Virus alerte de sécurité windows
jean-noel
-
darkcrystal33 Messages postés 3815 Statut Contributeur -
darkcrystal33 Messages postés 3815 Statut Contributeur -
Bonjour,
j'ai un virus deouis peu. Il s'agit de celui qui prend l'apparence d'une alerte de sécurité windows, puis plusieurs pub s'ouvrent m'incitant a télécharger des logiciles anti-virus.
EN parcourant ce forum, j'ai vu un post similaire. J'ai donc suivi les indications de lancer une analyse via hijackthis.
Je met le résultat du scanner. Est-ce que quelqu'un peut me dire comment faire par la suite?
Merci beaucoup à vous.
Jean-Noel
RAPPORT:
Deckard's System Scanner v20071014.68
Run by Jean-Noël KUNTZ on 2008-03-08 21:55:42
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
42: 2008-03-08 20:55:53 UTC - RP324 - Deckard's System Scanner Restore Point
41: 2008-03-07 23:26:02 UTC - RP323 - Point de vérification système
40: 2008-03-06 23:02:48 UTC - RP322 - Point de vérification système
39: 2008-03-04 23:46:19 UTC - RP321 - Point de vérification système
38: 2008-03-02 10:22:22 UTC - RP320 - Last known good configuration
-- First Restore Point --
1: 2008-03-02 10:22:05 UTC - RP283 - Point de vérification système
Backed up registry hives.
Performed disk cleanup.
[color=red]Total Physical Memory: 447 MiB (512 MiB recommended)./color
[color=red]System Drive C: has 3.14 GiB (less than 15%) free./color
-- HijackThis (run as Jean-Noël KUNTZ.exe) -------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:59:06, on 08/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ACS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\Fichiers communs\WinAnonymous\stm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearch.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearchIndexer.exe
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Jean-Noël KUNTZ\Bureau\dss.exe
C:\Program Files\MSN Toolbar Suite\SL\02.05.0001.1119\fr-fr\msn_sl.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Jean-Noël KUNTZ.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://uk.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: e404 helper - {03B902B1-9B25-4173-9468-56775C85A8D4} - C:\Program Files\Helper\1204453004.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1AF7CEE0-F7FA-4432-9939-D3C98F966B08} - C:\WINDOWS\system32\mljjh.dll
O2 - BHO: {a30f94d5-5a93-09bb-74b4-fb41ad3d14c2} - {2c41d3da-14bf-4b47-bb90-39a55d49f03a} - C:\WINDOWS\system32\ihggeuox.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {8E1DB2B5-D02A-4082-A650-345857F03206} - C:\WINDOWS\system32\awtsrpm.dll
O2 - BHO: e404 helper - {A3D76B96-30B9-4DCC-9B3D-D12E31280D29} - C:\Program Files\Helper\1203803533.dll
O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O2 - BHO: (no name) - {C2A1C5CB-C0EF-4689-9436-F62CCA1C5383} - C:\Program Files\NetProject\sbmdl.dll (file missing)
O3 - Toolbar: Barre d'outils MSN Search - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Fichiers communs\WinAnonymous\stm.exe" dm=http://winanonymous.com ad=http://winanonymous.com sd=http://ilp.winanonymous.com
O4 - HKLM\..\Run: [bm] "C:\Program Files\Fichiers communs\WinSpyControl\bm.exe" dm=http://winspycontrol.com ad=http://winspycontrol.com sd=http://ykeeper.winspycontrol.com
O4 - HKLM\..\Run: [BM675b4629] Rundll32.exe "C:\WINDOWS\system32\giyrclnn.dll",s
O4 - HKLM\..\Run: [646875b5] rundll32.exe "C:\WINDOWS\system32\okefqrdy.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?df590edfa2a94f819a469816cae8415a
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?df590edfa2a94f819a469816cae8415a
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.secuser.com
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1ED42878-ECF8-41C2-B6BD-79FA977ED263}: NameServer = 85.255.116.124,85.255.112.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{78A4A6A3-846F-4EDA-AD2F-635B3E3F150D}: NameServer = 85.255.116.124,85.255.112.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{AB691576-8937-49F0-BF63-0255AAB6FA97}: NameServer = 85.255.116.124,85.255.112.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{F3685336-B022-4856-8062-4BDA98D13951}: NameServer = 85.255.116.124,85.255.112.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{F6A2D709-FC10-4BD2-8978-CD0A2C7423B2}: NameServer = 85.255.116.124,85.255.112.131
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.124 85.255.112.131
O17 - HKLM\System\CS1\Services\Tcpip\..\{1ED42878-ECF8-41C2-B6BD-79FA977ED263}: NameServer = 85.255.116.124,85.255.112.131
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.124 85.255.112.131
O17 - HKLM\System\CS2\Services\Tcpip\..\{1ED42878-ECF8-41C2-B6BD-79FA977ED263}: NameServer = 85.255.116.124,85.255.112.131
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.124 85.255.112.131
O20 - Winlogon Notify: awtsrpm - C:\WINDOWS\SYSTEM32\awtsrpm.dll
O22 - SharedTaskScheduler: djuka - {ee9f7cf5-cd49-4cd8-8ba6-1514e7a5c22c} - C:\WINDOWS\system32\wbchha.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
--
End of file - 13037 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 cdrbsdrv - c:\windows\system32\drivers\cdrbsdrv.sys <Not Verified; B.H.A Corporation; B's Recorder GOLD7>
R1 meiudf - c:\windows\system32\drivers\meiudf.sys <Not Verified; Matsushita Electric Industrial Co.,Ltd.; >
R2 ElbyCDIO (ElbyCDIO Driver) - c:\windows\system32\drivers\elbycdio.sys <Not Verified; Elaborate Bytes AG; CDRTools>
R2 MDC8021X (AEGIS Protocol (IEEE 802.1x) v2.3.1.10) - c:\windows\system32\drivers\mdc8021x.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 2.3.1.10>
R2 Netdevio (TOSHIBA Network Device Usermode I/O Protocol) - c:\windows\system32\drivers\netdevio.sys <Not Verified; TOSHIBA Corporation.; TOSHIBA Network Device Usermode I/O protocol>
R3 ElbyDelay - c:\windows\system32\drivers\elbydelay.sys <Not Verified; Elaborate Bytes; CDRTools>
R3 Iviaspi (IVI ASPI Shell) - c:\windows\system32\drivers\iviaspi.sys <Not Verified; InterVideo, Inc.; InterVideo ASPI Shell>
R3 Pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>
R3 TVALD (Toshiba Mobile PC Service) - c:\windows\system32\drivers\nbsmi.sys <Not Verified; Toshiba Corporation; Toshiba Notebook PC SMI Service>
R3 Tvs (Toshiba Virtual Sound with SRS technologies) - c:\windows\system32\drivers\tvs.sys <Not Verified; TOSHIBA Corporation; Audio Filter>
S3 catchme - c:\docume~1\jean-n~1\locals~1\temp\catchme.sys (file missing)
S3 NTPASp50 (NTPASp50 NDIS Protocol Driver) - c:\windows\system32\drivers\ntpasp50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 ACS (Atheros Configuration Service) - c:\windows\system32\acs.exe
R2 CFSvcs (ConfigFree Service) - c:\program files\toshiba\configfree\cfsvcs.exe <Not Verified; TOSHIBA CORPORATION; ConfigFree(TM)>
R2 DVD-RAM_Service - c:\windows\system32\dvdramsv.exe <Not Verified; Matsushita Electric Industrial Co., Ltd.; >
R2 TAPPSRV (TOSHIBA Application Service) - "c:\program files\toshiba\toshiba applet\tappsrv.exe" <Not Verified; TOSHIBA Corp.; TOSHIBA TAPPSRV>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-01-09 18:54:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-02-08 and 2008-03-08 -----------------------------
2008-03-08 21:58:49 0 d-------- C:\Program Files\Trend Micro
2008-03-08 21:09:00 92224 --a------ C:\WINDOWS\system32\ihggeuox.dll
2008-03-08 21:05:50 87104 --a------ C:\WINDOWS\system32\okefqrdy.dll
2008-03-08 21:02:50 88640 --a------ C:\WINDOWS\system32\giyrclnn.dll
2008-03-07 21:09:45 87104 -----n--- C:\WINDOWS\system32\ocaonpnc.dll
2008-03-07 21:06:47 90688 --a------ C:\WINDOWS\system32\jrdngbhn.dll
2008-03-07 21:03:46 88640 --a------ C:\WINDOWS\system32\mvcgdokd.dll
2008-03-06 21:08:21 91200 --a------ C:\WINDOWS\system32\fwyfiwrp.dll
2008-03-06 21:05:13 96320 --a------ C:\WINDOWS\system32\fhjqnrkb.dll
2008-03-06 21:02:17 92736 --a------ C:\WINDOWS\system32\arnxvvsd.dll
2008-03-04 21:35:07 96832 --a------ C:\WINDOWS\system32\bklyifkt.dll
2008-03-04 21:33:29 91712 --a------ C:\WINDOWS\system32\jfypaxvu.dll
2008-03-03 23:28:18 89664 --a------ C:\WINDOWS\system32\mpgakifk.dll
2008-03-03 23:28:11 91712 --a------ C:\WINDOWS\system32\tqlnxmfg.dll
2008-03-02 23:25:35 89664 --a------ C:\WINDOWS\system32\siroqrie.dll
2008-03-02 23:25:26 91712 --a------ C:\WINDOWS\system32\yfybtlun.dll
2008-03-02 11:21:54 171693 --ahs---- C:\WINDOWS\system32\hjjlm.ini2
2008-03-02 11:21:52 291328 --a------ C:\WINDOWS\system32\mljjh.dll
2008-03-02 11:16:46 39424 --a------ C:\WINDOWS\system32\awtsrpm.dll
2008-02-24 02:38:35 0 d--hs---- C:\WinSpyControl
2008-02-24 02:27:04 0 d-------- C:\Program Files\Navilog1
2008-02-24 02:10:39 0 d-------- C:\Documents and Settings\Jean-Noël KUNTZ\Application Data\WinSpyControl
2008-02-24 02:10:09 0 d-------- C:\Program Files\WinSpyControl
2008-02-24 01:33:55 0 d-------- C:\WINDOWS\BDOSCAN8
2008-02-24 00:42:24 0 d-------- C:\Documents and Settings\Jean-Noël KUNTZ\Application Data\Uniblue
2008-02-24 00:24:00 0 d-------- C:\Documents and Settings\Jean-Noël KUNTZ\Application Data\WinAnonymous
2008-02-24 00:19:52 0 dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
2008-02-24 00:19:51 0 d-------- C:\Documents and Settings\All Users\Application Data\WinAnonymous
2008-02-24 00:19:50 0 d-------- C:\Program Files\Fichiers communs\WinAnonymous
2008-02-23 23:44:39 0 d-------- C:\Program Files\Multi Virus Cleaner 2008
2008-02-23 23:34:26 0 d-------- C:\Program Files\Registry Easy
2008-02-23 22:52:33 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-23 22:52:27 0 d-------- C:\Program Files\VirusHeat 4.3
2008-02-23 22:52:13 0 d-------- C:\Program Files\Helper
2008-02-23 22:51:59 0 d-------- C:\Program Files\NetProject
2008-02-23 18:45:52 0 d-------- C:\Program Files\TVAnts
-- Find3M Report ---------------------------------------------------------------
2008-02-24 02:39:19 0 d-------- C:\Program Files\Fichiers communs
2008-02-24 01:46:23 0 d-------- C:\Program Files\SopCast
2008-02-24 01:13:48 0 d-------- C:\Documents and Settings\Jean-Noël KUNTZ\Application Data\LimeWire
2008-02-23 18:45:46 13312 --a-s---- C:\WINDOWS\system32\wbchha.dll
2008-02-14 00:56:10 0 d-------- C:\Documents and Settings\Jean-Noël KUNTZ\Application Data\BitTorrent
2008-02-02 21:18:59 0 d-------- C:\Program Files\Warcraft III
2008-02-02 20:22:45 18041 --a------ C:\WINDOWS\War3Unin.dat
2008-02-02 20:22:42 2829 --a------ C:\WINDOWS\War3Unin.pif
2008-02-02 20:22:41 126976 --a------ C:\WINDOWS\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller>
2008-01-23 03:05:35 474972 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-01-23 03:05:35 77476 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-01-01 20:41:32 4930 --a------ C:\Documents and Settings\Jean-Noël KUNTZ\Application Data\wklnhst.dat
2007-12-15 17:23:51 520192 --a------ C:\WINDOWS\system32\home box office.scr <Not Verified; ScreenTime Media; ScreenTime For Flash>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{03B902B1-9B25-4173-9468-56775C85A8D4}]
02/03/2008 11:16 12800 --a------ C:\Program Files\Helper\1204453004.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1AF7CEE0-F7FA-4432-9939-D3C98F966B08}]
02/03/2008 11:21 291328 --a------ C:\WINDOWS\system32\mljjh.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2c41d3da-14bf-4b47-bb90-39a55d49f03a}]
08/03/2008 21:09 92224 --a------ C:\WINDOWS\system32\ihggeuox.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8E1DB2B5-D02A-4082-A650-345857F03206}]
02/03/2008 11:16 39424 --a------ C:\WINDOWS\system32\awtsrpm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3D76B96-30B9-4DCC-9B3D-D12E31280D29}]
23/02/2008 22:52 12800 --a------ C:\Program Files\Helper\1203803533.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C2A1C5CB-C0EF-4689-9436-F62CCA1C5383}]
C:\Program Files\NetProject\sbmdl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [11/04/2005 09:00]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [14/10/2004 23:28]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [14/10/2004 23:26]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [12/04/2005 23:24]
"AGRSMMSG"="AGRSMMSG.exe" [12/04/2005 23:23 C:\WINDOWS\agrsmmsg.exe]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [25/04/2005 08:15]
"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [05/04/2005 15:25]
"TPSMain"="TPSMain.exe" [21/01/2005 09:28 C:\WINDOWS\system32\TPSMain.exe]
"NDSTray.exe"="NDSTray.exe" []
"SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [11/04/2005 10:14]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [17/11/2004 09:56]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [31/05/2005 04:33]
"LVCOMS"="C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE" [04/09/2003 10:45]
"POINTER"="point32.exe" []
"CFSServ.exe"="CFSServ.exe" []
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [01/04/2006 18:58]
"CloneDVDElbyDelay"="C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" [02/11/2002 07:33]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [25/10/2006 18:58]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [30/10/2006 09:36]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [26/10/2005 16:17]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" []
"Salestart"="C:\Program Files\Fichiers communs\WinAnonymous\stm.exe" [24/12/2007 13:48]
"bm"="C:\Program Files\Fichiers communs\WinSpyControl\bm.exe" []
"BM675b4629"="C:\WINDOWS\system32\giyrclnn.dll" [08/03/2008 21:02]
"646875b5"="C:\WINDOWS\system32\okefqrdy.dll" [08/03/2008 21:05]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [05/08/2004 11:00]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [11/04/2005 15:08]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [02/03/2007 00:11]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []
C:\Documents and Settings\Jean-No‰l KUNTZ\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide de Microsoft Office OneNote 2003.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [17/06/2004 07:03:44]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [06/09/2005 07:14:12]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [14/12/2004 03:44:06]
Picture Package Menu.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [16/06/2006 11:47:20]
Picture Package VCD Maker.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [16/06/2006 11:47:11]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [04/03/2006 14:30:13]
Windows Desktop Search.lnk - C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearch.exe [20/09/2005 18:10:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"some"=C:\Program Files\NetProject\scit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{ee9f7cf5-cd49-4cd8-8ba6-1514e7a5c22c}"= C:\WINDOWS\system32\wbchha.dll [23/02/2008 18:45 13312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{8E1DB2B5-D02A-4082-A650-345857F03206}"= C:\WINDOWS\system32\awtsrpm.dll [02/03/2008 11:16 39424]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="kddws.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtsrpm]
awtsrpm.dll 02/03/2008 11:16 39424 C:\WINDOWS\system32\awtsrpm.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\mljjh.dll
-- End of Deckard's System Scanner: finished at 2008-03-08 22:00:54 ------------
j'ai un virus deouis peu. Il s'agit de celui qui prend l'apparence d'une alerte de sécurité windows, puis plusieurs pub s'ouvrent m'incitant a télécharger des logiciles anti-virus.
EN parcourant ce forum, j'ai vu un post similaire. J'ai donc suivi les indications de lancer une analyse via hijackthis.
Je met le résultat du scanner. Est-ce que quelqu'un peut me dire comment faire par la suite?
Merci beaucoup à vous.
Jean-Noel
RAPPORT:
Deckard's System Scanner v20071014.68
Run by Jean-Noël KUNTZ on 2008-03-08 21:55:42
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
42: 2008-03-08 20:55:53 UTC - RP324 - Deckard's System Scanner Restore Point
41: 2008-03-07 23:26:02 UTC - RP323 - Point de vérification système
40: 2008-03-06 23:02:48 UTC - RP322 - Point de vérification système
39: 2008-03-04 23:46:19 UTC - RP321 - Point de vérification système
38: 2008-03-02 10:22:22 UTC - RP320 - Last known good configuration
-- First Restore Point --
1: 2008-03-02 10:22:05 UTC - RP283 - Point de vérification système
Backed up registry hives.
Performed disk cleanup.
[color=red]Total Physical Memory: 447 MiB (512 MiB recommended)./color
[color=red]System Drive C: has 3.14 GiB (less than 15%) free./color
-- HijackThis (run as Jean-Noël KUNTZ.exe) -------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:59:06, on 08/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ACS.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\Fichiers communs\WinAnonymous\stm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearch.exe
C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearchIndexer.exe
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Jean-Noël KUNTZ\Bureau\dss.exe
C:\Program Files\MSN Toolbar Suite\SL\02.05.0001.1119\fr-fr\msn_sl.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Jean-Noël KUNTZ.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://uk.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: e404 helper - {03B902B1-9B25-4173-9468-56775C85A8D4} - C:\Program Files\Helper\1204453004.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1AF7CEE0-F7FA-4432-9939-D3C98F966B08} - C:\WINDOWS\system32\mljjh.dll
O2 - BHO: {a30f94d5-5a93-09bb-74b4-fb41ad3d14c2} - {2c41d3da-14bf-4b47-bb90-39a55d49f03a} - C:\WINDOWS\system32\ihggeuox.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {8E1DB2B5-D02A-4082-A650-345857F03206} - C:\WINDOWS\system32\awtsrpm.dll
O2 - BHO: e404 helper - {A3D76B96-30B9-4DCC-9B3D-D12E31280D29} - C:\Program Files\Helper\1203803533.dll
O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O2 - BHO: (no name) - {C2A1C5CB-C0EF-4689-9436-F62CCA1C5383} - C:\Program Files\NetProject\sbmdl.dll (file missing)
O3 - Toolbar: Barre d'outils MSN Search - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Fichiers communs\WinAnonymous\stm.exe" dm=http://winanonymous.com ad=http://winanonymous.com sd=http://ilp.winanonymous.com
O4 - HKLM\..\Run: [bm] "C:\Program Files\Fichiers communs\WinSpyControl\bm.exe" dm=http://winspycontrol.com ad=http://winspycontrol.com sd=http://ykeeper.winspycontrol.com
O4 - HKLM\..\Run: [BM675b4629] Rundll32.exe "C:\WINDOWS\system32\giyrclnn.dll",s
O4 - HKLM\..\Run: [646875b5] rundll32.exe "C:\WINDOWS\system32\okefqrdy.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearch.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?df590edfa2a94f819a469816cae8415a
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?df590edfa2a94f819a469816cae8415a
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.secuser.com
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1ED42878-ECF8-41C2-B6BD-79FA977ED263}: NameServer = 85.255.116.124,85.255.112.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{78A4A6A3-846F-4EDA-AD2F-635B3E3F150D}: NameServer = 85.255.116.124,85.255.112.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{AB691576-8937-49F0-BF63-0255AAB6FA97}: NameServer = 85.255.116.124,85.255.112.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{F3685336-B022-4856-8062-4BDA98D13951}: NameServer = 85.255.116.124,85.255.112.131
O17 - HKLM\System\CCS\Services\Tcpip\..\{F6A2D709-FC10-4BD2-8978-CD0A2C7423B2}: NameServer = 85.255.116.124,85.255.112.131
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.124 85.255.112.131
O17 - HKLM\System\CS1\Services\Tcpip\..\{1ED42878-ECF8-41C2-B6BD-79FA977ED263}: NameServer = 85.255.116.124,85.255.112.131
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.124 85.255.112.131
O17 - HKLM\System\CS2\Services\Tcpip\..\{1ED42878-ECF8-41C2-B6BD-79FA977ED263}: NameServer = 85.255.116.124,85.255.112.131
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.124 85.255.112.131
O20 - Winlogon Notify: awtsrpm - C:\WINDOWS\SYSTEM32\awtsrpm.dll
O22 - SharedTaskScheduler: djuka - {ee9f7cf5-cd49-4cd8-8ba6-1514e7a5c22c} - C:\WINDOWS\system32\wbchha.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
--
End of file - 13037 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 cdrbsdrv - c:\windows\system32\drivers\cdrbsdrv.sys <Not Verified; B.H.A Corporation; B's Recorder GOLD7>
R1 meiudf - c:\windows\system32\drivers\meiudf.sys <Not Verified; Matsushita Electric Industrial Co.,Ltd.; >
R2 ElbyCDIO (ElbyCDIO Driver) - c:\windows\system32\drivers\elbycdio.sys <Not Verified; Elaborate Bytes AG; CDRTools>
R2 MDC8021X (AEGIS Protocol (IEEE 802.1x) v2.3.1.10) - c:\windows\system32\drivers\mdc8021x.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 2.3.1.10>
R2 Netdevio (TOSHIBA Network Device Usermode I/O Protocol) - c:\windows\system32\drivers\netdevio.sys <Not Verified; TOSHIBA Corporation.; TOSHIBA Network Device Usermode I/O protocol>
R3 ElbyDelay - c:\windows\system32\drivers\elbydelay.sys <Not Verified; Elaborate Bytes; CDRTools>
R3 Iviaspi (IVI ASPI Shell) - c:\windows\system32\drivers\iviaspi.sys <Not Verified; InterVideo, Inc.; InterVideo ASPI Shell>
R3 Pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>
R3 TVALD (Toshiba Mobile PC Service) - c:\windows\system32\drivers\nbsmi.sys <Not Verified; Toshiba Corporation; Toshiba Notebook PC SMI Service>
R3 Tvs (Toshiba Virtual Sound with SRS technologies) - c:\windows\system32\drivers\tvs.sys <Not Verified; TOSHIBA Corporation; Audio Filter>
S3 catchme - c:\docume~1\jean-n~1\locals~1\temp\catchme.sys (file missing)
S3 NTPASp50 (NTPASp50 NDIS Protocol Driver) - c:\windows\system32\drivers\ntpasp50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 ACS (Atheros Configuration Service) - c:\windows\system32\acs.exe
R2 CFSvcs (ConfigFree Service) - c:\program files\toshiba\configfree\cfsvcs.exe <Not Verified; TOSHIBA CORPORATION; ConfigFree(TM)>
R2 DVD-RAM_Service - c:\windows\system32\dvdramsv.exe <Not Verified; Matsushita Electric Industrial Co., Ltd.; >
R2 TAPPSRV (TOSHIBA Application Service) - "c:\program files\toshiba\toshiba applet\tappsrv.exe" <Not Verified; TOSHIBA Corp.; TOSHIBA TAPPSRV>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-01-09 18:54:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-02-08 and 2008-03-08 -----------------------------
2008-03-08 21:58:49 0 d-------- C:\Program Files\Trend Micro
2008-03-08 21:09:00 92224 --a------ C:\WINDOWS\system32\ihggeuox.dll
2008-03-08 21:05:50 87104 --a------ C:\WINDOWS\system32\okefqrdy.dll
2008-03-08 21:02:50 88640 --a------ C:\WINDOWS\system32\giyrclnn.dll
2008-03-07 21:09:45 87104 -----n--- C:\WINDOWS\system32\ocaonpnc.dll
2008-03-07 21:06:47 90688 --a------ C:\WINDOWS\system32\jrdngbhn.dll
2008-03-07 21:03:46 88640 --a------ C:\WINDOWS\system32\mvcgdokd.dll
2008-03-06 21:08:21 91200 --a------ C:\WINDOWS\system32\fwyfiwrp.dll
2008-03-06 21:05:13 96320 --a------ C:\WINDOWS\system32\fhjqnrkb.dll
2008-03-06 21:02:17 92736 --a------ C:\WINDOWS\system32\arnxvvsd.dll
2008-03-04 21:35:07 96832 --a------ C:\WINDOWS\system32\bklyifkt.dll
2008-03-04 21:33:29 91712 --a------ C:\WINDOWS\system32\jfypaxvu.dll
2008-03-03 23:28:18 89664 --a------ C:\WINDOWS\system32\mpgakifk.dll
2008-03-03 23:28:11 91712 --a------ C:\WINDOWS\system32\tqlnxmfg.dll
2008-03-02 23:25:35 89664 --a------ C:\WINDOWS\system32\siroqrie.dll
2008-03-02 23:25:26 91712 --a------ C:\WINDOWS\system32\yfybtlun.dll
2008-03-02 11:21:54 171693 --ahs---- C:\WINDOWS\system32\hjjlm.ini2
2008-03-02 11:21:52 291328 --a------ C:\WINDOWS\system32\mljjh.dll
2008-03-02 11:16:46 39424 --a------ C:\WINDOWS\system32\awtsrpm.dll
2008-02-24 02:38:35 0 d--hs---- C:\WinSpyControl
2008-02-24 02:27:04 0 d-------- C:\Program Files\Navilog1
2008-02-24 02:10:39 0 d-------- C:\Documents and Settings\Jean-Noël KUNTZ\Application Data\WinSpyControl
2008-02-24 02:10:09 0 d-------- C:\Program Files\WinSpyControl
2008-02-24 01:33:55 0 d-------- C:\WINDOWS\BDOSCAN8
2008-02-24 00:42:24 0 d-------- C:\Documents and Settings\Jean-Noël KUNTZ\Application Data\Uniblue
2008-02-24 00:24:00 0 d-------- C:\Documents and Settings\Jean-Noël KUNTZ\Application Data\WinAnonymous
2008-02-24 00:19:52 0 dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
2008-02-24 00:19:51 0 d-------- C:\Documents and Settings\All Users\Application Data\WinAnonymous
2008-02-24 00:19:50 0 d-------- C:\Program Files\Fichiers communs\WinAnonymous
2008-02-23 23:44:39 0 d-------- C:\Program Files\Multi Virus Cleaner 2008
2008-02-23 23:34:26 0 d-------- C:\Program Files\Registry Easy
2008-02-23 22:52:33 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-23 22:52:27 0 d-------- C:\Program Files\VirusHeat 4.3
2008-02-23 22:52:13 0 d-------- C:\Program Files\Helper
2008-02-23 22:51:59 0 d-------- C:\Program Files\NetProject
2008-02-23 18:45:52 0 d-------- C:\Program Files\TVAnts
-- Find3M Report ---------------------------------------------------------------
2008-02-24 02:39:19 0 d-------- C:\Program Files\Fichiers communs
2008-02-24 01:46:23 0 d-------- C:\Program Files\SopCast
2008-02-24 01:13:48 0 d-------- C:\Documents and Settings\Jean-Noël KUNTZ\Application Data\LimeWire
2008-02-23 18:45:46 13312 --a-s---- C:\WINDOWS\system32\wbchha.dll
2008-02-14 00:56:10 0 d-------- C:\Documents and Settings\Jean-Noël KUNTZ\Application Data\BitTorrent
2008-02-02 21:18:59 0 d-------- C:\Program Files\Warcraft III
2008-02-02 20:22:45 18041 --a------ C:\WINDOWS\War3Unin.dat
2008-02-02 20:22:42 2829 --a------ C:\WINDOWS\War3Unin.pif
2008-02-02 20:22:41 126976 --a------ C:\WINDOWS\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller>
2008-01-23 03:05:35 474972 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-01-23 03:05:35 77476 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-01-01 20:41:32 4930 --a------ C:\Documents and Settings\Jean-Noël KUNTZ\Application Data\wklnhst.dat
2007-12-15 17:23:51 520192 --a------ C:\WINDOWS\system32\home box office.scr <Not Verified; ScreenTime Media; ScreenTime For Flash>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{03B902B1-9B25-4173-9468-56775C85A8D4}]
02/03/2008 11:16 12800 --a------ C:\Program Files\Helper\1204453004.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1AF7CEE0-F7FA-4432-9939-D3C98F966B08}]
02/03/2008 11:21 291328 --a------ C:\WINDOWS\system32\mljjh.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2c41d3da-14bf-4b47-bb90-39a55d49f03a}]
08/03/2008 21:09 92224 --a------ C:\WINDOWS\system32\ihggeuox.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8E1DB2B5-D02A-4082-A650-345857F03206}]
02/03/2008 11:16 39424 --a------ C:\WINDOWS\system32\awtsrpm.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3D76B96-30B9-4DCC-9B3D-D12E31280D29}]
23/02/2008 22:52 12800 --a------ C:\Program Files\Helper\1203803533.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C2A1C5CB-C0EF-4689-9436-F62CCA1C5383}]
C:\Program Files\NetProject\sbmdl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [11/04/2005 09:00]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [14/10/2004 23:28]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [14/10/2004 23:26]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [12/04/2005 23:24]
"AGRSMMSG"="AGRSMMSG.exe" [12/04/2005 23:23 C:\WINDOWS\agrsmmsg.exe]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [25/04/2005 08:15]
"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [05/04/2005 15:25]
"TPSMain"="TPSMain.exe" [21/01/2005 09:28 C:\WINDOWS\system32\TPSMain.exe]
"NDSTray.exe"="NDSTray.exe" []
"SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [11/04/2005 10:14]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [17/11/2004 09:56]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [31/05/2005 04:33]
"LVCOMS"="C:\Program Files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE" [04/09/2003 10:45]
"POINTER"="point32.exe" []
"CFSServ.exe"="CFSServ.exe" []
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [01/04/2006 18:58]
"CloneDVDElbyDelay"="C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" [02/11/2002 07:33]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [25/10/2006 18:58]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [30/10/2006 09:36]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [26/10/2005 16:17]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" []
"Salestart"="C:\Program Files\Fichiers communs\WinAnonymous\stm.exe" [24/12/2007 13:48]
"bm"="C:\Program Files\Fichiers communs\WinSpyControl\bm.exe" []
"BM675b4629"="C:\WINDOWS\system32\giyrclnn.dll" [08/03/2008 21:02]
"646875b5"="C:\WINDOWS\system32\okefqrdy.dll" [08/03/2008 21:05]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [05/08/2004 11:00]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [11/04/2005 15:08]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [02/03/2007 00:11]
"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" []
C:\Documents and Settings\Jean-No‰l KUNTZ\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide de Microsoft Office OneNote 2003.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [17/06/2004 07:03:44]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [06/09/2005 07:14:12]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [14/12/2004 03:44:06]
Picture Package Menu.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [16/06/2006 11:47:20]
Picture Package VCD Maker.lnk - C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [16/06/2006 11:47:11]
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [04/03/2006 14:30:13]
Windows Desktop Search.lnk - C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\fr-fr\bin\WindowsSearch.exe [20/09/2005 18:10:04]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"some"=C:\Program Files\NetProject\scit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{ee9f7cf5-cd49-4cd8-8ba6-1514e7a5c22c}"= C:\WINDOWS\system32\wbchha.dll [23/02/2008 18:45 13312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{8E1DB2B5-D02A-4082-A650-345857F03206}"= C:\WINDOWS\system32\awtsrpm.dll [02/03/2008 11:16 39424]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"System"="kddws.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtsrpm]
awtsrpm.dll 02/03/2008 11:16 39424 C:\WINDOWS\system32\awtsrpm.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\mljjh.dll
-- End of Deckard's System Scanner: finished at 2008-03-08 22:00:54 ------------
Configuration: Windows XP Internet Explorer 6.0
A voir également:
- Virus alerte de sécurité windows
- Clé de sécurité windows 10 gratuit - Guide
- Montage video windows - Guide
- Mode securite - Guide
- Mcafee alerte de virus critique - Accueil - Piratage
- Fin windows 10 - Guide
1 réponse
A supprimer:
O2 - BHO: e404 helper - {03B902B1-9B25-4173-9468-56775C85A8D4} - C:\Program Files\Helper\1204453004.dll
O2 - BHO: (no name) - {1AF7CEE0-F7FA-4432-9939-D3C98F966B08} - C:\WINDOWS\system32\mljjh.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: e404 helper - {A3D76B96-30B9-4DCC-9B3D-D12E31280D29} - C:\Program Files\Helper\1203803533.dll
O2 - BHO: (no name) - {C2A1C5CB-C0EF-4689-9436-F62CCA1C5383} - C:\Program Files\NetProject\sbmdl.dll (file missing)
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Fichiers communs\WinAnonymous\stm.exe" dm=http://winanonymous.com ad=http://winanonymous.com sd=http://ilp.winanonymous.com
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
Tu ne semble pas avoir d'antivirus sérieux installé
Installe Antivir (gratuit): https://www.avira.com
***
O2 - BHO: e404 helper - {03B902B1-9B25-4173-9468-56775C85A8D4} - C:\Program Files\Helper\1204453004.dll
O2 - BHO: (no name) - {1AF7CEE0-F7FA-4432-9939-D3C98F966B08} - C:\WINDOWS\system32\mljjh.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: e404 helper - {A3D76B96-30B9-4DCC-9B3D-D12E31280D29} - C:\Program Files\Helper\1203803533.dll
O2 - BHO: (no name) - {C2A1C5CB-C0EF-4689-9436-F62CCA1C5383} - C:\Program Files\NetProject\sbmdl.dll (file missing)
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Fichiers communs\WinAnonymous\stm.exe" dm=http://winanonymous.com ad=http://winanonymous.com sd=http://ilp.winanonymous.com
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.explorertool.net/redirect.php (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/Windows/Initial/VideoEggPublisher.exe
Tu ne semble pas avoir d'antivirus sérieux installé
Installe Antivir (gratuit): https://www.avira.com
***