Win32:sinowal; win32:agent-oxw; win32:tiny-II

Bonjour,
j'ai donc des trojans win32 dont je n'arrive aps a me débarasser... mais aussi des rapports d'erreur a envoyer a chaque fois que j'ouvre une application... merci de m'apporter une solution si vous en avez une...
Configuration: Windows XP
Internet Explorer 7.0

5 réponses

  1. slt essaye sa:Dr Web CureIt ! , puis sa:Ad-Aware SE Personal Edition
    fait une mise a jour des 2 et pour le 1er fait une analyse rapide puis complete

    repond moi merci
    0
    1. la mise a jour de Ad-aware est impossible, il me donne une erreur a chaque fois...
      0
      1. fait pas de mise a jour alors
        0
        1. voila le rapport de Ad-aware

          Ad-Aware SE Build 1.06r1
          Logfile Created on:dimanche 27 janvier 2008 12:12:55
          Created with Ad-Aware SE Personal, free for private use.
          Using definitions file:SE1R47 24.05.2005
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

          References detected during the scan:
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
          AltnetBDE(TAC index:4):4 total references
          Cydoor(TAC index:7):5 total references
          Instafinder(TAC index:4):1 total references
          MRU List(TAC index:0):21 total references
          Tracking Cookie(TAC index:3):17 total references
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

          Ad-Aware SE Settings
          ===========================
          Set : Search for negligible risk entries
          Set : Safe mode (always request confirmation)
          Set : Scan active processes
          Set : Scan registry
          Set : Deep-scan registry
          Set : Scan my IE Favorites for banned URLs
          Set : Scan my Hosts file

          Extended Ad-Aware SE Settings
          ===========================
          Set : Unload recognized processes & modules during scan
          Set : Scan registry for all users instead of current user only
          Set : Always try to unload modules before deletion
          Set : During removal, unload Explorer and IE if necessary
          Set : Let Windows remove files in use at next reboot
          Set : Delete quarantined objects after restoring
          Set : Include basic Ad-Aware settings in log file
          Set : Include additional Ad-Aware settings in log file
          Set : Include reference summary in log file
          Set : Include alternate data stream details in log file
          Set : Play sound at scan completion if scan locates critical objects

          27-01-2008 12:12:55 - Scan started. (Full System Scan)

          MRU List Object Recognized!
          Location: : C:\Documents and Settings\JAMY\recent
          Description : list of recently opened documents

          MRU List Object Recognized!
          Location: : software\microsoft\direct3d\mostrecentapplication
          Description : most recent application to use microsoft direct3d

          MRU List Object Recognized!
          Location: : software\microsoft\direct3d\mostrecentapplication
          Description : most recent application to use microsoft direct X

          MRU List Object Recognized!
          Location: : software\microsoft\directdraw\mostrecentapplication
          Description : most recent application to use microsoft directdraw

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\internet explorer
          Description : last download directory used in microsoft internet explorer

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\internet explorer\typedurls
          Description : list of recently entered addresses in microsoft internet explorer

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\mediaplayer\medialibraryui
          Description : last selected node in the microsoft windows media player media library

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\mediaplayer\player\recentfilelist
          Description : list of recently used files in microsoft windows media player

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\mediaplayer\player\settings
          Description : last save as directory used in jasc paint shop pro

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\mediaplayer\player\settings
          Description : last open directory used in jasc paint shop pro

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\mediaplayer\preferences
          Description : last cd record path used in microsoft windows media player

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\mediaplayer\preferences
          Description : last search path used in microsoft windows media player

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\microsoft management console\recent file list
          Description : list of recent snap-ins used in the microsoft management console

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\office\11.0\common\general
          Description : list of recently used symbols in microsoft office

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\search assistant\acmru
          Description : list of recent search terms used with the search assistant

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
          Description : list of recent programs opened

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
          Description : list of recently saved files, stored according to file extension

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\windows\currentversion\explorer\recentdocs
          Description : list of recent documents opened

          MRU List Object Recognized!
          Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general
          Description : windows media sdk

          MRU List Object Recognized!
          Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general
          Description : windows media sdk

          MRU List Object Recognized!
          Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\windows media\wmsdk\general
          Description : windows media sdk

          Listing running processes
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

          #:1 [smss.exe]
          FilePath : \SystemRoot\System32\
          ProcessID : 548
          ThreadCreationTime : 27-01-2008 10:26:18
          BasePriority : Normal

          #:2 [csrss.exe]
          FilePath : \??\C:\WINDOWS\system32\
          ProcessID : 596
          ThreadCreationTime : 27-01-2008 10:26:20
          BasePriority : Normal

          #:3 [winlogon.exe]
          FilePath : \??\C:\WINDOWS\system32\
          ProcessID : 620
          ThreadCreationTime : 27-01-2008 10:26:20
          BasePriority : High

          #:4 [services.exe]
          FilePath : C:\WINDOWS\system32\
          ProcessID : 664
          ThreadCreationTime : 27-01-2008 10:26:20
          BasePriority : Normal
          FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
          ProductVersion : 5.1.2600.2180
          ProductName : Système d'exploitation Microsoft® Windows®
          CompanyName : Microsoft Corporation
          FileDescription : Applications Services et Contrôleur
          InternalName : services.exe
          LegalCopyright : © Microsoft Corporation. Tous droits réservés.
          OriginalFilename : services.exe

          #:5 [lsass.exe]
          FilePath : C:\WINDOWS\system32\
          ProcessID : 676
          ThreadCreationTime : 27-01-2008 10:26:20
          BasePriority : Normal
          FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
          ProductVersion : 5.1.2600.2180
          ProductName : Microsoft® Windows® Operating System
          CompanyName : Microsoft Corporation
          FileDescription : LSA Shell (Export Version)
          InternalName : lsass.exe
          LegalCopyright : © Microsoft Corporation. All rights reserved.
          OriginalFilename : lsass.exe

          #:6 [svchost.exe]
          FilePath : C:\WINDOWS\system32\
          ProcessID : 840
          ThreadCreationTime : 27-01-2008 10:26:21
          BasePriority : Normal
          FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
          ProductVersion : 5.1.2600.2180
          ProductName : Microsoft® Windows® Operating System
          CompanyName : Microsoft Corporation
          FileDescription : Generic Host Process for Win32 Services
          InternalName : svchost.exe
          LegalCopyright : © Microsoft Corporation. All rights reserved.
          OriginalFilename : svchost.exe

          #:7 [svchost.exe]
          FilePath : C:\WINDOWS\system32\
          ProcessID : 928
          ThreadCreationTime : 27-01-2008 10:26:21
          BasePriority : Normal
          FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
          ProductVersion : 5.1.2600.2180
          ProductName : Microsoft® Windows® Operating System
          CompanyName : Microsoft Corporation
          FileDescription : Generic Host Process for Win32 Services
          InternalName : svchost.exe
          LegalCopyright : © Microsoft Corporation. All rights reserved.
          OriginalFilename : svchost.exe

          #:8 [svchost.exe]
          FilePath : C:\WINDOWS\System32\
          ProcessID : 1024
          ThreadCreationTime : 27-01-2008 10:26:21
          BasePriority : Normal
          FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
          ProductVersion : 5.1.2600.2180
          ProductName : Microsoft® Windows® Operating System
          CompanyName : Microsoft Corporation
          FileDescription : Generic Host Process for Win32 Services
          InternalName : svchost.exe
          LegalCopyright : © Microsoft Corporation. All rights reserved.
          OriginalFilename : svchost.exe

          #:9 [svchost.exe]
          FilePath : C:\WINDOWS\system32\
          ProcessID : 1112
          ThreadCreationTime : 27-01-2008 10:26:21
          BasePriority : Normal
          FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
          ProductVersion : 5.1.2600.2180
          ProductName : Microsoft® Windows® Operating System
          CompanyName : Microsoft Corporation
          FileDescription : Generic Host Process for Win32 Services
          InternalName : svchost.exe
          LegalCopyright : © Microsoft Corporation. All rights reserved.
          OriginalFilename : svchost.exe

          #:10 [svchost.exe]
          FilePath : C:\WINDOWS\system32\
          ProcessID : 1252
          ThreadCreationTime : 27-01-2008 10:26:21
          BasePriority : Normal
          FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
          ProductVersion : 5.1.2600.2180
          ProductName : Microsoft® Windows® Operating System
          CompanyName : Microsoft Corporation
          FileDescription : Generic Host Process for Win32 Services
          InternalName : svchost.exe
          LegalCopyright : © Microsoft Corporation. All rights reserved.
          OriginalFilename : svchost.exe

          #:11 [aswupdsv.exe]
          FilePath : C:\Program Files\Alwil Software\Avast4\
          ProcessID : 1308
          ThreadCreationTime : 27-01-2008 10:26:22
          BasePriority : Normal
          FileVersion : 4, 7, 1098, 0
          ProductVersion : 4, 7, 0, 0
          ProductName : avast! Antivirus
          CompanyName : ALWIL Software
          FileDescription : avast! Antivirus updating service
          InternalName : aswUpdSv.exe
          LegalCopyright : Copyright (c) 2007 ALWIL Software
          OriginalFilename : aswUpdSv.exe

          #:12 [ashserv.exe]
          FilePath : C:\Program Files\Alwil Software\Avast4\
          ProcessID : 1356
          ThreadCreationTime : 27-01-2008 10:26:22
          BasePriority : High
          FileVersion : 4, 7, 1098, 0
          ProductVersion : 4, 7, 0, 0
          ProductName : avast! Antivirus
          CompanyName : ALWIL Software
          FileDescription : avast! antivirus service
          InternalName : aswServ
          LegalCopyright : Copyright (c) 2007 ALWIL Software
          OriginalFilename : aswServ.exe

          #:13 [spoolsv.exe]
          FilePath : C:\WINDOWS\system32\
          ProcessID : 1792
          ThreadCreationTime : 27-01-2008 10:26:24
          BasePriority : Normal
          FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
          ProductVersion : 5.1.2600.2696
          ProductName : Microsoft® Windows® Operating System
          CompanyName : Microsoft Corporation
          FileDescription : Spooler SubSystem App
          InternalName : spoolsv.exe
          LegalCopyright : © Microsoft Corporation. All rights reserved.
          OriginalFilename : spoolsv.exe

          #:14 [explorer.exe]
          FilePath : C:\WINDOWS\
          ProcessID : 1808
          ThreadCreationTime : 27-01-2008 10:26:24
          BasePriority : Normal
          FileVersion : 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)
          ProductVersion : 6.00.2900.3156
          ProductName : Système d'exploitation Microsoft® Windows®
          CompanyName : Microsoft Corporation
          FileDescription : Explorateur Windows
          InternalName : explorer
          LegalCopyright : © Microsoft Corporation. Tous droits réservés.
          OriginalFilename : EXPLORER.EXE

          #:15 [adeck.exe]
          FilePath : C:\Program Files\VIAudioi\SBADeck\
          ProcessID : 248
          ThreadCreationTime : 27-01-2008 10:26:26
          BasePriority : Normal
          FileVersion : 1.0.0.0
          ProductVersion : 1.62
          ProductName : Vinyl Deck
          CompanyName : VIA Technologies, Inc.
          FileDescription : VIA Codec Control Panel
          InternalName : Vinyl Deck

          #:16 [wkufind.exe]
          FilePath : C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\
          ProcessID : 272
          ThreadCreationTime : 27-01-2008 10:26:26
          BasePriority : Normal
          FileVersion : 9.00.0603.0
          ProductVersion : 9.00.0603.0
          ProductName : Update Detection Module
          CompanyName : Microsoft® Corporation
          FileDescription : Détection Microsoft® Works Update
          InternalName : WkUFind
          LegalCopyright : Copyright © 1987-2003 Microsoft Corporation.
          OriginalFilename : WkUFind.exe

          #:17 [hpwuschd2.exe]
          FilePath : C:\Program Files\HP\HP Software Update\
          ProcessID : 352
          ThreadCreationTime : 27-01-2008 10:26:26
          BasePriority : Normal
          FileVersion : 53.0.13.000
          ProductVersion : 053.000.013.000
          ProductName : hp digital imaging - hp all-in-one series
          CompanyName : Hewlett-Packard Co.
          FileDescription : Hewlett-Packard Product Assistant
          InternalName : hpwuSchd2
          LegalCopyright : Copyright (C) Hewlett-Packard Co. 1995-2004
          OriginalFilename : hpwuSchd2.exe
          Comments : Hewlett-Packard Product Assistant

          #:18 [logitray.exe]
          FilePath : C:\Program Files\Logitech\Video\
          ProcessID : 344
          ThreadCreationTime : 27-01-2008 10:26:27
          BasePriority : Normal
          FileVersion : 8.0.3.1112
          ProductVersion : 8.0.3.1112
          ProductName : Logitech QuickCam
          CompanyName : Logitech Inc.
          FileDescription : ImageStudio Tray Application
          InternalName : LogiTray.exe
          LegalCopyright : (c) 1996-2003 Logitech. All rights reserved.
          OriginalFilename : LogiTray.exe

          #:19 [jusched.exe]
          FilePath : C:\Program Files\Java\jre1.6.0_03\bin\
          ProcessID : 388
          ThreadCreationTime : 27-01-2008 10:26:27
          BasePriority : Normal

          #:20 [ashdisp.exe]
          FilePath : C:\PROGRA~1\ALWILS~1\Avast4\
          ProcessID : 416
          ThreadCreationTime : 27-01-2008 10:26:27
          BasePriority : Normal
          FileVersion : 4, 7, 1098, 0
          ProductVersion : 4, 7, 0, 0
          ProductName : avast! Antivirus
          CompanyName : ALWIL Software
          FileDescription : avast! service GUI component
          InternalName : aswDisp
          LegalCopyright : Copyright (c) 2007 ALWIL Software
          OriginalFilename : aswDisp.exe

          #:21 [systrayapp.exe]
          FilePath : C:\Program Files\Orange HSS\Systray\
          ProcessID : 480
          ThreadCreationTime : 27-01-2008 10:26:27
          BasePriority : Normal
          FileVersion : 1.0.37.730
          ProductVersion : 6.0.0.730
          ProductName : CSS-Corporate
          CompanyName : France Telecom SA
          InternalName : Systray
          LegalCopyright : Copyright (c) 2006
          OriginalFilename : SystrayApp.exe

          #:22 [lowlight.exe]
          FilePath : C:\Program Files\Logitech\Video\
          ProcessID : 296
          ThreadCreationTime : 27-01-2008 10:26:27
          BasePriority : Normal
          FileVersion : 8.0.3.1112
          ProductVersion : 8.0.3.1112
          ProductName : Logitech QuickCam
          CompanyName : Logitech Inc.
          FileDescription : Automatic Low Light Module
          InternalName : LowLight.exe
          LegalCopyright : (c) 1996-2003 Logitech. All rights reserved.
          OriginalFilename : LowLight.exe

          #:23 [qttask.exe]
          FilePath : C:\Program Files\QuickTime\
          ProcessID : 536
          ThreadCreationTime : 27-01-2008 10:26:27
          BasePriority : Normal
          FileVersion : 7.3.1
          ProductVersion : QuickTime 7.3.1
          ProductName : QuickTime
          CompanyName : Apple Inc.
          FileDescription : QuickTime Task
          InternalName : QuickTime Task
          LegalCopyright : Copyright Apple Inc. 1989-2007
          OriginalFilename : QTTask.exe

          #:24 [alertmodule.exe]
          FilePath : C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\
          ProcessID : 580
          ThreadCreationTime : 27-01-2008 10:26:27
          BasePriority : Normal
          FileVersion : 1.0.10.730
          ProductVersion : 6.0.0.730
          ProductName : CSS-Corporate
          CompanyName : France Telecom SA
          InternalName : AlertModule.dll
          LegalCopyright : Copyright (c) 2006
          OriginalFilename : AlertModule.dll

          #:25 [ituneshelper.exe]
          FilePath : C:\Program Files\iTunes\
          ProcessID : 808
          ThreadCreationTime : 27-01-2008 10:26:28
          BasePriority : Normal
          FileVersion : 7.5.0.20
          ProductVersion : 7.5.0.20
          ProductName : iTunes
          CompanyName : Apple Inc.
          FileDescription : iTunesHelper Module
          InternalName : iTunesHelper
          LegalCopyright : © 2003-2007 Apple Inc. All Rights Reserved.
          OriginalFilename : iTunesHelper.exe

          #:26 [launcher.exe]
          FilePath : C:\Program Files\Orange HSS\Launcher\
          ProcessID : 964
          ThreadCreationTime : 27-01-2008 10:26:28
          BasePriority : Normal
          FileVersion : 1.0.117.730
          ProductVersion : 6.0.0.730
          ProductName : CSS-Corporate
          CompanyName : France Telecom SA
          InternalName : Launcher.exe
          LegalCopyright : Copyright (c) 2006
          OriginalFilename : Launcher.exe

          #:27 [rtegprs.exe]
          FilePath : C:\Program Files\Fichiers communs\SmartCom\
          ProcessID : 1152
          ThreadCreationTime : 27-01-2008 10:26:28
          BasePriority : Normal
          FileVersion : 2, 2, 0, 0
          ProductVersion : 2, 2, 0, 0
          ProductName : Contrôleur RTEGPRS
          CompanyName : SmartCom
          FileDescription : Contrôleur de mobile GPRS/GSM
          InternalName : RTEGPRS
          LegalCopyright : Copyright © SmartCom 2001-2005
          OriginalFilename : RTEGPRS.exe

          #:28 [ctfmon.exe]
          FilePath : C:\WINDOWS\system32\
          ProcessID : 1164
          ThreadCreationTime : 27-01-2008 10:26:28
          BasePriority : Normal
          FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
          ProductVersion : 5.1.2600.2180
          ProductName : Microsoft® Windows® Operating System
          CompanyName : Microsoft Corporation
          FileDescription : CTF Loader
          InternalName : CTFMON
          LegalCopyright : © Microsoft Corporation. All rights reserved.
          OriginalFilename : CTFMON.EXE

          #:29 [gstart.exe]
          FilePath : C:\Garmin\
          ProcessID : 1204
          ThreadCreationTime : 27-01-2008 10:26:29
          BasePriority : Normal

          #:30 [hpqtra08.exe]
          FilePath : C:\Program Files\HP\Digital Imaging\bin\
          ProcessID : 1284
          ThreadCreationTime : 27-01-2008 10:26:29
          BasePriority : Normal
          FileVersion : 53.0.13.000
          ProductVersion : 053.000.013.000
          ProductName : hp digital imaging - hp all-in-one series
          CompanyName : Hewlett-Packard Co.
          FileDescription : HP Digital Imaging Monitor
          InternalName : HPQTRA00
          LegalCopyright : Copyright (C) Hewlett-Packard Co. 1995-2004
          OriginalFilename : HPQTRA00.EXE
          Comments : HP Digital Imaging Monitor

          #:31 [applemobiledeviceservice.exe]
          FilePath : C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\
          ProcessID : 1648
          ThreadCreationTime : 27-01-2008 10:26:31
          BasePriority : Normal
          FileVersion : 1, 14, 0, 0
          ProductVersion : 1, 14, 0, 0
          ProductName : Apple Mobile Device Service
          CompanyName : Apple, Inc.
          FileDescription : Apple Mobile Device Service
          InternalName : usbaapld
          LegalCopyright : Copyright 2007 Apple, Inc. All Rights Reserved.
          OriginalFilename : AppleMobileDeviceService.exe

          #:32 [ftrtsvc.exe]
          FilePath : C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\
          ProcessID : 1888
          ThreadCreationTime : 27-01-2008 10:26:31
          BasePriority : Normal
          FileVersion : 12.1.74.730
          ProductVersion : 6.0.0.730
          ProductName : CSS-Corporate
          CompanyName : France Telecom SA
          InternalName : FTRTSVC.exe
          LegalCopyright : Copyright (c) 2006
          OriginalFilename : FTRTSVC.exe

          #:33 [hpqimzone.exe]
          FilePath : C:\Program Files\HP\Digital Imaging\bin\
          ProcessID : 2100
          ThreadCreationTime : 27-01-2008 10:26:32
          BasePriority : Normal

          #:34 [deskboard.exe]
          FilePath : C:\Program Files\Orange HSS\Deskboard\
          ProcessID : 2152
          ThreadCreationTime : 27-01-2008 10:26:34
          BasePriority : Normal

          #:35 [connectivitymanager.exe]
          FilePath : C:\Program Files\Orange HSS\connectivity\
          ProcessID : 2164
          ThreadCreationTime : 27-01-2008 10:26:34
          BasePriority : Normal
          FileVersion : 1.1.65.730
          ProductVersion : 6.0.0.730
          ProductName : CSS-Corporate
          CompanyName : France Telecom SA
          InternalName : ConnectivityManager.exe
          LegalCopyright : Copyright (c) 2006
          OriginalFilename : ConnectivityManager.exe

          #:36 [corecom.exe]
          FilePath : C:\Program Files\Orange HSS\connectivity\CoreCom\
          ProcessID : 2196
          ThreadCreationTime : 27-01-2008 10:26:35
          BasePriority : Normal
          FileVersion : 12.1.74.730
          ProductVersion : 6.0.0.730
          ProductName : CSS-Corporate
          CompanyName : France Telecom SA
          InternalName : CoreCom.exe
          LegalCopyright : Copyright (c) 2006
          OriginalFilename : CoreCom.exe

          #:37 [svchost.exe]
          FilePath : C:\WINDOWS\system32\
          ProcessID : 2248
          ThreadCreationTime : 27-01-2008 10:26:35
          BasePriority : Normal
          FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
          ProductVersion : 5.1.2600.2180
          ProductName : Microsoft® Windows® Operating System
          CompanyName : Microsoft Corporation
          FileDescription : Generic Host Process for Win32 Services
          InternalName : svchost.exe
          LegalCopyright : © Microsoft Corporation. All rights reserved.
          OriginalFilename : svchost.exe

          #:38 [mdm.exe]
          FilePath : C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\
          ProcessID : 2260
          ThreadCreationTime : 27-01-2008 10:26:35
          BasePriority : Normal
          FileVersion : 7.00.9466
          ProductVersion : 7.00.9466
          ProductName : Microsoft® Visual Studio .NET
          CompanyName : Microsoft Corporation
          FileDescription : Machine Debug Manager
          InternalName : mdm.exe
          LegalCopyright : © Microsoft Corporation. All rights reserved.
          OriginalFilename : mdm.exe

          #:39 [svchost.exe]
          FilePath : C:\WINDOWS\system32\
          ProcessID : 2384
          ThreadCreationTime : 27-01-2008 10:26:36
          BasePriority : Normal
          FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
          ProductVersion : 5.1.2600.2180
          ProductName : Microsoft® Windows® Operating System
          CompanyName : Microsoft Corporation
          FileDescription : Generic Host Process for Win32 Services
          InternalName : svchost.exe
          LegalCopyright : © Microsoft Corporation. All rights reserved.
          OriginalFilename : svchost.exe

          #:40 [ashmaisv.exe]
          FilePath : C:\Program Files\Alwil Software\Avast4\
          ProcessID : 2596
          ThreadCreationTime : 27-01-2008 10:26:46
          BasePriority : Normal

          #:41 [ashwebsv.exe]
          FilePath : C:\Program Files\Alwil Software\Avast4\
          ProcessID : 2680
          ThreadCreationTime : 27-01-2008 10:26:49
          BasePriority : Normal

          #:42 [hpqste08.exe]
          FilePath : C:\Program Files\HP\Digital Imaging\bin\
          ProcessID : 2860
          ThreadCreationTime : 27-01-2008 10:26:51
          BasePriority : Normal
          FileVersion : 53.0.13.000
          ProductVersion : 053.000.013.000
          ProductName : hp digital imaging - hp all-in-one series
          CompanyName : Hewlett-Packard Co.
          FileDescription : HP CUE Status
          InternalName : HPQSTS00
          LegalCopyright : Copyright (C) Hewlett-Packard Co. 1995-2004
          OriginalFilename : HPQSTS00.EXE
          Comments : HP CUE Status

          #:43 [ipodservice.exe]
          FilePath : C:\Program Files\iPod\bin\
          ProcessID : 3380
          ThreadCreationTime : 27-01-2008 10:27:03
          BasePriority : Normal
          FileVersion : 7.5.0.20
          ProductVersion : 7.5.0.20
          ProductName : iTunes
          CompanyName : Apple Inc.
          FileDescription : iPodService Module
          InternalName : iPodService
          LegalCopyright : © 2003-2007 Apple Inc. All Rights Reserved.
          OriginalFilename : iPodService.exe

          #:44 [alg.exe]
          FilePath : C:\WINDOWS\System32\
          ProcessID : 3692
          ThreadCreationTime : 27-01-2008 10:27:10
          BasePriority : Normal
          FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
          ProductVersion : 5.1.2600.2180
          ProductName : Microsoft® Windows® Operating System
          CompanyName : Microsoft Corporation
          FileDescription : Application Layer Gateway Service
          InternalName : ALG.exe
          LegalCopyright : © Microsoft Corporation. All rights reserved.
          OriginalFilename : ALG.exe

          #:45 [oraconfigrecover.exe]
          FilePath : C:\Program Files\Orange HSS\connectivity\CoreCom\
          ProcessID : 724
          ThreadCreationTime : 27-01-2008 10:27:24
          BasePriority : Normal
          FileVersion : 12.1.74.730
          ProductVersion : 6.0.0.730
          ProductName : CSS-Corporate
          CompanyName : France Telecom SA
          InternalName : OraConfigRecover.exe
          LegalCopyright : Copyright (c) 2006
          OriginalFilename : OraConfigRecover.exe

          #:46 [ftcommodule.exe]
          FilePath : C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\
          ProcessID : 2708
          ThreadCreationTime : 27-01-2008 10:27:25
          BasePriority : Normal
          FileVersion : 12.1.74.730
          ProductVersion : 6.0.0.730
          ProductName : CSS-Corporate
          CompanyName : France Telecom SA
          InternalName : FTCOMModule.exe
          LegalCopyright : Copyright (c) 2006
          OriginalFilename : FTCOMModule.exe

          #:47 [wmiprvse.exe]
          FilePath : C:\WINDOWS\system32\wbem\
          ProcessID : 3472
          ThreadCreationTime : 27-01-2008 10:27:33
          BasePriority : Normal
          FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
          ProductVersion : 5.1.2600.2180
          ProductName : Microsoft® Windows® Operating System
          CompanyName : Microsoft Corporation
          FileDescription : WMI
          InternalName : Wmiprvse.exe
          LegalCopyright : © Microsoft Corporation. All rights reserved.
          OriginalFilename : Wmiprvse.exe

          #:48 [wlloginproxy.exe]
          FilePath : C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\
          ProcessID : 4020
          ThreadCreationTime : 27-01-2008 10:28:27
          BasePriority : Normal
          FileVersion : 4.200.520.1
          ProductVersion : 4.200.520.1
          ProductName : Microsoft® Windows Live Login Helper
          CompanyName : Microsoft Corporation
          FileDescription : WLLoginProxy.exe
          InternalName : WLLoginProxy
          LegalCopyright : Copyright © 1995-2006 Microsoft Corporation.
          LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation.
          OriginalFilename : WLLoginProxy.exe

          #:49 [iexplore.exe]
          FilePath : C:\Program Files\Internet Explorer\
          ProcessID : 1232
          ThreadCreationTime : 27-01-2008 10:29:13
          BasePriority : Normal
          FileVersion : 7.00.6000.16574 (vista_gdr.071008-1500)
          ProductVersion : 7.00.6000.16574
          ProductName : Windows® Internet Explorer
          CompanyName : Microsoft Corporation
          FileDescription : Internet Explorer
          InternalName : iexplore
          LegalCopyright : © Microsoft Corporation. All rights reserved.
          OriginalFilename : IEXPLORE.EXE

          #:50 [browser.exe]
          FilePath : C:\Program Files\Orange HSS\browser\
          ProcessID : 3664
          ThreadCreationTime : 27-01-2008 11:01:56
          BasePriority : Normal

          #:51 [cureit[2].exe]
          FilePath : C:\Documents and Settings\JAMY\Local Settings\Temporary Internet Files\Content.IE5\FD93BTS6\
          ProcessID : 3376
          ThreadCreationTime : 27-01-2008 11:03:37
          BasePriority : Normal

          #:52 [_start.exe]
          FilePath : C:\DOCUME~1\JAMY\LOCALS~1\Temp\RarSFX2\
          ProcessID : 4012
          ThreadCreationTime : 27-01-2008 11:03:38
          BasePriority : Normal
          FileVersion : 2.53
          ProductVersion : 2.53
          ProductName : AutoRun Manager
          CompanyName : Doctor Web, Ltd.
          FileDescription : AutoRun
          InternalName : AutoRun
          LegalCopyright : Copyright © 2005 Doctor Web, Ltd.
          OriginalFilename : AutoRun.exe

          #:53 [setup.exe]
          FilePath : C:\DOCUME~1\JAMY\LOCALS~1\Temp\RarSFX2\
          ProcessID : 860
          ThreadCreationTime : 27-01-2008 11:03:47
          BasePriority : Normal

          #:54 [ad-aware.exe]
          FilePath : C:\PROGRA~1\Lavasoft\AD-AWA~1\
          ProcessID : 3852
          ThreadCreationTime : 27-01-2008 11:09:30
          BasePriority : Normal
          FileVersion : 6.2.0.236
          ProductVersion : SE 106
          ProductName : Lavasoft Ad-Aware SE
          CompanyName : Lavasoft Sweden
          FileDescription : Ad-Aware SE Core application
          InternalName : Ad-Aware.exe
          LegalCopyright : Copyright © Lavasoft AB Sweden
          OriginalFilename : Ad-Aware.exe
          Comments : All Rights Reserved

          Memory scan result:
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
          New critical objects: 0
          Objects found so far: 21

          Started registry scan
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

          Cydoor Object Recognized!
          Type : Regkey
          Data :
          TAC Rating : 7
          Category : Data Miner
          Comment :
          Rootkey : HKEY_USERS
          Object : S-1-5-21-746137067-616249376-682003330-1004\software\cydoor

          Cydoor Object Recognized!
          Type : RegValue
          Data :
          TAC Rating : 7
          Category : Data Miner
          Comment :
          Rootkey : HKEY_USERS
          Object : S-1-5-21-746137067-616249376-682003330-1004\software\cydoor
          Value : ConnType

          AltnetBDE Object Recognized!
          Type : Regkey
          Data :
          TAC Rating : 4
          Category : Data Miner
          Comment :
          Rootkey : HKEY_LOCAL_MACHINE
          Object : software\classes\adm25.adm25

          AltnetBDE Object Recognized!
          Type : Regkey
          Data :
          TAC Rating : 4
          Category : Data Miner
          Comment :
          Rootkey : HKEY_LOCAL_MACHINE
          Object : software\classes\adm4.adm4

          AltnetBDE Object Recognized!
          Type : Regkey
          Data :
          TAC Rating : 4
          Category : Data Miner
          Comment :
          Rootkey : HKEY_LOCAL_MACHINE
          Object : software\classes\appid\adm.exe

          AltnetBDE Object Recognized!
          Type : Regkey
          Data :
          TAC Rating : 4
          Category : Data Miner
          Comment :
          Rootkey : HKEY_LOCAL_MACHINE
          Object : software\classes\appid\altnet signing module.exe

          Cydoor Object Recognized!
          Type : Regkey
          Data :
          TAC Rating : 7
          Category : Data Miner
          Comment :
          Rootkey : HKEY_LOCAL_MACHINE
          Object : software\cydoor

          Instafinder Object Recognized!
          Type : Regkey
          Data :
          TAC Rating : 4
          Category : Malware
          Comment :
          Rootkey : HKEY_LOCAL_MACHINE
          Object : software\microsoft\windows\currentversion\explorer\browser helper objects\{4e7bd74f-2b8d-469e-90f0-f66ab581a933}

          Cydoor Object Recognized!
          Type : Regkey
          Data :
          TAC Rating : 7
          Category : Data Miner
          Comment :
          Rootkey : HKEY_USERS
          Object : S-1-5-21-746137067-616249376-682003330-1004\\software\cydoor

          Cydoor Object Recognized!
          Type : RegValue
          Data :
          TAC Rating : 7
          Category : Data Miner
          Comment :
          Rootkey : HKEY_USERS
          Object : S-1-5-21-746137067-616249376-682003330-1004\\software\cydoor
          Value : ConnType

          Registry Scan result:
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
          New critical objects: 10
          Objects found so far: 31

          Started deep registry scan
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

          Deep registry scan result:
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
          New critical objects: 0
          Objects found so far: 31

          Started Tracking Cookie scan
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@serving-sys[2].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:13
          Value : Cookie:jamy@serving-sys.com/
          Expires : 31-12-2037 23:00:00
          LastSync : Hits:13
          UseCount : 0
          Hits : 13

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@estat[1].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:1
          Value : Cookie:jamy@estat.com/
          Expires : 24-01-2018 11:40:38
          LastSync : Hits:1
          UseCount : 0
          Hits : 1

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@247realmedia[1].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:1
          Value : Cookie:jamy@247realmedia.com/
          Expires : 01-01-2021 01:00:00
          LastSync : Hits:1
          UseCount : 0
          Hits : 1

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@doubleclick[1].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:13
          Value : Cookie:jamy@doubleclick.net/
          Expires : 25-01-2010 23:10:36
          LastSync : Hits:13
          UseCount : 0
          Hits : 13

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@hitbox[1].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:57
          Value : Cookie:jamy@hitbox.com/
          Expires : 26-01-2009 12:00:46
          LastSync : Hits:57
          UseCount : 0
          Hits : 57

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@tradedoubler[1].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:5
          Value : Cookie:jamy@tradedoubler.com/
          Expires : 25-02-2008 21:10:26
          LastSync : Hits:5
          UseCount : 0
          Hits : 5

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@bs.serving-sys[1].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:4
          Value : Cookie:jamy@bs.serving-sys.com/
          Expires : 31-12-2037 23:00:00
          LastSync : Hits:4
          UseCount : 0
          Hits : 4

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@weborama[1].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:7
          Value : Cookie:jamy@weborama.fr/
          Expires : 24-01-2013 20:13:20
          LastSync : Hits:7
          UseCount : 0
          Hits : 7

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@atdmt[2].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:12
          Value : Cookie:jamy@atdmt.com/
          Expires : 24-01-2013 01:00:00
          LastSync : Hits:12
          UseCount : 0
          Hits : 12

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@ehg-neuftelecom.hitbox[1].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:21
          Value : Cookie:jamy@ehg-neuftelecom.hitbox.com/
          Expires : 26-01-2009 12:00:46
          LastSync : Hits:21
          UseCount : 0
          Hits : 21

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@advertising[2].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:162
          Value : Cookie:jamy@advertising.com/
          Expires : 25-01-2013 00:16:56
          LastSync : Hits:162
          UseCount : 0
          Hits : 162

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@mediaplex[1].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:6
          Value : Cookie:jamy@mediaplex.com/
          Expires : 22-06-2009 01:00:00
          LastSync : Hits:6
          UseCount : 0
          Hits : 6

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@adtech[1].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:1
          Value : Cookie:jamy@adtech.de/
          Expires : 25-01-2010 20:13:54
          LastSync : Hits:1
          UseCount : 0
          Hits : 1

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@adviva[2].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:2
          Value : Cookie:jamy@adviva.net/
          Expires : 30-12-2012 21:10:06
          LastSync : Hits:2
          UseCount : 0
          Hits : 2

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@ehg-telecomitalia.hitbox[1].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:7
          Value : Cookie:jamy@ehg-telecomitalia.hitbox.com/
          Expires : 26-01-2009 11:46:26
          LastSync : Hits:7
          UseCount : 0
          Hits : 7

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@bluestreak[2].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:8
          Value : Cookie:jamy@bluestreak.com/
          Expires : 24-01-2018 07:19:52
          LastSync : Hits:8
          UseCount : 0
          Hits : 8

          Tracking Cookie Object Recognized!
          Type : IECache Entry
          Data : jamy@smartadserver[1].txt
          TAC Rating : 3
          Category : Data Miner
          Comment : Hits:25
          Value : Cookie:jamy@smartadserver.com/
          Expires : 22-01-2028 12:17:28
          LastSync : Hits:25
          UseCount : 0
          Hits : 25

          Tracking cookie scan result:
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
          New critical objects: 17
          Objects found so far: 48

          Deep scanning and examining files (C:)
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

          Disk Scan Result for C:\
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
          New critical objects: 0
          Objects found so far: 48

          Hosts file scan result:
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
          0 entries scanned.
          New critical objects:0
          Objects found so far: 48

          Performing conditional scans...
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

          Conditional scan result:
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
          New critical objects: 0
          Objects found so far: 48

          12:45:24 Scan Complete

          Summary Of This Scan
          »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
          Total scanning time:00:32:28.562
          Objects scanned:149216
          Objects identified:27
          Objects ignored:0
          New critical objects:27
          0