Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e)

Bonjour,

 

Là j'ai besoin d'aide car je n'arrive pas à me défaire d'une contamination malgré un passage entre les fourches caudines de smithfraudFix.exe. J'ai un truc dans la barre des tâches "System Alert" avec des messages en anglais. Ce truc m'agace ! Je ne sais pas quel processus est en cause.

J'ai déjà fait un nettoyage par avast et smithfraudFix sans succès. :P

Si quelqu'un peut m'aider, j'en serai ravi. Merci d'avance. :P

 

Voici déjà le rapport HijackThis : (précision : j'utilise Firefox par défaut et non IE mais qui reste installé).

 

Logfile of HijackThis v1.99.1

Scan saved at 15:48:26, on 12/01/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avast4\aswUpdSv.exe

C:\Program Files\Avast4\ashServ.exe

C:\Program Files\D-Link\Logiciel Bluetooth\bin\btwdins.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Avast4\ashMaiSv.exe

C:\Program Files\Avast4\ashWebSv.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\BroadJump\Client Foundation\CFD.exe

C:\PROGRA~1\Avast4\ashDisp.exe

C:\Program Files\Microsoft IntelliType Pro\type32.exe

C:\Program Files\Microsoft IntelliPoint\point32.exe

C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

C:\Program Files\TomTom HOME\TomTomHOME.exe

C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\MSN Messenger\MsnMsgr.Exe

C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe

C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe

C:\Program Files\D-Link\Logiciel Bluetooth\BTTray.exe

C:\Program Files\Club-Internet\Lanceur\lanceur.exe

C:\Program Files\Club-Internet\Dr Club Internet\bin\mpbtn.exe

C:\PROGRA~1\D-Link\LOGICI~1\BTSTAC~1.EXE

C:\WINDOWS\system32\devldr32.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\svchost.exe

C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

C:\Program Files\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.club-internet.fr

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - C:\Program Files\Video ActiveX Object\isaddon.dll (file missing)

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll

O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll

O4 - HKLM\..\Run: [bJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"

O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [ssAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"

O4 - Startup: Club Internet.lnk = C:\Program Files\Club-Internet\Lanceur\lanceur.exe

O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe

O4 - Global Startup: BTTray.lnk = ?

O4 - Global Startup: Docteur Club Internet.lnk = C:\Program Files\Club-Internet\Dr Club Internet\bin\matcli.exe

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\D-Link\Logiciel Bluetooth\btsendto_ie_ctx.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll

O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\D-Link\Logiciel Bluetooth\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\D-Link\Logiciel Bluetooth\btsendto_ie.htm

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll

O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - C:\WINDOWS\system32\gwquvw.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\D-Link\Logiciel Bluetooth\bin\btwdins.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe

O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe

O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe

O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe

 

Et maintenant le tout dernier rapport de smithfraudFix :

 

SmitFraudFix v2.127

 

Rapport fait à 15:51:23,08, 12/01/2007

Executé à partir de C:\Documents and Settings\Jean-Christophe\Mes documents\Mes fichiers re‡us\SmitfraudFix

OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT

Le type du système de fichiers est NTFS

Fix executé en mode normal

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Jean-Christophe

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Jean-Christophe\Application Data

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\JEAN-C~1\Favoris

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Bureau

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

 

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]

"{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"

 

[HKEY_CLASSES_ROOT\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]

@="C:\WINDOWS\system32\gwquvw.dll"

 

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]

@="C:\WINDOWS\system32\gwquvw.dll"

 

 

 

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=""

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

"System"=""

 

 

»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Fin

 

Merci d'avance à ceux qui pourront m'aider. :P

 

Tripad

Posté(e)

Re

 

Voici ce que tu vas faire STP

 

Comme tu n'as pas la dernière version de smitfraudfix => supprime là ou met la à jour en utilisant l'option 4 !

 

1ére étape :

 

Télécharge AVG Anti-Spyware

  1. Lance AVG Anti-Spyware et clique sur le bouton Update (barre d'outils - au haut). Sous Manual Update clique Start update.
     
  2. Tu verras ceci juste au bas, lorsque la mise à jour sera complétée : "Update successful"
     
  3. Ferme AVG Anti-Spyware. Ne pas le lancer tout de suite.

Télécharger ATF Cleaner par Atribune.

http://www.atribune.org/ccount/click.php?id=1

 

Télécharger SmitfraudFix de S!Ri (Si besoin ):P sur http://siri.urz.free.fr/Fix/SmitfraudFix.zip

Dézipper la totalité de l'archive smitfraudfix.zip

-Son tutorial

http://siri.urz.free.fr/Fix/SmitfraudFix.php

 

process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky...) comme étant un RiskTool.

Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.

 

Utilisation ----- option 1 - Recherche :

Double cliquer sur smitfraudfix.cmd

Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

 

Poster le rapport sur le forum et continuer la procédure.

 

2éme étape : Le nettoyage !

 

Redémarrer l'ordinateur en mode sans échec (tapoter F8 au boot pour obtenir le menu de démarrage

ou tuto Symantec).

http://service1.symantec.com/support/inter...020905112131924

 

Double-clique ATF-Cleaner.exe afin de lancer le programme.

Sous l'onglet Main, choisis : Select All

Clique sur le bouton Empty Selected

 

Si tu utilises le navigateur Firefox : Clique Firefox au haut et choisis : Select All

Clique le bouton Empty Selected

NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

Si tu utilises le navigateur Opera : Clique Opera au haut et choisis : Select All

Clique le bouton Empty Selected

NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

Clique Exit, du menu prinicipal, afin de fermer le programme.

Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.

 

Ensuite double cliquer sur smitfraudfix.cmd

Sélectionner 2 pour supprimer les fichiers responsables de l'infection.

A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran

et supprimer les clés de démarrage automatique de l'infection.

Le fix déterminera si le fichier wininet.dll est infecté.

A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

 

A la fin du scan, sauvegarder le rapport (Fichier/Enregistrer sous...) sur le Bureau.

 

N.B.: Cette étape élimine les fichiers infectieux détectés à l'étape #1

Attention : l'option 2 de l'outil supprime le fond d'écran !

 

process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky...) comme étant un RiskTool.

Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.

 

 

Du mode Sans Échec, lance AVG Anti-Spyware et clique sur le bouton Scanner (de la barre d'outils) et ensuite clique sur Complete System Scan. Le scan prendra un certain temps, donc sois patient.

  • AVG Anti-Spyware affichera une liste des fichiers détectés, sur la gauche. En fin de scan, l'outil appliquera les "Actions" à appliquer automatiquement. Clique sur le bouton Apply all actions. AVG Anti-Spyware affichera "All actions have been applied" du côté droit.
     
  • Clique sur "Save Report", puis "Save Report As". Ceci génère un rapport en fichier texte. Assure-toi de le sauvegarder dans un endroit sûr (sur ton Bureau, par exemple).

 

-Redémarrer en mode normal :

 

-Poster une réponse dans le même sujet

(Cliquer sur répondre entre "flash" et "nouveau " tout en bas de page!)

-Mettre le rapport de Smitfraudfix

-Mettre un nouveau rapport HijackThis

-Poster le rapport AVG Anti-Spyware

-Indiquer si le Pc présente encore des dysfonctionnements

 

A plus et bon courage :P !

Posté(e)

Bonsoir et merci pour cette aide. Je commence seulement la procédure mais voici d'ores et déjà le rapport de SmithfraudFix en version 2.132.

Je continue la procédure et compléte ce post.

 

Merci.

C'est super de trouver de l'aide !

Tripad :P

 

 

 

SmitFraudFix v2.132

 

Rapport fait à 19:24:45,64, 12/01/2007

Executé à partir de C:\Documents and Settings\Jean-Christophe\Mes documents\Mes fichiers re‡us\SmitfraudFix

OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT

Le type du système de fichiers est NTFS

Fix executé en mode normal

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Jean-Christophe

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Jean-Christophe\Application Data

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\JEAN-C~1\Favoris

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Bureau

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

 

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]

"{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"

 

[HKEY_CLASSES_ROOT\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]

@="C:\WINDOWS\system32\gwquvw.dll"

 

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]

@="C:\WINDOWS\system32\gwquvw.dll"

 

 

 

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=""

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

"System"=""

 

 

»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Fin

Posté(e)

Bonsoir ! :P

 

Super content car cela a visiblement marché ! :P

Merci bien de ton aide. Je n'y serai pas arrivé seul !

 

Comme demandé, voici les rapports demandés :

 

SmitFraudFix v2.132

 

Rapport fait à 19:49:49,69, 12/01/2007

Executé à partir de C:\Documents and Settings\Jean-Christophe\Mes documents\Mes fichiers re‡us\Antivermins by Zebulon\SmitfraudFix\SmitfraudFix

OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT

Le type du système de fichiers est NTFS

Fix executé en mode sans echec

 

»»»»»»»»»»»»»»»»»»»»»»»» Avant SmitFraudFix

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]

"{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"

 

[HKEY_CLASSES_ROOT\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]

@="C:\WINDOWS\system32\gwquvw.dll"

 

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]

@="C:\WINDOWS\system32\gwquvw.dll"

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

 

GenericRenosFix by S!Ri

 

C:\WINDOWS\system32\gwquvw.dll -> Hoax.Win32.Renos.gen.i

C:\WINDOWS\system32\gwquvw.dll -> Deleted

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

"System"=""

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

 

Nettoyage terminé.

 

»»»»»»»»»»»»»»»»»»»»»»»» Après SmitFraudFix

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Fin

 

---------------------------------------------------------

AVG Anti-Spyware - Rapport d'analyse

---------------------------------------------------------

 

+ Créé à: 21:01:33 12/01/2007

 

+ Résultat de l'analyse:

 

 

 

D:\P2P Incoming\ [Full Albums Album 2006][mp3] Various Artists - VA-Monsieur_Gainsbourg_Revisited.RAR/[PC GAME MULTILANGUAGE] Europa Casino - Win real money from your home - Bonus 2400 _ to all new players.exe -> Adware.Casino : Ignoré.

D:\System Volume Information\_restore{F6F2AB7F-4A16-43A3-A67C-B3588F32E36F}\RP544\A0145513.exe -> Adware.Gator : Ignoré.

D:\System Volume Information\_restore{F6F2AB7F-4A16-43A3-A67C-B3588F32E36F}\RP544\A0146529.exe -> Adware.Gator : Ignoré.

HKU\S-1-5-21-2052111302-152049171-1202660629-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Ignoré.

C:\System Volume Information\_restore{B34EA09D-FD8A-4991-B16A-2B10C0B6B623}\RP114\A0025058.dll -> Adware.WorldSecurityOnline : Ignoré.

C:\Program Files\eMule\Incoming\Microsoft Money Premium 2007 Crack and Serial.exe -> Downloader.Agent.aii : Nettoyé.

C:\Program Files\eMule\Incoming\Microsoft(MS) Money 2007 Crack and Serial.exe -> Downloader.Agent.aii : Nettoyé.

C:\RECYCLER\S-1-5-21-2052111302-152049171-1202660629-1003\Dc6\isamonitor.exe -> Downloader.Zlob.bjc : Ignoré.

C:\System Volume Information\_restore{B34EA09D-FD8A-4991-B16A-2B10C0B6B623}\RP100\A0022448.exe -> Downloader.Zlob.bjc : Ignoré.

C:\System Volume Information\_restore{B34EA09D-FD8A-4991-B16A-2B10C0B6B623}\RP100\A0022528.exe -> Downloader.Zlob.bjc : Ignoré.

C:\Documents and Settings\Jean-Christophe\Mes documents\Mes fichiers reçus\Trojans_First_Aid_Kit_5.0.zip/tfak.exe -> Not-A-Virus.RemoteAdmin.Win32.TFAK : Ignoré.

:mozilla.166:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.247realmedia : Ignoré.

:mozilla.167:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.247realmedia : Ignoré.

:mozilla.241:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.247realmedia : Ignoré.

:mozilla.242:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.247realmedia : Ignoré.

:mozilla.243:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.247realmedia : Ignoré.

:mozilla.244:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.247realmedia : Ignoré.

:mozilla.245:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.247realmedia : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@247realmedia[2].txt -> TrackingCookie.247realmedia : Ignoré.

:mozilla.350:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.

:mozilla.61:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.

:mozilla.62:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.

:mozilla.63:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.

:mozilla.64:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.

:mozilla.65:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.

:mozilla.668:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.

:mozilla.66:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.

:mozilla.67:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.

:mozilla.68:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.

:mozilla.69:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.

:mozilla.6:C:\Documents and Settings\Audrey\Application Data\Mozilla\Firefox\Profiles\vt8fcw3v.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.

:mozilla.844:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@2o7[2].txt -> TrackingCookie.2o7 : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@aolfr.122.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.

C:\Documents and Settings\Carole\Cookies\carole@2o7[2].txt -> TrackingCookie.2o7 : Ignoré.

C:\Documents and Settings\Carole\Cookies\carole@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.

C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@2o7[2].txt -> TrackingCookie.2o7 : Ignoré.

C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.

C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@sonyeurope.112.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.

:mozilla.463:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Adbrite : Ignoré.

:mozilla.464:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Adbrite : Ignoré.

:mozilla.323:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Adtech : Ignoré.

:mozilla.326:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Adtech : Ignoré.

:mozilla.8:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Adtech : Ignoré.

:mozilla.9:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Adtech : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@adtech[2].txt -> TrackingCookie.Adtech : Ignoré.

C:\Documents and Settings\Carole\Cookies\carole@adtech[2].txt -> TrackingCookie.Adtech : Ignoré.

:mozilla.40:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Advertising : Ignoré.

:mozilla.41:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Advertising : Ignoré.

:mozilla.42:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Advertising : Ignoré.

:mozilla.43:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Advertising : Ignoré.

:mozilla.49:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Advertising : Ignoré.

:mozilla.51:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Advertising : Ignoré.

:mozilla.52:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Advertising : Ignoré.

:mozilla.53:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Advertising : Ignoré.

:mozilla.54:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Advertising : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@advertising[2].txt -> TrackingCookie.Advertising : Ignoré.

:mozilla.294:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Atdmt : Ignoré.

:mozilla.50:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Atdmt : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@atdmt[2].txt -> TrackingCookie.Atdmt : Ignoré.

C:\Documents and Settings\Carole\Cookies\carole@atdmt[2].txt -> TrackingCookie.Atdmt : Ignoré.

C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@atdmt[2].txt -> TrackingCookie.Atdmt : Ignoré.

:mozilla.45:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Bluestreak : Ignoré.

:mozilla.46:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Bluestreak : Ignoré.

:mozilla.681:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Bluestreak : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@bluestreak[1].txt -> TrackingCookie.Bluestreak : Ignoré.

C:\Documents and Settings\Carole\Cookies\carole@bluestreak[1].txt -> TrackingCookie.Bluestreak : Ignoré.

C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@bluestreak[2].txt -> TrackingCookie.Bluestreak : Ignoré.

:mozilla.770:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Casalemedia : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@casalemedia[2].txt -> TrackingCookie.Casalemedia : Ignoré.

:mozilla.750:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Casinotropez : Ignoré.

:mozilla.751:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Casinotropez : Ignoré.

:mozilla.752:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Casinotropez : Ignoré.

:mozilla.753:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Casinotropez : Ignoré.

:mozilla.754:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Casinotropez : Ignoré.

:mozilla.14:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Comclick : Ignoré.

:mozilla.15:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Comclick : Ignoré.

:mozilla.16:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Comclick : Ignoré.

:mozilla.58:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Comclick : Ignoré.

:mozilla.59:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Comclick : Ignoré.

:mozilla.60:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Comclick : Ignoré.

C:\Documents and Settings\Carole\Cookies\carole@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : Ignoré.

:mozilla.596:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Coremetrics : Ignoré.

:mozilla.44:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Doubleclick : Ignoré.

:mozilla.47:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Doubleclick : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignoré.

C:\Documents and Settings\Carole\Cookies\carole@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignoré.

C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignoré.

:mozilla.17:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Estat : Ignoré.

:mozilla.28:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Estat : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@estat[1].txt -> TrackingCookie.Estat : Ignoré.

C:\Documents and Settings\Carole\Cookies\carole@estat[1].txt -> TrackingCookie.Estat : Ignoré.

C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@estat[1].txt -> TrackingCookie.Estat : Ignoré.

:mozilla.659:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Etracker : Ignoré.

:mozilla.101:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Falkag : Ignoré.

:mozilla.102:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Falkag : Ignoré.

:mozilla.103:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Falkag : Ignoré.

:mozilla.104:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Falkag : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@as1.falkag[2].txt -> TrackingCookie.Falkag : Ignoré.

:mozilla.285:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Fastclick : Ignoré.

:mozilla.342:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Fastclick : Ignoré.

:mozilla.343:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Fastclick : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@fastclick[1].txt -> TrackingCookie.Fastclick : Ignoré.

:mozilla.138:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Googleadservices : Ignoré.

:mozilla.447:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Googleadservices : Ignoré.

:mozilla.152:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Hitbox : Ignoré.

:mozilla.153:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Hitbox : Ignoré.

:mozilla.154:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Hitbox : Ignoré.

:mozilla.321:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Hitbox : Ignoré.

:mozilla.351:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Hitbox : Ignoré.

:mozilla.805:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Hitbox : Ignoré.

:mozilla.806:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Hitbox : Ignoré.

:mozilla.807:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Hitbox : Ignoré.

:mozilla.814:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Hitbox : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@searchportal.information[1].txt -> TrackingCookie.Information : Ignoré.

:mozilla.511:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Itrack : Ignoré.

:mozilla.512:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Itrack : Ignoré.

:mozilla.291:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Liveperson : Ignoré.

:mozilla.292:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Liveperson : Ignoré.

:mozilla.293:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Liveperson : Ignoré.

:mozilla.516:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Liveperson : Ignoré.

:mozilla.517:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Liveperson : Ignoré.

:mozilla.518:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Liveperson : Ignoré.

:mozilla.12:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Mediaplex : Ignoré.

:mozilla.13:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Mediaplex : Ignoré.

:mozilla.445:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Mediaplex : Ignoré.

:mozilla.446:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Mediaplex : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignoré.

C:\Documents and Settings\Carole\Cookies\carole@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignoré.

C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignoré.

:mozilla.452:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Overture : Ignoré.

:mozilla.453:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Overture : Ignoré.

:mozilla.7:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Overture : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@overture[2].txt -> TrackingCookie.Overture : Ignoré.

C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@perf.overture[1].txt -> TrackingCookie.Overture : Ignoré.

C:\Documents and Settings\Carole\Cookies\carole@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Ignoré.

:mozilla.810:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Qksrv : Ignoré.

:mozilla.811:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Qksrv : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@questionmarket[2].txt -> TrackingCookie.Questionmarket : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@revenue[2].txt -> TrackingCookie.Revenue : Ignoré.

:mozilla.116:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.

:mozilla.117:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.

:mozilla.118:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.

:mozilla.119:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.

:mozilla.120:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.

:mozilla.121:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.

:mozilla.364:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.

:mozilla.365:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.

:mozilla.366:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.

:mozilla.367:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.

:mozilla.368:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.

:mozilla.369:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@serving-sys[1].txt -> TrackingCookie.Serving-sys : Ignoré.

C:\Documents and Settings\Carole\Cookies\carole@serving-sys[1].txt -> TrackingCookie.Serving-sys : Ignoré.

C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Ignoré.

C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@serving-sys[2].txt -> TrackingCookie.Serving-sys : Ignoré.

:mozilla.236:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Sitestat : Ignoré.

:mozilla.237:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Sitestat : Ignoré.

:mozilla.618:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Sitestat : Ignoré.

:mozilla.619:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Sitestat : Ignoré.

:mozilla.620:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Sitestat : Ignoré.

:mozilla.62:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Sitestat : Ignoré.

:mozilla.761:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Sitestat : Ignoré.

:mozilla.792:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Sitestat : Ignoré.

:mozilla.19:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.

:mozilla.20:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.

:mozilla.21:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.

:mozilla.22:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.

:mozilla.25:C:\Documents and Settings\Audrey\Application Data\Mozilla\Firefox\Profiles\vt8fcw3v.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.

:mozilla.26:C:\Documents and Settings\Audrey\Application Data\Mozilla\Firefox\Profiles\vt8fcw3v.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.

:mozilla.27:C:\Documents and Settings\Audrey\Application Data\Mozilla\Firefox\Profiles\vt8fcw3v.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.

:mozilla.27:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.

:mozilla.30:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.

:mozilla.31:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.

:mozilla.32:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Ignoré.

C:\Documents and Settings\Carole\Cookies\carole@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Ignoré.

C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Ignoré.

:mozilla.134:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Statcounter : Ignoré.

:mozilla.135:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Statcounter : Ignoré.

:mozilla.829:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Tacoda : Ignoré.

:mozilla.830:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Tacoda : Ignoré.

:mozilla.468:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Targetnet : Ignoré.

:mozilla.469:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Targetnet : Ignoré.

:mozilla.153:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.

:mozilla.154:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.

:mozilla.155:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.

:mozilla.156:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.

:mozilla.46:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.

:mozilla.47:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.

:mozilla.48:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.

:mozilla.49:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.

:mozilla.312:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Valueclick : Ignoré.

:mozilla.331:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Valueclick : Ignoré.

:mozilla.672:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Valueclick : Ignoré.

:mozilla.288:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.

:mozilla.290:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.

:mozilla.291:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.

:mozilla.37:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.

:mozilla.38:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.

:mozilla.39:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@weborama[1].txt -> TrackingCookie.Weborama : Ignoré.

C:\Documents and Settings\Carole\Cookies\carole@weborama[2].txt -> TrackingCookie.Weborama : Ignoré.

C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@weborama[2].txt -> TrackingCookie.Weborama : Ignoré.

:mozilla.359:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Webtrendslive : Ignoré.

:mozilla.459:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Yadro : Ignoré.

:mozilla.283:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignoré.

:mozilla.438:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignoré.

:mozilla.439:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignoré.

:mozilla.440:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Ignoré.

:mozilla.318:C:\Documents and Settings\Carole\Application Data\Mozilla\Firefox\Profiles\0v2ae9tj.default\cookies.txt -> TrackingCookie.Zedo : Ignoré.

:mozilla.604:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Zedo : Ignoré.

:mozilla.605:C:\Documents and Settings\Jean-Christophe\Application Data\Mozilla\Firefox\Profiles\bt4pxoip.default\cookies.txt -> TrackingCookie.Zedo : Ignoré.

C:\Documents and Settings\Audrey\Cookies\audrey@zedo[1].txt -> TrackingCookie.Zedo : Ignoré.

 

 

Fin du rapport

 

Et enfin le HijackThis :

 

Logfile of HijackThis v1.99.1

Scan saved at 21:35:05, on 12/01/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avast4\aswUpdSv.exe

C:\Program Files\Avast4\ashServ.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\Program Files\D-Link\Logiciel Bluetooth\bin\btwdins.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Avast4\ashMaiSv.exe

C:\Program Files\Avast4\ashWebSv.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\BroadJump\Client Foundation\CFD.exe

C:\PROGRA~1\Avast4\ashDisp.exe

C:\Program Files\Microsoft IntelliType Pro\type32.exe

C:\Program Files\Microsoft IntelliPoint\point32.exe

C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

C:\Program Files\TomTom HOME\TomTomHOME.exe

C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\MSN Messenger\MsnMsgr.Exe

C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe

C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe

C:\Program Files\D-Link\Logiciel Bluetooth\BTTray.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Club-Internet\Lanceur\lanceur.exe

C:\Program Files\Club-Internet\Dr Club Internet\bin\mpbtn.exe

C:\PROGRA~1\D-Link\LOGICI~1\BTSTAC~1.EXE

C:\WINDOWS\system32\devldr32.exe

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZENG10.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Outlook Express\msimn.exe

C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

C:\WINDOWS\system32\NOTEPAD.EXE

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.club-internet.fr

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll

O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll

O4 - HKLM\..\Run: [bJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"

O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [ssAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"

O4 - Startup: Club Internet.lnk = C:\Program Files\Club-Internet\Lanceur\lanceur.exe

O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe

O4 - Global Startup: BTTray.lnk = ?

O4 - Global Startup: Docteur Club Internet.lnk = C:\Program Files\Club-Internet\Dr Club Internet\bin\matcli.exe

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\D-Link\Logiciel Bluetooth\btsendto_ie_ctx.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll

O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\D-Link\Logiciel Bluetooth\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\D-Link\Logiciel Bluetooth\btsendto_ie.htm

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\D-Link\Logiciel Bluetooth\bin\btwdins.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe

O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe

O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe

O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe

 

Merci pour tout !

Posté(e)

Re

 

Pourrait tu faire ceci STP

 

Télécharge SpySweeper - Télécharge SpySweeper - Aide SpySweeper

- Clic sur sur le lien "Free Trial" pour le télécharger tout à droite

- Installe le et démare le

- Il va te demander de télécharger la dernière définition, accepte

- Ensuite, clic sur le bouton Options à gauche

- Clic sur l'onglet Options

- Assure toi que les options suivantes sont cochées :

o Windows Registery

o Memory Object

o Cookies

o System Restore Folder

o Plus bas :

o Sweep all users accounts

o Sweep for rootkis

 

-- Redémarre en mode sans échec, si tu sais pas comment on fait lis ceci

- Démarre SpySweeper

- Clic sur "Sweep Now" à gauche

- Clic sur le bouton "Start"

- Quand le scan est terminé, clic sur le bouton "Next"

- Assure toi que tout est coché et clic sur le bouton "Next"

- Lorsque tous les éléments trouvés ont été supprimés

- Clic sur "Session Log" en haut à droite, copie tous les élements du log.

- Ferme les fenêtres et colle tout le log ici ainsi qu'un log HiJackThis

 

 

Aide : N'hésite pas à consulter l'Aide de SpySweeper

 

Je te fais passer un autre outil :

 

Télécharge Blacklight (de F-Secure) et sauvegarde le sur ton Bureau.

 

Double-clique blbeta.exe et accepte la licence; laisse [X]scan through Windows Explorer activé; clique Scan puis Next

 

Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).

 

Copie et colle le contenu de ce rapport dans ta prochaine réponse. NE PAS choisir l'option "Rename" de suite : nous devons analyser le rapport, car des fichiers légitimes peuvent être présents, tel wbemtest.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

Prière de poster les rapports suivant dans ta prochaine réponse :

 

1) spysweeper

2) BlackLight

3) Nouveau rapport HijackThis!

 

Bon courage, et @+

Posté(e)

Bonsoir !

 

En mon absence, je vois que ça tourne et que l'aide continue ! Merci beaucoup pour cette aide. :P

Je fais dès que possible le nécessaire et je t'envoie sur le forum les rapports demandés.

 

Vraiment du bon boulot les gars ! Toutes mes félicitations ! :P

 

Affaire donc à suivre ! Je te tiens au courant.

 

Merci :P

  • 2 semaines après...
Posté(e)

Bonjour !

 

J'ai pris le temps de faire ce que tu m'as demandé puisque je suis revenu.

 

Voici le rapport de Spysweeper (en 2 fois car je me suis aperçu que c'était long ...) :

 

10:54: Traces Found: 88

10:54: Custom Sweep has completed. Elapsed time 03:21:18

10:54: File Sweep Complete, Elapsed Time: 03:18:22

10:53: active.undelete.v5.1.010-ror.lnk (ID = 0)

10:31: Warning: AntiVirus engine returned [File Corrupted] on [c:\documents and settings\jean-christophe\local settings\temp\nero7.tmp\cab\b7b2933b.cab]

10:22: tnero.zip (ID = 0)

10:22: Found Troj/Keygen-R: Troj/Keygen-R

10:13: active.undelete.v5.1.010-ror.zip (ID = 0)

10:08: Warning: Failed to access drive F:

10:08: Warning: Failed to access drive E:

10:05: Warning: AntiVirus engine returned [File Corrupted] on [d:\system volume information\_restore{f6f2ab7f-4a16-43a3-a67c-b3588f32e36f}\rp544\a0146535.exe]

10:04: Warning: AntiVirus engine returned [File Corrupted] on [d:\system volume information\_restore{f6f2ab7f-4a16-43a3-a67c-b3588f32e36f}\rp544\a0145519.exe]

09:59: a0146545.exe (ID = 0)

09:44: Warning: AntiVirus engine returned [File Encrypted] on [d:\albums musique\genesis best of\sblaster.part02.drv]

09:44: Warning: AntiVirus engine returned [File Encrypted] on [d:\albums musique\genesis best of\sblaster.part04.drv]

09:44: Warning: AntiVirus engine returned [File Encrypted] on [d:\system volume information\_restore{82308b42-b513-4941-bbfd-3430442ee051}\rp195\a0077878.drv]

09:44: Warning: AntiVirus engine returned [File Encrypted] on [d:\system volume information\_restore{82308b42-b513-4941-bbfd-3430442ee051}\rp195\a0077870.drv]

09:44: Warning: AntiVirus engine returned [File Encrypted] on [d:\system volume information\_restore{82308b42-b513-4941-bbfd-3430442ee051}\rp195\a0077879.drv]

09:44: Warning: AntiVirus engine returned [File Encrypted] on [d:\system volume information\_restore{82308b42-b513-4941-bbfd-3430442ee051}\rp195\a0077871.drv]

09:44: Warning: AntiVirus engine returned [File Encrypted] on [d:\albums musique\genesis best of\sblaster.part01.drv]

09:44: Warning: AntiVirus engine returned [File Encrypted] on [d:\albums musique\genesis best of\sblaster.part08.drv]

09:44: Warning: AntiVirus engine returned [File Encrypted] on [d:\albums musique\genesis best of\sblaster.part05.drv]

09:44: Warning: AntiVirus engine returned [File Encrypted] on [d:\albums musique\genesis best of\sblaster.part03.drv]

09:44: Warning: AntiVirus engine returned [File Encrypted] on [d:\albums musique\genesis best of\sblaster.part06.drv]

09:43: Warning: AntiVirus engine returned [File Encrypted] on [d:\albums musique\genesis best of\sblaster.part07.drv]

09:43: Warning: AntiVirus engine returned [File Encrypted] on [d:\albums musique\genesis best of\sblaster.part09.drv]

09:43: Warning: AntiVirus engine returned [File Encrypted] on [d:\system volume information\_restore{82308b42-b513-4941-bbfd-3430442ee051}\rp195\a0077876.drv]

09:43: Warning: AntiVirus engine returned [File Encrypted] on [d:\system volume information\_restore{82308b42-b513-4941-bbfd-3430442ee051}\rp195\a0077875.drv]

09:43: Warning: AntiVirus engine returned [File Encrypted] on [d:\albums musique\genesis best of\sblaster.part10.drv]

09:43: Warning: AntiVirus engine returned [File Encrypted] on [d:\system volume information\_restore{82308b42-b513-4941-bbfd-3430442ee051}\rp195\a0077873.drv]

09:43: Warning: AntiVirus engine returned [File Encrypted] on [d:\system volume information\_restore{82308b42-b513-4941-bbfd-3430442ee051}\rp195\a0077874.drv]

09:42: Warning: AntiVirus engine returned [File Encrypted] on [d:\system volume information\_restore{82308b42-b513-4941-bbfd-3430442ee051}\rp195\a0077877.drv]

09:38: Warning: AntiVirus engine returned [File Encrypted] on [d:\system volume information\_restore{82308b42-b513-4941-bbfd-3430442ee051}\rp195\a0077872.drv]

09:33: a0022193.lnk (ID = 430866)

09:07: a0025062.exe (ID = 0)

09:07: a0025061.exe (ID = 0)

09:07: Found Troj/Dloadr-AOB: Troj/Dloadr-AOB

09:06: isaddon.dll (ID = 0)

09:02: a0022522.dll (ID = 0)

09:00: a0022523.exe (ID = 0)

08:56: a0022491.dll (ID = 0)

08:48: a0022697.dll (ID = 0)

08:47: isamini.exe (ID = 0)

08:45: Warning: AntiVirus engine returned [Access Denied] on [c:\pagefile.sys]

08:39: Warning: AntiVirus engine returned [File Corrupted] on [c:\documents and settings\jean-christophe\mes documents\mes fichiers reçus\nero\nero_nero_7.0.1.4b_francais_10297.exe]

08:39: a0022181.dll (ID = 0)

08:39: a0022492.exe (ID = 0)

08:31: 50578.exe (ID = 0)

08:31: Found Troj/Dloader-HK: Troj/Dloader-HK

08:27: a0022528.exe (ID = 0)

08:22: a0022213.exe (ID = 0)

08:22: a0022182.exe (ID = 0)

08:22: a0022534.dll (ID = 0)

08:20: a0022696.exe (ID = 0)

08:20: a0022507.exe (ID = 0)

08:18: a0022506.dll (ID = 0)

08:18: a0022449.exe (ID = 0)

08:18: a0022536.exe (ID = 0)

08:11: a0025058.dll (ID = 431210)

08:07: a0022447.dll (ID = 0)

08:06: Warning: AntiVirus engine returned [File Encrypted] on [c:\documents and settings\carole\mes documents\my cdiscount photos files\tmp\zip.tmp]

08:06: a0022212.dll (ID = 0)

07:56: a0022555.exe (ID = 0)

07:44: a0022199.exe (ID = 430775)

07:39: isamonitor.exe (ID = 0)

07:39: Found Troj/Zlobmi-Gen: Troj/Zlobmi-Gen

07:39: isamonitor.exe (ID = 0)

07:39: isamonitor.exe (ID = 0)

07:38: run.exe (ID = 0)

07:37: a0022557.dll (ID = 0)

07:37: Found Troj/Zlob-XT: Troj/Zlob-XT

07:37: a0022529.exe (ID = 0)

07:37: Found Troj/Zlobun-Gen: Troj/Zlobun-Gen

07:37: isauninst.exe (ID = 354604)

07:35: Starting File Sweep

07:35: Warning: Failed to access drive A:

07:35: Cookie Sweep Complete, Elapsed Time: 00:00:01

07:35: jean-christophe@weborama[2].txt (ID = 3658)

07:35: jean-christophe@sonyeurope.112.2o7[1].txt (ID = 1958)

07:35: jean-christophe@serving-sys[2].txt (ID = 3343)

07:35: jean-christophe@perf.overture[1].txt (ID = 3106)

07:35: jean-christophe@msnportal.112.2o7[1].txt (ID = 1958)

07:35: jean-christophe@mediaplex[1].txt (ID = 6442)

07:35: jean-christophe@bs.serving-sys[1].txt (ID = 2330)

07:35: jean-christophe@bluestreak[2].txt (ID = 2314)

07:35: jean-christophe@atdmt[2].txt (ID = 2253)

07:35: jean-christophe@2o7[2].txt (ID = 1957)

07:35: carole@xiti[1].txt (ID = 3717)

07:35: carole@weborama[2].txt (ID = 3658)

07:35: carole@serving-sys[1].txt (ID = 3343)

07:35: carole@msnportal.112.2o7[1].txt (ID = 1958)

07:35: carole@mediaplex[1].txt (ID = 6442)

07:35: carole@fl01.ct2.comclick[1].txt (ID = 2450)

07:35: Found Spy Cookie: comclick cookie

07:35: carole@bluestreak[2].txt (ID = 2314)

07:35: carole@atdmt[2].txt (ID = 2253)

07:35: carole@adtech[2].txt (ID = 2155)

07:35: carole@ads.pointroll[2].txt (ID = 3148)

07:35: Found Spy Cookie: pointroll cookie

07:35: carole@2o7[2].txt (ID = 1957)

07:35: audrey@zedo[2].txt (ID = 3762)

07:35: Found Spy Cookie: zedo cookie

07:35: audrey@xiti[1].txt (ID = 3717)

07:35: Found Spy Cookie: xiti cookie

07:35: audrey@weborama[2].txt (ID = 3658)

07:35: Found Spy Cookie: weborama cookie

07:35: audrey@tradedoubler[1].txt (ID = 3575)

07:35: Found Spy Cookie: tradedoubler cookie

07:35: audrey@stat.dealtime[2].txt (ID = 2506)

07:35: Found Spy Cookie: dealtime cookie

07:35: audrey@sfr.122.2o7[1].txt (ID = 1958)

07:35: audrey@serving-sys[1].txt (ID = 3343)

07:35: Found Spy Cookie: serving-sys cookie

07:35: audrey@revenue[2].txt (ID = 3257)

07:35: Found Spy Cookie: revenue.net cookie

07:35: audrey@questionmarket[2].txt (ID = 3217)

07:35: Found Spy Cookie: questionmarket cookie

07:35: audrey@overture[2].txt (ID = 3105)

07:35: Found Spy Cookie: overture cookie

07:35: audrey@msnportal.112.2o7[1].txt (ID = 1958)

07:35: audrey@mediaplex[1].txt (ID = 6442)

07:35: Found Spy Cookie: mediaplex cookie

07:35: audrey@hotbar[1].txt (ID = 2797)

07:35: Found Spy Cookie: hotbar cookie

07:35: audrey@cassava[1].txt (ID = 2362)

07:35: Found Spy Cookie: cassava cookie

07:35: audrey@casalemedia[2].txt (ID = 2354)

07:35: Found Spy Cookie: casalemedia cookie

07:35: audrey@bs.serving-sys[1].txt (ID = 2330)

07:35: Found Spy Cookie: bs.serving-sys cookie

07:35: audrey@bluestreak[1].txt (ID = 2314)

07:35: Found Spy Cookie: bluestreak cookie

07:35: audrey@atdmt[2].txt (ID = 2253)

07:35: Found Spy Cookie: atlas dmt cookie

07:35: audrey@as1.falkag[2].txt (ID = 2650)

07:35: Found Spy Cookie: falkag cookie

07:35: audrey@aolfr.122.2o7[1].txt (ID = 1958)

07:35: audrey@advertising[1].txt (ID = 2175)

07:35: Found Spy Cookie: advertising cookie

07:35: audrey@adtech[2].txt (ID = 2155)

07:35: Found Spy Cookie: adtech cookie

07:35: audrey@ad.yieldmanager[2].txt (ID = 3751)

07:35: Found Spy Cookie: yieldmanager cookie

07:35: audrey@888[2].txt (ID = 2019)

07:35: audrey@888[1].txt (ID = 2019)

07:35: Found Spy Cookie: 888 cookie

07:35: audrey@2o7[2].txt (ID = 1957)

07:35: Found Spy Cookie: 2o7.net cookie

07:35: audrey@247realmedia[1].txt (ID = 1953)

07:35: Found Spy Cookie: 247realmedia cookie

07:35: Starting Cookie Sweep

07:35: Registry Sweep Complete, Elapsed Time:00:00:35

07:35: HKU\WRSS_Profile_S-1-5-21-2052111302-152049171-1202660629-1004\software\internet security\ (ID = 1553896)

07:35: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || none (ID = 1915396)

07:35: Found Trojan Horse: trojan-downloader-zlob

07:35: HKLM\software\microsoft\windows\currentversion\uninstall\system alert popup\ (ID = 1895397)

07:35: Found Adware: antivermins

07:34: Starting Registry Sweep

07:34: Memory Sweep Complete, Elapsed Time: 00:01:58

07:33: Starting Memory Sweep

07:32: Sweep initiated using definitions version 847

07:32: Spy Sweeper 5.2.3.2138 started

07:32: | Start of Session, mardi 30 janvier 2007 |

********

07:32: | End of Session, mardi 30 janvier 2007 |

07:31: Traces Found: 0

07:31: Sweep Canceled

07:30: Sweep initiated using definitions version 847

07:30: Spy Sweeper 5.2.3.2138 started

07:30: | Start of Session, mardi 30 janvier 2007 |

********

07:30: | End of Session, mardi 30 janvier 2007 |

07:30: Program Version 5.2.3.2138 Using Spyware Definitions 847

07:30: Informational: Loaded AntiVirus Engine: 2.41.0; SDK Version: 4.13; Virus Definitions: 29/01/2007 06:27:34 (GMT)

07:21: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE

07:17: Deleted error log without sending: C:\Documents and Settings\Jean-Christophe\Application Data\Webroot\Spy Sweeper\Logs\bugreport.txt

Keylogger: Off

BHO Shield: On

IE Security Shield: On

Alternate Data Stream (ADS) Execution Shield: On

Startup Shield: On

Common Ad Sites: Off

Hosts File Shield: On

Internet Communication Shield: On

ActiveX Shield: On

Windows Messenger Service Shield: On

IE Favorites Shield: On

Spy Installation Shield: On

Memory Shield: On

IE Hijack Shield: On

IE Tracking Cookies Shield: Off

07:16: Shield States

07:16: Spyware Definitions: 847

07:16: Informational: Loaded AntiVirus Engine: 2.41.0; SDK Version: 4.13; Virus Definitions: 29/01/2007 06:27:34 (GMT)

07:15: Spy Sweeper 5.2.3.2138 started

21:21: | End of Session, lundi 29 janvier 2007 |

21:17: Program Version 5.2.3.2138 Using Spyware Definitions 847

21:17: Informational: Loaded AntiVirus Engine: 2.41.0; SDK Version: 4.13; Virus Definitions: 29/01/2007 06:27:34 (GMT)

20:05: Your definitions are up to date.

20:02: Your virus definitions have been updated.

20:02: Informational: Loaded AntiVirus Engine: 2.41.0; SDK Version: 4.13; Virus Definitions: 29/01/2007 06:27:34 (GMT)

20:01: Your spyware definitions have been updated.

Operation: File Access

Target:

Source: C:\PROGRAM FILES\AVAST4\ASHSERV.EXE

20:01: Tamper Detection

19:55: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE

Keylogger: Off

BHO Shield: On

IE Security Shield: On

Alternate Data Stream (ADS) Execution Shield: On

Startup Shield: On

Common Ad Sites: Off

Hosts File Shield: On

Internet Communication Shield: On

ActiveX Shield: On

Windows Messenger Service Shield: On

IE Favorites Shield: On

Spy Installation Shield: On

Memory Shield: On

IE Hijack Shield: On

IE Tracking Cookies Shield: Off

19:50: Shield States

19:50: Spyware Definitions: 816

19:50: Warning: Virus definitions files are invalid, please update your virus definitions. 220

19:49: Spy Sweeper 5.2.3.2138 started

19:49: Spy Sweeper 5.2.3.2138 started

19:49: | Start of Session, lundi 29 janvier 2007 |

********

22:31: Traces Found: 76

22:31: File Sweep Complete, Elapsed Time: 01:07:47

22:31: Sweep Canceled

22:31: a0022697.dll (ID = 0)

22:29: isamini.exe (ID = 0)

22:27: Warning: AntiVirus engine returned [Access Denied] on [c:\pagefile.sys]

22:22: a0022181.dll (ID = 0)

22:22: a0022492.exe (ID = 0)

22:16: a0022528.exe (ID = 0)

22:10: a0022213.exe (ID = 0)

22:10: a0022182.exe (ID = 0)

22:10: a0022534.dll (ID = 0)

22:08: a0022696.exe (ID = 0)

22:07: a0022507.exe (ID = 0)

22:06: a0022506.dll (ID = 0)

22:06: a0022449.exe (ID = 0)

22:06: a0022536.exe (ID = 0)

22:00: a0025058.dll (ID = 431210)

21:56: a0022447.dll (ID = 0)

21:54: a0022212.dll (ID = 0)

21:44: a0022555.exe (ID = 0)

21:33: a0022199.exe (ID = 430775)

21:27: isamonitor.exe (ID = 0)

21:27: Found Troj/Zlobmi-Gen: Troj/Zlobmi-Gen

21:27: isamonitor.exe (ID = 0)

21:27: isamonitor.exe (ID = 0)

21:26: run.exe (ID = 0)

21:26: a0022557.dll (ID = 0)

21:26: Found Troj/Zlob-XT: Troj/Zlob-XT

21:26: a0022529.exe (ID = 0)

21:26: Found Troj/Zlobun-Gen: Troj/Zlobun-Gen

21:26: isauninst.exe (ID = 354604)

21:24: Starting File Sweep

21:24: Warning: Failed to access drive A:

21:24: Cookie Sweep Complete, Elapsed Time: 00:00:01

21:24: jean-christophe@weborama[2].txt (ID = 3658)

21:24: jean-christophe@sonyeurope.112.2o7[1].txt (ID = 1958)

21:24: jean-christophe@serving-sys[2].txt (ID = 3343)

21:24: jean-christophe@perf.overture[1].txt (ID = 3106)

21:24: jean-christophe@msnportal.112.2o7[1].txt (ID = 1958)

21:24: jean-christophe@mediaplex[1].txt (ID = 6442)

21:24: jean-christophe@bs.serving-sys[1].txt (ID = 2330)

21:24: jean-christophe@bluestreak[2].txt (ID = 2314)

21:24: jean-christophe@atdmt[2].txt (ID = 2253)

21:24: jean-christophe@2o7[2].txt (ID = 1957)

21:24: carole@xiti[1].txt (ID = 3717)

21:24: carole@weborama[2].txt (ID = 3658)

21:24: carole@serving-sys[1].txt (ID = 3343)

21:24: carole@msnportal.112.2o7[1].txt (ID = 1958)

21:24: carole@mediaplex[1].txt (ID = 6442)

21:24: carole@fl01.ct2.comclick[1].txt (ID = 2450)

21:24: Found Spy Cookie: comclick cookie

21:24: carole@bluestreak[2].txt (ID = 2314)

21:24: carole@atdmt[2].txt (ID = 2253)

21:24: carole@adtech[2].txt (ID = 2155)

21:24: carole@ads.pointroll[2].txt (ID = 3148)

21:24: Found Spy Cookie: pointroll cookie

21:24: carole@2o7[2].txt (ID = 1957)

21:24: audrey@zedo[2].txt (ID = 3762)

21:24: Found Spy Cookie: zedo cookie

21:24: audrey@xiti[1].txt (ID = 3717)

21:24: Found Spy Cookie: xiti cookie

21:24: audrey@weborama[2].txt (ID = 3658)

21:24: Found Spy Cookie: weborama cookie

21:24: audrey@tradedoubler[1].txt (ID = 3575)

21:24: Found Spy Cookie: tradedoubler cookie

21:24: audrey@stat.dealtime[2].txt (ID = 2506)

21:24: Found Spy Cookie: dealtime cookie

21:24: audrey@sfr.122.2o7[1].txt (ID = 1958)

21:24: audrey@serving-sys[1].txt (ID = 3343)

21:24: Found Spy Cookie: serving-sys cookie

21:24: audrey@revenue[2].txt (ID = 3257)

21:24: Found Spy Cookie: revenue.net cookie

21:24: audrey@questionmarket[2].txt (ID = 3217)

21:24: Found Spy Cookie: questionmarket cookie

21:24: audrey@overture[2].txt (ID = 3105)

21:24: Found Spy Cookie: overture cookie

21:24: audrey@msnportal.112.2o7[1].txt (ID = 1958)

21:24: audrey@mediaplex[1].txt (ID = 6442)

21:24: Found Spy Cookie: mediaplex cookie

21:24: audrey@hotbar[1].txt (ID = 2797)

21:24: Found Spy Cookie: hotbar cookie

21:24: audrey@cassava[1].txt (ID = 2362)

21:24: Found Spy Cookie: cassava cookie

21:24: audrey@casalemedia[2].txt (ID = 2354)

21:24: Found Spy Cookie: casalemedia cookie

21:24: audrey@bs.serving-sys[1].txt (ID = 2330)

21:24: Found Spy Cookie: bs.serving-sys cookie

21:24: audrey@bluestreak[1].txt (ID = 2314)

21:24: Found Spy Cookie: bluestreak cookie

21:24: audrey@atdmt[2].txt (ID = 2253)

21:24: Found Spy Cookie: atlas dmt cookie

21:24: audrey@as1.falkag[2].txt (ID = 2650)

21:24: Found Spy Cookie: falkag cookie

21:24: audrey@aolfr.122.2o7[1].txt (ID = 1958)

21:24: audrey@advertising[1].txt (ID = 2175)

21:24: Found Spy Cookie: advertising cookie

21:24: audrey@adtech[2].txt (ID = 2155)

21:24: Found Spy Cookie: adtech cookie

21:24: audrey@ad.yieldmanager[2].txt (ID = 3751)

21:24: Found Spy Cookie: yieldmanager cookie

21:24: audrey@888[2].txt (ID = 2019)

21:24: audrey@888[1].txt (ID = 2019)

21:24: Found Spy Cookie: 888 cookie

21:24: audrey@2o7[2].txt (ID = 1957)

21:24: Found Spy Cookie: 2o7.net cookie

21:24: audrey@247realmedia[1].txt (ID = 1953)

21:24: Found Spy Cookie: 247realmedia cookie

21:24: Starting Cookie Sweep

21:23: Registry Sweep Complete, Elapsed Time:00:00:35

21:23: HKU\WRSS_Profile_S-1-5-21-2052111302-152049171-1202660629-1004\software\internet security\ (ID = 1553896)

21:23: HKLM\software\microsoft\windows\currentversion\policies\explorer\run\ || none (ID = 1915396)

21:23: Found Trojan Horse: trojan-downloader-zlob

21:23: HKLM\software\microsoft\windows\currentversion\uninstall\system alert popup\ (ID = 1895397)

21:23: Found Adware: antivermins

21:23: Starting Registry Sweep

21:23: Memory Sweep Complete, Elapsed Time: 00:01:54

21:21: Starting Memory Sweep

21:21: Sweep initiated using definitions version 847

21:21: Spy Sweeper 5.2.3.2138 started

21:21: | Start of Session, lundi 29 janvier 2007 |

********

 

Pour Blacklight : pas de rapport car état néant (??).

 

Et voici le dernier rapport Hijackthis :

 

Logfile of HijackThis v1.99.1

Scan saved at 18:20:48, on 30/01/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avast4\aswUpdSv.exe

C:\Program Files\Avast4\ashServ.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\Program Files\D-Link\Logiciel Bluetooth\bin\btwdins.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

C:\Program Files\Avast4\ashMaiSv.exe

C:\Program Files\Avast4\ashWebSv.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\BroadJump\Client Foundation\CFD.exe

C:\PROGRA~1\Avast4\ashDisp.exe

C:\Program Files\Microsoft IntelliType Pro\type32.exe

C:\Program Files\Microsoft IntelliPoint\point32.exe

C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe

C:\Program Files\TomTom HOME\TomTomHOME.exe

C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\MSN Messenger\MsnMsgr.Exe

C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

C:\WINDOWS\system32\devldr32.exe

C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe

C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe

C:\Program Files\D-Link\Logiciel Bluetooth\BTTray.exe

C:\Program Files\Club-Internet\Dr Club Internet\bin\mpbtn.exe

C:\PROGRA~1\D-Link\LOGICI~1\BTSTAC~1.EXE

C:\Program Files\Club-Internet\Lanceur\lanceur.exe

C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Webroot\Spy Sweeper\SSU.EXE

C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.club-internet.fr

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll

O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll

O4 - HKLM\..\Run: [bJCFD] "C:\Program Files\BroadJump\Client Foundation\CFD.exe"

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"

O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKLM\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [ssAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"

O4 - Startup: Club Internet.lnk = C:\Program Files\Club-Internet\Lanceur\lanceur.exe

O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe

O4 - Global Startup: BTTray.lnk = ?

O4 - Global Startup: Docteur Club Internet.lnk = C:\Program Files\Club-Internet\Dr Club Internet\bin\matcli.exe

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\D-Link\Logiciel Bluetooth\btsendto_ie_ctx.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\D-Link\Logiciel Bluetooth\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\D-Link\Logiciel Bluetooth\btsendto_ie.htm

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll

O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll

O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Avast4\aswUpdSv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\D-Link\Logiciel Bluetooth\bin\btwdins.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe

O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe

O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe

O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe

O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

 

Merci pour tout !

 

J'ai une question subsidiaire : j'ai maintenant Avast!, AVG Anti-Spyware et Spy Sweeper. Faut-il les 3 ?

Je me suis aperçu que cela ralentissait le démarrage de Windows. Il y a peut-être d'autres défauts que je n'ai pas encore noté ...

 

Merci et bon courage !

 

Tripad

Posté(e)

Bonsoir Tripad !

 

si ton système est trop ralentit tu peut désintaller Spysweeper et AVG

 

Peut tu faire ceci STP ?

-Faire un scan en ligne ici et coller le rapport.

Panda si tu n'y arrives pas : tutorial

 

A plus.

 

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...