Hello kmisol, voici le rapport SDFix :
SDFix: Version 1.113
Run by ours on 04/11/2007 at 17:36
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Trojan Files Found:
C:\WINDOWS\system32\service.exe - Deleted
Removing Temp Files...
ADS Check:
C:\WINDOWS
No streams found.
C:\WINDOWS\system32
No streams found.
C:\WINDOWS\system32\svchost.exe
No streams found.
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
catchme 0.3.1253 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-04 18:04:02
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System]
"OODEFRAG08.00.00.01WORKSTATION"="FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E6675D575E7D6A3B9808A2D97226D213B5559DB7CE019D40AA5C3112E5D0C6C55F64CC1A994082633187D41174B5D39EA13A7821D185FC7184B37C3D84300C7A9680740A9F0DDC09CA99FB9447471D022AC8915B1AAAE70DBF5A73A729C0F6969B2715B47D3C5021DBE2A12CAC349C624FC48CE700B2FCB9A2FA3590AE93F4E91E6C19801FAAE4AEF4D398844045171A241C44D970F4D5C65F1C458EF1AB1CD890964BA873AAC84CE90F931C24BAF017FA7075145E3BB1986A7F0B8CD781A25B2BA0DC3C6E7FCC2652EB2E47FCC3B35AEF13C4CF3D46F224FE125147C481E5FEE838E11C0964E4000B7764AE72898EFB5D0FB59908C6A0779CFC4850250BE46288BFD280BC04AA2C356F19CBB0A3D2266721B5D3BCE6E5300497838F67F1C33A0D4E8D740A81DA95B24811716AA1769670379131DCBE11813AEF79BB7D7FCACE3DAE4FD6F4705739ADA9F3C0D105139FA2F87ABC6C5F16B38BC806E45DEDE47DA5DE3E58055A23A811EE5233A2C3E627EBBC89D0F7CA0C220516E9EA836FA2351491E203C5BCE7098C279B9396485328FC90389E8A77AB3AF803C506EDA5B77B1C2EAA2F4708F292969525026F6FDEB1CAB3E3ACB752D580FD6A24BD1FAAFB67164D638C1C22B593653329F2F10C33E28E1BCFD193B88D8CEDDF6D719D09EB251BBE441E5DE1436D75AAC4AC67E41E75C46F223DB7FDF789E6A9F2D073C1A6760B06E33A2616569507DBF84C9AB213B2AF8D656D446A62B64ABE676431C871AD89573E0B957F4B151FD9AB415E242577D48508B75837B967BFCEE283E78532B5FD9E35905054A108846C27CF855B8FB77B9CDC441A141102303A60DDAE547688137A0D9C7C3B80A0440E168E6A6E31F8B1491912B3252182CA97BEF39F85EC37B73D6DD6C6D2AFA42E700CE9E7660BD5493AD76F5300C278812F429CDADCEAE420ECE23ADE2C1C6D5675FE2160C242FC5750988229AFF507897F9101011267CCC144DD94784BD6E794B446C8B7F4222FB31D3B446BB35D65DDB8B81E3B527D38583233884AA9941506FAA0C8D56218C3FC6C0901D400BFDD3C42A6C6323CEE88E3599A0D11342E890B46AEDC28E5B42594B9AAD921F908D0A7B4AEA014649E32A71031ED8CCC21EF46CAF613204DB0D11E34AD42147E45B1E45E09A595D394BD29DF764900478D05207062D0305AE35B82C18604F1D92A877F3ECF23EB047C473509CF12B26E381AC5513E4E54C24CE7F07A0B3C04528E6D458D84BA5367A67EDA7D060E707C0C1427BFBB1606B18C3259ABF4DB191CEB9247B28863086186A7EB63C3D889A4136D783C6F09C6C4EA89F0D46327036461BA5C4D2465CE4A349B00151B61D08C0032B000"
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\InstantTouch\\bin\\CmCenterV2.exe"="C:\\Program Files\\InstantTouch\\bin\\CmCenterV2.exe:*:Enabled:CmCenter Module"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\AIM95\\aim.exe"="C:\\Program Files\\AIM95\\aim.exe:*:Disabled:AOL Instant Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
Remaining Files:
---------------
File Backups: - C:\SDFix\backups\backups.zip
Files with Hidden Attributes:
Thu 21 Aug 2003 4,348 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\DRMv1.bak"
Sat 13 Sep 2003 401 ..SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\DRMv14.bak"
Sat 3 Mar 2007 0 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\Cache\Indiv02.tmp"
Sun 21 Oct 2007 68 A..H. --- "C:\Documents and Settings\ours\Local Settings\Temp\Free Download Manager\tic1.tmp"
--- 73,770 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImAnim.dll"
--- 127,017 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImApp.exe"
--- 307,242 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImBook.dll"
--- 41,004 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImBrowse.dll"
--- 65,580 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImComUtl.dll"
--- 389,162 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImFeat.dll"
--- 225,324 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImFoldrs.dll"
--- 77,866 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImHook.dll"
--- 262,187 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImImprt.dll"
--- 274,474 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImLook.dll"
--- 94,252 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImLookEx.dll"
--- 389,163 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImMangr.dll"
--- 32,810 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImMapi.dll"
--- 77,870 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImNotfy.dll"
--- 188,462 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImNotfy.exe"
--- 90,155 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImPackr.exe"
--- 245,804 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImParser.dll"
--- 65,578 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImpCnt.exe"
--- 143,402 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImServ.dll"
--- 53,291 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\imsetup.exe"
Wed 28 May 2003 57,344 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\IMShExt.dll"
--- 323,627 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImSpool.dll"
--- 446,506 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImSupp.dll"
--- 69,675 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImTools.dll"
--- 466,987 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImUtils.dll"
--- 802,858 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\ImView.dll"
--- 167,979 A..HR --- "C:\Documents and Settings\FRANCIS\Local Settings\Temp\IncrediMail\IMInstall\binaries\IncMail.exe"
Finished!
Et le nouveau rapport HijachThis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:54:50, on 04/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\PROGRA~1\FREEDO~1\fdm.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.noos.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.01net.com/telecharger/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.01net.com/telecharger/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.5] "C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe" /nosplash
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [SRUUninstall] "C:\WINDOWS\System32\msiexec.exe" /x {6AF90EF6-F7F9-466C-99F4-1774826FBB40} /qn REBOOT=ReallySuppress (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [SRUUninstall] "C:\WINDOWS\System32\msiexec.exe" /x {6AF90EF6-F7F9-466C-99F4-1774826FBB40} /qn REBOOT=ReallySuppress (User 'Default user')
O4 - Global Startup: Barre d'état système d'ATI CATALYST.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZNxmk142CFFR
O8 - Extra context menu item: &Windows Live Search -
res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: Download all with Free Download Manager -
file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager -
file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager -
file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager -
file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Voir les cookies - C:\WINDOWS\web\cookies.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} (ITPPDiagIE Class) -
http://data.jeuxclassiques.com/npwwg.cab
O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} -
http://akamai.downloadv3.com/binaries/IA/dtc32_FR_XP.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) -
http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -
http://software-dl.real.com/13dc1c6cd50061001519/netzip/RdxIE601_fr.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} -
http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
http://noos.metaboli.fr/components/Metaboli.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb(...)
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housec(...)
O16 - DPF: {7DBFDA8E-D33B-11D4-9269-00600868E56E} -
http://go.securelive.com/speed/WebInstall.dll
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) -
http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} -
http://62.39.141.133/tools/FlipsideWebLauncherControl.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) -
https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
O16 - DPF: {ABB08127-7417-11D4-8566-00500448008D} (Chat Class) -
http://downloads.winwise.fr/Common/npchatlax.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {BD4C7EDB-A392-11D9-8BFB-0040953018D7} (PhaseCaster Widget) -
http://www.streamerp2p.com/sfiles/phasex.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697519} (NsvPlayX Control) -
http://www.nullsoft.com/nsv/embed/nsvplayx_vp6_aac.cab
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) -
http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://bin.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4376/mcfsc(...)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Evaluation Service - Evalution Customer - C:\Program Files\Fichiers communs\Evalution Customer Shared\Service\Evaluation Service FileName.exe
O23 - Service: OneCare Firewall (msfwsvc) - Unknown owner - C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe (file missing)
O23 - Service: OneCare AntiSpyware and AntiVirus (OneCareMP) - Unknown owner - C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe (file missing)
O23 - Service: Windows Live OneCare (winss) - Unknown owner - C:\Program Files\Microsoft Windows OneCare Live\winss.exe (file missing)
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
--
End of file - 11957 bytes
A noter qu'après le 1er rapport je ne pouvais plus me connecter à Internet; j'ai dû faire un nouveau redémarrage pour enfin obtenir l'accès.