gros probleme avec spyaxe - Sécurité - Windows & Software
Marsh Posté le 05-12-2005 à 15:47:48
je met mon hijackthis 
 
 
 
Logfile of HijackThis v1.99.1 
Scan saved at 15:47:03, on 05/12/2005 
Platform: Windows XP SP2 (WinNT 5.01.2600) 
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) 
 
Running processes: 
C:\WINDOWS\System32\smss.exe 
C:\WINDOWS\system32\winlogon.exe 
C:\WINDOWS\system32\services.exe 
C:\WINDOWS\system32\lsass.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\System32\svchost.exe 
C:\WINDOWS\Explorer.EXE 
C:\WINDOWS\system32\spoolsv.exe 
C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE 
C:\Program Files\AVPersonal\AVWUPSRV.EXE 
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE 
C:\WINDOWS\system32\nvsvc32.exe 
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe 
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe 
C:\WINDOWS\system32\CAP3RSK.EXE 
C:\WINDOWS\system32\wscntfy.exe 
C:\WINDOWS\system32\mssearchnet.exe 
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe 
C:\Program Files\AVPersonal\AVGNT.EXE 
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe 
C:\PROGRA~1\Wanadoo\CnxMon.exe 
C:\PROGRA~1\MESSAG~1\Demon.exe 
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe 
C:\Program Files\Wanadoo\taskbaricon.exe 
C:\Program Files\D-Tools\daemon.exe 
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe 
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3LAK.EXE 
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE 
C:\WINDOWS\system32\svchost.exe 
C:\Program Files\Wanadoo\EspaceWanadoo.exe 
C:\Program Files\Wanadoo\ComComp.exe 
C:\Program Files\Wanadoo\Watch.exe 
C:\Program Files\MSN Messenger\msnmsgr.exe 
C:\WINDOWS\system32\nvctrl.exe 
C:\Program Files\Internet Explorer\iexplore.exe 
C:\Documents and Settings\xp2600\Bureau\HijackThis.exe 
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/ 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo 
R3 - URLSearchHook: (no name) - _{1B0E7716-898E-48cc-9690-4E338E8DE1D3} - (no file) 
O2 - BHO: HomepageBHO - {3e9b951e-6f72-431b-82cf-4a9fbf2f53bc} - C:\WINDOWS\system32\hpE5FE.tmp 
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll 
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe 
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min 
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe 
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" 
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC 
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC 
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName 
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe 
O4 - HKLM\..\Run: [Demon] C:\PROGRA~1\MESSAG~1\Demon.exe 
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon 
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe 
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe 
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033 
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup 
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install 
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit 
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" 
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime 
O4 - Global Startup: Fenêtre d'état de Canon LASER SHOT LBP-1120.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3LAK.EXE 
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe 
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html 
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm 
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm 
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html 
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html 
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html 
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html 
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL 
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe 
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe 
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe 
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe 
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU) 
O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php 
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537 [...] scan53.cab 
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/ [...] loader.cab 
O17 - HKLM\System\CCS\Services\Tcpip\..\{ECD8EE4D-A422-45B7-99DF-B998F09A8214}: NameServer = 80.10.246.130 80.10.246.3 
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) 
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE 
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE 
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe 
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe 
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe 
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe 
 
Marsh Posté le 05-12-2005 à 22:46:20
Slt, 
 
D'abord, télécharge smitRem.zip sur ton bureau.  
Fais un clic droit -> extraire sur le bureau. 
 
Ensuite, télécharge CECI. 
Click droit -> extraire. 
 
Redémarre en mode sans échec. 
- Ouvre le dossier smitRem et lance RunThs.bat. 
Suis les indications et laisse-le travailler. 
- Ensuite : ouvre le dossier SpyAxeFix et lance SpyAxeFix.bat. La barre de tâches disparaîtra un moment, c'est normal. A la fin, il y a un reboot. 
 
A l'issue de ce reboot, poste : 
- un nouvel HijackThis 
- le log : C:\smitfiles.txt 
- le log spyaxe.txt créé ds le dossier SpyAxeFix. 
Marsh Posté le 06-12-2005 à 14:25:57
Je te remercie voila mon nouveau hijackthis 
 
Logfile of HijackThis v1.99.1 
Scan saved at 14:22:50, on 06/12/2005 
Platform: Windows XP SP2 (WinNT 5.01.2600) 
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) 
 
Running processes: 
C:\WINDOWS\System32\smss.exe 
C:\WINDOWS\system32\winlogon.exe 
C:\WINDOWS\system32\services.exe 
C:\WINDOWS\system32\lsass.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\System32\svchost.exe 
C:\WINDOWS\Explorer.EXE 
C:\WINDOWS\system32\spoolsv.exe 
C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE 
C:\Program Files\AVPersonal\AVWUPSRV.EXE 
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE 
C:\WINDOWS\system32\nvsvc32.exe 
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe 
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe 
C:\WINDOWS\system32\CAP3RSK.EXE 
C:\WINDOWS\system32\wscntfy.exe 
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe 
C:\Program Files\AVPersonal\AVGNT.EXE 
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe 
C:\PROGRA~1\Wanadoo\CnxMon.exe 
C:\PROGRA~1\MESSAG~1\Demon.exe 
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe 
C:\Program Files\Wanadoo\taskbaricon.exe 
C:\Program Files\D-Tools\daemon.exe 
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe 
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe 
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3LAK.EXE 
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE 
C:\WINDOWS\system32\svchost.exe 
C:\Program Files\Wanadoo\EspaceWanadoo.exe 
C:\Program Files\Wanadoo\ComComp.exe 
C:\Program Files\Wanadoo\Watch.exe 
C:\WINDOWS\system32\wuauclt.exe 
C:\Program Files\Internet Explorer\iexplore.exe 
C:\Documents and Settings\xp2600\Bureau\HijackThis.exe 
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/ 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo 
R3 - URLSearchHook: (no name) - _{1B0E7716-898E-48cc-9690-4E338E8DE1D3} - (no file) 
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll 
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe 
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min 
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe 
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" 
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC 
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC 
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName 
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe 
O4 - HKLM\..\Run: [Demon] C:\PROGRA~1\MESSAG~1\Demon.exe 
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon 
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe 
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe 
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033 
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup 
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install 
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit 
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" 
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime 
O4 - Global Startup: Fenêtre d'état de Canon LASER SHOT LBP-1120.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAP3LAK.EXE 
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe 
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html 
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm 
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm 
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html 
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html 
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html 
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html 
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL 
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe 
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe 
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe 
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe 
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU) 
O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php 
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537 [...] scan53.cab 
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/ [...] loader.cab 
O17 - HKLM\System\CCS\Services\Tcpip\..\{ECD8EE4D-A422-45B7-99DF-B998F09A8214}: NameServer = 80.10.246.130 80.10.246.3 
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) 
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE 
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE 
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe 
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe 
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe 
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe 
 
 
Le log smitfiles.txt: 
 
   smitRem © log file 
     version 2.8 
 
     by noahdfear 
 
 
Microsoft Windows XP [version 5.1.2600] 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
 
 checking for ShudderLTD key 
 
ShudderLTD key not present! 
 
 checking for PSGuard.com key 
 
 
PSGuard.com key not present! 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
 
SpyAxeFix © by noahdfear 
 
spyaxe directory present 
 
spyaxe uninstaller present 
 
Starting spyaxe uninstaller 
 
REGEDIT4 
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] 
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui" 
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant" 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
 
 Existing Pre-run Files 
 
 
 ~~~ Program Files ~~~ 
 
 
 
 ~~~ Shortcuts ~~~ 
 
 
 
 ~~~ Favorites ~~~ 
 
 
 
 ~~~ system32 folder ~~~ 
 
svchosts.dll 
1024 dir 
msvol.tlb 
ld****.tmp 
mssearchnet.exe 
ncompat.tlb 
nvctrl.exe 
mscornet.exe 
hp***.tmp 
 
 
 ~~~ Icons in System32 ~~~ 
 
ts.ico 
ot.ico 
 
 
 ~~~ Windows directory ~~~ 
 
 
 
 ~~~ Drive root ~~~ 
 
 
 ~~~ Miscellaneous Files/folders ~~~ 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
 
 
 
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org 
Killing PID 820 'explorer.exe' 
Killing PID 820 'explorer.exe' 
 
Starting registry repairs 
 
Deleting files 
 
 
   Remaining Post-run Files 
 
 
 ~~~ Program Files ~~~ 
 
 
 
 ~~~ Shortcuts ~~~ 
 
 
 
 ~~~ Favorites ~~~ 
 
 
 
 ~~~ system32 folder ~~~ 
 
 
 
 ~~~ Icons in System32 ~~~ 
 
 
 
 ~~~ Windows directory ~~~ 
 
 
 
 ~~~ Drive root ~~~ 
 
 
 
 ~~~ Miscellaneous Files/folders ~~~ 
 
 
 
 
 ~~~ Wininet.dll ~~~ 
 
 CLEAN!  
 
 
Et le log spyaxe.txt 
 
SpyAxeFix © by noahdfear 
 
 
Microsoft Windows XP [version 5.1.2600] 
 
 
 
 
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org 
Killing PID 1648 'explorer.exe' 
 
 
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03 
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org 
Error, Cannot find a process with an image name of rundll32.exe 
 
 
REGEDIT4 
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] 
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui" 
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant" 
 
 
voila je t'ai tout mis 
 
 
 
Marsh Posté le 07-12-2005 à 11:00:10
Ok. En fait, il vient juste d'intégrer la recherche de spyaxe dans smitrem. 
 
Bon, et où en est le problème de fenêtre et etc?
Marsh Posté le 08-12-2005 à 07:09:58
bin pour le moment il n'y as plus de probleme j'ai plu de fenetre qui s'affiche ni rien tout a l'air de fonctionner correctement
Marsh Posté le 20-12-2005 à 12:43:54
j'ai eu le meme probleme ; mais depuis je ne peux plus réinstaller mon imprimante ni autre news programmes 
 
merci
Marsh Posté le 05-12-2005 à 13:15:35
Bonjour,
j'ai un probleme, une petite fenetre s'ouvre et il y a ecrit dedans your computer is infected et quand j'appui dessus il m'installe spyaxe et je doit payer si quelq'un peut m'aider.
je vous en remercie beaucoup.