Analyse Hijackthis ^^

Résolu
zinko Messages postés 31 Statut Membre -  
duflox Messages postés 2014 Statut Membre -
Bonjour! Voila mon rapport d'analyse apres avoir nettoyé avec ad-aware, ccleaner, etc..
Je vous le laisse ^^

Logfile of HijackThis v1.99.1
Scan saved at 18:10:22, on 10/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\Program Files\Fichiers communs\AOL\1171904441\ee\AOLSoftware.exe
C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Program Files\Fichiers communs\SystemDoctor\usdrmdr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WINSOS\WINSOS.EXE
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Messenger\Msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\AOL Compagnon\companion.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Class - {F4A41C9A-A713-9C96-601E-1966003429F8} - C:\WINDOWS\addke.dll (file missing)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll (file missing)
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [AOLSAV] C:\PROGRA~1\TECHCI~1\AOLSAV\AOLAgent.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [1E1.tmp] C:\DOCUME~1\Bryan\LOCALS~1\Temp\1E1.tmp.exe 3 10001
O4 - HKLM\..\Run: [apigq32.exe] C:\WINDOWS\system32\apigq32.exe
O4 - HKLM\..\Run: [vs7W36i] icfgrcoi.exe
O4 - HKLM\..\Run: [msiz.exe] C:\WINDOWS\system32\msiz.exe
O4 - HKLM\..\Run: [apigo.exe] C:\WINDOWS\system32\apigo.exe
O4 - HKLM\..\Run: [atlnj32.exe] C:\WINDOWS\system32\atlnj32.exe
O4 - HKLM\..\Run: [sdkil.exe] C:\WINDOWS\system32\sdkil.exe
O4 - HKLM\..\Run: [d3mo32.exe] C:\WINDOWS\system32\d3mo32.exe
O4 - HKLM\..\Run: [addmu.exe] C:\WINDOWS\system32\addmu.exe
O4 - HKLM\..\Run: [cray.exe] C:\WINDOWS\system32\cray.exe
O4 - HKLM\..\Run: [atlrm.exe] C:\WINDOWS\system32\atlrm.exe
O4 - HKLM\..\Run: [crsa32.exe] C:\WINDOWS\system32\crsa32.exe
O4 - HKLM\..\Run: [netpa.exe] C:\WINDOWS\system32\netpa.exe
O4 - HKLM\..\Run: [apiyb32.exe] C:\WINDOWS\apiyb32.exe
O4 - HKLM\..\Run: [netao32.exe] C:\WINDOWS\system32\netao32.exe
O4 - HKLM\..\Run: [crha32.exe] C:\WINDOWS\system32\crha32.exe
O4 - HKLM\..\Run: [addut.exe] C:\WINDOWS\system32\addut.exe
O4 - HKLM\..\Run: [sdkiu.exe] C:\WINDOWS\sdkiu.exe
O4 - HKLM\..\Run: [iezt.exe] C:\WINDOWS\system32\iezt.exe
O4 - HKLM\..\Run: [javaea.exe] C:\WINDOWS\system32\javaea.exe
O4 - HKLM\..\Run: [appng.exe] C:\WINDOWS\system32\appng.exe
O4 - HKLM\..\Run: [cron.exe] C:\WINDOWS\cron.exe
O4 - HKLM\..\Run: [appjb32.exe] C:\WINDOWS\appjb32.exe
O4 - HKLM\..\Run: [addyu.exe] C:\WINDOWS\system32\addyu.exe
O4 - HKLM\..\Run: [atlrt32.exe] C:\WINDOWS\system32\atlrt32.exe
O4 - HKLM\..\Run: [d3tj32.exe] C:\WINDOWS\d3tj32.exe
O4 - HKLM\..\Run: [sysgc.exe] C:\WINDOWS\system32\sysgc.exe
O4 - HKLM\..\Run: [winuy32.exe] C:\WINDOWS\system32\winuy32.exe
O4 - HKLM\..\Run: [winrc32.exe] C:\WINDOWS\system32\winrc32.exe
O4 - HKLM\..\Run: [atlza32.exe] C:\WINDOWS\atlza32.exe
O4 - HKLM\..\Run: [addru32.exe] C:\WINDOWS\system32\addru32.exe
O4 - HKLM\..\Run: [crxk.exe] C:\WINDOWS\system32\crxk.exe
O4 - HKLM\..\Run: [nettk32.exe] C:\WINDOWS\system32\nettk32.exe
O4 - HKLM\..\Run: [apipj.exe] C:\WINDOWS\apipj.exe
O4 - HKLM\..\Run: [addac32.exe] C:\WINDOWS\system32\addac32.exe
O4 - HKLM\..\Run: [crre32.exe] C:\WINDOWS\crre32.exe
O4 - HKLM\..\Run: [ntbb.exe] C:\WINDOWS\ntbb.exe
O4 - HKLM\..\Run: [d3so32.exe] C:\WINDOWS\system32\d3so32.exe
O4 - HKLM\..\Run: [apijt.exe] C:\WINDOWS\system32\apijt.exe
O4 - HKLM\..\Run: [apprq.exe] C:\WINDOWS\apprq.exe
O4 - HKLM\..\Run: [ntgw.exe] C:\WINDOWS\ntgw.exe
O4 - HKLM\..\Run: [sysll.exe] C:\WINDOWS\system32\sysll.exe
O4 - HKLM\..\Run: [msxp.exe] C:\WINDOWS\system32\msxp.exe
O4 - HKLM\..\Run: [sdkql32.exe] C:\WINDOWS\system32\sdkql32.exe
O4 - HKLM\..\Run: [netoc32.exe] C:\WINDOWS\netoc32.exe
O4 - HKLM\..\Run: [ntox32.exe] C:\WINDOWS\ntox32.exe
O4 - HKLM\..\Run: [atlvu32.exe] C:\WINDOWS\system32\atlvu32.exe
O4 - HKLM\..\Run: [addwq32.exe] C:\WINDOWS\addwq32.exe
O4 - HKLM\..\Run: [atlmw.exe] C:\WINDOWS\atlmw.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [ievc32.exe] C:\WINDOWS\ievc32.exe
O4 - HKLM\..\Run: [javaxp32.exe] C:\WINDOWS\javaxp32.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [apilm.exe] C:\WINDOWS\system32\apilm.exe
O4 - HKLM\..\Run: [NI.UWFX5V_0001_0802] "C:\Documents and Settings\Bryan\Local Settings\Temporary Internet Files\Content.IE5\H01B3ME6\WFI_FRA[1].exe"
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Controleur de calendrier pour Ulead Photo Express] C:\Program Files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe
O4 - HKLM\..\Run: [hxlcvuq] C:\WINDOWS\system32\bxznsr.exe r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Fichiers communs\AOL\1171904441\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKLM\..\Run: [CAST SURF BROWSE TOOL] C:\Documents and Settings\All Users\Application Data\Shim Cdrom Cast Surf\Sect Way.exe
O4 - HKLM\..\Run: [MDRV_Check] "C:\Program Files\Fichiers communs\SystemDoctor\usdrmdr.exe"
O4 - HKLM\..\Run: [DC6V_Check] "C:\Program Files\Fichiers communs\SystemDoctor\usdrdc.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [eBo6RWGEi] htini11.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\WINSOS\WINSOS.EXE" MINI
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\Msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: AOL 9.0 Icône AOL.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: AOL Compagnon.lnk = C:\Program Files\AOL Compagnon\companion.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O16 - DPF: ServerPushBox - http://www.turismodoalgarve.pt/meteo/rta/faroport/servp14.cab
O16 - DPF: {093F9CF8-0DE1-491C-95D5-5EC257BD4CA3} - https://www.afternic.com/domains/downloadv3.com
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.fr/computercheckup/qdiagcc.cab
O16 - DPF: {4BA12BBE-A1CD-4E13-85E4-A05E3FF6F658} (Pygmy Productions - Installer of Bluedot Game Object) - http://www.bluedotproject.com/BlueInstaller.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/10497be59b7623c58915/netzip/RdxIE601.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/7/532/6712/2.0.0.33/player.virtools.com/downloads/player/Install2.0/Installer.exe
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://guard.gunbound.net/nProtect/keyCrypt/npkcx.cab
O16 - DPF: {E6A3C1E2-F792-483E-9133-596215172BE9} (AcceptLang Class) - http://runonce.msn.com/setacceptlang.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\Program Files\Fichiers communs\AOL\AOL Spyware Protection\\aolserv.exe (file missing)
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\System32\npkcsvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
A voir également:

53 réponses

duflox Messages postés 2014 Statut Membre 43
 
fais ceci:

Étape 1:
Télécharge eScan Antivirus Toolkit ici:

http://www.spywareinfo.dk/download/mwav.exe

Sauvegarde-le sur ton Bureau.
Avant de lancer le programme, il faut le mettre à jour tel qu'indiqué à l'étape 2.

Étape 2:
Voici comment mettre l'outil à jour :

1.) Double-clique le fichier mwav.exe qui se trouve sur le Bureau ; dézippe les fichiers dans le nouveau dossier suggéré (C:\Kaspersky). Le programme va se lancer, et tu dois le quitter (clique sur "Exit" puis "Exit").

2.) Double-clique sur le Poste de travail, puis double-clique sur le lecteur principal (habituellement C:\), double-clique sur le dossier Kaspersky ; ensuite, double-clique sur le fichier kavupd.exe. Tu verras maintenant une fenêtre DOS apparaître, et la mise à jour se complètera en quelques minutes.

3.) Lorsque la mise à jour sera complétée, tu verras "Press any key to continue" ; tape sur une clé pour continuer. Deux nouveaux répertoires (dossiers) ont été créés lors de la mise à jour (C:\Bases et C:\Downloads).

4.) Sélectionne/copie tous les fichiers présents dans le dossier C:\Downloads, puis colle-les dans le dossier C:\Kaspersky. Accepte à l'invite de remplacer les fichiers existants.

Ne pas lancer le scan tout de suite !

Étape 3:
Redémarre en mode Sans Échec :
1) Redémarre ton ordi
2) Tapote la touche F8 immédiatement, juste après le "Bip"
3) Tu verras un écran avec options de démarrage apparaître
4) Choisi la première option : Sans Échec, et valide avec "Entrée"
5) Choisi ton compte régulier, et non Administrateur

Étape 4:
Du mode Sans Échec, voici comment utiliser le programme :

1.) Pour lancer "eScan Antivirus Toolkit", trouve le fichier mwavscan.com situé dans le dossier C:\Kaspersky

2.) Double-clique sur mwavscan.com ; l'interface d'eScan va apparaître à l'écran.

3.) Il est très important de bien cocher ces boîtes sous Scan Option : Memory, Registry, Startup Folders, System Folders, Services.

4.) Coche la boîte Drive, ce qui donne accès à une nouvelle boîte Drive (bouton rond) juste dessous ; coche ce bouton "Drive" (très important..), et tu verras une nouvelle boîte de navigation apparaître à la droite. Clique sur la petite flèche de cette boîte and choisi la lettre de ton disque dur, habituellement C:\.

5.) Juste au-dessous, assure-toi que Scan All Files est coché, et non Program Files.

6.) Clique sur Scan Clean et laisse le tool vérifier tout le disque dur (ça peut être long..). Lorsque terminé, tu verras Scan Completed. Ne pas quitter tout de suite !

7.) Ouvre un nouveau fichier Bloc notes (clique sur "Démarrer" >> "Programmes" >>"Accessoires" >> "Bloc notes"), puis copie/colle tout le contenu de la fenêtre Virus Log Information (la deuxième, au bas) dans le fichier texte, et sauvegarde le. eScan génère également un rapport complet dans le dossier C:\Kaspersky (nommé mwav.log), mais il est trop lourd pour poster sur le forum.

Ferme le programme. Redémarre ton PC en mode Normal. Poste (copie/colle) le rapport que tu as sauvegardé dans ta prochaine réponse.

Tutoriel :

http://www.malekal.com/tutorial_eScan_antivirus_toolkit.php
0
zinko Messages postés 31 Statut Membre
 
voila c'est fait !

File C:\WINDOWS\lsbeuutbdn.exe tagged as not-a-virus:AdWare.Win32.Bestofer.d. No Action Taken.

File C:\WINDOWS\xmnjhcg.exe tagged as not-a-virus:AdWare.Win32.BetterInternet.ai. No Action Taken.

File C:\WINDOWS\system32\winsdrv.dll tagged as not-a-virus:AdWare.Win32.BHO.ba. No Action Taken.

File C:\WINDOWS\system32\wmidext.dll tagged as not-a-virus:AdWare.Win32.VB.y. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051209212833.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051209220807.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051209222422.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051211153820.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051214195425.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051214201036.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051215185634.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051216182556.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051218113049.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051225202549.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051225204145.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051226090817.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051226180547.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051227091944.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051227115833.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060115200924.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060115202630.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060115234012.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060116133017.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060116134805.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060116144348.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060117183300.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060117184902.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060118123717.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060118125314.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060120184157.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060120185954.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060121193623.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060131205536.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060201123607.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060201173412.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060201181400.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060201205031.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060202160954.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060202205916.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060203183604.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060204190835.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060204192401.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060213120532.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060214090259.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060214092031.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060216190215.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\WINDOWS\lsbeuutbdn.exe tagged as not-a-virus:AdWare.Win32.Bestofer.d. No Action Taken.

File C:\WINDOWS\system32\winsdrv.dll tagged as not-a-virus:AdWare.Win32.BHO.ba. No Action Taken.

File C:\WINDOWS\system32\wmidext.dll tagged as not-a-virus:AdWare.Win32.VB.y. No Action Taken.

File C:\WINDOWS\xmnjhcg.exe tagged as not-a-virus:AdWare.Win32.BetterInternet.ai. No Action Taken.
0
duflox Messages postés 2014 Statut Membre 43
 
No Action Taken tu ne les a pas supprimé????????
0
zinko Messages postés 31 Statut Membre
 
comment ? T-T j'me disais bien aussi que c'était bizarre :S
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
duflox Messages postés 2014 Statut Membre 43
 
va falloir que tu refasse le scan et que tu les supprimes car il ya du beau rootkit sur le pc!!

si tu as un souci regarde le tutoriel :

http://www.malekal.com/tutorial_eScan_antivirus_toolkit.php
0
zinko Messages postés 31 Statut Membre
 
j'ai fais comme tu m'a dis.. et comme c'est marqué sur le tutoriel pourtant !
0
duflox Messages postés 2014 Statut Membre 43
 
refais le comme meme!!!pour voir si il ne les a pas supprimé au redemarrage!!

a+
0
zinko Messages postés 31 Statut Membre
 
okay ! Toujours en mode sans échec ?
0
duflox Messages postés 2014 Statut Membre 43
 
oui tjrs!!
0
zinko Messages postés 31 Statut Membre
 
ok ! let's go alors j'y retourne !
0
duflox Messages postés 2014 Statut Membre 43
 
ok a toute!!!

et redonne moi le nouveau rapport

merci
0
zinko Messages postés 31 Statut Membre
 
voilà c'est fait ! toujours " No Action Taken :S

File C:\WINDOWS\lsbeuutbdn.exe tagged as not-a-virus:AdWare.Win32.Bestofer.d. No Action Taken.

File C:\WINDOWS\xmnjhcg.exe tagged as not-a-virus:AdWare.Win32.BetterInternet.ai. No Action Taken.

File C:\WINDOWS\system32\winsdrv.dll tagged as not-a-virus:AdWare.Win32.BHO.ba. No Action Taken.

File C:\WINDOWS\system32\wmidext.dll tagged as not-a-virus:AdWare.Win32.VB.y. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051209212833.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051209220807.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051209222422.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051211153820.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051214195425.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051214201036.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051215185634.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051216182556.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051218113049.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051225202549.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051225204145.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051226090817.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051226180547.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051227091944.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20051227115833.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060115200924.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060115202630.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060115234012.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060116133017.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060116134805.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060116144348.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060117183300.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060117184902.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060118123717.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060118125314.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060120184157.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060120185954.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060121193623.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060131205536.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060201123607.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060201173412.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060201181400.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060201205031.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060202160954.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060202205916.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060203183604.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060204190835.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060204192401.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060213120532.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060214090259.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060214092031.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\Quarantine\20060216190215.zip tagged as not-a-virus:AdWare.Win32.BetterInternet.b. No Action Taken.

File C:\WINDOWS\lsbeuutbdn.exe tagged as not-a-virus:AdWare.Win32.Bestofer.d. No Action Taken.

File C:\WINDOWS\system32\winsdrv.dll tagged as not-a-virus:AdWare.Win32.BHO.ba. No Action Taken.

File C:\WINDOWS\system32\wmidext.dll tagged as not-a-virus:AdWare.Win32.VB.y. No Action Taken.

File C:\WINDOWS\xmnjhcg.exe tagged as not-a-virus:AdWare.Win32.BetterInternet.ai. No Action Taken.
0
kris6943 Messages postés 1517 Statut Membre 144
 
Supprimes les manuellement

C:\WINDOWS\lsbeuutbdn.exe

C:\WINDOWS\system32\winsdrv.dll

C:\WINDOWS\system32\wmidext.dll

C:\WINDOWS\xmnjhcg.exe

Tous les autres sont en quarantaine donc inactivés
0
zinko Messages postés 31 Statut Membre
 
c'est fait ! y'en a un que j'ai pas réussi a supprimer.
0
kris6943 Messages postés 1517 Statut Membre 144
 
et pourquoi? il refuse de s'effacer?
0
zinko Messages postés 31 Statut Membre
 
oui.
0
duflox Messages postés 2014 Statut Membre 43
 
ok bon on va prendre le taureau par les cornes:

Télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe (de Old_Timer) sur ton Bureau.

double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

Citation :

C:\WINDOWS\lsbeuutbdn.exe

C:\WINDOWS\xmnjhcg.exe

C:\WINDOWS\system32\winsdrv.dll

C:\WINDOWS\system32\wmidext.dll

clique sur MoveIt! pour lancer la suppression.
le résultat apparaîtra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

il te sera peut-être demander de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.

puis remets moi un rapport hijackthis

a+
0
zinko Messages postés 31 Statut Membre
 
le rappor de OTMoveIt !

File/Folder C:\WINDOWS\lsbeuutbdn.exe not found.
File/Folder not found.
File/Folder C:\WINDOWS\xmnjhcg.exe not found.
File/Folder not found.
C:\WINDOWS\system32\winsdrv.dll unregistered successfully.
C:\WINDOWS\system32\winsdrv.dll moved successfully.
File/Folder not found.
File/Folder C:\WINDOWS\system32\wmidext.dll not found.

Created on 09/14/2007 10:25:13

Ceux marqué "not found" c'est ceux que j'ai déja réussi a supprimer.
0
zinko
 
Et le rapport Hijackthis !

Logfile of HijackThis v1.99.1
Scan saved at 10:36:01, on 14/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\lexpps.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AOL Compagnon\companion.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: AOL 9.0 Icône AOL.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: AOL Compagnon.lnk = C:\Program Files\AOL Compagnon\companion.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ServerPushBox - http://www.turismodoalgarve.pt/meteo/rta/faroport/servp14.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.fr/computercheckup/qdiagcc.cab
O16 - DPF: {4BA12BBE-A1CD-4E13-85E4-A05E3FF6F658} (Pygmy Productions - Installer of Bluedot Game Object) - http://www.bluedotproject.com/BlueInstaller.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/10497be59b7623c58915/netzip/RdxIE601.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/7/532/6712/2.0.0.33/player.virtools.com/downloads/player/Install2.0/Installer.exe
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://guard.gunbound.net/nProtect/keyCrypt/npkcx.cab
O16 - DPF: {E6A3C1E2-F792-483E-9133-596215172BE9} (AcceptLang Class) - http://runonce.msn.com/setacceptlang.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir Service (AntiVirService) - Unknown owner - C:\Program Files\AVPersonal\AVGUARD.EXE (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\Program Files\Fichiers communs\AOL\AOL Spyware Protection\\aolserv.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AntiVir Update (AVWUpSrv) - Unknown owner - C:\Program Files\AVPersonal\AVWUPSRV.EXE (file missing)
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: npkcsvc - INCA Internet Co., Ltd. - C:\WINDOWS\System32\npkcsvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
0
duflox Messages postés 2014 Statut Membre 43
 
relance hijackthis puis clic sur "do a system scan only"

apres le scan coche ces lignes et seulement celles ci !!

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)

O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fr\msntb.dll (file missing)

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

O16 - DPF: ServerPushBox - http://www.turismodoalgarve.pt/meteo/rta/faroport/servp14.cab

O16 - DPF: {4BA12BBE-A1CD-4E13-85E4-A05E3FF6F658} (Pygmy Productions - Installer of Bluedot Game Object) - http://www.bluedotproject.com/BlueInstaller.cab

O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/

O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} (NPKCX Control) - http://guard.gunbound.net/nProtect/keyCrypt/npkcx.cab

O23 - Service: AntiVir Service (AntiVirService) - Unknown owner - C:\Program Files\AVPersonal\AVGUARD.EXE (file missing)

O23 - Service: AntiVir Update (AVWUpSrv) - Unknown owner - C:\Program Files\AVPersonal\AVWUPSRV.EXE (file missing)

referme ton navigateur (internet explorer ) puis clic sur " fix check"

ensuite a tu encore des problemes?
0