Help!! j'ai un virus!!!

Résolu
amyann -  
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité -
Bonjour,

je pense avoir un virus!!!

merci de m'aider!!

avast ne le détecte pas et je n'arrive pas à le supprimer ac spybot!!!

je vien s de faire un rapport hijack :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:34:31, on 01/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\vVX1000.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\HomePlayer\HomePlayer.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\amélie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ST291DH5\HiJackThis[1].exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
A voir également:

24 réponses

pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 502
 
Fait ceci et poste moi le rapport à la suite de la question êtes vous aider par quelqu'un. Merci.

Télécharge GenProc sur ton bureau (Attention le fichier est un fichier zip)
Dézippe le dossier, double-clique sur GenProc.bat
En final, poste le contenu du rapport qui s'affiche.
Comment utiliser GenProc

Pour ceux qui ont vista, ne pas oublier de désactiver Le contrôle des comptes utilisateurs

0
amyann
 
Merci bcp de m'aider!!
voici le rapport :
Rapport GenProc 2.398 [1] - 02/03/2009 à 19:31:04,55 - Windows Vista

Il est impératif de désactiver le résident TeaTimer de Spybot pendant l'ensemble des manipulations qui vont suivre. Aide Tea-Timer : http://ww11.genproc.com/spybot/spybot.html

Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
Par la suite, laisse-le avec ses réglages par défaut. C'est tout.


# Etape 1/ Télécharge :

- Lop S&D https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2 (Eric 71 & Angeldark) sur ton Bureau.

- Toolbar-S&D https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2 (Team IDN) sur ton Bureau.


Redémarre en mode sans échec comme indiqué ici https://www.wekyo.com/demarrer-le-pc-en-mode-sans-echec-windows-7-et-8/ ; pour retrouver le rapport, clique sur le raccourci "GenProc" sur ton bureau. Choisis ta session courante *** amélie ***


# Etape 2/

Lance Toolbar-S&D situé sur le Bureau.
Tape sur "2" puis valide en appuyant sur "Entrée". Ne ferme pas la fenêtre lors de la suppression.

# Etape 3/

Double-clique sur Lop S&D pour lancer l'installation, séléctionne la langue souhaitée, puis choisis l'Option 2 - Suppression - et patiente jusqu'à ce qu'il ait terminé.

# Etape 4/

Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

# Etape 5/

Redémarre normalement et poste, dans la même réponse :

- Le contenu du rapport C:\TB.txt ;
- Le contenu du rapport C:\lopR.txt ;
- Un nouveau rapport HijackThis http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/hijackthis-version-install-sujet_199100_1.htm ;

Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.

----------------------------------------------------------------------

Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
----------------------------------------------------------------------

~~ Arguments ~~

# Détections GenProc 2.398 02/03/2009 à 19:30:17,80
Lop:le 02/03/2009 à 19:30:21,27 "C:\Program Files\Circle Developement"
Toolbar:le 02/03/2009 à 19:30:26,52 "C:\Program Files\MSN Messenger\msimg32.dll"
0
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 502
 
Tu peux faire ce qui est indiqué et me poster les rapports.
0
AMYAN
 
VOICI LES 3 RAPPORTS :

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft® Windows Vista™ Édition Familiale Basique ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Intel(R) Celeron(R) D CPU 3.46GHz )
BIOS : BIOS Date: 03/09/07 18:46:32 Ver: 08.00.13
USER : amélie ( Not Administrator ! )
BOOT : Fail-safe boot
Antivirus : avast! antivirus 4.8.1335 [VPS 090302-0] 4.8.1335 (Activated)
C:\ (Local Disk) - NTFS - Total:227 Go (Free:158 Go)
D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 02/03/2009|22:09 )

[ UAC => 1 ]


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@advertstream[1].txt
Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@adultfriendfinder[2].txt
Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@advertising[1].txt
Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@ero-advertising[1].txt
Supprime! - C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@adopt.euroclick[2].txt
Supprime! - C:\Program Files\Circle Developement
-
[ Fichier Hosts ] .. Restaure!

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans Local

[23/08/2007|17:14] C:\Users\AMLIE~1\AppData\Local\Adobe
[29/09/2007|16:13] C:\Users\AMLIE~1\AppData\Local\Ahead
[21/08/2007|18:35] C:\Users\AMLIE~1\AppData\Local\Application Data
[23/10/2007|21:03] C:\Users\AMLIE~1\AppData\Local\Codemasters
[22/11/2007|00:16] C:\Users\AMLIE~1\AppData\Local\d3d8caps.dat
[13/12/2007|21:10] C:\Users\AMLIE~1\AppData\Local\d3d9caps.dat
[01/03/2009|22:42] C:\Users\AMLIE~1\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[16/02/2008|17:25] C:\Users\AMLIE~1\AppData\Local\DNA
[03/05/2008|09:16] C:\Users\AMLIE~1\AppData\Local\DVDPlay
[18/10/2008|15:40] C:\Users\AMLIE~1\AppData\Local\GDIPFONTCACHEV1.DAT
[18/01/2009|16:43] C:\Users\AMLIE~1\AppData\Local\Google
[21/08/2007|18:35] C:\Users\AMLIE~1\AppData\Local\Historique
[02/03/2009|22:00] C:\Users\AMLIE~1\AppData\Local\IconCache.db
[31/10/2007|13:59] C:\Users\AMLIE~1\AppData\Local\IM
[10/09/2007|14:34] C:\Users\AMLIE~1\AppData\Local\Lphant
[11/11/2007|20:38] C:\Users\AMLIE~1\AppData\Local\Magentic
[29/10/2008|22:47] C:\Users\AMLIE~1\AppData\Local\Microsoft
[24/08/2007|23:35] C:\Users\AMLIE~1\AppData\Local\Microsoft Games
[22/09/2007|13:29] C:\Users\AMLIE~1\AppData\Local\Mozilla
[24/11/2008|17:46] C:\Users\AMLIE~1\AppData\Local\PowerCinema
[02/03/2009|22:09] C:\Users\AMLIE~1\AppData\Local\Temp
[21/08/2007|18:35] C:\Users\AMLIE~1\AppData\Local\Temporary Internet Files
[23/08/2007|17:00] C:\Users\AMLIE~1\AppData\Local\VirtualStore

--------------------\\ Tâches planifiées dans C:\Windows\tasks

[02/03/2009 11:38][--ah-----] C:\Windows\tasks\User_Feed_Synchronization-{B7D7C3D9-A772-409F-8943-DB61DE2FAEC5}.job
[02/03/2009 22:01][--ah-----] C:\Windows\tasks\SA.DAT
[02/03/2009 22:01][--a------] C:\Windows\tasks\SCHEDLGU.TXT

--------------------\\ Listing des dossiers dans C:\ProgramData

[08/03/2007|06:14] C:\ProgramData\Adobe
[02/11/2006|13:59] C:\ProgramData\Application Data
[29/10/2007|11:34] C:\ProgramData\AVS4YOU
[21/08/2007|18:31] C:\ProgramData\Bureau
[21/07/2008|09:25] C:\ProgramData\CyberLink
[02/11/2006|13:59] C:\ProgramData\Desktop
[02/11/2006|13:59] C:\ProgramData\Documents
[11/09/2007|15:56] C:\ProgramData\eMule
[10/01/2008|22:20] C:\ProgramData\EPSON
[21/08/2007|18:31] C:\ProgramData\Favoris
[02/11/2006|13:59] C:\ProgramData\Favorites
[18/01/2009|16:24] C:\ProgramData\Google
[17/01/2008|18:32] C:\ProgramData\Grisoft
[08/03/2007|06:39] C:\ProgramData\Hewlett-Packard
[08/03/2007|06:20] C:\ProgramData\InstallShield
[15/02/2009|21:17] C:\ProgramData\Kaspersky Lab Setup Files
[17/01/2008|13:47] C:\ProgramData\Lavasoft
[25/09/2007|10:45] C:\ProgramData\LightScribe
[21/08/2007|18:31] C:\ProgramData\Menu D‚marrer
[22/12/2008|17:54] C:\ProgramData\Messenger Plus!
[17/10/2008|20:32] C:\ProgramData\Microsoft
[21/08/2007|18:31] C:\ProgramData\ModŠles
[22/09/2007|13:28] C:\ProgramData\Mozilla
[25/09/2007|10:32] C:\ProgramData\Nero
[13/12/2007|21:51] C:\ProgramData\NFS Underground
[17/05/2008|17:39] C:\ProgramData\RoboForm
[24/09/2007|21:21] C:\ProgramData\Roxio
[26/08/2007|17:49] C:\ProgramData\Sonic
[15/02/2009|23:11] C:\ProgramData\Spybot - Search & Destroy
[02/11/2006|13:59] C:\ProgramData\Start Menu
[28/10/2007|10:17] C:\ProgramData\Symantec
[02/11/2006|13:59] C:\ProgramData\Templates
[10/01/2008|22:27] C:\ProgramData\UDL
[30/10/2007|09:13] C:\ProgramData\vsosdk

--------------------\\ Listing des dossiers dans C:\Program Files

[08/03/2007|06:14] C:\Program Files\Adobe
[27/11/2007|14:26] C:\Program Files\Alwil Software
[16/01/2008|15:46] C:\Program Files\a-squared Anti-Malware
[23/12/2007|18:56] C:\Program Files\AVS4YOU
[14/12/2008|23:22] C:\Program Files\BarreConfCMCIC
[28/10/2007|11:15] C:\Program Files\BitDefender
[16/02/2008|17:25] C:\Program Files\BitTorrent
[22/08/2008|16:53] C:\Program Files\CCleaner
[26/12/2007|20:43] C:\Program Files\Codemasters
[30/12/2008|18:01] C:\Program Files\Common Files
[30/12/2008|17:52] C:\Program Files\Computer Artworks
[08/03/2007|06:04] C:\Program Files\CyberLink
[17/11/2008|21:58] C:\Program Files\Dactylo
[17/10/2007|20:35] C:\Program Files\DAEMON Tools
[26/12/2007|20:36] C:\Program Files\DivX
[30/08/2008|08:57] C:\Program Files\DNA
[11/09/2007|15:56] C:\Program Files\eMule
[10/01/2008|22:24] C:\Program Files\epson
[21/08/2007|18:31] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[14/01/2009|21:21] C:\Program Files\Freeplayer
[18/01/2009|16:37] C:\Program Files\Google
[08/03/2007|06:20] C:\Program Files\Hewlett-Packard
[15/01/2009|20:55] C:\Program Files\HomePlayer
[08/03/2007|06:15] C:\Program Files\HP
[16/01/2008|15:44] C:\Program Files\IncrediMail
[30/12/2008|17:52] C:\Program Files\InstallShield Installation Information
[13/02/2009|14:35] C:\Program Files\Internet Explorer
[01/08/2008|23:08] C:\Program Files\Java
[11/09/2007|16:23] C:\Program Files\K-Lite Codec Pack
[25/03/2008|17:19] C:\Program Files\LimeWire
[15/01/2008|15:02] C:\Program Files\Macrogaming
[23/12/2007|18:56] C:\Program Files\Magentic
[22/08/2008|16:47] C:\Program Files\Messenger Plus! Live
[02/11/2006|13:35] C:\Program Files\Microsoft Games
[17/10/2007|12:51] C:\Program Files\Microsoft LifeCam
[17/10/2008|20:33] C:\Program Files\Microsoft Office
[08/03/2007|06:16] C:\Program Files\Microsoft Works
[17/10/2008|20:32] C:\Program Files\Microsoft.NET
[08/03/2007|14:42] C:\Program Files\Movie Maker
[22/09/2007|13:29] C:\Program Files\Mozilla Firefox
[02/11/2006|13:35] C:\Program Files\MSBuild
[02/11/2006|13:35] C:\Program Files\MSN
[22/08/2008|16:47] C:\Program Files\MSN Messenger
[12/09/2007|02:02] C:\Program Files\MSXML 4.0
[25/09/2007|10:32] C:\Program Files\Nero
[30/12/2007|13:13] C:\Program Files\NovaLogic
[08/10/2008|20:46] C:\Program Files\OpenOffice.org 2.4
[14/01/2008|21:47] C:\Program Files\PC-Doctor 5 for Windows
[01/11/2007|20:22] C:\Program Files\QuickTime
[17/11/2008|22:07] C:\Program Files\RapidTyping
[08/03/2007|06:13] C:\Program Files\Real
[08/03/2007|06:01] C:\Program Files\Realtek
[02/11/2006|13:35] C:\Program Files\Reference Assemblies
[08/03/2007|06:12] C:\Program Files\Roxio
[08/03/2007|06:23] C:\Program Files\Services en ligne
[17/05/2008|17:38] C:\Program Files\Siber Systems
[15/02/2009|22:03] C:\Program Files\Spybot - Search & Destroy
[17/01/2008|14:52] C:\Program Files\Trend Micro
[02/11/2006|13:58] C:\Program Files\Uninstall Information
[09/01/2009|20:49] C:\Program Files\uTorrent
[05/09/2007|18:04] C:\Program Files\VideoLAN
[29/03/2008|22:52] C:\Program Files\VSO
[12/09/2007|02:18] C:\Program Files\Windows Calendar
[08/03/2007|14:42] C:\Program Files\Windows Collaboration
[12/09/2007|02:18] C:\Program Files\Windows Defender
[22/08/2008|16:47] C:\Program Files\Windows Live
[12/02/2009|23:11] C:\Program Files\Windows Mail
[10/10/2007|14:27] C:\Program Files\Windows Media Player
[21/08/2007|18:31] C:\Program Files\Windows NT
[08/03/2007|14:42] C:\Program Files\Windows Photo Gallery
[09/01/2008|14:59] C:\Program Files\Windows Sidebar
[25/09/2007|13:15] C:\Program Files\WinRAR

--------------------\\ Listing des dossiers dans C:\Program Files\Common Files

[08/03/2007|06:14] C:\Program Files\Common Files\Adobe
[25/09/2007|10:38] C:\Program Files\Common Files\Ahead
[23/12/2007|18:56] C:\Program Files\Common Files\AVSMedia
[27/11/2007|14:12] C:\Program Files\Common Files\BitDefender
[17/10/2008|20:33] C:\Program Files\Common Files\DESIGNER
[15/01/2008|15:02] C:\Program Files\Common Files\DisqudurProtection
[08/03/2007|06:20] C:\Program Files\Common Files\InstallShield
[22/03/2008|20:11] C:\Program Files\Common Files\Java
[08/03/2007|06:05] C:\Program Files\Common Files\LightScribe
[08/03/2007|06:04] C:\Program Files\Common Files\LS Getting Started
[17/10/2008|20:35] C:\Program Files\Common Files\microsoft shared
[22/09/2007|13:28] C:\Program Files\Common Files\PX Storage Engine
[08/03/2007|06:13] C:\Program Files\Common Files\Real
[08/03/2007|06:03] C:\Program Files\Common Files\Roxio Shared
[02/11/2006|12:18] C:\Program Files\Common Files\Services
[08/03/2007|06:11] C:\Program Files\Common Files\Sonic Shared
[02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
[08/03/2007|06:03] C:\Program Files\Common Files\SureThing Shared
[30/12/2008|18:01] C:\Program Files\Common Files\SWF Studio
[28/10/2007|10:17] C:\Program Files\Common Files\Symantec Shared
[17/10/2008|20:32] C:\Program Files\Common Files\System
[08/03/2007|06:13] C:\Program Files\Common Files\xing shared

--------------------\\ Process

( 21 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-02 22:09:37
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 134

--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !

[F:51][D:11]-> C:\Users\AMLIE~1\AppData\Local\Temp
[F:260][D:1]-> C:\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies
[F:6283][D:9]-> C:\Users\AMLIE~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:29][D:6]-> C:\$Recycle.Bin

1 - "C:\Lop SD\LopR_1.txt" - 02/03/2009|22:11 - Option : [2]

--------------------\\ Fin du rapport a 22:11:18
[ UAC => 1 ]



-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft® Windows Vista™ Édition Familiale Basique ( v6.0.6000 )
X86-based PC ( Multiprocessor Free : Intel(R) Celeron(R) D CPU 3.46GHz )
BIOS : BIOS Date: 03/09/07 18:46:32 Ver: 08.00.13
USER : amélie ( Not Administrator ! )
BOOT : Fail-safe boot
Antivirus : avast! antivirus 4.8.1335 [VPS 090302-0] 4.8.1335 (Activated)
C:\ (Local Disk) - NTFS - Total:227 Go (Free:158 Go)
D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (CD or DVD)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 02/03/2009|22:05 )

[ UAC => 0 ]

-----------\\ Recherche de Fichiers / Dossiers ...


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.google.fr/?gws_rd=ssl"
"Local Page"="C:\\Windows\\system32\\blank.htm"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Url"="https://www.msn.com/fr-fr/actualite/"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://www.msn.com/fr-fr/"
"Default_Page_URL"="https://www.google.com/?gws_rd=ssl"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"


--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !

[ UAC => 1 ]


1 - "C:\ToolBar SD\TB_1.txt" - 02/03/2009|22:06 - Option : [2]

-----------\\ Fin du rapport a 22:06:36,89
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:33:42, on 02/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\vVX1000.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
0
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 502
 
Bien maintenant fait ceci :

Telecharge malwarebytes

NB : S'il te manque COMCTL32.OCX alors télécharge le ici

Tu l´instale; le programme va se mettre automatiquement a jour.

Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

Puis click sur "rechercher".

Laisse le scanner le pc...

Si des elements on ete trouvés > click sur supprimer la selection.

si il t´es demandé de redemarrer > click sur "yes".

A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
Copie et colle le rapport stp.

PS : les rapport sont aussi rangé dans l onglet rapport/log

Tutoriaux

0
AMYAN
 
VOICI LE RAPPORT :

Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1815
Windows 6.0.6000

03/03/2009 22:45:05
mbam-log-2009-03-03 (22-45-05).txt

Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 192194
Temps écoulé: 1 hour(s), 0 minute(s), 5 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 3
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\DomainService (Trojan.Agent) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\Users\amélie\Desktop\GenProc\outil\curl.exe (Trojan.Agent) -> Quarantined and deleted successfully.
0
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 502
 
pas mal ensuite vide la quarantaine de malware et fait ceci :

Pour commencer : faire un petit nettoyage de l'ordi et du registre avec Ccleaner, regarde bien le Tuto CCleaner

Télécharge Superantispyware (SAS)

Choisis "enregistrer" et enregistre-le sur ton bureau.

Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

Créé une icône sur le bureau.

Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

- Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
- Sous Configuration and Preferences, clique sur le bouton "Preferences"
- Clique sur l'onglet "Scanning Control "
- Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

Close browsers before scanning
Scan for tracking cookies
Terminate memory threats before quarantining
- Laisse les autres lignes décochées.

- Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

- Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

Dans la colonne de gauche, coche C:\Fixed Drive.

Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

Pour recopier les informations sur le forum, fais ceci :

- après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
- Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
- Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

- Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

- Copie son contenu dans ta réponse.

Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
0
AMYAN
 
BONSOIR,

SAS SCANNE DEPUIS HIER SOIR!!!!
tjs pas fini!!!!
je poste le rapport dés q ça sera fini!!!
0
amyann > AMYAN
 
j'ai arrété le scan car il allait depuis plusieurs jours!!
SUPERAntiSpyware Scan Log
https://www.superantispyware.com/

Generated 03/09/2009 at 10:20 PM

Application Version : 4.25.1014

Core Rules Database Version : 3784
Trace Rules Database Version: 1741

Scan type : Complete Scan
Total Scan Time : 23:53:34

Memory items scanned : 725
Memory threats detected : 0
Registry items scanned : 8444
Registry threats detected : 1
File items scanned : 7395352
File threats detected : 365

Adware.Vundo Variant
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{7555906D-70F1-4FD6-8250-4FBE75252F58}

Adware.Tracking Cookie
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@smartadserver[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ads.monster[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@mediaplex[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@serving-sys[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@yourmedia[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\amélie@smartadserver[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ads.monster[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@mediaplex[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@serving-sys[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@yourmedia[1].txt
C:\Documents and Settings\amélie\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Cookies\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Cookies\amélie@smartadserver[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adrevolver[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@ads.monster[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@mediaplex[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@serving-sys[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@yourmedia[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@ad.wedoo[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@ad.zanox[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@adserver.aol[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@adv.surinter[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@advertstream[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@cdiscount[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@clickintext[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@d2.advertserve[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@proximedia[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@roiservice[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@track.effiliation[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracker.affistats[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[4].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[5].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[6].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.proximedia[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Documents and Settings\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@xiti[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@ad.wedoo[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@ad.zanox[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@adserver.aol[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@adv.surinter[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@advertstream[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@cdiscount[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@clickintext[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@d2.advertserve[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@proximedia[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@roiservice[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@track.effiliation[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracker.affistats[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[4].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[5].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[6].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.proximedia[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Documents and Settings\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@xiti[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@ad.wedoo[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@ad.zanox[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@adserver.aol[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@adv.surinter[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@advertstream[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@cdiscount[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@clickintext[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@d2.advertserve[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@proximedia[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@roiservice[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@track.effiliation[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@tracker.affistats[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.googleadservices[4].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.googleadservices[5].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.googleadservices[6].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.proximedia[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Documents and Settings\yann\Cookies\Low\yann@xiti[1].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@adopt.euroclick[2].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@adultfriendfinder[2].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@advertising[1].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@advertstream[1].txt
C:\Lop SD\Backup-Lop\Users\AMLIE~1\AppData\Roaming\MICROS~1\Windows\Cookies\amélie@ero-advertising[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@doubleclick[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@smartadserver[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@2o7[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.caradisiac[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.zanox[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adopt.euroclick[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ads-dev.youporn[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ads.monster[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@advertising[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bluestreak[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@boursoramabanque.solution.weborama[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ero-advertising[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@serving-sys[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@smartadserver[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[2].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@www.googleadservices[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@youporn[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@yourmedia[1].txt
C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@zedo[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\amélie@doubleclick[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\amélie@smartadserver[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@2o7[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.caradisiac[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.zanox[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adopt.euroclick[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ads-dev.youporn[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ads.monster[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@advertising[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bluestreak[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@boursoramabanque.solution.weborama[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ero-advertising[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@serving-sys[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@smartadserver[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[2].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@www.googleadservices[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@youporn[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@yourmedia[1].txt
C:\Users\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@zedo[1].txt
C:\Users\amélie\Cookies\amélie@atdmt[2].txt
C:\Users\amélie\Cookies\amélie@doubleclick[1].txt
C:\Users\amélie\Cookies\amélie@smartadserver[2].txt
C:\Users\amélie\Cookies\Low\amélie@2o7[1].txt
C:\Users\amélie\Cookies\Low\amélie@ad.caradisiac[2].txt
C:\Users\amélie\Cookies\Low\amélie@ad.proxad[1].txt
C:\Users\amélie\Cookies\Low\amélie@ad.zanox[1].txt
C:\Users\amélie\Cookies\Low\amélie@adopt.euroclick[2].txt
C:\Users\amélie\Cookies\Low\amélie@adrevolver[2].txt
C:\Users\amélie\Cookies\Low\amélie@ads-dev.youporn[1].txt
C:\Users\amélie\Cookies\Low\amélie@ads.monster[1].txt
C:\Users\amélie\Cookies\Low\amélie@adserver.aol[1].txt
C:\Users\amélie\Cookies\Low\amélie@adtech[1].txt
C:\Users\amélie\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Users\amélie\Cookies\Low\amélie@advertising[1].txt
C:\Users\amélie\Cookies\Low\amélie@apmebf[1].txt
C:\Users\amélie\Cookies\Low\amélie@atdmt[2].txt
C:\Users\amélie\Cookies\Low\amélie@bluestreak[2].txt
C:\Users\amélie\Cookies\Low\amélie@boursoramabanque.solution.weborama[2].txt
C:\Users\amélie\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Users\amélie\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Users\amélie\Cookies\Low\amélie@doubleclick[1].txt
C:\Users\amélie\Cookies\Low\amélie@ero-advertising[1].txt
C:\Users\amélie\Cookies\Low\amélie@intermarche2009.solution.weborama[2].txt
C:\Users\amélie\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Users\amélie\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Users\amélie\Cookies\Low\amélie@mediaplex[1].txt
C:\Users\amélie\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Users\amélie\Cookies\Low\amélie@serving-sys[2].txt
C:\Users\amélie\Cookies\Low\amélie@smartadserver[1].txt
C:\Users\amélie\Cookies\Low\amélie@tracking.publicidees[2].txt
C:\Users\amélie\Cookies\Low\amélie@tradedoubler[2].txt
C:\Users\amélie\Cookies\Low\amélie@weborama[1].txt
C:\Users\amélie\Cookies\Low\amélie@www.googleadservices[1].txt
C:\Users\amélie\Cookies\Low\amélie@xiti[1].txt
C:\Users\amélie\Cookies\Low\amélie@youporn[1].txt
C:\Users\amélie\Cookies\Low\amélie@yourmedia[1].txt
C:\Users\amélie\Cookies\Low\amélie@zedo[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@ad.wedoo[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@ad.zanox[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@adserver.aol[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@adv.surinter[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@advertstream[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@cdiscount[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@clickintext[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@d2.advertserve[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@proximedia[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@roiservice[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@track.effiliation[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracker.affistats[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[4].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[5].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[6].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.proximedia[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Users\yann\AppData\Roaming\Microsoft\Windows\Cookies\Low\yann@xiti[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@ad.wedoo[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@ad.zanox[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@adserver.aol[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@adv.surinter[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@advertstream[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@cdiscount[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@clickintext[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@d2.advertserve[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@proximedia[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@roiservice[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@track.effiliation[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracker.affistats[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[4].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[5].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.googleadservices[6].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.proximedia[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Users\yann\Application Data\Microsoft\Windows\Cookies\Low\yann@xiti[1].txt
C:\Users\yann\Cookies\Low\yann@2101.stats.misstrends[2].txt
C:\Users\yann\Cookies\Low\yann@ad.wedoo[1].txt
C:\Users\yann\Cookies\Low\yann@ad.zanox[2].txt
C:\Users\yann\Cookies\Low\yann@adserver.aol[1].txt
C:\Users\yann\Cookies\Low\yann@adv.surinter[2].txt
C:\Users\yann\Cookies\Low\yann@advertstream[1].txt
C:\Users\yann\Cookies\Low\yann@cdiscount[1].txt
C:\Users\yann\Cookies\Low\yann@clickintext[2].txt
C:\Users\yann\Cookies\Low\yann@d2.advertserve[1].txt
C:\Users\yann\Cookies\Low\yann@fr.classic.clickintext[1].txt
C:\Users\yann\Cookies\Low\yann@m1.webstats.motigo[1].txt
C:\Users\yann\Cookies\Low\yann@proximedia[1].txt
C:\Users\yann\Cookies\Low\yann@richmedia.yahoo[1].txt
C:\Users\yann\Cookies\Low\yann@roiservice[1].txt
C:\Users\yann\Cookies\Low\yann@stat.hi-pi[1].txt
C:\Users\yann\Cookies\Low\yann@track.effiliation[1].txt
C:\Users\yann\Cookies\Low\yann@tracker.affistats[2].txt
C:\Users\yann\Cookies\Low\yann@tracker.esecure-transaction[1].txt
C:\Users\yann\Cookies\Low\yann@tracking.veille-referencement[2].txt
C:\Users\yann\Cookies\Low\yann@weba.cdiscount[1].txt
C:\Users\yann\Cookies\Low\yann@www.googleadservices[4].txt
C:\Users\yann\Cookies\Low\yann@www.googleadservices[5].txt
C:\Users\yann\Cookies\Low\yann@www.googleadservices[6].txt
C:\Users\yann\Cookies\Low\yann@www.proximedia[2].txt
C:\Users\yann\Cookies\Low\yann@www.sexyavenue[2].txt
C:\Users\yann\Cookies\Low\yann@www.sexyvideos[2].txt
C:\Users\yann\Cookies\Low\yann@xiti[1].txt




SUPERAntiSpyware Scan Log
https://www.superantispyware.com/

Generated 03/05/2009 at 10:25 PM

Application Version : 4.25.1014

Core Rules Database Version : 3784
Trace Rules Database Version: 1741

Scan type : Complete Scan
Total Scan Time : 02:39:24

Memory items scanned : 715
Memory threats detected : 0
Registry items scanned : 8444
Registry threats detected : 1
File items scanned : 2021264
File threats detected : 63

Adware.Vundo Variant
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{7555906D-70F1-4FD6-8250-4FBE75252F58}

Adware.Tracking Cookie
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@serving-sys[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@serving-sys[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\Application Data\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
C:\Documents and Settings\amélie\Cookies\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@ad.proxad[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adserver.aol[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adtech[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@adultfriendfinder[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@advertising[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@apmebf[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@atdmt[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@bluestreak[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@bs.serving-sys[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@cetelem.solution.weborama[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@doubleclick[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@media.adrevolver[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@media.brandreachsys[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@mediaplex[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@rm.piximedia[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@serving-sys[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@smartadserver[2].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@tradedoubler[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@weborama[1].txt
C:\Documents and Settings\amélie\Cookies\Low\amélie@xiti[1].txt
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 502
 
Supprimer déjà en regardant bien le tuto ce qu'à trouvé SAS, ensuite fait moi unn dernier hijackthis, puis ceci :
https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
0
amyann
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:33:42, on 02/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\vVX1000.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
0
amyann
 
je ne pense pas q ce soit le bon rapport!!
0
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 502
 
si j'attends maintenant le scan panda.
0
amyann
 
ok, c'est en route!!
0
amyann
 
Résultats : 17 virus ou logiciels espions détectés.
Eléments suspects: Aucun fichier suspect détecté.
Vulnérabilités : Aucune vulnérabilité détectée.
0
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 502
 
tu peux me poster le rapport STP. Merci.
0
amyann
 
je dois recommencer le scan car j'ai dû m'absenter et je n'ai pas le rapport!!
il ne comporte qu'une ligne :
<div class="decalage1"><img src="GenProcPage/1.gif" />Poste un rapport <a href="https://www.micro-astuce.com/securite/NanoScan-Panda.php" target="_blank"><em>NanoScan</em></a><br /><br /></div>
0
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 502
 
il faut que je sache le nom des virus pour finir la désinfection.
0
amyann
 
ok! c'est en route
0
amyann
 
;***********************************************************************************************************************************************************************************
ANALYSIS: 2009-03-11 07:05:22
PROTECTIONS: 5
MALWARE: 17
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
avast! antivirus 4.8.1335 [VPS 090309-0] 4.8.1335 Yes Yes
Spybot - Search and Destroy 1.0.0.6 No No
Windows Defender 1.1.1505.0 No Yes
SUPERAntiSpyware 4, 25, 0, 1014 No Yes
avast! antivirus 4.8.1335 [VPS 090309-0] 4.8.1335 No Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@doubleclick[2].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@doubleclick[2].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@atdmt[2].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@atdmt[2].txt
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@tradedoubler[1].txt
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@247realmedia[1].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@mediaplex[1].txt
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@xiti[1].txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@apmebf[1].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@serving-sys[1].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bs.serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\amélie@bs.serving-sys[2].txt
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[3].txt
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@weborama[2].txt
00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adtech[1].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@advertising[1].txt
00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@bluestreak[1].txt
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adrevolver[2].txt
00191644 Cookie/adultfriendfinder TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adultfriendfinder[2].txt
00207936 Cookie/Adviva TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adviva[2].txt
00207936 Cookie/Adviva TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@adviva[3].txt
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Users\amélie\AppData\Roaming\Microsoft\Windows\Cookies\Low\amélie@smartadserver[2].txt
;===================================================================================================================================================================================
SUSPECTS
Sent Location ��&W���39
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description ��&W���39
;===================================================================================================================================================================================
;===================================================================================================================================================================================
0
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 502
 
plus de virus que des cookies à supprimer avec ccleaner.

Maintenant un dernier hiajckthis.
0
amyann
 
ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:33:42, on 02/03/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16809)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\vVX1000.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O3 - Toolbar: Barre de confiance - {55BDF3B0-C0A8-481A-B8A6-01CD2BE0F3FD} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
O4 - HKLM\..\Run: [HP Software Update] c:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HomePlayer] C:\Program Files\HomePlayer\HomePlayer.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/VistaMSNPUpldfr-fr.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
0
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 502
 
Tu relance hijackthis, mais là tu clique juste sur faire un scan, ensuite tu sélectionne les lignes puis,

O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"

O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)

O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)

O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)

O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...

O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.fr/ImageUploader4.cab

O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.photoservice.com/telechargement/ImageUploader4.cab

Tu cliques en bas sur le bouton FIX CHECKED et valides .

2- Redémarres l'ordi .
( important pour que certaines modifs faites avec hijakthis soient prises en compte )

Ensuite ceci :

Télécharge Toolscleaner sur ton Bureau :

* Double-clique sur ToolsCleaner2.exe et laisse le travailler
* Clique sur Recherche et laisse le scan se terminer.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options facultatives.
* Clique sur Quitter, pour que le rapport puisse se créer.
* Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse

Et enfin comme ton pc n'est pas à jour, il va faloir télécharger le service pack trois de windows et faire ceci pour mettre à jour ton pc :

pour voir si ton pc est à jour :

http://www.filehippo.com/updatechecker/UpdateChecker.exe (attention certain logiciels mis en lien pour les mises à jour peuvent être en anglais, rechercher à ce moment là celui en français)

0
amyann
 
j'ai fait un copier/coller car pas possible d'enregister le rapport : acces refusé!!

C:\Users\amélie\Desktop\LopSD.exe: supprimé !
C:\Users\amélie\Desktop\HJTInstall.exe: supprimé !
C:\Users\amélie\Desktop\ToolBarSD.exe: supprimé !
C:\Users\amélie\Downloads\GenProc.zip: supprimé !
C:\VundoFix.txt: ERREUR DE SUPPRESSION !!
C:\lopR.txt: ERREUR DE SUPPRESSION !!
C:\TB.txt: ERREUR DE SUPPRESSION !!
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Users\amélie\Desktop\GenProc\Page\GenProc[*].html: ERREUR DE SUPPRESSION !!
C:\Lop SD: supprimé !
C:\Vundofix backups: supprimé !
C:\Toolbar SD: supprimé !
C:\Program Files\Trend Micro\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\amélie\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: supprimé !
C:\Users\amélie\Desktop\GenProc: supprimé !
0
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 502
 
Il va y avoir ça à supprimer manuellement :

C:\VundoFix.txt: ERREUR DE SUPPRESSION !!
C:\lopR.txt: ERREUR DE SUPPRESSION !!
C:\TB.txt: ERREUR DE SUPPRESSION !!
C:\Users\amélie\Desktop\GenProc\Page\GenProc[*].html: ERREUR DE SUPPRESSION !!
C:\Program Files\Trend Micro\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: ERREUR DE SUPPRESSION !!
0
amyann
 
je pense que j'ai tt enlevé!!
0
pimprenelle27 Messages postés 22182 Statut Contributeur sécurité 2 502
 
Tu as fait le dernier pour la mise à jour de ton pc?
0
amyann
 
il y a tt ça!!!

13 Updates Detected
CCleaner 2.17.853
Installed Version: 2.10.0.618 3.04MB
DAEMON Tools Lite 4.30.3
Installed Version: 4.10.0.0 6.98MB
eMule 0.49c
Installed Version: 0.48.0.8 3.19MB
Firefox 3.0.7
Installed Version: 2.0.0.2 7.17MB
Flash Player 10.0.22.87 (IE)
Installed Version: 9.0.124.0 1.83MB
Java Runtime Environment 1.6.0.12
Installed Version: 1.6.0.7 15.52MB
LimeWire Basic 5.1.2
Installed Version: 4.16.6.0 15.74MB
OpenOffice.org 3.0.1 Final
Installed Version: 2.4.1 128.05MB
QuickTime Player 7.60.92.0
Installed Version: 7.2.0.240 20.86MB
RealPlayer 11.0.0.581
Installed Version: 6.0.12.1741 12.72MB
uTorrent 1.8.2 Build 14458
Installed Version: 1.8.1.12639 264KB
Windows Live Messenger 2009 (14.0.8064)
Installed Version: 8.1.178.0 1.09MB
WinRAR 3.80
Installed Version: 3.50.0.0 1.18MB
Total size: 217.63MB

2 Beta Updates Detected
Firefox 3.1 Beta 3
Installed Version: 2.0.0.2 7.55MB
uTorrent 1.8.3 Beta 14755
Installed Version: 1.8.1.12639 275KB
Total size: 7.82MB

Computer scan time: 5.436 secs
FileHippo processing time: 0.003 secs
Update Checker version: 1.030
Clear results - Report a Problem
0