Problème de spyware

Bonjour

Je ss déjà venu une paire de fois et vous m'aviez bien aider c'est pourqoi je fé encore apel à vous aujourd'hui.
Mon problème est que je me connecte à internet par Mozilla Firefox donc je ne peut pas faire des scan sur ravantivirus.com je le fait donc avec spywarestromer qui me detecte 22 virus je n'arrive pa à copier le resultat mais dans les résultats il est marqué que C'est de types: adware, spyware et tracking cookie!!

Je ne sais pas qoi faire est ce que quelqu'un peut m'aider?

Merci d'avance

Sophie

26 réponses

Résumé de la discussion

Le problème principal est l'installation présumée d'un logiciel jugé douteux, SpywareStormer, qui est considéré comme une menace et produit des adwares et des cookies de suivi qui compromettent la navigation. Pour remédier à cela, la meilleure réponse préconise de désinstaller ce programme, puis de lancer des scans avec plusieurs outils anti‑spyware tels qu AdAware SE, Spybot S&D, SpySweeper, PestPatrol et SpyDoctor. Si aucun élément n'est détecté, il est recommandé de poursuivre la surveillance, de maintenir l'antivirus et le pare‑feu à jour et d'envisager des nettoyages complémentaires si nécessaire. Des précautions additionnelles impliquent l'utilisation éventuelle du mode sans échec pour supprimer les menaces résiduelles et le respect de bonnes pratiques comme la mise à jour système et l'installation d'un firewall efficace.

Bobot (l’IA à votre service)
  1. Bonsoir Sophie,

    D'abord commences par faire une élimination de tous les cookies par outils/options/vie privée.
    Ensuite passes un antivirus (au choix norton ou autre), puis spybot(pour les spywares), a² (pour les adwares), cwschredder, et toute la panoplie possible d'antibestiole.
    Curieux que tu ne puisses pas faire de scan en ligne avec mozilla ?
    Ce ne serait pas plutôt un firewall que tu aurais ???
    Si tu n'as pas d'amélioration fais un log avec hijackthis et passes le sur le forum, une bonne âme t'éclairera.
    Va également sur ce site où il y a une biblio très complète sur les traitements antiviraux:
    http://assiste.free.fr/p/frameset/01.php

    Bon courage
    0
    1. salut sophie.

      je sais pas si sa va te venir en aide mais tu peux telecharger

      microsoft aitispyware beta 1 il et gratuit sur telecharger .com

      tiens moi au courant
      0
      1. Bonsoir merci pour la rapidité de réponse c'est très gentil!

        Je n'ai pas compris comment surpimer mes cokies!Pour outils option des dossiers c'est bon mais vie privé j'ai pas!!
        Et pour lre rest des logiciels vous savez ou je pourrais aller les chercher?

        Merci d'avance

        Sophie
        0
        1. Re

          Je ne trouve pas microsoft aitispyware beta 1 sur telecharger.com il me dit qu'il n'y a aucun logiciel à ce nom!!
          Et j'ai norton comme antivirus mais pour le reste des logiciel je ne connai pas ou je vais les chercher

          Merci d'avance

          Sophie
          0
          1. recoucou voila le non preci Microsoft AntiSpyware

            dans recherche tu mais AntiSpyware tu verra il sont deux tu prend

            le premier tien moi au courrant
            0
            1. salut tu a resolut ton probleme?
              0
              1. Bonjour

                Merci encore une fois pour votre aide!!ALor j'ai t élécharger aitispyware beta 1 qui ne ma trouver q'un virus et qui ne la pas suprimer j' ai télécharger un autre spybot qui ma suprimer 13 virus et il me reste tt les virus avec les cookies et ladwres.

                Merci d'avance

                Sophie
                0
                1. Salut Sophie,

                  Désolé de n'être pas revenu plus tôt dans le forum.
                  Ce que tu me réponds correspond plus à la fenêtre de l'explorateur windows que de mozilla. Il faut que tu soies dans mozilla pour outils/option/vie privée. Tu peux même lancer mozilla sans être connectée pour le faire.
                  Tu peux passer aussi ad aware SE personnal téléchargeable là:
                  Ad-aware
                  N'oublies pas de faire une mise à jour avant de lancer le logiciel

                  Bon courage
                  0
                  1. Bonjour

                    Merci de votre aide.Je ne comprend pas le rapport avec l'explorateur windows moi on m'avais dit de supprimer les cookies

                    MErci d'avance

                    Sophie
                    0
                    1. Salut Sophie,

                      Simplement dans ton message n°3 tu parles "d'option des dossiers", ce qui est l'appellation dans l'explorateur windows, mais non dans mozilla.
                      Les coockies peuvent également se supprimer par l'explorateur windows mais il faut y aller à la pêche et à la main. C'est plus simple de passer par l'explorateur internet (ie ou mozilla°

                      Autrement ça s'arrange ??
                      A+
                      0
                      1. Bonsoir

                        Merci de votre aide alor ça s'arrange doucement mais j'ai toujours mes virus dans mes cokies et je ne sais toujours pas les supptimer

                        Merci d'avance

                        Sophie
                        0
                        1. Bonsoir

                          Merci pour votre aide. J'ai télécharger tout les logociels que vous m'avez conseillé mes rien ne marche j'ai mintean 20 virus que je ne sais pas suprrimer dont une grtande partie de cookies que je ne sais pas supprimer il y a des adware s psyware...malgrès les logiciels!!

                          Que dois je faire?

                          Merci d'avance

                          Sophie
                          0
                          1. Bonoir

                            Merci pr votre aide!!

                            Mon problème est que malgrès tt ce que vous m'avez conseiller meme clean up!!Mais mes virus perssitent j'an ei mintenan 7 constants que des spywares ils sont en extreme risques mon ordinateur est de plus en plus long sur internet!!

                            Que dois je faire?

                            Merci d'avance

                            Sophie
                            0
                            1. Bonsoir

                              Merci de votre aide!!Pour le scan sur ravantivirus je n'y arrive pas!!Il me demande de choisir ce que je doi scanner et je ne pe que scanner un dossier à la fois pas mo disque dur!!!

                              J'ai télécharger hijckthis et voila le scan je ne sais pas quoi en faire

                              Logfile of HijackThis v1.99.1
                              Scan saved at 19:50:25, on 16/03/2005
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                              C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                              C:\Program Files\Norton AntiVirus\navapsvc.exe
                              C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                              C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
                              C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
                              C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                              C:\Program Files\RamBoost XP\rambxpfr.exe
                              C:\Program Files\eMule\emule.exe
                              C:\PROGRA~1\NORTON~1\navw32.exe
                              C:\WINDOWS\explorer.exe
                              C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
                              C:\Program Files\WinRAR\WinRAR.exe
                              C:\DOCUME~1\Sylvie\LOCALS~1\Temp\Rar$EX04.813\HijackThis.exe
                              C:\Program Files\Messenger\msmsgs.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.free.fr/search/
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.free.fr/
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                              O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                              O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                              O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
                              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                              O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Fichiers communs\Symantec Shared\ccRegVfy.exe"
                              O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                              O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
                              O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
                              O4 - HKLM\..\Run: [Spyware Stormer] C:\Program Files\Spyware Stormer\SpywareStormer.Exe
                              O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\nbj.exe"
                              O4 - Global Startup: PI Monitor.lnk = C:\Program Files\ArcSoft\PhotoImpression 5\PI Monitor.exe
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                              O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
                              O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
                              O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
                              O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O14 - IERESET.INF: START_PAGE_URL=http://home.free.fr/
                              O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                              O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                              O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                              O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                              O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
                              O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                              O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                              O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

                              Merci d'avance

                              Sophie
                              0
                              1. Salut Sophie,

                                Pas facile de se protéger sur le net de nos jours...

                                Pour scanner ton pc en ligne tu peux aller sur secuser.com;

                                Si tu utilises Norton antivirus, il arrive qu'il detecte des virus mais qu'il n'arrive pas à les supprimer. En demarrant ton pc en
                                'mode sans echec' par contre, il arrivera a les supprimer ou alors tu pourra les supprimer manuellement.
                                1. Mettre a jour ton antivirus,
                                2. Demarrer en mode sans echec (appuyer sur F8 au demarrage, quand l'ecran est noir)
                                3. Lancer un scan
                                4. Supprimer manuellement ceux que l'antivirus ne veut pas supprimer;

                                Contre les spywares, utilise adaware, spybot, a2;

                                Comme antivirus tu peux utiliser Bitdefender;

                                Si tu arrives a désinfecter ton pc :
                                1. mettre a jour ton windows (windows update)
                                2. installer un firewall (zone alarme,par ex)
                                3. avoir un antivirus a jour
                                4. lancer un logiciel antispyware 1*/semaine

                                Voila, j'espere que ca pourra t'aider

                                courage...
                                0
                            2. Bonjour

                              Je n'arrive toujours pas à enlever les 5 spyware restant commen dois je faire?

                              Merci d'avance

                              Sophie
                              0
                              1. salut
                                en fait ton pbm est lié a l'installation de ce logiciel SpywareStormer peu recommandable selon ceci listé comme ROGUE
                                http://startup.iamnotageek.com/srch-Spyware%20Stormer.html
                                c'est lui le pollueur de spy.

                                donc désinstalle ce pgm et fais un scan avec AdAwareSE , SpybotS&D et SpySwepper, PestPatrol, SpyDoctor
                                si eux ne détectent rien alors ok
                                a+
                                0
                              2. Bonsoir

                                Merci beaucoup pour votre aide!!

                                Comme vous me l'avez conseillé j'ai télécherger adawar mais d'après le scan de hijackthis (ci dessus) je ne dois rien faire?

                                Pour celui de adaware je ne sais pascomment copier et coller le scan

                                Ad-Aware SE Build 1.05
                                Logfile Created on:vendredi 18 mars 2005 19:25:06
                                Created with Ad-Aware SE Personal, free for private use.
                                Using definitions file:SE1R33 16.03.2005
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                References detected during the scan:
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                Masta Dialer(TAC index:5):3 total references
                                Possible Browser Hijack attempt(TAC index:3):1 total references
                                Tracking Cookie(TAC index:3):4 total references
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                Ad-Aware SE Settings
                                ===========================
                                Set : Search for negligible risk entries
                                Set : Safe mode (always request confirmation)
                                Set : Scan active processes
                                Set : Scan registry
                                Set : Deep-scan registry
                                Set : Scan my IE Favorites for banned URLs
                                Set : Scan my Hosts file

                                Extended Ad-Aware SE Settings
                                ===========================
                                Set : Unload recognized processes & modules during scan
                                Set : Scan registry for all users instead of current user only
                                Set : Always try to unload modules before deletion
                                Set : During removal, unload Explorer and IE if necessary
                                Set : Let Windows remove files in use at next reboot
                                Set : Delete quarantined objects after restoring
                                Set : Include basic Ad-Aware settings in log file
                                Set : Include additional Ad-Aware settings in log file
                                Set : Include reference summary in log file
                                Set : Include alternate data stream details in log file
                                Set : Play sound at scan completion if scan locates critical objects

                                18-03-2005 19:25:06 - Scan started. (Full System Scan)

                                Listing running processes
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                #:1 [smss.exe]
                                FilePath : \SystemRoot\System32\
                                ProcessID : 460
                                ThreadCreationTime : 18-03-2005 16:38:03
                                BasePriority : Normal

                                #:2 [csrss.exe]
                                FilePath : \??\C:\WINDOWS\system32\
                                ProcessID : 672
                                ThreadCreationTime : 18-03-2005 16:38:05
                                BasePriority : Normal

                                #:3 [winlogon.exe]
                                FilePath : \??\C:\WINDOWS\system32\
                                ProcessID : 704
                                ThreadCreationTime : 18-03-2005 16:38:05
                                BasePriority : High

                                #:4 [services.exe]
                                FilePath : C:\WINDOWS\system32\
                                ProcessID : 748
                                ThreadCreationTime : 18-03-2005 16:38:06
                                BasePriority : Normal
                                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                ProductVersion : 5.1.2600.2180
                                ProductName : Système d'exploitation Microsoft® Windows®
                                CompanyName : Microsoft Corporation
                                FileDescription : Applications Services et Contrôleur
                                InternalName : services.exe
                                LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                                OriginalFilename : services.exe

                                #:5 [lsass.exe]
                                FilePath : C:\WINDOWS\system32\
                                ProcessID : 760
                                ThreadCreationTime : 18-03-2005 16:38:06
                                BasePriority : Normal
                                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                ProductVersion : 5.1.2600.2180
                                ProductName : Microsoft® Windows® Operating System
                                CompanyName : Microsoft Corporation
                                FileDescription : LSA Shell (Export Version)
                                InternalName : lsass.exe
                                LegalCopyright : © Microsoft Corporation. All rights reserved.
                                OriginalFilename : lsass.exe

                                #:6 [svchost.exe]
                                FilePath : C:\WINDOWS\system32\
                                ProcessID : 900
                                ThreadCreationTime : 18-03-2005 16:38:07
                                BasePriority : Normal
                                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                ProductVersion : 5.1.2600.2180
                                ProductName : Microsoft® Windows® Operating System
                                CompanyName : Microsoft Corporation
                                FileDescription : Generic Host Process for Win32 Services
                                InternalName : svchost.exe
                                LegalCopyright : © Microsoft Corporation. All rights reserved.
                                OriginalFilename : svchost.exe

                                #:7 [svchost.exe]
                                FilePath : C:\WINDOWS\system32\
                                ProcessID : 956
                                ThreadCreationTime : 18-03-2005 16:38:08
                                BasePriority : Normal
                                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                ProductVersion : 5.1.2600.2180
                                ProductName : Microsoft® Windows® Operating System
                                CompanyName : Microsoft Corporation
                                FileDescription : Generic Host Process for Win32 Services
                                InternalName : svchost.exe
                                LegalCopyright : © Microsoft Corporation. All rights reserved.
                                OriginalFilename : svchost.exe

                                #:8 [svchost.exe]
                                FilePath : C:\WINDOWS\System32\
                                ProcessID : 1112
                                ThreadCreationTime : 18-03-2005 16:38:08
                                BasePriority : Normal
                                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                ProductVersion : 5.1.2600.2180
                                ProductName : Microsoft® Windows® Operating System
                                CompanyName : Microsoft Corporation
                                FileDescription : Generic Host Process for Win32 Services
                                InternalName : svchost.exe
                                LegalCopyright : © Microsoft Corporation. All rights reserved.
                                OriginalFilename : svchost.exe

                                #:9 [svchost.exe]
                                FilePath : C:\WINDOWS\System32\
                                ProcessID : 1168
                                ThreadCreationTime : 18-03-2005 16:38:08
                                BasePriority : Normal
                                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                ProductVersion : 5.1.2600.2180
                                ProductName : Microsoft® Windows® Operating System
                                CompanyName : Microsoft Corporation
                                FileDescription : Generic Host Process for Win32 Services
                                InternalName : svchost.exe
                                LegalCopyright : © Microsoft Corporation. All rights reserved.
                                OriginalFilename : svchost.exe

                                #:10 [svchost.exe]
                                FilePath : C:\WINDOWS\System32\
                                ProcessID : 1260
                                ThreadCreationTime : 18-03-2005 16:38:08
                                BasePriority : Normal
                                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                ProductVersion : 5.1.2600.2180
                                ProductName : Microsoft® Windows® Operating System
                                CompanyName : Microsoft Corporation
                                FileDescription : Generic Host Process for Win32 Services
                                InternalName : svchost.exe
                                LegalCopyright : © Microsoft Corporation. All rights reserved.
                                OriginalFilename : svchost.exe

                                #:11 [spoolsv.exe]
                                FilePath : C:\WINDOWS\system32\
                                ProcessID : 1640
                                ThreadCreationTime : 18-03-2005 16:38:09
                                BasePriority : Normal
                                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                ProductVersion : 5.1.2600.2180
                                ProductName : Microsoft® Windows® Operating System
                                CompanyName : Microsoft Corporation
                                FileDescription : Spooler SubSystem App
                                InternalName : spoolsv.exe
                                LegalCopyright : © Microsoft Corporation. All rights reserved.
                                OriginalFilename : spoolsv.exe

                                #:12 [ccevtmgr.exe]
                                FilePath : C:\Program Files\Fichiers communs\Symantec Shared\
                                ProcessID : 1700
                                ThreadCreationTime : 18-03-2005 16:38:10
                                BasePriority : Normal
                                FileVersion : 1.03.4
                                ProductVersion : 1.03.4
                                ProductName : Event Manager
                                CompanyName : Symantec Corporation
                                FileDescription : Event Manager Service
                                InternalName : ccEvtMgr
                                LegalCopyright : Copyright (c) 2000-2002 Symantec Corporation. All rights reserved.
                                OriginalFilename : ccEvtMgr.exe

                                #:13 [explorer.exe]
                                FilePath : C:\WINDOWS\
                                ProcessID : 1800
                                ThreadCreationTime : 18-03-2005 16:38:10
                                BasePriority : Normal
                                FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
                                ProductVersion : 6.00.2900.2180
                                ProductName : Système d'exploitation Microsoft® Windows®
                                CompanyName : Microsoft Corporation
                                FileDescription : Explorateur Windows
                                InternalName : explorer
                                LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                                OriginalFilename : EXPLORER.EXE

                                #:14 [cdac11ba.exe]
                                FilePath : C:\WINDOWS\system32\drivers\
                                ProcessID : 616
                                ThreadCreationTime : 18-03-2005 16:38:12
                                BasePriority : Normal
                                FileVersion : 4.20.020
                                ProductVersion : 4.20.020 Windows NT 2002/12/10
                                ProductName : SafeCast Windows NT
                                CompanyName : Macrovision
                                FileDescription : Macrovision RTS Service
                                InternalName : CDANTSRV
                                LegalCopyright : Copyright (c) 1998-2002 Macrovision Corp.
                                OriginalFilename : CDANTSRV.EXE
                                Comments : StringFileInfo: U.S. English

                                #:15 [ccapp.exe]
                                FilePath : C:\Program Files\Fichiers communs\Symantec Shared\
                                ProcessID : 724
                                ThreadCreationTime : 18-03-2005 16:38:12
                                BasePriority : Normal
                                FileVersion : 1.0.10.006
                                ProductVersion : 1.0.10.006
                                ProductName : Common Client
                                CompanyName : Symantec Corporation
                                FileDescription : Common Client CC App
                                InternalName : ccApp
                                LegalCopyright : Copyright (c) 2000-2002 Symantec Corporation. All rights reserved.
                                OriginalFilename : ccApp.exe

                                #:16 [navapsvc.exe]
                                FilePath : C:\Program Files\Norton AntiVirus\
                                ProcessID : 908
                                ThreadCreationTime : 18-03-2005 16:38:12
                                BasePriority : Normal
                                FileVersion : 9.05.1015
                                ProductVersion : 9.05.1015
                                ProductName : Norton AntiVirus
                                CompanyName : Symantec Corporation
                                FileDescription : Norton AntiVirus Auto-Protect Service
                                InternalName : NAVAPSVC
                                LegalCopyright : Copyright (c) 2000-2002 Symantec Corporation. All rights reserved.
                                OriginalFilename : NAVAPSVC.EXE

                                #:17 [nprotect.exe]
                                FilePath : C:\Program Files\Norton AntiVirus\AdvTools\
                                ProcessID : 1056
                                ThreadCreationTime : 18-03-2005 16:38:13
                                BasePriority : Normal
                                FileVersion : 16.00.0.22
                                ProductVersion : 16.00.0.22
                                ProductName : Norton Utilities
                                CompanyName : Symantec Corporation
                                FileDescription : Norton Protection Status
                                InternalName : NPROTECT
                                LegalCopyright : Copyright (C) 2003 Symantec Corporation
                                LegalTrademarks : Norton Utilities
                                OriginalFilename : NPROTECT.EXE

                                #:18 [jusched.exe]
                                FilePath : C:\Program Files\Java\jre1.5.0\bin\
                                ProcessID : 1104
                                ThreadCreationTime : 18-03-2005 16:38:13
                                BasePriority : Normal

                                #:19 [svchost.exe]
                                FilePath : C:\WINDOWS\System32\
                                ProcessID : 1416
                                ThreadCreationTime : 18-03-2005 16:38:15
                                BasePriority : Normal
                                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                ProductVersion : 5.1.2600.2180
                                ProductName : Microsoft® Windows® Operating System
                                CompanyName : Microsoft Corporation
                                FileDescription : Generic Host Process for Win32 Services
                                InternalName : svchost.exe
                                LegalCopyright : © Microsoft Corporation. All rights reserved.
                                OriginalFilename : svchost.exe

                                #:20 [wdfmgr.exe]
                                FilePath : C:\WINDOWS\System32\
                                ProcessID : 1580
                                ThreadCreationTime : 18-03-2005 16:38:15
                                BasePriority : Normal
                                FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
                                ProductVersion : 5.2.3790.1230
                                ProductName : Microsoft® Windows® Operating System
                                CompanyName : Microsoft Corporation
                                FileDescription : Windows User Mode Driver Manager
                                InternalName : WdfMgr
                                LegalCopyright : © Microsoft Corporation. All rights reserved.
                                OriginalFilename : WdfMgr.exe

                                #:21 [pi monitor.exe]
                                FilePath : C:\Program Files\ArcSoft\PhotoImpression 5\
                                ProcessID : 1612
                                ThreadCreationTime : 18-03-2005 16:38:15
                                BasePriority : Normal
                                FileVersion : 1, 0, 0, 7
                                ProductVersion : 1, 0, 0, 7
                                ProductName : PI Monitor
                                CompanyName : Arcsoft, Inc.
                                FileDescription : PI Monitor
                                InternalName : PI Monitor
                                LegalCopyright : Copyright 2003
                                OriginalFilename : PI Monitor.exe

                                #:22 [symwsc.exe]
                                FilePath : C:\Program Files\Fichiers communs\Symantec Shared\Security Center\
                                ProcessID : 600
                                ThreadCreationTime : 18-03-2005 16:38:21
                                BasePriority : Normal
                                FileVersion : 2005.1.2.20
                                ProductVersion : 2005.1
                                ProductName : Norton Security Center
                                CompanyName : Symantec Corporation
                                FileDescription : Norton Security Center Service
                                InternalName : SymWSC.exe
                                LegalCopyright : Copyright (c) 1997-2004 Symantec Corporation
                                OriginalFilename : SymWSC.exe

                                #:23 [alg.exe]
                                FilePath : C:\WINDOWS\System32\
                                ProcessID : 2516
                                ThreadCreationTime : 18-03-2005 16:38:27
                                BasePriority : Normal
                                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                                ProductVersion : 5.1.2600.2180
                                ProductName : Microsoft® Windows® Operating System
                                CompanyName : Microsoft Corporation
                                FileDescription : Application Layer Gateway Service
                                InternalName : ALG.exe
                                LegalCopyright : © Microsoft Corporation. All rights reserved.
                                OriginalFilename : ALG.exe

                                #:24 [emule.exe]
                                FilePath : C:\Program Files\eMule\
                                ProcessID : 3624
                                ThreadCreationTime : 18-03-2005 16:52:19
                                BasePriority : Normal
                                FileVersion : 0.44.3 Unicode
                                ProductVersion : 0.44.3 Unicode
                                ProductName : eMule
                                CompanyName : http://www.emule-project.net
                                FileDescription : eMule
                                InternalName : emule.exe
                                LegalCopyright : Copyright © 2002-2004 Merkur - read license.txt for more infos
                                OriginalFilename : emule.exe

                                #:25 [msiexec.exe]
                                FilePath : C:\WINDOWS\System32\
                                ProcessID : 2244
                                ThreadCreationTime : 18-03-2005 18:21:17
                                BasePriority : Normal

                                #:26 [msmsgs.exe]
                                FilePath : C:\Program Files\Messenger\
                                ProcessID : 3316
                                ThreadCreationTime : 18-03-2005 18:24:57
                                BasePriority : Normal
                                FileVersion : 4.7.3001
                                ProductVersion : Version 4.7.3001
                                ProductName : Messenger
                                CompanyName : Microsoft Corporation
                                FileDescription : Windows Messenger
                                InternalName : msmsgs
                                LegalCopyright : Copyright (c) Microsoft Corporation 2004
                                LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
                                OriginalFilename : msmsgs.exe

                                #:27 [ad-aware.exe]
                                FilePath : C:\PROGRA~1\LAVASOFT\AD-AWA~1\
                                ProcessID : 2864
                                ThreadCreationTime : 18-03-2005 18:24:59
                                BasePriority : Normal
                                FileVersion : 6.2.0.206
                                ProductVersion : VI.Second Edition
                                ProductName : Lavasoft Ad-Aware SE
                                CompanyName : Lavasoft Sweden
                                FileDescription : Ad-Aware SE Core application
                                InternalName : Ad-Aware.exe
                                LegalCopyright : Copyright © Lavasoft Sweden
                                OriginalFilename : Ad-Aware.exe
                                Comments : All Rights Reserved

                                Memory scan result:
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                New critical objects: 0
                                Objects found so far: 0

                                Started registry scan
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                Masta Dialer Object Recognized!
                                Type : Regkey
                                Data :
                                Category : Malware
                                Comment :
                                Rootkey : HKEY_USERS
                                Object : S-1-5-21-507921405-329068152-839522115-1003\software\masta

                                Masta Dialer Object Recognized!
                                Type : RegValue
                                Data :
                                Category : Malware
                                Comment :
                                Rootkey : HKEY_USERS
                                Object : S-1-5-21-507921405-329068152-839522115-1003\software\masta
                                Value : KNum

                                Registry Scan result:
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                New critical objects: 2
                                Objects found so far: 2

                                Started deep registry scan
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                Possible Browser Hijack attempt : S-1-5-21-507921405-329068152-839522115-1003\Software\Microsoft\Internet Explorer\MainStart Pagerunonce.msn.com

                                Possible Browser Hijack attempt Object Recognized!
                                Type : RegData
                                Data : "http://runonce.msn.com/"
                                Category : Malware
                                Comment : Possible Browser Hijack attempt
                                Rootkey : HKEY_USERS
                                Object : S-1-5-21-507921405-329068152-839522115-1003\Software\Microsoft\Internet Explorer\Main
                                Value : Start Page
                                Data : "http://runonce.msn.com/"

                                Deep registry scan result:
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                New critical objects: 1
                                Objects found so far: 3

                                Started Tracking Cookie scan
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                Tracking Cookie Object Recognized!
                                Type : IECache Entry
                                Data : sylvie@advertising[1].txt
                                Category : Data Miner
                                Comment : Hits:2
                                Value : Cookie:sylvie@advertising.com/
                                Expires : 16-03-2010 19:28:14
                                LastSync : Hits:2
                                UseCount : 0
                                Hits : 2

                                Tracking Cookie Object Recognized!
                                Type : IECache Entry
                                Data : sylvie@atdmt[2].txt
                                Category : Data Miner
                                Comment : Hits:4
                                Value : Cookie:sylvie@atdmt.com/
                                Expires : 16-03-2010 01:00:00
                                LastSync : Hits:4
                                UseCount : 0
                                Hits : 4

                                Tracking Cookie Object Recognized!
                                Type : IECache Entry
                                Data : sylvie@weborama[2].txt
                                Category : Data Miner
                                Comment : Hits:4
                                Value : Cookie:sylvie@weborama.fr/
                                Expires : 17-03-2007 19:28:10
                                LastSync : Hits:4
                                UseCount : 0
                                Hits : 4

                                Tracking Cookie Object Recognized!
                                Type : IECache Entry
                                Data : sylvie@servedby.advertising[2].txt
                                Category : Data Miner
                                Comment : Hits:3
                                Value : Cookie:sylvie@servedby.advertising.com/
                                Expires : 17-04-2005 19:22:32
                                LastSync : Hits:3
                                UseCount : 0
                                Hits : 3

                                Tracking cookie scan result:
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                New critical objects: 4
                                Objects found so far: 7

                                Deep scanning and examining files (C:)
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                Disk Scan Result for C:\
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                New critical objects: 0
                                Objects found so far: 7

                                Deep scanning and examining files (D:)
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                Disk Scan Result for D:\
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                New critical objects: 0
                                Objects found so far: 7

                                Deep scanning and examining files (E:)
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                Disk Scan Result for E:\
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                New critical objects: 0
                                Objects found so far: 7

                                Scanning Hosts file......
                                Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                Hosts file scan result:
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                1 entries scanned.
                                New critical objects:0
                                Objects found so far: 7

                                Performing conditional scans...
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                                Masta Dialer Object Recognized!
                                Type : Folder
                                Category : Malware
                                Comment :
                                Object : C:\Program Files\Masta

                                Conditional scan result:
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                New critical objects: 1
                                Objects found so far: 8

                                19:32:29 Scan Complete

                                Summary Of This Scan
                                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                                Total scanning time:00:07:22.891
                                Objects scanned:90889
                                Objects identified:8
                                Objects ignored:0
                                New critical objects:8

                                Je sais pas si c'est ça mais que dois j faire car je ne sais pas lire les résultats!!

                                Merci d'avance

                                Sophie
                                0
                              3. Bonjour

                                Merci de votre aide voici le dernier scan de clean up!!
                                CleanUp! started on 03/19/05 13:29:44.
                                C:\Documents and Settings\Sylvie\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
                                C:\Documents and Settings\Sylvie\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
                                C:\Documents and Settings\Sylvie\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
                                Visited: Sylvie@about:blank - deleted
                                Visited: Sylvie@res://C:\PROGRA~1\NORTON~1\NAVUI.dll/scan.htm - deleted
                                Visited: Sylvie@res://C:\PROGRA~1\NORTON~1\NAVUI.dll/navstats.htm - deleted
                                Visited: Sylvie@res://C:\PROGRA~1\NORTON~1\NAVComUI.DLL/CommonUIProgress.htm - deleted
                                'Typed URLs' (Internet Explorer) - removed from the registry.
                                C:\Documents and Settings\Sylvie\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
                                C:\DOCUME~1\Sylvie\LOCALS~1\Temp\jusched.log - deleted
                                C:\Documents and Settings\Sylvie\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
                                C:\Documents and Settings\Sylvie\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
                                C:\Documents and Settings\Sylvie\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
                                C:\Documents and Settings\Sylvie\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
                                C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
                                C:\Documents and Settings\LocalService\locals~1\tempor~1\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
                                C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
                                C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
                                'Run MRU' list - removed from the registry.
                                Telnet's MRU list - removed from the registry.
                                CleanUp! recovered 206 bytes of disk space from 5 files.
                                CleanUp! finished on 03/19/05 13:29:45.

                                Qu'est ce qui ve dire?Que dois je faire?

                                Merci d'avance

                                Sophie
                                0
                            3. bonjour,
                              j ai une suggestion mais je ne sais pas si elle est correct lol
                              le dernier scan affiche ce message Will be deleted when Windows is restarted. c est a dire qu au prochain demarrage, sophie n aura plus rien car cela sera supprimer automatiquement?
                              Mais en ce qui concerne temporary intenretC :\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted<<<ceci n est pas grave car c est juste l historique de ce qu elle consulte sur internet non? elle a juste a vider cela non?
                              0
                              • 1
                              • 2