Bonjour !
j'ai suivi vos instructions pour nettoyer mon PC...je vous envoie maintenant les 3 rapports de scan ewido,bitdefender et hijackthis
je vous remercie
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 14:40:38 2006-10-26
+ Scan result:
C:\System Volume Information\_restore{F4366600-3349-4568-8E77-53B1930FD393}\RP454\A0109359.dll -> Adware.BHO : No action taken.
C:\WINDOWS\system32\ucsi.exe -> Backdoor.Agent.bc : No action taken.
C:\eied_s7.cab/eied_s7_c_145.exe -> Downloader.Mediket.aa : No action taken.
C:\tpjtsip.exe -> Downloader.Small.csn : No action taken.
C:\awcqywdq.exe -> Downloader.Small.ctf : No action taken.
C:\Documents and Settings\Dedi\Local Settings\Temp\5.dlb -> Downloader.Small.dgk : No action taken.
C:\Documents and Settings\Dedi\Local Settings\Temp\setup.exe -> Downloader.Tibs.if : No action taken.
C:\Documents and Settings\Dedi\Local Settings\Temp\2.dlb -> Downloader.Tibs.ir : No action taken.
C:\Documents and Settings\Dedi\Local Settings\Temp\6.dlb -> Downloader.Tibs.ir : No action taken.
C:\Documents and Settings\Dedi\Local Settings\Temp\7.dlb -> Downloader.Tibs.ir : No action taken.
C:\ms1.exe -> Downloader.Tiny.bz : No action taken.
C:\WINDOWS\system32\ld89D.tmp -> Downloader.Zlob.ju : No action taken.
C:\System Volume Information\_restore{F4366600-3349-4568-8E77-53B1930FD393}\RP454\A0109357.exe -> Hijacker.Small.kr : No action taken.
C:\Documents and Settings\Dedi\Local Settings\Temporary Internet Files\Content.IE5\8R3FIC9H\WinAntiVirusPro2006FreeInstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\awuakqbw.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : No action taken.
C:\WINDOWS\system32\0mcamcap.exe -> Proxy.Small.bo : No action taken.
C:\WINDOWS\system32\eventwvr.exe -> Proxy.Small.bo : No action taken.
C:\sgncjm.exe -> Proxy.Small.bo : No action taken.
C:\tool3.exe -> Proxy.Small.bo : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Virginie.EZAKITOK-X52U22\Cookies\virginie@opodo.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@adjuggler[1].txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@rotator.adjuggler[2].txt -> TrackingCookie.Adjuggler : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@www.belstat[3].txt -> TrackingCookie.Belstat : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@bluestreak[2].txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : No action taken.
C:\Documents and Settings\rimdel.EZAKITOK-SYYNI2\Cookies\rimdel@com[2].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@fl01.ct2.comclick[1].txt -> TrackingCookie.Comclick : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@estat[1].txt -> TrackingCookie.Estat : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@as1.falkag[2].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@ivwbox[1].txt -> TrackingCookie.Ivwbox : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@sales.liveperson[1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\Virginie.EZAKITOK-X52U22\Cookies\virginie@image.masterstats[1].txt -> TrackingCookie.Masterstats : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@ads.planetactive[1].txt -> TrackingCookie.Planetactive : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@webstat[1].txt -> TrackingCookie.Web-stat : No action taken.
C:\Documents and Settings\rimdel\Cookies\rimdel@webstat[1].txt -> TrackingCookie.Web-stat : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@weborama[2].txt -> TrackingCookie.Weborama : No action taken.
C:\Documents and Settings\rimdel\Cookies\rimdel@yadro[1].txt -> TrackingCookie.Yadro : No action taken.
C:\Documents and Settings\Dedi\Cookies\dedi@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Dedi\Local Settings\Temp\maxdd1.game -> Trojan.Dialer.ay : No action taken.
C:\WINDOWS\Downloaded Program Files\__delete_on_reboot__s_p_o_n_s_o_r_a_d_u_l_t_o_._d_l_l_ -> Trojan.Dialer.fu : No action taken.
[956] C:\WINDOWS\Downloaded Program Files\sponsoradulto.dll -> Trojan.Dialer.fu : No action taken.
C:\System Volume Information\_restore{F4366600-3349-4568-8E77-53B1930FD393}\RP454\A0109360.exe -> Trojan.ProcKill.DJ : No action taken.
C:\System Volume Information\_restore{F4366600-3349-4568-8E77-53B1930FD393}\RP454\A0109361.exe -> Trojan.ProcKill.DJ : No action taken.
C:\System Volume Information\_restore{F4366600-3349-4568-8E77-53B1930FD393}\RP454\A0109362.exe -> Trojan.ProcKill.DJ : No action taken.
C:\System Volume Information\_restore{F4366600-3349-4568-8E77-53B1930FD393}\RP454\A0109363.exe -> Trojan.ProcKill.DJ : No action taken.
C:\WINDOWS\hosts -> Trojan.Qhosts.HE : No action taken.
C:\tool4.exe -> Trojan.Regger.s : No action taken.
C:\kl1.exe -> Trojan.Sinowal.i : No action taken.
C:\splp.exe -> Trojan.Sinowal.v : No action taken.
::Report end
BitDefender Online Scanner
Scan report generated at: Thu, Oct 26, 2006 - 19:39:23
Scan path: A:\;C:\;D:\;E:\;
Statistics
Time
03:47:08
Files
614965
Folders
6119
Boot Sectors
2
Archives
4061
Packed Files
79676
Results
Identified Viruses
2
Infected Files
2
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
2
Engines Info
Virus Definitions
479005
Engine build
AVCORE v1.0 (build 2310) (i386) (Apr 17 2006 16:24:38)
Scan plugins
13
Archive plugins
38
Unpack plugins
6
E-mail plugins
6
System plugins
1
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00003.exe
Infected with: Trojan.PWS.Sinowal.D
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00003.exe
Disinfection failed
C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\_ibm00003.exe
Deleted
C:\Program Files\secure32.html
Infected with: Trojan.SpySheriff.C
C:\Program Files\secure32.html
Disinfection failed
C:\Program Files\secure32.html
Deleted
Logfile of HijackThis v1.99.1
Scan saved at 20:02:32, on 2006-10-26
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe
C:\WINDOWS\System32\wuauclt.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\LVComS.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\System32\WISPTIS.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Dedi\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://www.google.ca/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {03D794A2-1E87-5F0B-8B82-00B118AD587E} - C:\WINDOWS\System32\tnoahwi.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SponsorAdulto Class - {511F9316-771B-4953-A268-1C36DA667FE9} - C:\WINDOWS\Downloaded Program Files\sponsoradulto.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [McRegWiz] C:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [bguhljk.dll] C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\bguhljk.dll,hwkoto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} (SponsorAdulto Class) - http://ip.sponsoradulto.com/cab/3/fr/SysWebTelecomInt.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Afficher la suite