Hi Armodeluxe,
Thank you for your time and your help.
I ran the Hoster program according to your instructions, and then the Kaspersky Online Scanner.
Here is the Kaspersky result:
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Saturday, December 10, 2005 12:03:41
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 10/12/2005
Kaspersky Anti-Virus database records: 164254
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 46038
Number of viruses found: 4
Number of infected objects: 121
Number of suspicious objects: 0
Duration of the scan process: 3508 sec
Infected Object Name - Virus Name
C:\Documents and Settings\NP\Local Settings\Temp\10.tmp Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\11.tmp Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\12.tmp Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\14.tmp Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\16.tmp Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\18.tmp Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\1A.tmp Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\1E.tmp Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\3.tmp Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\8.tmp Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\9.tmp Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\A.tmp Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\D.tmp Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\~1.tmp.exe Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\~13.tmp.exe Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\~15.tmp.exe Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\~17.tmp.exe Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\~19.tmp.exe Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\~1D.tmp.exe Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\~4.tmp.exe Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\~6.tmp.exe Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\~7.tmp.exe Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\~B.tmp.exe Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\~C.tmp.exe Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\~E.tmp.exe Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Local Settings\Temp\~F.tmp.exe Infected: Net-Worm.Win32.Bobic.ac
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051125-183720-597 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051125-190843-830 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051125-195415-400 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051126-152842-548 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051126-162536-877 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051126-163226-513 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051126-211448-703 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051126-212721-755 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051126-235931-426 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051127-142741-817 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051127-191340-948 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051128-080752-156 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051128-144242-621 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051128-190940-132 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051129-092706-856 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051129-101721-873 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051129-110806-722 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051129-191444-853 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051130-111743-409 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051201-002224-614 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051201-085506-754 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051201-115325-563 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051201-133026-158 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051201-150055-633 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051201-165852-729 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051201-185531-379 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051202-084919-245 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051202-092719-122 Infected: Trojan.Win32.Qhost
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\backups\backup-20051202-134958-586 Infected: Trojan.Win32.Qhost
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0000022.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0001003.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0001010.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0001011.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0002007.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0003008.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0003015.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0003016.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0003018.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0003019.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0003020.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0005004.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0005006.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0006005.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0006006.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0006007.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0006008.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0006084.exe Infected: Trojan-Proxy.Win32.Agent.ib
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0007006.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP1\A0007007.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0008005.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0008006.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0009005.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0009006.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0010005.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0010006.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0010009.exe Infected: Trojan-Proxy.Win32.Agent.ib
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0010018.exe Infected: Trojan-Proxy.Win32.Agent.ib
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0011006.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0011009.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0012005.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0012006.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0013005.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0013006.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0013051.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP2\A0013072.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP5\A0015169.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP5\A0015179.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP5\A0015189.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP5\A0016227.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP6\A0017260.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP6\A0017261.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP6\A0017264.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP6\A0018242.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP6\A0018243.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP7\A0018265.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP7\A0018266.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP7\A0018267.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP7\A0018279.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP7\A0018288.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP7\A0018289.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP7\A0018291.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP7\A0018295.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP7\A0018296.exe Infected: Net-Worm.Win32.Bobic.ac
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP8\A0018306.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP8\A0018307.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP8\A0018308.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP8\A0018309.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP8\A0018310.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP8\A0018311.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP8\A0018312.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP8\A0018313.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP8\A0018314.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP8\A0018315.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP8\A0018316.exe Infected: Net-Worm.Win32.Bobic.k
C:\System Volume Information\_restore{97C70649-EF83-44ED-AB32-80E4241CCD72}\RP8\A0018317.exe Infected: Net-Worm.Win32.Bobic.k
Scan process completed.
And here the complete HiJackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 12:06:30, on 10/12/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\WINDOWS\System32\ati2evxx.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\Atiptaxx.exe
C:\WINDOWS\kdx\KHost.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\Messager Wanadoo\StartMessager.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\NP\Mes documents\Docs\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.club-vaio.sony-europe.comR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [Paste-it Notes] C:\Program Files\Paste-it\NoteManager.exe
O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\Messager Wanadoo\StartMessager.exe Messager Wanadoo
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} -
http://www.wanadoo.fr (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.sony-europe.com
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) -
http://us-housecall....ivex/hcImpl.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{E202E436-658E-4721-BBFD-3814CFABE41B}: NameServer = 80.10.246.130 80.10.246.3
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WB - C:\PROGRA~1\Object Desktop\WindowBlinds\fastload.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\ati2evxx.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
Thanks again.
Lost_In_Paris