Bon, j'ai fait un scan avec Hijackthis et voilà le
résultat:
Logfile of HijackThis v1.98.2
Scan saved at 19:14:59, on 23/08/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSYSTEMKERNEL32.DLL
C:WINDOWSSYSTEMMSGSRV32.EXE
C:WINDOWSSYSTEMSPOOL32.EXE
C:WINDOWSSYSTEMMPREXE.EXE
C:WINDOWSSYSTEMMSTASK.EXE
C:WINDOWSSYSTEMSSDPSRV.EXE
C:PROGRAM FILESFICHIERS COMMUNSWINTOOLSWTOOLSA.EXE
C:WINDOWSSYSTEMLEXBCES.EXE
C:WINDOWSSYSTEMRPCSS.EXE
C:WINDOWSSYSTEMLEXPPS.EXE
C:WINDOWSSYSTEMRESTORESTMGR.EXE
C:PROGRAM FILESFICHIERS COMMUNSWINTOOLSWSUP.EXE
C:WINDOWSSYSTEMmmtask.tsk
C:WINDOWSEXPLORER.EXE
C:WINDOWSRUNDLL32.EXE
C:WINDOWSTASKMON.EXE
C:WINDOWSSYSTEMSYSTRAY.EXE
C:WINDOWSSYSTEMATI2EVXX.EXE
C:WINDOWSSYSTEMATIPTAXX.EXE
C:WINDOWSSYSTEMATI2CWXX.EXE
C:PROGRAM FILESEZBUTTONCP51NBTN.EXE
C:PROGRAM FILESMYWAYBAR4.BINMWSOEMON.EXE
C:WINDOWSSYSTEMLXSUPMON.EXE
C:PROGRAM FILESWINAMPWINAMPA.EXE
C:PROGRAM FILESFICHIERS
COMMUNSREALUPDATE_OBREALSCHED.EXE
C:PROGRAM FILESOUTLASTERSHHOST.EXE
C:WINDOWSRUNDLL32.EXE
C:PROGRAM FILESSAGEMSAGEM 800-908DSLMON.EXE
C:PROGRAM FILESFICHIERS COMMUNSMICROSOFT SHAREDWORKS
SHAREDWKCALREM.EXE
C:PROGRAM FILESFICHIERS
COMMUNSREALUPDATE_OBRNATHCHK.EXE
C:WINDOWSSYSTEMWMIEXE.EXE
C:PROGRAM FILESEZBUTTONCPHKCNT.EXE
C:WINDOWSSYSTEMINTERNAT.EXE
C:WINDOWSSYSTEMPSTORES.EXE
C:PROGRAM FILESWINRARWINRAR.EXE
C:WINDOWSBUREAUHIJACKTHIS.EXE
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start
Page = http://home.free.fr/
R0 - HKCUSoftwareMicrosoftInternet
ExplorerToolbar,LinksFolderName = Liens
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: (no name) - {87766247-311C-43B4-8499-
3D5FEC94A183} - C:PROGRA~1FICHIE~1WINTOOLSWTOOLSB.DLL
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-
14154ECE70AC} - C:PROGRAM
FILESMYWAYMYBAR2.BINMYBAR.DLL
O3 - Toolbar: (no name) - {0CFF8334-022B-4DAB-943E-
62A08857EB7D} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - C:WINDOWSSYSTEMMSDXM.OCX
O4 - HKLM..Run: [ScanRegistry]
C:WINDOWSscanregw.exe /autorun
O4 - HKLM..Run: [TaskMonitor] C:WINDOWStaskmon.exe
O4 - HKLM..Run: [PCHealth]
C:WINDOWSPCHealthSupportPCHSchd.exe -s
O4 - HKLM..Run: [SystemTray] SysTray.Exe
O4 - HKLM..Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..Run: [ATIPOLAB] ati2evxx.exe
O4 - HKLM..Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM..Run: [Ati2cwxx] Ati2cwxx.exe
O4 - HKLM..Run: [CP51NBtn] C:PROGRA~1
EZBUTTONCP51NBtn.EXE
O4 - HKLM..Run: [autoclk] autoclk.exe
O4 - HKLM..Run: [MyWebSearch Email Plugin] C:PROGRA~1
MYWAYBAR4.BINMWSOEMON.EXE
O4 - HKLM..Run: [LexStart] Lexstart.exe
O4 - HKLM..Run: [LXSUPMON]
C:WINDOWSSYSTEMLXSUPMON.EXE RUN
O4 - HKLM..Run: [WinampAgent] C:Program
FilesWinampwinampa.exe
O4 - HKLM..Run: [TkBellExe] "C:Program FilesFichiers
communsRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [ALCHEM] C:WINDOWSALCHEM.exe
O4 - HKLM..Run: [shhost] C:PROGRAM
FILESOUTLASTERSHHOST.exe
O4 - HKLM..Run: [webHancer Survey Companion] "C:Program
FileswebHancerProgramswhSurvey.exe"
O4 - HKLM..Run: [Miniphone] C:WINDOWSglophone.exe /w
O4 - HKLM..Run: [New.net Startup] rundll32 C:PROGRA~1
NEWDOT~1NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM..Run: [WinTools] C:Program FilesFichiers
communsWinToolsWToolsA.exe
O4 - HKLM..RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM..RunServices: [SSDPSRV]
C:WINDOWSSYSTEMssdpsrv.exe
O4 - HKLM..RunServices: [*StateMgr]
C:WINDOWSSystemRestoreStateMgr.exe
O4 - HKLM..RunServices: [WinTools] C:Program
FilesFichiers communsWinToolsWToolsA.exe
O4 - HKLM..RunServicesOnce: [WinTools] C:PROGRA~1
FICHIE~1WINTOOLSWTOOLSA.EXE /boot
O4 - HKCU..Run: [MoneyAgent] "C:Program FilesMicrosoft
MoneySystemMoney Express.exe"
O4 - HKCU..Run: [System Update]
C:WINDOWSSystemwebcheck.exe
O4 - HKCU..Run: [MyWebSearch Email Plugin] C:PROGRA~1
MYWAYBAR4.BINMWSOEMON.EXE
O4 - Startup: DSLMON.lnk = C:Program FilesSAGEMSAGEM
800-908dslmon.exe
O4 - Startup: Rappels du Calendrier Microsoft Works.lnk > C:Program FilesFichiers communsMicrosoft SharedWorks
Sharedwkcalrem.exe
O4 - Startup: Microsoft Office.lnk = C:Program
FilesMicrosoft OfficeOfficeOSA9.EXE
O4 - Startup: MyWebSearch Email Plugin.lnk = C:Program
FilesMyWaybar4.binMWSOEMON.EXE
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZSihp004
O8 - Extra context menu item: Web Savings -
file://C:Program
FilesWebSavingsfromEbatesSystemTempebateswebsavings_scr
ipt0.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-
00aa003c157a} - C:WINDOWSwebrelated.htm
O9 - Extra 'Tools' menuitem: Show &Related Links -
{c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:WINDOWSwebrelated.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:PROGRA~1MESSEN~1MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:PROGRA~1
MESSEN~1MSMSGS.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} - C:WINDOWSSYSTEMMSJAVA.DLL
O9 - Extra 'Tools' menuitem: Console Java (Sun) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:WINDOWSSYSTEMMSJAVA.DLL
O9 - Extra button: Voiceglo directory - {C9B8ABB6-1CC3-
4957-9CA3-053036B2EE3A} - C:WINDOWSAll
UsersBureauGlophone.lnk (file missing)
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache/funwebproducts/ei/PopS
watterInitialSetup1.0.0.8.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN
File Upload Control) -
http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE
Class) - http://software-
dl.real.com/10497be59b7623c58915/netzip/RdxIE601_fr.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1}
(ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo!
Audio Conferencing) -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacs
com.cab
O16 - DPF: Yahoo! Chat -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/cha
t.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN
Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61}
(HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.tre
ndmicro.com/housecall/xscan53.cab
Bon, j'ai fait un scan avec Hijackthis et voilà le
résultat:
Logfile of HijackThis v1.98.2
Scan saved at 19:14:59, on 23/08/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSYSTEMKERNEL32.DLL
C:WINDOWSSYSTEMMSGSRV32.EXE
C:WINDOWSSYSTEMSPOOL32.EXE
C:WINDOWSSYSTEMMPREXE.EXE
C:WINDOWSSYSTEMMSTASK.EXE
C:WINDOWSSYSTEMSSDPSRV.EXE
C:PROGRAM FILESFICHIERS COMMUNSWINTOOLSWTOOLSA.EXE
C:WINDOWSSYSTEMLEXBCES.EXE
C:WINDOWSSYSTEMRPCSS.EXE
C:WINDOWSSYSTEMLEXPPS.EXE
C:WINDOWSSYSTEMRESTORESTMGR.EXE
C:PROGRAM FILESFICHIERS COMMUNSWINTOOLSWSUP.EXE
C:WINDOWSSYSTEMmmtask.tsk
C:WINDOWSEXPLORER.EXE
C:WINDOWSRUNDLL32.EXE
C:WINDOWSTASKMON.EXE
C:WINDOWSSYSTEMSYSTRAY.EXE
C:WINDOWSSYSTEMATI2EVXX.EXE
C:WINDOWSSYSTEMATIPTAXX.EXE
C:WINDOWSSYSTEMATI2CWXX.EXE
C:PROGRAM FILESEZBUTTONCP51NBTN.EXE
C:PROGRAM FILESMYWAYBAR4.BINMWSOEMON.EXE
C:WINDOWSSYSTEMLXSUPMON.EXE
C:PROGRAM FILESWINAMPWINAMPA.EXE
C:PROGRAM FILESFICHIERS
COMMUNSREALUPDATE_OBREALSCHED.EXE
C:PROGRAM FILESOUTLASTERSHHOST.EXE
C:WINDOWSRUNDLL32.EXE
C:PROGRAM FILESSAGEMSAGEM F@ST 800-908DSLMON.EXE
C:PROGRAM FILESFICHIERS COMMUNSMICROSOFT SHAREDWORKS
SHAREDWKCALREM.EXE
C:PROGRAM FILESFICHIERS
COMMUNSREALUPDATE_OBRNATHCHK.EXE
C:WINDOWSSYSTEMWMIEXE.EXE
C:PROGRAM FILESEZBUTTONCPHKCNT.EXE
C:WINDOWSSYSTEMINTERNAT.EXE
C:WINDOWSSYSTEMPSTORES.EXE
C:PROGRAM FILESWINRARWINRAR.EXE
C:WINDOWSBUREAUHIJACKTHIS.EXE
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start
Page = http://home.free.fr/
R0 - HKCUSoftwareMicrosoftInternet
ExplorerToolbar,LinksFolderName = Liens
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: (no name) - {87766247-311C-43B4-8499-
3D5FEC94A183} - C:PROGRA~1FICHIE~1WINTOOLSWTOOLSB.DLL
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-
14154ECE70AC} - C:PROGRAM
FILESMYWAYMYBAR2.BINMYBAR.DLL
O3 - Toolbar: (no name) - {0CFF8334-022B-4DAB-943E-
62A08857EB7D} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - C:WINDOWSSYSTEMMSDXM.OCX
O4 - HKLM..Run: [ScanRegistry]
C:WINDOWSscanregw.exe /autorun
O4 - HKLM..Run: [TaskMonitor] C:WINDOWStaskmon.exe
O4 - HKLM..Run: [PCHealth]
C:WINDOWSPCHealthSupportPCHSchd.exe -s
O4 - HKLM..Run: [SystemTray] SysTray.Exe
O4 - HKLM..Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..Run: [ATIPOLAB] ati2evxx.exe
O4 - HKLM..Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM..Run: [Ati2cwxx] Ati2cwxx.exe
O4 - HKLM..Run: [CP51NBtn] C:PROGRA~1
EZBUTTONCP51NBtn.EXE
O4 - HKLM..Run: [autoclk] autoclk.exe
O4 - HKLM..Run: [MyWebSearch Email Plugin] C:PROGRA~1
MYWAYBAR4.BINMWSOEMON.EXE
O4 - HKLM..Run: [LexStart] Lexstart.exe
O4 - HKLM..Run: [LXSUPMON]
C:WINDOWSSYSTEMLXSUPMON.EXE RUN
O4 - HKLM..Run: [WinampAgent] C:Program
FilesWinampwinampa.exe
O4 - HKLM..Run: [TkBellExe] "C:Program FilesFichiers
communsRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [ALCHEM] C:WINDOWSALCHEM.exe
O4 - HKLM..Run: [shhost] C:PROGRAM
FILESOUTLASTERSHHOST.exe
O4 - HKLM..Run: [webHancer Survey Companion] "C:Program
FileswebHancerProgramswhSurvey.exe"
O4 - HKLM..Run: [Miniphone] C:WINDOWSglophone.exe /w
O4 - HKLM..Run: [New.net Startup] rundll32 C:PROGRA~1
NEWDOT~1NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM..Run: [WinTools] C:Program FilesFichiers
communsWinToolsWToolsA.exe
O4 - HKLM..RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM..RunServices: [SSDPSRV]
C:WINDOWSSYSTEMssdpsrv.exe
O4 - HKLM..RunServices: [*StateMgr]
C:WINDOWSSystemRestoreStateMgr.exe
O4 - HKLM..RunServices: [WinTools] C:Program
FilesFichiers communsWinToolsWToolsA.exe
O4 - HKLM..RunServicesOnce: [WinTools] C:PROGRA~1
FICHIE~1WINTOOLSWTOOLSA.EXE /boot
O4 - HKCU..Run: [MoneyAgent] "C:Program FilesMicrosoft
MoneySystemMoney Express.exe"
O4 - HKCU..Run: [System Update]
C:WINDOWSSystemwebcheck.exe
O4 - HKCU..Run: [MyWebSearch Email Plugin] C:PROGRA~1
MYWAYBAR4.BINMWSOEMON.EXE
O4 - Startup: DSLMON.lnk = C:Program FilesSAGEMSAGEM
F@st 800-908dslmon.exe
O4 - Startup: Rappels du Calendrier Microsoft Works.lnk > C:Program FilesFichiers communsMicrosoft SharedWorks
Sharedwkcalrem.exe
O4 - Startup: Microsoft Office.lnk = C:Program
FilesMicrosoft OfficeOfficeOSA9.EXE
O4 - Startup: MyWebSearch Email Plugin.lnk = C:Program
FilesMyWaybar4.binMWSOEMON.EXE
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZSihp004
O8 - Extra context menu item: Web Savings -
file://C:Program
FilesWebSavingsfromEbatesSystemTempebateswebsavings_scr
ipt0.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-
00aa003c157a} - C:WINDOWSwebrelated.htm
O9 - Extra 'Tools' menuitem: Show &Related Links -
{c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:WINDOWSwebrelated.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:PROGRA~1MESSEN~1MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:PROGRA~1
MESSEN~1MSMSGS.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} - C:WINDOWSSYSTEMMSJAVA.DLL
O9 - Extra 'Tools' menuitem: Console Java (Sun) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:WINDOWSSYSTEMMSJAVA.DLL
O9 - Extra button: Voiceglo directory - {C9B8ABB6-1CC3-
4957-9CA3-053036B2EE3A} - C:WINDOWSAll
UsersBureauGlophone.lnk (file missing)
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache/funwebproducts/ei/PopS
watterInitialSetup1.0.0.8.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN
File Upload Control) -
http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE
Class) - http://software-
dl.real.com/10497be59b7623c58915/netzip/RdxIE601_fr.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1}
(ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo!
Audio Conferencing) -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacs
com.cab
O16 - DPF: Yahoo! Chat -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/cha
t.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN
Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61}
(HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.tre
ndmicro.com/housecall/xscan53.cab
Bon, j'ai fait un scan avec Hijackthis et voilà le
résultat:
Logfile of HijackThis v1.98.2
Scan saved at 19:14:59, on 23/08/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSYSTEMKERNEL32.DLL
C:WINDOWSSYSTEMMSGSRV32.EXE
C:WINDOWSSYSTEMSPOOL32.EXE
C:WINDOWSSYSTEMMPREXE.EXE
C:WINDOWSSYSTEMMSTASK.EXE
C:WINDOWSSYSTEMSSDPSRV.EXE
C:PROGRAM FILESFICHIERS COMMUNSWINTOOLSWTOOLSA.EXE
C:WINDOWSSYSTEMLEXBCES.EXE
C:WINDOWSSYSTEMRPCSS.EXE
C:WINDOWSSYSTEMLEXPPS.EXE
C:WINDOWSSYSTEMRESTORESTMGR.EXE
C:PROGRAM FILESFICHIERS COMMUNSWINTOOLSWSUP.EXE
C:WINDOWSSYSTEMmmtask.tsk
C:WINDOWSEXPLORER.EXE
C:WINDOWSRUNDLL32.EXE
C:WINDOWSTASKMON.EXE
C:WINDOWSSYSTEMSYSTRAY.EXE
C:WINDOWSSYSTEMATI2EVXX.EXE
C:WINDOWSSYSTEMATIPTAXX.EXE
C:WINDOWSSYSTEMATI2CWXX.EXE
C:PROGRAM FILESEZBUTTONCP51NBTN.EXE
C:PROGRAM FILESMYWAYBAR4.BINMWSOEMON.EXE
C:WINDOWSSYSTEMLXSUPMON.EXE
C:PROGRAM FILESWINAMPWINAMPA.EXE
C:PROGRAM FILESFICHIERS
COMMUNSREALUPDATE_OBREALSCHED.EXE
C:PROGRAM FILESOUTLASTERSHHOST.EXE
C:WINDOWSRUNDLL32.EXE
C:PROGRAM FILESSAGEMSAGEM 800-908DSLMON.EXE
C:PROGRAM FILESFICHIERS COMMUNSMICROSOFT SHAREDWORKS
SHAREDWKCALREM.EXE
C:PROGRAM FILESFICHIERS
COMMUNSREALUPDATE_OBRNATHCHK.EXE
C:WINDOWSSYSTEMWMIEXE.EXE
C:PROGRAM FILESEZBUTTONCPHKCNT.EXE
C:WINDOWSSYSTEMINTERNAT.EXE
C:WINDOWSSYSTEMPSTORES.EXE
C:PROGRAM FILESWINRARWINRAR.EXE
C:WINDOWSBUREAUHIJACKTHIS.EXE
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start
Page = http://home.free.fr/
R0 - HKCUSoftwareMicrosoftInternet
ExplorerToolbar,LinksFolderName = Liens
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: (no name) - {87766247-311C-43B4-8499-
3D5FEC94A183} - C:PROGRA~1FICHIE~1WINTOOLSWTOOLSB.DLL
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-
14154ECE70AC} - C:PROGRAM
FILESMYWAYMYBAR2.BINMYBAR.DLL
O3 - Toolbar: (no name) - {0CFF8334-022B-4DAB-943E-
62A08857EB7D} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-
00A0C9082467} - C:WINDOWSSYSTEMMSDXM.OCX
O4 - HKLM..Run: [ScanRegistry]
C:WINDOWSscanregw.exe /autorun
O4 - HKLM..Run: [TaskMonitor] C:WINDOWStaskmon.exe
O4 - HKLM..Run: [PCHealth]
C:WINDOWSPCHealthSupportPCHSchd.exe -s
O4 - HKLM..Run: [SystemTray] SysTray.Exe
O4 - HKLM..Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..Run: [ATIPOLAB] ati2evxx.exe
O4 - HKLM..Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM..Run: [Ati2cwxx] Ati2cwxx.exe
O4 - HKLM..Run: [CP51NBtn] C:PROGRA~1
EZBUTTONCP51NBtn.EXE
O4 - HKLM..Run: [autoclk] autoclk.exe
O4 - HKLM..Run: [MyWebSearch Email Plugin] C:PROGRA~1
MYWAYBAR4.BINMWSOEMON.EXE
O4 - HKLM..Run: [LexStart] Lexstart.exe
O4 - HKLM..Run: [LXSUPMON]
C:WINDOWSSYSTEMLXSUPMON.EXE RUN
O4 - HKLM..Run: [WinampAgent] C:Program
FilesWinampwinampa.exe
O4 - HKLM..Run: [TkBellExe] "C:Program FilesFichiers
communsRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [ALCHEM] C:WINDOWSALCHEM.exe
O4 - HKLM..Run: [shhost] C:PROGRAM
FILESOUTLASTERSHHOST.exe
O4 - HKLM..Run: [webHancer Survey Companion] "C:Program
FileswebHancerProgramswhSurvey.exe"
O4 - HKLM..Run: [Miniphone] C:WINDOWSglophone.exe /w
O4 - HKLM..Run: [New.net Startup] rundll32 C:PROGRA~1
NEWDOT~1NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM..Run: [WinTools] C:Program FilesFichiers
communsWinToolsWToolsA.exe
O4 - HKLM..RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM..RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM..RunServices: [SSDPSRV]
C:WINDOWSSYSTEMssdpsrv.exe
O4 - HKLM..RunServices: [*StateMgr]
C:WINDOWSSystemRestoreStateMgr.exe
O4 - HKLM..RunServices: [WinTools] C:Program
FilesFichiers communsWinToolsWToolsA.exe
O4 - HKLM..RunServicesOnce: [WinTools] C:PROGRA~1
FICHIE~1WINTOOLSWTOOLSA.EXE /boot
O4 - HKCU..Run: [MoneyAgent] "C:Program FilesMicrosoft
MoneySystemMoney Express.exe"
O4 - HKCU..Run: [System Update]
C:WINDOWSSystemwebcheck.exe
O4 - HKCU..Run: [MyWebSearch Email Plugin] C:PROGRA~1
MYWAYBAR4.BINMWSOEMON.EXE
O4 - Startup: DSLMON.lnk = C:Program FilesSAGEMSAGEM
800-908dslmon.exe
O4 - Startup: Rappels du Calendrier Microsoft Works.lnk > C:Program FilesFichiers communsMicrosoft SharedWorks
Sharedwkcalrem.exe
O4 - Startup: Microsoft Office.lnk = C:Program
FilesMicrosoft OfficeOfficeOSA9.EXE
O4 - Startup: MyWebSearch Email Plugin.lnk = C:Program
FilesMyWaybar4.binMWSOEMON.EXE
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearch.html?p=ZSihp004
O8 - Extra context menu item: Web Savings -
file://C:Program
FilesWebSavingsfromEbatesSystemTempebateswebsavings_scr
ipt0.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-
00aa003c157a} - C:WINDOWSwebrelated.htm
O9 - Extra 'Tools' menuitem: Show &Related Links -
{c95fe080-8f5d-11d2-a20b-00aa003c157a} -
C:WINDOWSwebrelated.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:PROGRA~1MESSEN~1MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:PROGRA~1
MESSEN~1MSMSGS.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} - C:WINDOWSSYSTEMMSJAVA.DLL
O9 - Extra 'Tools' menuitem: Console Java (Sun) -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:WINDOWSSYSTEMMSJAVA.DLL
O9 - Extra button: Voiceglo directory - {C9B8ABB6-1CC3-
4957-9CA3-053036B2EE3A} - C:WINDOWSAll
UsersBureauGlophone.lnk (file missing)
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O10 - Unknown file in Winsock LSP:
c:windowssystemlspak.dll
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache/funwebproducts/ei/PopS
watterInitialSetup1.0.0.8.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN
File Upload Control) -
http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE
Class) - http://software-
dl.real.com/10497be59b7623c58915/netzip/RdxIE601_fr.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1}
(ActiveScan Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo!
Audio Conferencing) -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacs
com.cab
O16 - DPF: Yahoo! Chat -
http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/cha
t.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN
Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61}
(HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.tre
ndmicro.com/housecall/xscan53.cab