O4 - HKCU\..\Run: [c004772B] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c004772B.mat", sh
O4 - HKCU\..\Run: [c00EC346] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00EC346.mat", sh
O4 - HKCU\..\Run: [c005F81E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c005F81E.mat", sh
O4 - HKCU\..\Run: [c00A8BE9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A8BE9.mat", sh
O4 - HKCU\..\Run: [c003549C] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c003549C.mat", sh
O4 - HKCU\..\Run: [c00B156A] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00B156A.mat", sh
O4 - HKCU\..\Run: [c0076E64] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0076E64.mat", sh
O4 - HKCU\..\Run: [c0056690] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0056690.mat", sh
O4 - HKCU\..\Run: [c007D70] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c007D70.mat", sh
O4 - HKCU\..\Run: [c0040B99] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0040B99.mat", sh
O4 - HKCU\..\Run: [c00CA368] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CA368.mat", sh
O4 - HKCU\..\Run: [c00992C9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00992C9.mat", sh
O4 - HKCU\..\Run: [c0018157] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0018157.mat", sh
O4 - HKCU\..\Run: [c0065844] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0065844.mat", sh
O4 - HKCU\..\Run: [c009F6E4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c009F6E4.mat", sh
O4 - HKCU\..\Run: [c00E07F8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E07F8.mat", sh
O4 - HKCU\..\Run: [c00DC9C3] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00DC9C3.mat", sh
O4 - HKCU\..\Run: [c006A3F8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c006A3F8.mat", sh
O4 - HKCU\..\Run: [c00F07C9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00F07C9.mat", sh
O4 - HKCU\..\Run: [c00CB411] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CB411.mat", sh
O4 - HKCU\..\Run: [c005E0F4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c005E0F4.mat", sh
O4 - HKCU\..\Run: [c0039AA8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0039AA8.mat", sh
O4 - HKCU\..\Run: [c00C68E2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00C68E2.mat", sh
O4 - HKCU\..\Run: [c0068E3E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0068E3E.mat", sh
O4 - HKCU\..\Run: [c0028CF1] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0028CF1.mat", sh
O4 - HKCU\..\Run: [c003095E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c003095E.mat", sh
O4 - HKCU\..\Run: [c008C650] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c008C650.mat", sh
O4 - HKCU\..\Run: [c00F5900] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00F5900.mat", sh
O4 - HKCU\..\Run: [c009B621] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c009B621.mat", sh
O4 - HKCU\..\Run: [c00E4AB9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E4AB9.mat", sh
O4 - HKCU\..\Run: [c0012D87] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0012D87.mat", sh
O4 - HKCU\..\Run: [c0049B2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0049B2.mat", sh
O4 - HKCU\..\Run: [c0088490] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0088490.mat", sh
O4 - HKCU\..\Run: [c00D62D2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D62D2.mat", sh
O4 - HKCU\..\Run: [c001F6C0] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c001F6C0.mat", sh
O4 - HKCU\..\Run: [c0036694] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0036694.mat", sh
O4 - HKCU\..\Run: [c0059853] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0059853.mat", sh
O4 - HKCU\..\Run: [c008CF04] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c008CF04.mat", sh
O4 - HKCU\..\Run: [c00DA4AC] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00DA4AC.mat", sh
O4 - HKCU\..\Run: [c00237D8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00237D8.mat", sh
O4 - HKCU\..\Run: [c00CC689] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CC689.mat", sh
O4 - HKCU\..\Run: [c00281EE] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00281EE.mat", sh
O4 - HKCU\..\Run: [c00E9624] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E9624.mat", sh
O4 - HKCU\..\Run: [c001676B] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c001676B.mat", sh
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Winamp Toolbar Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.co ... nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2B218E3-51B5-434A-8775-34E10D41BD45}: NameServer = 212.25.53.252,212.27.54.252
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\Windows\system32\c00ADB6B.mat
O20 - Winlogon Notify: c0047749 - C:\Windows\SYSTEM32\c0047749.mat
O20 - Winlogon Notify: c00ADB6B - C:\Windows\SYSTEM32\c00ADB6B.mat
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: lxct_device - - C:\Windows\system32\lxctcoms.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
--
End of file - 17943 bytes
- bernard53
- Support
- Messages : 3516
- Enregistré le : 25 avr. 2008, 22:05
- Configuration matérielle : Processeur intel 2 duo CPU E6750 2.66GHz
3GO mémoire vive
disque dur samsung 160Go
Re: tres UrGent SVP ...merci D'avance
Relance HijackThis > Do a system scan only > coche ces lignes: ensuite valides sur Fix checked
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [c00148FE] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00148FE.mat", sh
O4 - HKCU\..\Run: [c0082240] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0082240.mat", sh
O4 - HKCU\..\Run: [c00A6900] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A6900.mat", sh
O4 - HKCU\..\Run: [c0059A4A] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0059A4A.mat", sh
O4 - HKCU\..\Run: [c0081AA0] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0081AA0.mat", sh
O4 - HKCU\..\Run: [c00CB729] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CB729.mat", sh
O4 - HKCU\..\Run: [c0034D1] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0034D1.mat", sh
O4 - HKCU\..\Run: [c00E52AA] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E52AA.mat", sh
O4 - HKCU\..\Run: [c00D14C4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D14C4.mat", sh
O4 - HKCU\..\Run: [c00D4C8E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D4C8E.mat", sh
O4 - HKCU\..\Run: [c00BEB10] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00BEB10.mat", sh
O4 - HKCU\..\Run: [c00A2690] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A2690.mat", sh
O4 - HKCU\..\Run: [c0099DD8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0099DD8.mat", sh
O4 - HKCU\..\Run: [c004772B] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c004772B.mat", sh
O4 - HKCU\..\Run: [c00EC346] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00EC346.mat", sh
O4 - HKCU\..\Run: [c005F81E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c005F81E.mat", sh
O4 - HKCU\..\Run: [c00A8BE9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A8BE9.mat", sh
O4 - HKCU\..\Run: [c003549C] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c003549C.mat", sh
O4 - HKCU\..\Run: [c00B156A] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00B156A.mat", sh
O4 - HKCU\..\Run: [c0076E64] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0076E64.mat", sh
O4 - HKCU\..\Run: [c0056690] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0056690.mat", sh
O4 - HKCU\..\Run: [c007D70] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c007D70.mat", sh
O4 - HKCU\..\Run: [c0040B99] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0040B99.mat", sh
O4 - HKCU\..\Run: [c00CA368] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CA368.mat", sh
O4 - HKCU\..\Run: [c00992C9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00992C9.mat", sh
O4 - HKCU\..\Run: [c0018157] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0018157.mat", sh
O4 - HKCU\..\Run: [c0065844] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0065844.mat", sh
O4 - HKCU\..\Run: [c009F6E4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c009F6E4.mat", sh
O4 - HKCU\..\Run: [c00E07F8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E07F8.mat", sh
O4 - HKCU\..\Run: [c00DC9C3] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00DC9C3.mat", sh
O4 - HKCU\..\Run: [c006A3F8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c006A3F8.mat", sh
O4 - HKCU\..\Run: [c00F07C9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00F07C9.mat", sh
O4 - HKCU\..\Run: [c00CB411] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CB411.mat", sh
O4 - HKCU\..\Run: [c005E0F4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c005E0F4.mat", sh
O4 - HKCU\..\Run: [c0039AA8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0039AA8.mat", sh
O4 - HKCU\..\Run: [c00C68E2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00C68E2.mat", sh
O4 - HKCU\..\Run: [c0068E3E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0068E3E.mat", sh
O4 - HKCU\..\Run: [c0028CF1] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0028CF1.mat", sh
O4 - HKCU\..\Run: [c003095E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c003095E.mat", sh
O4 - HKCU\..\Run: [c008C650] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c008C650.mat", sh
O4 - HKCU\..\Run: [c00F5900] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00F5900.mat", sh
O4 - HKCU\..\Run: [c009B621] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c009B621.mat", sh
O4 - HKCU\..\Run: [c00E4AB9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E4AB9.mat", sh
O4 - HKCU\..\Run: [c0012D87] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0012D87.mat", sh
O4 - HKCU\..\Run: [c0049B2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0049B2.mat", sh
O4 - HKCU\..\Run: [c0088490] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0088490.mat", sh
O4 - HKCU\..\Run: [c00D62D2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D62D2.mat", sh
O4 - HKCU\..\Run: [c001F6C0] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c001F6C0.mat", sh
O4 - HKCU\..\Run: [c0036694] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0036694.mat", sh
O4 - HKCU\..\Run: [c0059853] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0059853.mat", sh
O4 - HKCU\..\Run: [c008CF04] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c008CF04.mat", sh
O4 - HKCU\..\Run: [c00DA4AC] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00DA4AC.mat", sh
O4 - HKCU\..\Run: [c00237D8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00237D8.mat", sh
O4 - HKCU\..\Run: [c00CC689] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CC689.mat", sh
O4 - HKCU\..\Run: [c00281EE] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00281EE.mat", sh
O4 - HKCU\..\Run: [c00E9624] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E9624.mat", sh
O4 - HKCU\..\Run: [c001676B] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c001676B.mat", sh
O20 - AppInit_DLLs: C:\Windows\system32\c00ADB6B.mat
O20 - Winlogon Notify: c0047749 - C:\Windows\SYSTEM32\c0047749.mat
O20 - Winlogon Notify: c00ADB6B - C:\Windows\SYSTEM32\c00ADB6B.mat
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Ensuite:
Télécharge >>OTMoveIt3<< (de Old_Timer) sur ton Bureau.
Pour VISTA : Clic-droit et choisis "Exécuter en tant qu'administrateur".
Double-clique sur OTMoveIt3.exe pour le lancer.
Copie la liste qui se trouve en citation ci-dessous:

Clique sur
pour lancer la suppression.
attendre la fin du travail de l'outil puis fermer OTMoveIt3.
Le résultat apparaitra dans le cadre Results.
Clique sur Exit pour fermer.
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles\*******_******.log
NB: Il te sera peut-être demandé de redémarrer le pc pour achever la suppression.
si c'est le cas accepte par Oui/Yes.
ensuite puisque tu n'utilises plus norton fait ceci pour le supprimer.
Procédure pour bien supprimer Norton/Symantec
Tu télécharges cet OUTIL
Puis Démarrer Exécuter tape: services.msc
Tu double-cliques sur chaque service suivant, si présent, et tu l'arrêtes, puis dans Type de démarrage tu désactives.
-Symantec Event Manager (ccEvtMgr)
-Symantec Settings Manager (ccSetMgr)
-LiveUpdate
-LiveUpdate Notice Service
-Service Norton AntiVirus Auto-Protect
-Norton AntiVirus Firewall Monitor Service
-Norton Protection Center Service
-Planificateur LiveUpdate automatique
-Symantec AVScan
-Symantec Network Drivers Service
-SPBBCSvc
-Symantec Core LC
Puis tu lances Norton_Removal_Tools.exe
Dans : Panneau de configuration\Programmes\Programmes et fonctionnalités
Tu désinstalles Live Update
Et tu redémarres.
Il y a aussi un dossier un supprimer dans C:\Programmes\Common Files\Symantec
Ensuite mets ta version de Java a jour.
Mise à jour
Java Runtime Environment (JRE)6u10 :
Clique sur Download Java Runtime Environment (JRE) 6 update10
Dans la page suivante, choisis Windows, dans Platform coche I agree to the Java SE Runtime Environment 6 License Agreement et Continue
Dans la nouvelle page, coche Windows Offline Installation, et clique sur jre-6u10-windows-i586-p.exe //15.52 MB.
Tu l'installeras hors connexion.
Dans Démarrer, tape appwiz.cpl, puis Entrée et supprime toutes les autres versions.
un nouveau rapport HijackThis après.
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [c00148FE] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00148FE.mat", sh
O4 - HKCU\..\Run: [c0082240] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0082240.mat", sh
O4 - HKCU\..\Run: [c00A6900] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A6900.mat", sh
O4 - HKCU\..\Run: [c0059A4A] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0059A4A.mat", sh
O4 - HKCU\..\Run: [c0081AA0] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0081AA0.mat", sh
O4 - HKCU\..\Run: [c00CB729] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CB729.mat", sh
O4 - HKCU\..\Run: [c0034D1] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0034D1.mat", sh
O4 - HKCU\..\Run: [c00E52AA] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E52AA.mat", sh
O4 - HKCU\..\Run: [c00D14C4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D14C4.mat", sh
O4 - HKCU\..\Run: [c00D4C8E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D4C8E.mat", sh
O4 - HKCU\..\Run: [c00BEB10] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00BEB10.mat", sh
O4 - HKCU\..\Run: [c00A2690] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A2690.mat", sh
O4 - HKCU\..\Run: [c0099DD8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0099DD8.mat", sh
O4 - HKCU\..\Run: [c004772B] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c004772B.mat", sh
O4 - HKCU\..\Run: [c00EC346] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00EC346.mat", sh
O4 - HKCU\..\Run: [c005F81E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c005F81E.mat", sh
O4 - HKCU\..\Run: [c00A8BE9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A8BE9.mat", sh
O4 - HKCU\..\Run: [c003549C] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c003549C.mat", sh
O4 - HKCU\..\Run: [c00B156A] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00B156A.mat", sh
O4 - HKCU\..\Run: [c0076E64] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0076E64.mat", sh
O4 - HKCU\..\Run: [c0056690] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0056690.mat", sh
O4 - HKCU\..\Run: [c007D70] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c007D70.mat", sh
O4 - HKCU\..\Run: [c0040B99] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0040B99.mat", sh
O4 - HKCU\..\Run: [c00CA368] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CA368.mat", sh
O4 - HKCU\..\Run: [c00992C9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00992C9.mat", sh
O4 - HKCU\..\Run: [c0018157] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0018157.mat", sh
O4 - HKCU\..\Run: [c0065844] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0065844.mat", sh
O4 - HKCU\..\Run: [c009F6E4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c009F6E4.mat", sh
O4 - HKCU\..\Run: [c00E07F8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E07F8.mat", sh
O4 - HKCU\..\Run: [c00DC9C3] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00DC9C3.mat", sh
O4 - HKCU\..\Run: [c006A3F8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c006A3F8.mat", sh
O4 - HKCU\..\Run: [c00F07C9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00F07C9.mat", sh
O4 - HKCU\..\Run: [c00CB411] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CB411.mat", sh
O4 - HKCU\..\Run: [c005E0F4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c005E0F4.mat", sh
O4 - HKCU\..\Run: [c0039AA8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0039AA8.mat", sh
O4 - HKCU\..\Run: [c00C68E2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00C68E2.mat", sh
O4 - HKCU\..\Run: [c0068E3E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0068E3E.mat", sh
O4 - HKCU\..\Run: [c0028CF1] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0028CF1.mat", sh
O4 - HKCU\..\Run: [c003095E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c003095E.mat", sh
O4 - HKCU\..\Run: [c008C650] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c008C650.mat", sh
O4 - HKCU\..\Run: [c00F5900] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00F5900.mat", sh
O4 - HKCU\..\Run: [c009B621] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c009B621.mat", sh
O4 - HKCU\..\Run: [c00E4AB9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E4AB9.mat", sh
O4 - HKCU\..\Run: [c0012D87] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0012D87.mat", sh
O4 - HKCU\..\Run: [c0049B2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0049B2.mat", sh
O4 - HKCU\..\Run: [c0088490] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0088490.mat", sh
O4 - HKCU\..\Run: [c00D62D2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D62D2.mat", sh
O4 - HKCU\..\Run: [c001F6C0] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c001F6C0.mat", sh
O4 - HKCU\..\Run: [c0036694] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0036694.mat", sh
O4 - HKCU\..\Run: [c0059853] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0059853.mat", sh
O4 - HKCU\..\Run: [c008CF04] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c008CF04.mat", sh
O4 - HKCU\..\Run: [c00DA4AC] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00DA4AC.mat", sh
O4 - HKCU\..\Run: [c00237D8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00237D8.mat", sh
O4 - HKCU\..\Run: [c00CC689] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CC689.mat", sh
O4 - HKCU\..\Run: [c00281EE] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00281EE.mat", sh
O4 - HKCU\..\Run: [c00E9624] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E9624.mat", sh
O4 - HKCU\..\Run: [c001676B] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c001676B.mat", sh
O20 - AppInit_DLLs: C:\Windows\system32\c00ADB6B.mat
O20 - Winlogon Notify: c0047749 - C:\Windows\SYSTEM32\c0047749.mat
O20 - Winlogon Notify: c00ADB6B - C:\Windows\SYSTEM32\c00ADB6B.mat
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Ensuite:
Télécharge >>OTMoveIt3<< (de Old_Timer) sur ton Bureau.
Pour VISTA : Clic-droit et choisis "Exécuter en tant qu'administrateur".
Double-clique sur OTMoveIt3.exe pour le lancer.

Copie la liste qui se trouve en citation ci-dessous:
et colle-la dans le cadre de gauche de OTMoveIt3
:Files
C:\Windows\system32\c00ADB6B.mat
C:\Windows\SYSTEM32\c0047749.mat
C:\Windows\SYSTEM32\c00ADB6B.mat
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]


Clique sur

attendre la fin du travail de l'outil puis fermer OTMoveIt3.
Le résultat apparaitra dans le cadre Results.
Clique sur Exit pour fermer.
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles\*******_******.log
NB: Il te sera peut-être demandé de redémarrer le pc pour achever la suppression.
si c'est le cas accepte par Oui/Yes.
ensuite puisque tu n'utilises plus norton fait ceci pour le supprimer.
Procédure pour bien supprimer Norton/Symantec
Tu télécharges cet OUTIL
Puis Démarrer Exécuter tape: services.msc
Tu double-cliques sur chaque service suivant, si présent, et tu l'arrêtes, puis dans Type de démarrage tu désactives.
-Symantec Event Manager (ccEvtMgr)
-Symantec Settings Manager (ccSetMgr)
-LiveUpdate
-LiveUpdate Notice Service
-Service Norton AntiVirus Auto-Protect
-Norton AntiVirus Firewall Monitor Service
-Norton Protection Center Service
-Planificateur LiveUpdate automatique
-Symantec AVScan
-Symantec Network Drivers Service
-SPBBCSvc
-Symantec Core LC
Puis tu lances Norton_Removal_Tools.exe
Dans : Panneau de configuration\Programmes\Programmes et fonctionnalités
Tu désinstalles Live Update
Et tu redémarres.
Il y a aussi un dossier un supprimer dans C:\Programmes\Common Files\Symantec
Ensuite mets ta version de Java a jour.


Clique sur Download Java Runtime Environment (JRE) 6 update10
Dans la page suivante, choisis Windows, dans Platform coche I agree to the Java SE Runtime Environment 6 License Agreement et Continue
Dans la nouvelle page, coche Windows Offline Installation, et clique sur jre-6u10-windows-i586-p.exe //15.52 MB.
Tu l'installeras hors connexion.
Dans Démarrer, tape appwiz.cpl, puis Entrée et supprime toutes les autres versions.
un nouveau rapport HijackThis après.
Bonne visite sur: http://tuto-b.comli.com/
- nardino
- Modérateurs
- Messages : 11993
- Enregistré le : 05 févr. 2007, 17:38
- Localisation : Reims
- Contact :
Re: tres UrGent SVP ...merci D'avance
Bonjour.
Poste le rapport LopS&D.
Merci.
@+
Poste le rapport LopS&D.
Merci.
@+
-
- Novice
- Messages : 47
- Enregistré le : 23 nov. 2008, 17:10
- Configuration matérielle : urgent!!!
Re: tres UrGent SVP ...merci D'avance
pour bernard53 voici le rapport de otmovelt
Error: Unable to interpret <Files > in the current context!
Error: Unable to interpret <C:\Windows\system32\c00ADB6B.mat > in the current context!
Error: Unable to interpret <C:\Windows\SYSTEM32\c0047749.mat > in the current context!
Error: Unable to interpret <C:\Windows\SYSTEM32\c00ADB6B.mat > in the current context!
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11252008_153515
et pour nardino
ce que tu me demandes je peux le faire après la mise a jour de java?
Error: Unable to interpret <Files > in the current context!
Error: Unable to interpret <C:\Windows\system32\c00ADB6B.mat > in the current context!
Error: Unable to interpret <C:\Windows\SYSTEM32\c0047749.mat > in the current context!
Error: Unable to interpret <C:\Windows\SYSTEM32\c00ADB6B.mat > in the current context!
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11252008_153515
et pour nardino
ce que tu me demandes je peux le faire après la mise a jour de java?
- bernard53
- Support
- Messages : 3516
- Enregistré le : 25 avr. 2008, 22:05
- Configuration matérielle : Processeur intel 2 duo CPU E6750 2.66GHz
3GO mémoire vive
disque dur samsung 160Go
Re: tres UrGent SVP ...merci D'avance
Fait la demande de nardino avant ou après la mise a jour, comme tu veux.
Bonne visite sur: http://tuto-b.comli.com/
-
- Novice
- Messages : 47
- Enregistré le : 23 nov. 2008, 17:10
- Configuration matérielle : urgent!!!
Re: tres UrGent SVP ...merci D'avance
alors j'ai desactivé la liste en bleu que tu m'avais demandé par contre dans ma liste il manqué :
-Norton antivirus Firewall Monitor Service
-Norton Protection Center Service
-Symatec AVScan
-SPBBCSvc
DE + en desintallent LiveUpdate dans programmes fonctionnalités...il m'a demandé de redemarrer donc je l'ai fait et puis j'ai verifié en démarrant que dans prog.et fonction. il y été toujours présent : est-ce normal?
-Norton antivirus Firewall Monitor Service
-Norton Protection Center Service
-Symatec AVScan
-SPBBCSvc
DE + en desintallent LiveUpdate dans programmes fonctionnalités...il m'a demandé de redemarrer donc je l'ai fait et puis j'ai verifié en démarrant que dans prog.et fonction. il y été toujours présent : est-ce normal?
- bernard53
- Support
- Messages : 3516
- Enregistré le : 25 avr. 2008, 22:05
- Configuration matérielle : Processeur intel 2 duo CPU E6750 2.66GHz
3GO mémoire vive
disque dur samsung 160Go
Re: tres UrGent SVP ...merci D'avance
Possible que tous les services comme ci dessous n'y sont pas.
Pour ceci.
pas de soucis a se sujet.Norton antivirus Firewall Monitor Service
-Norton Protection Center Service
-Symatec AVScan
-SPBBCSvc
Pour ceci.
si tu cliques dessus que se passe t'il!DE + en desintallent LiveUpdate dans programmes fonctionnalités...il m'a demandé de redemarrer donc je l'ai fait et puis j'ai verifié en démarrant que dans prog.et fonction. il y été toujours présent :
Bonne visite sur: http://tuto-b.comli.com/
-
- Novice
- Messages : 47
- Enregistré le : 23 nov. 2008, 17:10
- Configuration matérielle : urgent!!!
Re: tres UrGent SVP ...merci D'avance
Là ça n 'y est plus
et Norton Internet Security(symantec corporation) y est toujours
je le supprime aussi?
et Lop S&D me prends du temps est-ce que j'annule et je fais la mise a jour de Java ou pas ?
Alala je sais je vous bombarde de question mais faut me supporter encor un tout petit peu pui tout s'arrangera

et Norton Internet Security(symantec corporation) y est toujours

et Lop S&D me prends du temps est-ce que j'annule et je fais la mise a jour de Java ou pas ?
Alala je sais je vous bombarde de question mais faut me supporter encor un tout petit peu pui tout s'arrangera

- bernard53
- Support
- Messages : 3516
- Enregistré le : 25 avr. 2008, 22:05
- Configuration matérielle : Processeur intel 2 duo CPU E6750 2.66GHz
3GO mémoire vive
disque dur samsung 160Go
Re: tres UrGent SVP ...merci D'avance
Pas des soucis, il faut mieux demander que de faire des bêtises.
Pour Norton il faut tout supprimer.
tu as télécharger la désinstallateur que je t'ai nommé.
http://service1.symantec.com/SUPPORT/IN ... 4110429924
pour Lop S&D laisse le faire son travail stp.
Pour Norton il faut tout supprimer.
tu as télécharger la désinstallateur que je t'ai nommé.
http://service1.symantec.com/SUPPORT/IN ... 4110429924
pour Lop S&D laisse le faire son travail stp.

Bonne visite sur: http://tuto-b.comli.com/
-
- Novice
- Messages : 47
- Enregistré le : 23 nov. 2008, 17:10
- Configuration matérielle : urgent!!!
Re: tres UrGent SVP ...merci D'avance
wé il mets 100ans norton int.sec. pr se désinstaller mais c pa grave et parcontre pour Lop S&D il m'affiche des fenêtres en me disant ""qu'il recherche des solutions pour mieux faire fonctionner ce programme en cours d'execution car y'a d'autres fonctionnalités que l'en empêche "" mais bon j'ai rien d'autre ouvert que Lop S&D du coup j'ai annuler la je desinstalle Norton Internet Security et je me déconnecte d'internet pour installer java et puis je t'envoie le hijackthis... C bon je fais commeca?
- bernard53
- Support
- Messages : 3516
- Enregistré le : 25 avr. 2008, 22:05
- Configuration matérielle : Processeur intel 2 duo CPU E6750 2.66GHz
3GO mémoire vive
disque dur samsung 160Go
Re: tres UrGent SVP ...merci D'avance
Ok fais comme cela.
Une chose a la fois pour ne pas perturber les autres actions.
Une chose a la fois pour ne pas perturber les autres actions.
Bonne visite sur: http://tuto-b.comli.com/
-
- Novice
- Messages : 47
- Enregistré le : 23 nov. 2008, 17:10
- Configuration matérielle : urgent!!!
Re: tres UrGent SVP ...merci D'avance
bon alors j'ai desinstaller tout Norton ... J'ai mis Java à jour hor connexion et pui j'ai supprimer les autres versions.....et là je t'ai fait le rapport Hijackthis le voici:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:59:24, on 23/11/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16757)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 5400 Series\lxctmon.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.fr.acer.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [lxctmon.exe] "C:\Program Files\Lexmark 5400 Series\lxctmon.exe"
O4 - HKLM\..\Run: [Lexmark 5400 Series Fax Server] "C:\Program Files\Lexmark 5400 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 5400 Series\ezprint.exe"
O4 - HKLM\..\Run: [LXCTCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [c00148FE] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00148FE.mat", sh
O4 - HKCU\..\Run: [c0082240] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0082240.mat", sh
O4 - HKCU\..\Run: [c00A6900] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A6900.mat", sh
O4 - HKCU\..\Run: [c0059A4A] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0059A4A.mat", sh
O4 - HKCU\..\Run: [c0081AA0] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0081AA0.mat", sh
O4 - HKCU\..\Run: [c00CB729] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CB729.mat", sh
O4 - HKCU\..\Run: [c0034D1] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0034D1.mat", sh
O4 - HKCU\..\Run: [c00E52AA] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E52AA.mat", sh
O4 - HKCU\..\Run: [c00D14C4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D14C4.mat", sh
O4 - HKCU\..\Run: [c00D4C8E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D4C8E.mat", sh
O4 - HKCU\..\Run: [c00BEB10] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00BEB10.mat", sh
O4 - HKCU\..\Run: [c00A2690] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A2690.mat", sh
O4 - HKCU\..\Run: [c0099DD8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0099DD8.mat", sh
O4 - HKCU\..\Run: [c004772B] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c004772B.mat", sh
O4 - HKCU\..\Run: [c00EC346] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00EC346.mat", sh
O4 - HKCU\..\Run: [c005F81E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c005F81E.mat", sh
O4 - HKCU\..\Run: [c00A8BE9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A8BE9.mat", sh
O4 - HKCU\..\Run: [c003549C] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c003549C.mat", sh
O4 - HKCU\..\Run: [c00B156A] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00B156A.mat", sh
O4 - HKCU\..\Run: [c0076E64] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0076E64.mat", sh
O4 - HKCU\..\Run: [c0056690] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0056690.mat", sh
O4 - HKCU\..\Run: [c007D70] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c007D70.mat", sh
O4 - HKCU\..\Run: [c0040B99] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0040B99.mat", sh
O4 - HKCU\..\Run: [c00CA368] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CA368.mat", sh
O4 - HKCU\..\Run: [c00992C9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00992C9.mat", sh
O4 - HKCU\..\Run: [c0018157] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0018157.mat", sh
O4 - HKCU\..\Run: [c0065844] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0065844.mat", sh
O4 - HKCU\..\Run: [c009F6E4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c009F6E4.mat", sh
O4 - HKCU\..\Run: [c00E07F8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E07F8.mat", sh
O4 - HKCU\..\Run: [c00DC9C3] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00DC9C3.mat", sh
O4 - HKCU\..\Run: [c006A3F8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c006A3F8.mat", sh
O4 - HKCU\..\Run: [c00F07C9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00F07C9.mat", sh
O4 - HKCU\..\Run: [c00CB411] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CB411.mat", sh
O4 - HKCU\..\Run: [c005E0F4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c005E0F4.mat", sh
O4 - HKCU\..\Run: [c0039AA8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0039AA8.mat", sh
O4 - HKCU\..\Run: [c00C68E2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00C68E2.mat", sh
O4 - HKCU\..\Run: [c0068E3E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0068E3E.mat", sh
O4 - HKCU\..\Run: [c0028CF1] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0028CF1.mat", sh
O4 - HKCU\..\Run: [c003095E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c003095E.mat", sh
O4 - HKCU\..\Run: [c008C650] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c008C650.mat", sh
O4 - HKCU\..\Run: [c00F5900] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00F5900.mat", sh
O4 - HKCU\..\Run: [c009B621] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c009B621.mat", sh
O4 - HKCU\..\Run: [c00E4AB9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E4AB9.mat", sh
O4 - HKCU\..\Run: [c0012D87] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0012D87.mat", sh
O4 - HKCU\..\Run: [c0049B2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0049B2.mat", sh
O4 - HKCU\..\Run: [c0088490] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0088490.mat", sh
O4 - HKCU\..\Run: [c00D62D2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D62D2.mat", sh
O4 - HKCU\..\Run: [c001F6C0] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c001F6C0.mat", sh
O4 - HKCU\..\Run: [c0036694] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0036694.mat", sh
O4 - HKCU\..\Run: [c0059853] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0059853.mat", sh
O4 - HKCU\..\Run: [c008CF04] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c008CF04.mat", sh
O4 - HKCU\..\Run: [c00DA4AC] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00DA4AC.mat", sh
O4 - HKCU\..\Run: [c00237D8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00237D8.mat", sh
O4 - HKCU\..\Run: [c00CC689] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CC689.mat", sh
O4 - HKCU\..\Run: [c00281EE] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00281EE.mat", sh
O4 - HKCU\..\Run: [c00E9624] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E9624.mat", sh
O4 - HKCU\..\Run: [c001676B] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c001676B.mat", sh
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Winamp Toolbar Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.co ... nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2B218E3-51B5-434A-8775-34E10D41BD45}: NameServer = 212.25.53.252,212.27.54.252
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\Windows\system32\c00ADB6B.mat
O20 - Winlogon Notify: c0047749 - C:\Windows\SYSTEM32\c0047749.mat
O20 - Winlogon Notify: c00ADB6B - C:\Windows\SYSTEM32\c00ADB6B.mat
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: lxct_device - - C:\Windows\system32\lxctcoms.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
--
End of file - 17943 bytes
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:59:24, on 23/11/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16757)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Lexmark 5400 Series\lxctmon.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Winamp Remote\bin\OrbTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.fr.acer.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "c:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\Acer\Empowering Technology\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [PCMMediaSharing] C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [lxctmon.exe] "C:\Program Files\Lexmark 5400 Series\lxctmon.exe"
O4 - HKLM\..\Run: [Lexmark 5400 Series Fax Server] "C:\Program Files\Lexmark 5400 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 5400 Series\ezprint.exe"
O4 - HKLM\..\Run: [LXCTCATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [c00148FE] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00148FE.mat", sh
O4 - HKCU\..\Run: [c0082240] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0082240.mat", sh
O4 - HKCU\..\Run: [c00A6900] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A6900.mat", sh
O4 - HKCU\..\Run: [c0059A4A] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0059A4A.mat", sh
O4 - HKCU\..\Run: [c0081AA0] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0081AA0.mat", sh
O4 - HKCU\..\Run: [c00CB729] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CB729.mat", sh
O4 - HKCU\..\Run: [c0034D1] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0034D1.mat", sh
O4 - HKCU\..\Run: [c00E52AA] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E52AA.mat", sh
O4 - HKCU\..\Run: [c00D14C4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D14C4.mat", sh
O4 - HKCU\..\Run: [c00D4C8E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D4C8E.mat", sh
O4 - HKCU\..\Run: [c00BEB10] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00BEB10.mat", sh
O4 - HKCU\..\Run: [c00A2690] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A2690.mat", sh
O4 - HKCU\..\Run: [c0099DD8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0099DD8.mat", sh
O4 - HKCU\..\Run: [c004772B] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c004772B.mat", sh
O4 - HKCU\..\Run: [c00EC346] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00EC346.mat", sh
O4 - HKCU\..\Run: [c005F81E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c005F81E.mat", sh
O4 - HKCU\..\Run: [c00A8BE9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00A8BE9.mat", sh
O4 - HKCU\..\Run: [c003549C] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c003549C.mat", sh
O4 - HKCU\..\Run: [c00B156A] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00B156A.mat", sh
O4 - HKCU\..\Run: [c0076E64] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0076E64.mat", sh
O4 - HKCU\..\Run: [c0056690] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0056690.mat", sh
O4 - HKCU\..\Run: [c007D70] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c007D70.mat", sh
O4 - HKCU\..\Run: [c0040B99] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0040B99.mat", sh
O4 - HKCU\..\Run: [c00CA368] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CA368.mat", sh
O4 - HKCU\..\Run: [c00992C9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00992C9.mat", sh
O4 - HKCU\..\Run: [c0018157] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0018157.mat", sh
O4 - HKCU\..\Run: [c0065844] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0065844.mat", sh
O4 - HKCU\..\Run: [c009F6E4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c009F6E4.mat", sh
O4 - HKCU\..\Run: [c00E07F8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E07F8.mat", sh
O4 - HKCU\..\Run: [c00DC9C3] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00DC9C3.mat", sh
O4 - HKCU\..\Run: [c006A3F8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c006A3F8.mat", sh
O4 - HKCU\..\Run: [c00F07C9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00F07C9.mat", sh
O4 - HKCU\..\Run: [c00CB411] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CB411.mat", sh
O4 - HKCU\..\Run: [c005E0F4] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c005E0F4.mat", sh
O4 - HKCU\..\Run: [c0039AA8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0039AA8.mat", sh
O4 - HKCU\..\Run: [c00C68E2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00C68E2.mat", sh
O4 - HKCU\..\Run: [c0068E3E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0068E3E.mat", sh
O4 - HKCU\..\Run: [c0028CF1] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0028CF1.mat", sh
O4 - HKCU\..\Run: [c003095E] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c003095E.mat", sh
O4 - HKCU\..\Run: [c008C650] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c008C650.mat", sh
O4 - HKCU\..\Run: [c00F5900] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00F5900.mat", sh
O4 - HKCU\..\Run: [c009B621] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c009B621.mat", sh
O4 - HKCU\..\Run: [c00E4AB9] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E4AB9.mat", sh
O4 - HKCU\..\Run: [c0012D87] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0012D87.mat", sh
O4 - HKCU\..\Run: [c0049B2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0049B2.mat", sh
O4 - HKCU\..\Run: [c0088490] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0088490.mat", sh
O4 - HKCU\..\Run: [c00D62D2] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00D62D2.mat", sh
O4 - HKCU\..\Run: [c001F6C0] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c001F6C0.mat", sh
O4 - HKCU\..\Run: [c0036694] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0036694.mat", sh
O4 - HKCU\..\Run: [c0059853] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c0059853.mat", sh
O4 - HKCU\..\Run: [c008CF04] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c008CF04.mat", sh
O4 - HKCU\..\Run: [c00DA4AC] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00DA4AC.mat", sh
O4 - HKCU\..\Run: [c00237D8] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00237D8.mat", sh
O4 - HKCU\..\Run: [c00CC689] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00CC689.mat", sh
O4 - HKCU\..\Run: [c00281EE] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00281EE.mat", sh
O4 - HKCU\..\Run: [c00E9624] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c00E9624.mat", sh
O4 - HKCU\..\Run: [c001676B] rundll32.exe "C:\Users\KOCHETSIAN\AppData\Roaming\c001676B.mat", sh
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\microsoft shared\Works Shared\WkCalRem.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Winamp Toolbar Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.co ... nos/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C2B218E3-51B5-434A-8775-34E10D41BD45}: NameServer = 212.25.53.252,212.27.54.252
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\Windows\system32\c00ADB6B.mat
O20 - Winlogon Notify: c0047749 - C:\Windows\SYSTEM32\c0047749.mat
O20 - Winlogon Notify: c00ADB6B - C:\Windows\SYSTEM32\c00ADB6B.mat
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acer HomeMedia Connect Service - CyberLink - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Validation de mot de passe Symantec IS (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: lxct_device - - C:\Windows\system32\lxctcoms.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
--
End of file - 17943 bytes
- nardino
- Modérateurs
- Messages : 11993
- Enregistré le : 05 févr. 2007, 17:38
- Localisation : Reims
- Contact :
Re: tres UrGent SVP ...merci D'avance
Bonsoir,
Tu envoies un rapport établi il y a deux jours , fais-en un nouveau..
@+

@+