Win32:sinowal; win32:agent-oxw; win32:tiny-II

letoulousain -  
 Profil bloqué -
Bonjour,
j'ai donc des trojans win32 dont je n'arrive aps a me débarasser... mais aussi des rapports d'erreur a envoyer a chaque fois que j'ouvre une application... merci de m'apporter une solution si vous en avez une...
Configuration: Windows XP
Internet Explorer 7.0

5 réponses

  1. Profil bloqué
     
    slt essaye sa:Dr Web CureIt ! , puis sa:Ad-Aware SE Personal Edition
    fait une mise a jour des 2 et pour le 1er fait une analyse rapide puis complete

    repond moi merci
    0
  2. novice47 Messages postés 1 Statut Membre
     
    la mise a jour de Ad-aware est impossible, il me donne une erreur a chaque fois...
    0
  3. Profil bloqué
     
    fait pas de mise a jour alors
    0
  4. letoulousain
     
    voila le rapport de Ad-aware

    Ad-Aware SE Build 1.06r1
    Logfile Created on:dimanche 27 janvier 2008 12:12:55
    Created with Ad-Aware SE Personal, free for private use.
    Using definitions file:SE1R47 24.05.2005
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    References detected during the scan:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    AltnetBDE(TAC index:4):4 total references
    Cydoor(TAC index:7):5 total references
    Instafinder(TAC index:4):1 total references
    MRU List(TAC index:0):21 total references
    Tracking Cookie(TAC index:3):17 total references
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    Ad-Aware SE Settings
    ===========================
    Set : Search for negligible risk entries
    Set : Safe mode (always request confirmation)
    Set : Scan active processes
    Set : Scan registry
    Set : Deep-scan registry
    Set : Scan my IE Favorites for banned URLs
    Set : Scan my Hosts file

    Extended Ad-Aware SE Settings
    ===========================
    Set : Unload recognized processes & modules during scan
    Set : Scan registry for all users instead of current user only
    Set : Always try to unload modules before deletion
    Set : During removal, unload Explorer and IE if necessary
    Set : Let Windows remove files in use at next reboot
    Set : Delete quarantined objects after restoring
    Set : Include basic Ad-Aware settings in log file
    Set : Include additional Ad-Aware settings in log file
    Set : Include reference summary in log file
    Set : Include alternate data stream details in log file
    Set : Play sound at scan completion if scan locates critical objects

    27-01-2008 12:12:55 - Scan started. (Full System Scan)

    MRU List Object Recognized!
    Location: : C:\Documents and Settings\JAMY\recent
    Description : list of recently opened documents

    MRU List Object Recognized!
    Location: : software\microsoft\direct3d\mostrecentapplication
    Description : most recent application to use microsoft direct3d

    MRU List Object Recognized!
    Location: : software\microsoft\direct3d\mostrecentapplication
    Description : most recent application to use microsoft direct X

    MRU List Object Recognized!
    Location: : software\microsoft\directdraw\mostrecentapplication
    Description : most recent application to use microsoft directdraw

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\internet explorer
    Description : last download directory used in microsoft internet explorer

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\internet explorer\typedurls
    Description : list of recently entered addresses in microsoft internet explorer

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\mediaplayer\medialibraryui
    Description : last selected node in the microsoft windows media player media library

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\mediaplayer\player\recentfilelist
    Description : list of recently used files in microsoft windows media player

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\mediaplayer\player\settings
    Description : last save as directory used in jasc paint shop pro

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\mediaplayer\player\settings
    Description : last open directory used in jasc paint shop pro

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\mediaplayer\preferences
    Description : last cd record path used in microsoft windows media player

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\mediaplayer\preferences
    Description : last search path used in microsoft windows media player

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\microsoft management console\recent file list
    Description : list of recent snap-ins used in the microsoft management console

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\office\11.0\common\general
    Description : list of recently used symbols in microsoft office

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\search assistant\acmru
    Description : list of recent search terms used with the search assistant

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
    Description : list of recent programs opened

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
    Description : list of recently saved files, stored according to file extension

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\windows\currentversion\explorer\recentdocs
    Description : list of recent documents opened

    MRU List Object Recognized!
    Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general
    Description : windows media sdk

    MRU List Object Recognized!
    Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general
    Description : windows media sdk

    MRU List Object Recognized!
    Location: : S-1-5-21-746137067-616249376-682003330-1004\software\microsoft\windows media\wmsdk\general
    Description : windows media sdk

    Listing running processes
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    #:1 [smss.exe]
    FilePath : \SystemRoot\System32\
    ProcessID : 548
    ThreadCreationTime : 27-01-2008 10:26:18
    BasePriority : Normal

    #:2 [csrss.exe]
    FilePath : \??\C:\WINDOWS\system32\
    ProcessID : 596
    ThreadCreationTime : 27-01-2008 10:26:20
    BasePriority : Normal

    #:3 [winlogon.exe]
    FilePath : \??\C:\WINDOWS\system32\
    ProcessID : 620
    ThreadCreationTime : 27-01-2008 10:26:20
    BasePriority : High

    #:4 [services.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 664
    ThreadCreationTime : 27-01-2008 10:26:20
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Système d'exploitation Microsoft® Windows®
    CompanyName : Microsoft Corporation
    FileDescription : Applications Services et Contrôleur
    InternalName : services.exe
    LegalCopyright : © Microsoft Corporation. Tous droits réservés.
    OriginalFilename : services.exe

    #:5 [lsass.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 676
    ThreadCreationTime : 27-01-2008 10:26:20
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : LSA Shell (Export Version)
    InternalName : lsass.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : lsass.exe

    #:6 [svchost.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 840
    ThreadCreationTime : 27-01-2008 10:26:21
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Generic Host Process for Win32 Services
    InternalName : svchost.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : svchost.exe

    #:7 [svchost.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 928
    ThreadCreationTime : 27-01-2008 10:26:21
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Generic Host Process for Win32 Services
    InternalName : svchost.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : svchost.exe

    #:8 [svchost.exe]
    FilePath : C:\WINDOWS\System32\
    ProcessID : 1024
    ThreadCreationTime : 27-01-2008 10:26:21
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Generic Host Process for Win32 Services
    InternalName : svchost.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : svchost.exe

    #:9 [svchost.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 1112
    ThreadCreationTime : 27-01-2008 10:26:21
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Generic Host Process for Win32 Services
    InternalName : svchost.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : svchost.exe

    #:10 [svchost.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 1252
    ThreadCreationTime : 27-01-2008 10:26:21
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Generic Host Process for Win32 Services
    InternalName : svchost.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : svchost.exe

    #:11 [aswupdsv.exe]
    FilePath : C:\Program Files\Alwil Software\Avast4\
    ProcessID : 1308
    ThreadCreationTime : 27-01-2008 10:26:22
    BasePriority : Normal
    FileVersion : 4, 7, 1098, 0
    ProductVersion : 4, 7, 0, 0
    ProductName : avast! Antivirus
    CompanyName : ALWIL Software
    FileDescription : avast! Antivirus updating service
    InternalName : aswUpdSv.exe
    LegalCopyright : Copyright (c) 2007 ALWIL Software
    OriginalFilename : aswUpdSv.exe

    #:12 [ashserv.exe]
    FilePath : C:\Program Files\Alwil Software\Avast4\
    ProcessID : 1356
    ThreadCreationTime : 27-01-2008 10:26:22
    BasePriority : High
    FileVersion : 4, 7, 1098, 0
    ProductVersion : 4, 7, 0, 0
    ProductName : avast! Antivirus
    CompanyName : ALWIL Software
    FileDescription : avast! antivirus service
    InternalName : aswServ
    LegalCopyright : Copyright (c) 2007 ALWIL Software
    OriginalFilename : aswServ.exe

    #:13 [spoolsv.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 1792
    ThreadCreationTime : 27-01-2008 10:26:24
    BasePriority : Normal
    FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
    ProductVersion : 5.1.2600.2696
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Spooler SubSystem App
    InternalName : spoolsv.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : spoolsv.exe

    #:14 [explorer.exe]
    FilePath : C:\WINDOWS\
    ProcessID : 1808
    ThreadCreationTime : 27-01-2008 10:26:24
    BasePriority : Normal
    FileVersion : 6.00.2900.3156 (xpsp_sp2_gdr.070613-1234)
    ProductVersion : 6.00.2900.3156
    ProductName : Système d'exploitation Microsoft® Windows®
    CompanyName : Microsoft Corporation
    FileDescription : Explorateur Windows
    InternalName : explorer
    LegalCopyright : © Microsoft Corporation. Tous droits réservés.
    OriginalFilename : EXPLORER.EXE

    #:15 [adeck.exe]
    FilePath : C:\Program Files\VIAudioi\SBADeck\
    ProcessID : 248
    ThreadCreationTime : 27-01-2008 10:26:26
    BasePriority : Normal
    FileVersion : 1.0.0.0
    ProductVersion : 1.62
    ProductName : Vinyl Deck
    CompanyName : VIA Technologies, Inc.
    FileDescription : VIA Codec Control Panel
    InternalName : Vinyl Deck

    #:16 [wkufind.exe]
    FilePath : C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\
    ProcessID : 272
    ThreadCreationTime : 27-01-2008 10:26:26
    BasePriority : Normal
    FileVersion : 9.00.0603.0
    ProductVersion : 9.00.0603.0
    ProductName : Update Detection Module
    CompanyName : Microsoft® Corporation
    FileDescription : Détection Microsoft® Works Update
    InternalName : WkUFind
    LegalCopyright : Copyright © 1987-2003 Microsoft Corporation.
    OriginalFilename : WkUFind.exe

    #:17 [hpwuschd2.exe]
    FilePath : C:\Program Files\HP\HP Software Update\
    ProcessID : 352
    ThreadCreationTime : 27-01-2008 10:26:26
    BasePriority : Normal
    FileVersion : 53.0.13.000
    ProductVersion : 053.000.013.000
    ProductName : hp digital imaging - hp all-in-one series
    CompanyName : Hewlett-Packard Co.
    FileDescription : Hewlett-Packard Product Assistant
    InternalName : hpwuSchd2
    LegalCopyright : Copyright (C) Hewlett-Packard Co. 1995-2004
    OriginalFilename : hpwuSchd2.exe
    Comments : Hewlett-Packard Product Assistant

    #:18 [logitray.exe]
    FilePath : C:\Program Files\Logitech\Video\
    ProcessID : 344
    ThreadCreationTime : 27-01-2008 10:26:27
    BasePriority : Normal
    FileVersion : 8.0.3.1112
    ProductVersion : 8.0.3.1112
    ProductName : Logitech QuickCam
    CompanyName : Logitech Inc.
    FileDescription : ImageStudio Tray Application
    InternalName : LogiTray.exe
    LegalCopyright : (c) 1996-2003 Logitech. All rights reserved.
    OriginalFilename : LogiTray.exe

    #:19 [jusched.exe]
    FilePath : C:\Program Files\Java\jre1.6.0_03\bin\
    ProcessID : 388
    ThreadCreationTime : 27-01-2008 10:26:27
    BasePriority : Normal

    #:20 [ashdisp.exe]
    FilePath : C:\PROGRA~1\ALWILS~1\Avast4\
    ProcessID : 416
    ThreadCreationTime : 27-01-2008 10:26:27
    BasePriority : Normal
    FileVersion : 4, 7, 1098, 0
    ProductVersion : 4, 7, 0, 0
    ProductName : avast! Antivirus
    CompanyName : ALWIL Software
    FileDescription : avast! service GUI component
    InternalName : aswDisp
    LegalCopyright : Copyright (c) 2007 ALWIL Software
    OriginalFilename : aswDisp.exe

    #:21 [systrayapp.exe]
    FilePath : C:\Program Files\Orange HSS\Systray\
    ProcessID : 480
    ThreadCreationTime : 27-01-2008 10:26:27
    BasePriority : Normal
    FileVersion : 1.0.37.730
    ProductVersion : 6.0.0.730
    ProductName : CSS-Corporate
    CompanyName : France Telecom SA
    InternalName : Systray
    LegalCopyright : Copyright (c) 2006
    OriginalFilename : SystrayApp.exe

    #:22 [lowlight.exe]
    FilePath : C:\Program Files\Logitech\Video\
    ProcessID : 296
    ThreadCreationTime : 27-01-2008 10:26:27
    BasePriority : Normal
    FileVersion : 8.0.3.1112
    ProductVersion : 8.0.3.1112
    ProductName : Logitech QuickCam
    CompanyName : Logitech Inc.
    FileDescription : Automatic Low Light Module
    InternalName : LowLight.exe
    LegalCopyright : (c) 1996-2003 Logitech. All rights reserved.
    OriginalFilename : LowLight.exe

    #:23 [qttask.exe]
    FilePath : C:\Program Files\QuickTime\
    ProcessID : 536
    ThreadCreationTime : 27-01-2008 10:26:27
    BasePriority : Normal
    FileVersion : 7.3.1
    ProductVersion : QuickTime 7.3.1
    ProductName : QuickTime
    CompanyName : Apple Inc.
    FileDescription : QuickTime Task
    InternalName : QuickTime Task
    LegalCopyright : Copyright Apple Inc. 1989-2007
    OriginalFilename : QTTask.exe

    #:24 [alertmodule.exe]
    FilePath : C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\
    ProcessID : 580
    ThreadCreationTime : 27-01-2008 10:26:27
    BasePriority : Normal
    FileVersion : 1.0.10.730
    ProductVersion : 6.0.0.730
    ProductName : CSS-Corporate
    CompanyName : France Telecom SA
    InternalName : AlertModule.dll
    LegalCopyright : Copyright (c) 2006
    OriginalFilename : AlertModule.dll

    #:25 [ituneshelper.exe]
    FilePath : C:\Program Files\iTunes\
    ProcessID : 808
    ThreadCreationTime : 27-01-2008 10:26:28
    BasePriority : Normal
    FileVersion : 7.5.0.20
    ProductVersion : 7.5.0.20
    ProductName : iTunes
    CompanyName : Apple Inc.
    FileDescription : iTunesHelper Module
    InternalName : iTunesHelper
    LegalCopyright : © 2003-2007 Apple Inc. All Rights Reserved.
    OriginalFilename : iTunesHelper.exe

    #:26 [launcher.exe]
    FilePath : C:\Program Files\Orange HSS\Launcher\
    ProcessID : 964
    ThreadCreationTime : 27-01-2008 10:26:28
    BasePriority : Normal
    FileVersion : 1.0.117.730
    ProductVersion : 6.0.0.730
    ProductName : CSS-Corporate
    CompanyName : France Telecom SA
    InternalName : Launcher.exe
    LegalCopyright : Copyright (c) 2006
    OriginalFilename : Launcher.exe

    #:27 [rtegprs.exe]
    FilePath : C:\Program Files\Fichiers communs\SmartCom\
    ProcessID : 1152
    ThreadCreationTime : 27-01-2008 10:26:28
    BasePriority : Normal
    FileVersion : 2, 2, 0, 0
    ProductVersion : 2, 2, 0, 0
    ProductName : Contrôleur RTEGPRS
    CompanyName : SmartCom
    FileDescription : Contrôleur de mobile GPRS/GSM
    InternalName : RTEGPRS
    LegalCopyright : Copyright © SmartCom 2001-2005
    OriginalFilename : RTEGPRS.exe

    #:28 [ctfmon.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 1164
    ThreadCreationTime : 27-01-2008 10:26:28
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : CTF Loader
    InternalName : CTFMON
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : CTFMON.EXE

    #:29 [gstart.exe]
    FilePath : C:\Garmin\
    ProcessID : 1204
    ThreadCreationTime : 27-01-2008 10:26:29
    BasePriority : Normal

    #:30 [hpqtra08.exe]
    FilePath : C:\Program Files\HP\Digital Imaging\bin\
    ProcessID : 1284
    ThreadCreationTime : 27-01-2008 10:26:29
    BasePriority : Normal
    FileVersion : 53.0.13.000
    ProductVersion : 053.000.013.000
    ProductName : hp digital imaging - hp all-in-one series
    CompanyName : Hewlett-Packard Co.
    FileDescription : HP Digital Imaging Monitor
    InternalName : HPQTRA00
    LegalCopyright : Copyright (C) Hewlett-Packard Co. 1995-2004
    OriginalFilename : HPQTRA00.EXE
    Comments : HP Digital Imaging Monitor

    #:31 [applemobiledeviceservice.exe]
    FilePath : C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\
    ProcessID : 1648
    ThreadCreationTime : 27-01-2008 10:26:31
    BasePriority : Normal
    FileVersion : 1, 14, 0, 0
    ProductVersion : 1, 14, 0, 0
    ProductName : Apple Mobile Device Service
    CompanyName : Apple, Inc.
    FileDescription : Apple Mobile Device Service
    InternalName : usbaapld
    LegalCopyright : Copyright 2007 Apple, Inc. All Rights Reserved.
    OriginalFilename : AppleMobileDeviceService.exe

    #:32 [ftrtsvc.exe]
    FilePath : C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\
    ProcessID : 1888
    ThreadCreationTime : 27-01-2008 10:26:31
    BasePriority : Normal
    FileVersion : 12.1.74.730
    ProductVersion : 6.0.0.730
    ProductName : CSS-Corporate
    CompanyName : France Telecom SA
    InternalName : FTRTSVC.exe
    LegalCopyright : Copyright (c) 2006
    OriginalFilename : FTRTSVC.exe

    #:33 [hpqimzone.exe]
    FilePath : C:\Program Files\HP\Digital Imaging\bin\
    ProcessID : 2100
    ThreadCreationTime : 27-01-2008 10:26:32
    BasePriority : Normal

    #:34 [deskboard.exe]
    FilePath : C:\Program Files\Orange HSS\Deskboard\
    ProcessID : 2152
    ThreadCreationTime : 27-01-2008 10:26:34
    BasePriority : Normal

    #:35 [connectivitymanager.exe]
    FilePath : C:\Program Files\Orange HSS\connectivity\
    ProcessID : 2164
    ThreadCreationTime : 27-01-2008 10:26:34
    BasePriority : Normal
    FileVersion : 1.1.65.730
    ProductVersion : 6.0.0.730
    ProductName : CSS-Corporate
    CompanyName : France Telecom SA
    InternalName : ConnectivityManager.exe
    LegalCopyright : Copyright (c) 2006
    OriginalFilename : ConnectivityManager.exe

    #:36 [corecom.exe]
    FilePath : C:\Program Files\Orange HSS\connectivity\CoreCom\
    ProcessID : 2196
    ThreadCreationTime : 27-01-2008 10:26:35
    BasePriority : Normal
    FileVersion : 12.1.74.730
    ProductVersion : 6.0.0.730
    ProductName : CSS-Corporate
    CompanyName : France Telecom SA
    InternalName : CoreCom.exe
    LegalCopyright : Copyright (c) 2006
    OriginalFilename : CoreCom.exe

    #:37 [svchost.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 2248
    ThreadCreationTime : 27-01-2008 10:26:35
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Generic Host Process for Win32 Services
    InternalName : svchost.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : svchost.exe

    #:38 [mdm.exe]
    FilePath : C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\
    ProcessID : 2260
    ThreadCreationTime : 27-01-2008 10:26:35
    BasePriority : Normal
    FileVersion : 7.00.9466
    ProductVersion : 7.00.9466
    ProductName : Microsoft® Visual Studio .NET
    CompanyName : Microsoft Corporation
    FileDescription : Machine Debug Manager
    InternalName : mdm.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : mdm.exe

    #:39 [svchost.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 2384
    ThreadCreationTime : 27-01-2008 10:26:36
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Generic Host Process for Win32 Services
    InternalName : svchost.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : svchost.exe

    #:40 [ashmaisv.exe]
    FilePath : C:\Program Files\Alwil Software\Avast4\
    ProcessID : 2596
    ThreadCreationTime : 27-01-2008 10:26:46
    BasePriority : Normal

    #:41 [ashwebsv.exe]
    FilePath : C:\Program Files\Alwil Software\Avast4\
    ProcessID : 2680
    ThreadCreationTime : 27-01-2008 10:26:49
    BasePriority : Normal

    #:42 [hpqste08.exe]
    FilePath : C:\Program Files\HP\Digital Imaging\bin\
    ProcessID : 2860
    ThreadCreationTime : 27-01-2008 10:26:51
    BasePriority : Normal
    FileVersion : 53.0.13.000
    ProductVersion : 053.000.013.000
    ProductName : hp digital imaging - hp all-in-one series
    CompanyName : Hewlett-Packard Co.
    FileDescription : HP CUE Status
    InternalName : HPQSTS00
    LegalCopyright : Copyright (C) Hewlett-Packard Co. 1995-2004
    OriginalFilename : HPQSTS00.EXE
    Comments : HP CUE Status

    #:43 [ipodservice.exe]
    FilePath : C:\Program Files\iPod\bin\
    ProcessID : 3380
    ThreadCreationTime : 27-01-2008 10:27:03
    BasePriority : Normal
    FileVersion : 7.5.0.20
    ProductVersion : 7.5.0.20
    ProductName : iTunes
    CompanyName : Apple Inc.
    FileDescription : iPodService Module
    InternalName : iPodService
    LegalCopyright : © 2003-2007 Apple Inc. All Rights Reserved.
    OriginalFilename : iPodService.exe

    #:44 [alg.exe]
    FilePath : C:\WINDOWS\System32\
    ProcessID : 3692
    ThreadCreationTime : 27-01-2008 10:27:10
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Application Layer Gateway Service
    InternalName : ALG.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : ALG.exe

    #:45 [oraconfigrecover.exe]
    FilePath : C:\Program Files\Orange HSS\connectivity\CoreCom\
    ProcessID : 724
    ThreadCreationTime : 27-01-2008 10:27:24
    BasePriority : Normal
    FileVersion : 12.1.74.730
    ProductVersion : 6.0.0.730
    ProductName : CSS-Corporate
    CompanyName : France Telecom SA
    InternalName : OraConfigRecover.exe
    LegalCopyright : Copyright (c) 2006
    OriginalFilename : OraConfigRecover.exe

    #:46 [ftcommodule.exe]
    FilePath : C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\
    ProcessID : 2708
    ThreadCreationTime : 27-01-2008 10:27:25
    BasePriority : Normal
    FileVersion : 12.1.74.730
    ProductVersion : 6.0.0.730
    ProductName : CSS-Corporate
    CompanyName : France Telecom SA
    InternalName : FTCOMModule.exe
    LegalCopyright : Copyright (c) 2006
    OriginalFilename : FTCOMModule.exe

    #:47 [wmiprvse.exe]
    FilePath : C:\WINDOWS\system32\wbem\
    ProcessID : 3472
    ThreadCreationTime : 27-01-2008 10:27:33
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : WMI
    InternalName : Wmiprvse.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : Wmiprvse.exe

    #:48 [wlloginproxy.exe]
    FilePath : C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\
    ProcessID : 4020
    ThreadCreationTime : 27-01-2008 10:28:27
    BasePriority : Normal
    FileVersion : 4.200.520.1
    ProductVersion : 4.200.520.1
    ProductName : Microsoft® Windows Live Login Helper
    CompanyName : Microsoft Corporation
    FileDescription : WLLoginProxy.exe
    InternalName : WLLoginProxy
    LegalCopyright : Copyright © 1995-2006 Microsoft Corporation.
    LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation.
    OriginalFilename : WLLoginProxy.exe

    #:49 [iexplore.exe]
    FilePath : C:\Program Files\Internet Explorer\
    ProcessID : 1232
    ThreadCreationTime : 27-01-2008 10:29:13
    BasePriority : Normal
    FileVersion : 7.00.6000.16574 (vista_gdr.071008-1500)
    ProductVersion : 7.00.6000.16574
    ProductName : Windows® Internet Explorer
    CompanyName : Microsoft Corporation
    FileDescription : Internet Explorer
    InternalName : iexplore
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : IEXPLORE.EXE

    #:50 [browser.exe]
    FilePath : C:\Program Files\Orange HSS\browser\
    ProcessID : 3664
    ThreadCreationTime : 27-01-2008 11:01:56
    BasePriority : Normal

    #:51 [cureit[2].exe]
    FilePath : C:\Documents and Settings\JAMY\Local Settings\Temporary Internet Files\Content.IE5\FD93BTS6\
    ProcessID : 3376
    ThreadCreationTime : 27-01-2008 11:03:37
    BasePriority : Normal

    #:52 [_start.exe]
    FilePath : C:\DOCUME~1\JAMY\LOCALS~1\Temp\RarSFX2\
    ProcessID : 4012
    ThreadCreationTime : 27-01-2008 11:03:38
    BasePriority : Normal
    FileVersion : 2.53
    ProductVersion : 2.53
    ProductName : AutoRun Manager
    CompanyName : Doctor Web, Ltd.
    FileDescription : AutoRun
    InternalName : AutoRun
    LegalCopyright : Copyright © 2005 Doctor Web, Ltd.
    OriginalFilename : AutoRun.exe

    #:53 [setup.exe]
    FilePath : C:\DOCUME~1\JAMY\LOCALS~1\Temp\RarSFX2\
    ProcessID : 860
    ThreadCreationTime : 27-01-2008 11:03:47
    BasePriority : Normal

    #:54 [ad-aware.exe]
    FilePath : C:\PROGRA~1\Lavasoft\AD-AWA~1\
    ProcessID : 3852
    ThreadCreationTime : 27-01-2008 11:09:30
    BasePriority : Normal
    FileVersion : 6.2.0.236
    ProductVersion : SE 106
    ProductName : Lavasoft Ad-Aware SE
    CompanyName : Lavasoft Sweden
    FileDescription : Ad-Aware SE Core application
    InternalName : Ad-Aware.exe
    LegalCopyright : Copyright © Lavasoft AB Sweden
    OriginalFilename : Ad-Aware.exe
    Comments : All Rights Reserved

    Memory scan result:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 0
    Objects found so far: 21

    Started registry scan
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    Cydoor Object Recognized!
    Type : Regkey
    Data :
    TAC Rating : 7
    Category : Data Miner
    Comment :
    Rootkey : HKEY_USERS
    Object : S-1-5-21-746137067-616249376-682003330-1004\software\cydoor

    Cydoor Object Recognized!
    Type : RegValue
    Data :
    TAC Rating : 7
    Category : Data Miner
    Comment :
    Rootkey : HKEY_USERS
    Object : S-1-5-21-746137067-616249376-682003330-1004\software\cydoor
    Value : ConnType

    AltnetBDE Object Recognized!
    Type : Regkey
    Data :
    TAC Rating : 4
    Category : Data Miner
    Comment :
    Rootkey : HKEY_LOCAL_MACHINE
    Object : software\classes\adm25.adm25

    AltnetBDE Object Recognized!
    Type : Regkey
    Data :
    TAC Rating : 4
    Category : Data Miner
    Comment :
    Rootkey : HKEY_LOCAL_MACHINE
    Object : software\classes\adm4.adm4

    AltnetBDE Object Recognized!
    Type : Regkey
    Data :
    TAC Rating : 4
    Category : Data Miner
    Comment :
    Rootkey : HKEY_LOCAL_MACHINE
    Object : software\classes\appid\adm.exe

    AltnetBDE Object Recognized!
    Type : Regkey
    Data :
    TAC Rating : 4
    Category : Data Miner
    Comment :
    Rootkey : HKEY_LOCAL_MACHINE
    Object : software\classes\appid\altnet signing module.exe

    Cydoor Object Recognized!
    Type : Regkey
    Data :
    TAC Rating : 7
    Category : Data Miner
    Comment :
    Rootkey : HKEY_LOCAL_MACHINE
    Object : software\cydoor

    Instafinder Object Recognized!
    Type : Regkey
    Data :
    TAC Rating : 4
    Category : Malware
    Comment :
    Rootkey : HKEY_LOCAL_MACHINE
    Object : software\microsoft\windows\currentversion\explorer\browser helper objects\{4e7bd74f-2b8d-469e-90f0-f66ab581a933}

    Cydoor Object Recognized!
    Type : Regkey
    Data :
    TAC Rating : 7
    Category : Data Miner
    Comment :
    Rootkey : HKEY_USERS
    Object : S-1-5-21-746137067-616249376-682003330-1004\\software\cydoor

    Cydoor Object Recognized!
    Type : RegValue
    Data :
    TAC Rating : 7
    Category : Data Miner
    Comment :
    Rootkey : HKEY_USERS
    Object : S-1-5-21-746137067-616249376-682003330-1004\\software\cydoor
    Value : ConnType

    Registry Scan result:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 10
    Objects found so far: 31

    Started deep registry scan
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    Deep registry scan result:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 0
    Objects found so far: 31

    Started Tracking Cookie scan
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@serving-sys[2].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:13
    Value : Cookie:jamy@serving-sys.com/
    Expires : 31-12-2037 23:00:00
    LastSync : Hits:13
    UseCount : 0
    Hits : 13

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@estat[1].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:1
    Value : Cookie:jamy@estat.com/
    Expires : 24-01-2018 11:40:38
    LastSync : Hits:1
    UseCount : 0
    Hits : 1

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@247realmedia[1].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:1
    Value : Cookie:jamy@247realmedia.com/
    Expires : 01-01-2021 01:00:00
    LastSync : Hits:1
    UseCount : 0
    Hits : 1

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@doubleclick[1].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:13
    Value : Cookie:jamy@doubleclick.net/
    Expires : 25-01-2010 23:10:36
    LastSync : Hits:13
    UseCount : 0
    Hits : 13

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@hitbox[1].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:57
    Value : Cookie:jamy@hitbox.com/
    Expires : 26-01-2009 12:00:46
    LastSync : Hits:57
    UseCount : 0
    Hits : 57

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@tradedoubler[1].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:5
    Value : Cookie:jamy@tradedoubler.com/
    Expires : 25-02-2008 21:10:26
    LastSync : Hits:5
    UseCount : 0
    Hits : 5

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@bs.serving-sys[1].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:4
    Value : Cookie:jamy@bs.serving-sys.com/
    Expires : 31-12-2037 23:00:00
    LastSync : Hits:4
    UseCount : 0
    Hits : 4

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@weborama[1].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:7
    Value : Cookie:jamy@weborama.fr/
    Expires : 24-01-2013 20:13:20
    LastSync : Hits:7
    UseCount : 0
    Hits : 7

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@atdmt[2].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:12
    Value : Cookie:jamy@atdmt.com/
    Expires : 24-01-2013 01:00:00
    LastSync : Hits:12
    UseCount : 0
    Hits : 12

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@ehg-neuftelecom.hitbox[1].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:21
    Value : Cookie:jamy@ehg-neuftelecom.hitbox.com/
    Expires : 26-01-2009 12:00:46
    LastSync : Hits:21
    UseCount : 0
    Hits : 21

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@advertising[2].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:162
    Value : Cookie:jamy@advertising.com/
    Expires : 25-01-2013 00:16:56
    LastSync : Hits:162
    UseCount : 0
    Hits : 162

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@mediaplex[1].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:6
    Value : Cookie:jamy@mediaplex.com/
    Expires : 22-06-2009 01:00:00
    LastSync : Hits:6
    UseCount : 0
    Hits : 6

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@adtech[1].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:1
    Value : Cookie:jamy@adtech.de/
    Expires : 25-01-2010 20:13:54
    LastSync : Hits:1
    UseCount : 0
    Hits : 1

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@adviva[2].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:2
    Value : Cookie:jamy@adviva.net/
    Expires : 30-12-2012 21:10:06
    LastSync : Hits:2
    UseCount : 0
    Hits : 2

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@ehg-telecomitalia.hitbox[1].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:7
    Value : Cookie:jamy@ehg-telecomitalia.hitbox.com/
    Expires : 26-01-2009 11:46:26
    LastSync : Hits:7
    UseCount : 0
    Hits : 7

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@bluestreak[2].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:8
    Value : Cookie:jamy@bluestreak.com/
    Expires : 24-01-2018 07:19:52
    LastSync : Hits:8
    UseCount : 0
    Hits : 8

    Tracking Cookie Object Recognized!
    Type : IECache Entry
    Data : jamy@smartadserver[1].txt
    TAC Rating : 3
    Category : Data Miner
    Comment : Hits:25
    Value : Cookie:jamy@smartadserver.com/
    Expires : 22-01-2028 12:17:28
    LastSync : Hits:25
    UseCount : 0
    Hits : 25

    Tracking cookie scan result:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 17
    Objects found so far: 48

    Deep scanning and examining files (C:)
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    Disk Scan Result for C:\
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 0
    Objects found so far: 48

    Hosts file scan result:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    0 entries scanned.
    New critical objects:0
    Objects found so far: 48

    Performing conditional scans...
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    Conditional scan result:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 0
    Objects found so far: 48

    12:45:24 Scan Complete

    Summary Of This Scan
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    Total scanning time:00:32:28.562
    Objects scanned:149216
    Objects identified:27
    Objects ignored:0
    New critical objects:27
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question