Infection IE 7
Résolu
niko99
Messages postés
80
Statut
Membre
-
philae83 Messages postés 12854 Statut Contributeur sécurité -
philae83 Messages postés 12854 Statut Contributeur sécurité -
salut!!
juste un problème de spam bizarre des pages web de IE 7 qui s'ouvre avec rien dedans ?? alors c pénible car ca arrive quand meme relativement souvent et il faut les fermer quand meme!!
alors voila un hijack this
Logfile of HijackThis v1.99.1
Scan saved at 17:12:15, on 20/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Media Player\wmplayer.exe
H:\labo\scanner.exe.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\qvevicei.dll
O2 - BHO: (no name) - {A39C8C71-AA47-4982-B22A-07D409B94109} - C:\WINDOWS\system32\awvtt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {B6B1F946-33F1-1028-DA5F-6A73133F58C9} - (no file)
O2 - BHO: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\vlltntkt.dll",setvm
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast! Kerio Update] C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Goo] C:\Program Files\?ymantec\wuauboot.exe
O4 - Startup: BJ Status Monitor Canon i560.lnk = C:\Documents and Settings\nyko\cnmss Canon i560 (Local).exe
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111w.bay111.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: awvtt - C:\WINDOWS\system32\awvtt.dll
O20 - Winlogon Notify: soxigqpx - c:\windows\system32\soxigqpx.dll
O20 - Winlogon Notify: winpdc32 - winpdc32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! for Kerio - Unknown owner - C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
merci du coup de clic!!!
a pluche
juste un problème de spam bizarre des pages web de IE 7 qui s'ouvre avec rien dedans ?? alors c pénible car ca arrive quand meme relativement souvent et il faut les fermer quand meme!!
alors voila un hijack this
Logfile of HijackThis v1.99.1
Scan saved at 17:12:15, on 20/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Media Player\wmplayer.exe
H:\labo\scanner.exe.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\qvevicei.dll
O2 - BHO: (no name) - {A39C8C71-AA47-4982-B22A-07D409B94109} - C:\WINDOWS\system32\awvtt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {B6B1F946-33F1-1028-DA5F-6A73133F58C9} - (no file)
O2 - BHO: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\vlltntkt.dll",setvm
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast! Kerio Update] C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Goo] C:\Program Files\?ymantec\wuauboot.exe
O4 - Startup: BJ Status Monitor Canon i560.lnk = C:\Documents and Settings\nyko\cnmss Canon i560 (Local).exe
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111w.bay111.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: awvtt - C:\WINDOWS\system32\awvtt.dll
O20 - Winlogon Notify: soxigqpx - c:\windows\system32\soxigqpx.dll
O20 - Winlogon Notify: winpdc32 - winpdc32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! for Kerio - Unknown owner - C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
merci du coup de clic!!!
a pluche
A voir également:
- Infection IE 7
- Photofiltre 7 - Télécharger - Retouche d'image
- Clé windows 7 - Guide
- Delphi 7 - Télécharger - Langages
- Télécharger 7-zip - Télécharger - Compression & Décompression
- Movie maker windows 7 - Télécharger - Montage & Édition
17 réponses
Bonjour,
* Télécharge VundoFix.exe (par Atribune) sur ton Bureau
http://www.atribune.org/ccount/click.php?id=4
* Double-clique VundoFix.exe afin de le lancer
* Clique sur le bouton Scan for Vundo
* Lorsque le scan est complété, clique sur le bouton Remove Vundo
* Une invite te demandera si tu veux supprimer les fichiers, clique YES
* Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
* Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK
* Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse
Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".
* Télécharge VundoFix.exe (par Atribune) sur ton Bureau
http://www.atribune.org/ccount/click.php?id=4
* Double-clique VundoFix.exe afin de le lancer
* Clique sur le bouton Scan for Vundo
* Lorsque le scan est complété, clique sur le bouton Remove Vundo
* Une invite te demandera si tu veux supprimer les fichiers, clique YES
* Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
* Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK
* Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse
Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".
bonjour et merci de l'aide sympa et rapide
voila mon post vundofix:
VundoFix V6.2.13
Checking Java version...
Java version is 1.5.0.6
Scan started at 17:26:38 20/01/2007
Listing files found while scanning....
C:\WINDOWS\system32\awvtt.dll
C:\WINDOWS\system32\ttvwa.ini
C:\WINDOWS\system32\ttvwa.bak1
C:\WINDOWS\system32\ttvwa.bak2
C:\WINDOWS\system32\ttvwa.ini2
C:\WINDOWS\system32\ttvwa.tmp
Beginning removal...
Attempting to delete C:\WINDOWS\system32\awvtt.dll
C:\WINDOWS\system32\awvtt.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ttvwa.ini
C:\WINDOWS\system32\ttvwa.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\ttvwa.bak1
C:\WINDOWS\system32\ttvwa.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ttvwa.bak2
C:\WINDOWS\system32\ttvwa.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ttvwa.ini2
C:\WINDOWS\system32\ttvwa.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ttvwa.tmp
C:\WINDOWS\system32\ttvwa.tmp Has been deleted!
Performing Repairs to the registry.
Done!
et hijackthis :
Logfile of HijackThis v1.99.1
Scan saved at 17:40:42, on 20/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
H:\labo\scanner.exe.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\qvevicei.dll
O2 - BHO: (no name) - {A39C8C71-AA47-4982-B22A-07D409B94109} - C:\WINDOWS\system32\awvtt.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {B6B1F946-33F1-1028-DA5F-6A73133F58C9} - (no file)
O2 - BHO: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\vlltntkt.dll",setvm
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast! Kerio Update] C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Goo] C:\Program Files\?ymantec\wuauboot.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - Startup: BJ Status Monitor Canon i560.lnk = C:\Documents and Settings\nyko\cnmss Canon i560 (Local).exe
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111w.bay111.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: soxigqpx - c:\windows\system32\soxigqpx.dll
O20 - Winlogon Notify: winpdc32 - winpdc32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! for Kerio - Unknown owner - C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
merci d'avance ;-)
voila mon post vundofix:
VundoFix V6.2.13
Checking Java version...
Java version is 1.5.0.6
Scan started at 17:26:38 20/01/2007
Listing files found while scanning....
C:\WINDOWS\system32\awvtt.dll
C:\WINDOWS\system32\ttvwa.ini
C:\WINDOWS\system32\ttvwa.bak1
C:\WINDOWS\system32\ttvwa.bak2
C:\WINDOWS\system32\ttvwa.ini2
C:\WINDOWS\system32\ttvwa.tmp
Beginning removal...
Attempting to delete C:\WINDOWS\system32\awvtt.dll
C:\WINDOWS\system32\awvtt.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\ttvwa.ini
C:\WINDOWS\system32\ttvwa.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\ttvwa.bak1
C:\WINDOWS\system32\ttvwa.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ttvwa.bak2
C:\WINDOWS\system32\ttvwa.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ttvwa.ini2
C:\WINDOWS\system32\ttvwa.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\ttvwa.tmp
C:\WINDOWS\system32\ttvwa.tmp Has been deleted!
Performing Repairs to the registry.
Done!
et hijackthis :
Logfile of HijackThis v1.99.1
Scan saved at 17:40:42, on 20/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
H:\labo\scanner.exe.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\qvevicei.dll
O2 - BHO: (no name) - {A39C8C71-AA47-4982-B22A-07D409B94109} - C:\WINDOWS\system32\awvtt.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {B6B1F946-33F1-1028-DA5F-6A73133F58C9} - (no file)
O2 - BHO: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\vlltntkt.dll",setvm
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast! Kerio Update] C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Goo] C:\Program Files\?ymantec\wuauboot.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - Startup: BJ Status Monitor Canon i560.lnk = C:\Documents and Settings\nyko\cnmss Canon i560 (Local).exe
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111w.bay111.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: soxigqpx - c:\windows\system32\soxigqpx.dll
O20 - Winlogon Notify: winpdc32 - winpdc32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! for Kerio - Unknown owner - C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
merci d'avance ;-)
re
ok
on continue
* télécharge AVG Anti-Spyware (ewido)
https://www.avg.com/en-ww/free-antivirus-download
* tu l'installes
* lance AVG Anti-Spyware et clique sur le bouton Mise à jour.<g/ras> Patiente
puis
Lance <gras>AVG Anti-Spyware
Clique sur le bouton Analyse (de la barre d'outils)
Puis sur l'onglets Comment réagir, clique sur Actions recommandées. Sélectionne Quarantaine.
Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
A la fin du scan, choisis l'option 3
"Appliquer toutes les actions " en bas.
Clique sur "Enregistrer le rapport".
Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.
Poste le.
et un nouveau rapport hijackthis
ok
on continue
* télécharge AVG Anti-Spyware (ewido)
https://www.avg.com/en-ww/free-antivirus-download
* tu l'installes
* lance AVG Anti-Spyware et clique sur le bouton Mise à jour.<g/ras> Patiente
puis
Lance <gras>AVG Anti-Spyware
Clique sur le bouton Analyse (de la barre d'outils)
Puis sur l'onglets Comment réagir, clique sur Actions recommandées. Sélectionne Quarantaine.
Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
A la fin du scan, choisis l'option 3
"Appliquer toutes les actions " en bas.
Clique sur "Enregistrer le rapport".
Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.
Poste le.
et un nouveau rapport hijackthis
re
merci encore!!
voila mon post de avg
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 19:20:07 20/01/2007
+ Résultat de l'analyse:
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP59\A0020853.exe -> Adware.ClickSpring : Nettoyé et sauvegardé (mise en quarantaine).
HKU\S-1-5-21-1454471165-362288127-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A1DDC19-5893-43AB-A73F-F41A0F34D115} -> Adware.Generic : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP65\A0023002.exe -> Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP69\A0023121.exe -> Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP72\A0025182.exe -> Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP95\A0029635.dll -> Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\chim.dll -> Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP52\A0017535.dll -> Adware.Systemdoctor : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP50\A0017222.exe -> Adware.VirusBurst : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP50\A0017231.exe -> Adware.VirusBurst : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\nyko\Local Settings\Temp\USDR6V_0001_D18M3107\installer.exe -> Adware.WinFixer : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP51\A0017378.dll -> Downloader.Zlob.amj : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP16\A0008320.exe -> Logger.Banker.ba : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP52\A0017534.exe -> Not-A-Virus.Downloader.Win32.WinFixer.t : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP56\A0020785.exe -> Not-A-Virus.Hacktool.EvID : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP101\A0030872.dll -> Not-A-Virus.Hoax.Win32.Renos.gi : Nettoyé et sauvegardé (mise en quarantaine).
:mozilla.21:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.22:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.23:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.24:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.401:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.435:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.567:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.570:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.61:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.62:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.63:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.64:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.450:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.134:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.135:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.136:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.137:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.287:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.165:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.161:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.301:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Burstnet : Nettoyé.
:mozilla.302:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Burstnet : Nettoyé.
:mozilla.304:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Burstnet : Nettoyé.
C:\Documents and Settings\nyko\Cookies\nyko@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Nettoyé.
:mozilla.45:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.204:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.131:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.132:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.532:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Hotlog : Nettoyé.
:mozilla.253:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\nyko\Cookies\nyko@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Nettoyé.
:mozilla.412:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.413:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.576:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Questionmarket : Nettoyé.
:mozilla.577:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Questionmarket : Nettoyé.
:mozilla.320:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.321:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.322:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.323:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.598:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Revenue : Nettoyé.
:mozilla.465:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.605:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.606:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.607:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.608:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.14:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.15:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.16:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.614:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Spylog : Nettoyé.
:mozilla.160:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.621:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Tribalfusion : Nettoyé.
:mozilla.643:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Tribalfusion : Nettoyé.
:mozilla.107:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.108:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.109:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.250:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
:mozilla.638:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Yadro : Nettoyé.
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP85\A0028487.exe -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP95\A0029640.exe -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\wnscpsv.exe -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).
Fin du rapport
voila le hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 19:22:56, on 20/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Pinnacle\SHARED~1\Filter\server.exe
C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\eMule\emule.exe
H:\labo\scanner.exe.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\qvevicei.dll
O2 - BHO: (no name) - {A39C8C71-AA47-4982-B22A-07D409B94109} - C:\WINDOWS\system32\awvtt.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {B6B1F946-33F1-1028-DA5F-6A73133F58C9} - (no file)
O2 - BHO: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\vlltntkt.dll",setvm
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast! Kerio Update] C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Goo] C:\Program Files\?ymantec\wuauboot.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - Startup: BJ Status Monitor Canon i560.lnk = C:\Documents and Settings\nyko\cnmss Canon i560 (Local).exe
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111w.bay111.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: soxigqpx - c:\windows\system32\soxigqpx.dll
O20 - Winlogon Notify: winpdc32 - winpdc32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! for Kerio - Unknown owner - C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
voila
sinon une question en passant
ilparait qu'il ne faut pas multiplier les anti spyware alors puis je garder avg que tu viens de me dire de télécharger ou bien faut il que je le désinstalle ?? car j'ai déja a squarred + autres
merci de tout coeur
sinon pourrais tu m'expliquer comment vous travailler sur ce site?? c du bénévolat??
merci a tout de suite
merci encore!!
voila mon post de avg
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 19:20:07 20/01/2007
+ Résultat de l'analyse:
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP59\A0020853.exe -> Adware.ClickSpring : Nettoyé et sauvegardé (mise en quarantaine).
HKU\S-1-5-21-1454471165-362288127-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A1DDC19-5893-43AB-A73F-F41A0F34D115} -> Adware.Generic : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP65\A0023002.exe -> Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP69\A0023121.exe -> Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP72\A0025182.exe -> Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP95\A0029635.dll -> Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\chim.dll -> Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP52\A0017535.dll -> Adware.Systemdoctor : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP50\A0017222.exe -> Adware.VirusBurst : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP50\A0017231.exe -> Adware.VirusBurst : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\nyko\Local Settings\Temp\USDR6V_0001_D18M3107\installer.exe -> Adware.WinFixer : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP51\A0017378.dll -> Downloader.Zlob.amj : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP16\A0008320.exe -> Logger.Banker.ba : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP52\A0017534.exe -> Not-A-Virus.Downloader.Win32.WinFixer.t : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP56\A0020785.exe -> Not-A-Virus.Hacktool.EvID : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP101\A0030872.dll -> Not-A-Virus.Hoax.Win32.Renos.gi : Nettoyé et sauvegardé (mise en quarantaine).
:mozilla.21:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.22:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.23:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.24:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.401:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.435:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.567:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.570:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.61:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.62:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.63:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.64:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.450:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.134:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.135:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.136:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.137:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.287:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.165:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.161:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.301:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Burstnet : Nettoyé.
:mozilla.302:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Burstnet : Nettoyé.
:mozilla.304:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Burstnet : Nettoyé.
C:\Documents and Settings\nyko\Cookies\nyko@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Nettoyé.
:mozilla.45:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.204:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.131:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.132:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.532:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Hotlog : Nettoyé.
:mozilla.253:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\nyko\Cookies\nyko@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Nettoyé.
:mozilla.412:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.413:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.576:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Questionmarket : Nettoyé.
:mozilla.577:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Questionmarket : Nettoyé.
:mozilla.320:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.321:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.322:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.323:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.598:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Revenue : Nettoyé.
:mozilla.465:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.605:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.606:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.607:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.608:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.14:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.15:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.16:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.614:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Spylog : Nettoyé.
:mozilla.160:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.621:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Tribalfusion : Nettoyé.
:mozilla.643:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Tribalfusion : Nettoyé.
:mozilla.107:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.108:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.109:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.250:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
:mozilla.638:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Yadro : Nettoyé.
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP85\A0028487.exe -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP95\A0029640.exe -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\wnscpsv.exe -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).
Fin du rapport
voila le hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 19:22:56, on 20/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Pinnacle\SHARED~1\Filter\server.exe
C:\Program Files\Pinnacle\Shared Files\Programs\Scheduler\PCLEScheduler.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\eMule\emule.exe
H:\labo\scanner.exe.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\qvevicei.dll
O2 - BHO: (no name) - {A39C8C71-AA47-4982-B22A-07D409B94109} - C:\WINDOWS\system32\awvtt.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {B6B1F946-33F1-1028-DA5F-6A73133F58C9} - (no file)
O2 - BHO: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\vlltntkt.dll",setvm
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast! Kerio Update] C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Goo] C:\Program Files\?ymantec\wuauboot.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - Startup: BJ Status Monitor Canon i560.lnk = C:\Documents and Settings\nyko\cnmss Canon i560 (Local).exe
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111w.bay111.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: soxigqpx - c:\windows\system32\soxigqpx.dll
O20 - Winlogon Notify: winpdc32 - winpdc32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! for Kerio - Unknown owner - C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
voila
sinon une question en passant
ilparait qu'il ne faut pas multiplier les anti spyware alors puis je garder avg que tu viens de me dire de télécharger ou bien faut il que je le désinstalle ?? car j'ai déja a squarred + autres
merci de tout coeur
sinon pourrais tu m'expliquer comment vous travailler sur ce site?? c du bénévolat??
merci a tout de suite
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
bonjour
plus personne pour me répondre??
comment je dois faire il faut que j'attende encore un peu??
merci de me conseiller
a bientot
plus personne pour me répondre??
comment je dois faire il faut que j'attende encore un peu??
merci de me conseiller
a bientot
je suis là.
Tu es toujours infecté, on va continuer
pour ce qui est de AVG il ne faudra pas garder avg et a2 certes, mais dans l'immédiat, garde le il faudra refaire certainement un scan avec
je n'aime pas A2 et n'ai pas trop confiance en lui, il génère trop de faux positifs à mon goût !
je vais revenir dans qq minutes
Tu es toujours infecté, on va continuer
pour ce qui est de AVG il ne faudra pas garder avg et a2 certes, mais dans l'immédiat, garde le il faudra refaire certainement un scan avec
je n'aime pas A2 et n'ai pas trop confiance en lui, il génère trop de faux positifs à mon goût !
je vais revenir dans qq minutes
re
redémarre en mode sans échec
http://service1.symantec.com/support/inter/tsgeninfointl.nsf/fr_docid/20020905112131924
et
* lance Hijackthis pour un scan seulement et coche
R3 - URLSearchHook: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll (file missing)
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\qvevicei.dll
O2 - BHO: (no name) - {A39C8C71-AA47-4982-B22A-07D409B94109} - C:\WINDOWS\system32\awvtt.dll (file missing)
O2 - BHO: (no name) - {B6B1F946-33F1-1028-DA5F-6A73133F58C9} - (no file)
O2 - BHO: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll (file missing)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\vlltntkt.dll",setvm
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Goo] C:\Program Files\?ymantec\wuauboot.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: soxigqpx - c:\windows\system32\soxigqpx.dll
O20 - Winlogon Notify: winpdc32 - winpdc32.dll (file missing)
* clique sur "fixer objet"
* redémarre en mode normal
puis
* Télécharge Pocket KillBox sur ton bureau.
http://www.downloads.subratam.org/KillBox.exe
* Double-clique sur le fichier Killbox.exe, et coche la case "Delete on reboot".
* copie d'un trait les lignes de la citation suivante :
Sur PocketKillBox --> menu "File" --> "Paste from Clipboard" (tu ne verras rien se passer).
- coche la case "Unregister dll before deleting" (si tu en as la possibilité)
- clique sur le bouton "All files"
- clique ensuite sur la croix rouge
Au deux messages qui vont s'afficher, tu réponds par "YES"
L'ordinateur doit redémarrer, sinon, fais le toi-même, quoiqu'il arrive.
* reposte un nouveau rapport HijackTHis
redémarre en mode sans échec
http://service1.symantec.com/support/inter/tsgeninfointl.nsf/fr_docid/20020905112131924
et
* lance Hijackthis pour un scan seulement et coche
R3 - URLSearchHook: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll (file missing)
O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\qvevicei.dll
O2 - BHO: (no name) - {A39C8C71-AA47-4982-B22A-07D409B94109} - C:\WINDOWS\system32\awvtt.dll (file missing)
O2 - BHO: (no name) - {B6B1F946-33F1-1028-DA5F-6A73133F58C9} - (no file)
O2 - BHO: (no name) - {F569826A-1BD3-3903-A4ED-1144908519C4} - C:\WINDOWS\system32\chim.dll (file missing)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\vlltntkt.dll",setvm
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Goo] C:\Program Files\?ymantec\wuauboot.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: soxigqpx - c:\windows\system32\soxigqpx.dll
O20 - Winlogon Notify: winpdc32 - winpdc32.dll (file missing)
* clique sur "fixer objet"
* redémarre en mode normal
puis
* Télécharge Pocket KillBox sur ton bureau.
http://www.downloads.subratam.org/KillBox.exe
* Double-clique sur le fichier Killbox.exe, et coche la case "Delete on reboot".
* copie d'un trait les lignes de la citation suivante :
C:\WINDOWS\system32\chim.dll C:\WINDOWS\system32\qvevicei.dll C:\WINDOWS\system32\awvtt.dll C:\WINDOWS\system32\vlltntkt.dll C:\Program Files\?ymantec\wuauboot.exe c:\windows\system32\soxigqpx.dll
Sur PocketKillBox --> menu "File" --> "Paste from Clipboard" (tu ne verras rien se passer).
- coche la case "Unregister dll before deleting" (si tu en as la possibilité)
- clique sur le bouton "All files"
- clique ensuite sur la croix rouge
Au deux messages qui vont s'afficher, tu réponds par "YES"
L'ordinateur doit redémarrer, sinon, fais le toi-même, quoiqu'il arrive.
* reposte un nouveau rapport HijackTHis
re philae
et merci de cette précieuse aide du bon coté de la force!!
sinon bénévole ou comment devenir informaticien??
bref voici mon hijack this!!
Logfile of HijackThis v1.99.1
Scan saved at 21:35:22, on 20/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast! Kerio Update] C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - Startup: BJ Status Monitor Canon i560.lnk = C:\Documents and Settings\nyko\cnmss Canon i560 (Local).exe
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111w.bay111.mail.live.com/mail/resources/MsnPUpld.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: soxigqpx - c:\windows\system32\soxigqpx.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! for Kerio - Unknown owner - C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
merci pour tout a tout'
et merci de cette précieuse aide du bon coté de la force!!
sinon bénévole ou comment devenir informaticien??
bref voici mon hijack this!!
Logfile of HijackThis v1.99.1
Scan saved at 21:35:22, on 20/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsoft.com/access/autosearch.asp?p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast! Kerio Update] C:\PROGRA~1\ALWILS~1\Kerio\Avast4\aswUpdCl.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - Startup: BJ Status Monitor Canon i560.lnk = C:\Documents and Settings\nyko\cnmss Canon i560 (Local).exe
O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by111w.bay111.mail.live.com/mail/resources/MsnPUpld.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: soxigqpx - c:\windows\system32\soxigqpx.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! for Kerio - Unknown owner - C:\Program Files\Alwil Software\Kerio\Avast4\aswUpdSc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
merci pour tout a tout'
re
de rien c'est avec plaisir.
Je ne suis que bénévole, et loin d'être informaticienne
ton dernier rapport est correct
comment se comporte ton pc ?
refait peut être un petit scan AVG pour la route.
et merci de cette précieuse aide du bon coté de la force!! sinon bénévole ou comment devenir informaticien??
de rien c'est avec plaisir.
Je ne suis que bénévole, et loin d'être informaticienne
ton dernier rapport est correct
comment se comporte ton pc ?
refait peut être un petit scan AVG pour la route.
re
il tournait déja correctement disons , juste que ca commencait a devenir ennuyeux !! les spams intempestifs!!
enfin quand j'ai vu l'état d'encrassement de la bécanne!!! je me dis que je devrais venir vous voir un peu plus souvent!!
ca tourne du tonerre maintenant!!
je vais refaire un petit scan pour la route!
quand meme!!
autrement, merci du suivi rapide et efficace tu m'as bien dépanné sinon j'ai des soucis avec kerio et avast pour kerio !! aurais tu un tuyaux pour me renseigner je n'ai rien trouvé de probant sur la toile
content de t'avoir connue!
je me pose la question sinon comment devient t-on calée a ce point avec tous ces petits logiciels anti virus comme toi??
cela m'interresse ??
a une prochaine alors peut être pourrais t'on rester en contact juste comme ca??
en toute simplicité si je revient sur le site comment te contacter??
en tout bien tout honneur!! je suis pas du genre chiant
en tout cas, au plaisir et encore merci
bonne soirée
kenavo (au revoir)
il tournait déja correctement disons , juste que ca commencait a devenir ennuyeux !! les spams intempestifs!!
enfin quand j'ai vu l'état d'encrassement de la bécanne!!! je me dis que je devrais venir vous voir un peu plus souvent!!
ca tourne du tonerre maintenant!!
je vais refaire un petit scan pour la route!
quand meme!!
autrement, merci du suivi rapide et efficace tu m'as bien dépanné sinon j'ai des soucis avec kerio et avast pour kerio !! aurais tu un tuyaux pour me renseigner je n'ai rien trouvé de probant sur la toile
content de t'avoir connue!
je me pose la question sinon comment devient t-on calée a ce point avec tous ces petits logiciels anti virus comme toi??
cela m'interresse ??
a une prochaine alors peut être pourrais t'on rester en contact juste comme ca??
en toute simplicité si je revient sur le site comment te contacter??
en tout bien tout honneur!! je suis pas du genre chiant
en tout cas, au plaisir et encore merci
bonne soirée
kenavo (au revoir)
sinon j'ai des soucis avec kerio et avast pour kerio !! aurais tu un tuyaux pour me renseigner je n'ai rien trouvé de probant sur la toile content de t'avoir connue!
je ne le connais pas, mais c'est quoi ton soucis ?
je me pose la question sinon comment devient t-on calée a ce point avec tous ces petits logiciels anti virus comme toi?? cela m'interresse ??
j'ai juste eu la chance à un moment donné, de rencontrer des gens fort sympathiques, et fort calés qui m'ont formé au départ, et ensuite bein avec un peu d'entrainement, et en se tenant à la page sur les divers forums, on avance tout doucement.
arpente les forums, regarde comment on procède, et tu as des sites fort intéressants pour te cultiver
ccm
assiste.com
zebulon
pcastuces
en toute simplicité si je revient sur le site comment te contacter?? en tout bien tout honneur!! je suis pas du genre chiant
tu cliques sur les MP
lol !
et messagerie privée c est ou?
en bas dans "répondre a philea"?
je pige pas trop ou c'est une boutade?
sinon voila le rapport de mon scan avg pour la route!!
juste un trojan élevé!!
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 22:30:39 20/01/2007
+ Résultat de l'analyse:
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP101\A0030929.dll -> Adware.PurityScan : Nettoyé.
:mozilla.36:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.37:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.38:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.39:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.400:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.434:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.566:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.569:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.76:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.77:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.78:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.79:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.449:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.143:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.144:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.145:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.146:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.288:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.167:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.164:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.302:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Burstnet : Nettoyé.
:mozilla.303:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Burstnet : Nettoyé.
:mozilla.305:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Burstnet : Nettoyé.
:mozilla.60:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.206:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.140:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.141:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.531:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Hotlog : Nettoyé.
:mozilla.254:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.411:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.412:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.575:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Questionmarket : Nettoyé.
:mozilla.576:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Questionmarket : Nettoyé.
:mozilla.321:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.322:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.323:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.324:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.597:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Revenue : Nettoyé.
:mozilla.464:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.604:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.605:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.606:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.607:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.31:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.32:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.33:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.613:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Spylog : Nettoyé.
:mozilla.163:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.620:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Tribalfusion : Nettoyé.
:mozilla.642:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Tribalfusion : Nettoyé.
:mozilla.116:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.117:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.118:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.251:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
:mozilla.637:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Yadro : Nettoyé.
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP101\A0030928.exe -> Trojan.Small : Nettoyé.
Fin du rapport
merci encore
en bas dans "répondre a philea"?
je pige pas trop ou c'est une boutade?
sinon voila le rapport de mon scan avg pour la route!!
juste un trojan élevé!!
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 22:30:39 20/01/2007
+ Résultat de l'analyse:
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP101\A0030929.dll -> Adware.PurityScan : Nettoyé.
:mozilla.36:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.37:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.38:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.39:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.400:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.434:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.566:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.569:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.76:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.77:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.78:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.79:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.449:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.143:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.144:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.145:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.146:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.288:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.167:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.164:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.302:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Burstnet : Nettoyé.
:mozilla.303:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Burstnet : Nettoyé.
:mozilla.305:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Burstnet : Nettoyé.
:mozilla.60:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.206:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.140:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.141:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.531:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Hotlog : Nettoyé.
:mozilla.254:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.411:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.412:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.575:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Questionmarket : Nettoyé.
:mozilla.576:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Questionmarket : Nettoyé.
:mozilla.321:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.322:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.323:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.324:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.597:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Revenue : Nettoyé.
:mozilla.464:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.604:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.605:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.606:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.607:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.31:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.32:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.33:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.613:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Spylog : Nettoyé.
:mozilla.163:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.620:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Tribalfusion : Nettoyé.
:mozilla.642:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Tribalfusion : Nettoyé.
:mozilla.116:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.117:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.118:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.251:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
:mozilla.637:C:\Documents and Settings\nyko\Application Data\Mozilla\Firefox\Profiles\cw7bom27.default\cookies.txt -> TrackingCookie.Yadro : Nettoyé.
C:\System Volume Information\_restore{206D38D5-D55B-4965-8D2C-88030284C36E}\RP101\A0030928.exe -> Trojan.Small : Nettoyé.
Fin du rapport
merci encore
re
il est dans ta restauration système. Tout va bien
démarrer-----------panneau de configuration------------système----------
onglet Restauration système-----------coche la case (Désactiver la restauration système)--------------
redémarre l'ordinateur
puis tu la ré actives.
Pour les MP, non ce n'est pas une boutade, tu cliques sur mon pseudo en haut des posts, et tu écris un MP c'est tout.
il est dans ta restauration système. Tout va bien
démarrer-----------panneau de configuration------------système----------
onglet Restauration système-----------coche la case (Désactiver la restauration système)--------------
redémarre l'ordinateur
puis tu la ré actives.
Pour les MP, non ce n'est pas une boutade, tu cliques sur mon pseudo en haut des posts, et tu écris un MP c'est tout.