Log HijackThis...Help

Storm40f Messages postés 2 Statut Membre -  
jlpjlp Messages postés 52399 Statut Contributeur sécurité -
Bonjour,
Divers pb avec mon PC (reset, platnage, redémarrage bloqué...)
je laisse mon rapport en espérant que qqun puisse m'aider
d'avance merci

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:23:58, on 24/03/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DeltTray.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\outils\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {76C3D4EC-7432-4F02-B945-9BF6C78403AC} - C:\WINDOWS\System32\ssqpo.dll (file missing)
O2 - BHO: (no name) - {C84D8A0A-E708-42B6-90CA-9C30956A87C6} - C:\WINDOWS\System32\mljihij.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [DeltTray] DeltTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WinTouch] C:\Program Files\WinTouch\WinTouch.exe
O4 - HKLM\..\Run: [FileZilla Server Interface] "C:\Program Files\FileZilla Server\FileZilla Server Interface.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [Words] C:\Program Files\Words\Words.exe
O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\Nicolas\LOCALS~1\Temp\winlogon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) - https://static.impots.gouv.fr/abos/securite/xenroll.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{649B4C5F-ECB1-4510-9586-E1BC059B6CF7}: NameServer = 212.151.137.170 212.151.136.246
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\System32\__c00159BB.dat
O20 - Winlogon Notify: mljihij - mljihij.dll (file missing)
O20 - Winlogon Notify: partnershipreg - C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\partnership.dll
O20 - Winlogon Notify: ssqpo - C:\WINDOWS\System32\ssqpo.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Client IP-IPX - Unknown owner - C:\WINDOWS\
O23 - Service: FCI - Unknown owner - C:\WINDOWS\System32\svchost.exe:ext.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
A voir également:

3 réponses

Utilisateur anonyme
 
bonsoir je laisse place a jlpjlp je regarde amities

Martin.
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
slt

tu n'a pas windows a jour depuis plusieurs année et pas de parfeu!!!!! bravo! ton ordi est donc infécté!

installe un parfeu:

Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)

http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall

https://forum.pcastuces.com/sujet.asp?f=25&s=35606
https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
https://manuelsdaide.com/contact/
http://www.open-files.com/forum/index.php?showtopic=29277
http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm

___________________

scan avec vundofix (colle le rapport)

Téléchargez VundoFix -> http://www.atribune.org/ccount/click.php?id=4

Double cliquez VundoFix.exe pour l'exécuter.
Quand VundoFix s'ouvre, cliquez sur le bouton Scan for Vundo.
Une fois le scan fini, cliquez sur le bouton Remove Vundo.
Vous recevrez un avertissement vous demandant si vous voulez effacer ces
fichiers répondez en cliquant sur YES
Une fois que vous avez cliqué yes, votre bureau deviendra vide au moment où il
enlève Vundo.

Quand c'est fini, il vous sera demandé de redémarrer votre ordinateur, cliquez
OK.

___________________

Télécharge Combofix de sUBs : Renomme le avant toute installation, par exemple, nomme le "KillBagle". aide ici : https://forum.pcastuces.com/sujet.asp?f=25&s=37315

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Sauvegarde le sur ton bureau et pas ailleurs !

Aide à l’utilisation de combofix ici: https://bibou0007.forumpro.fr/login?redirect=%2Ft121-topic

Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider, laisse toi guider.
Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
__________________

AVG antispyware
https://www.01net.com/telecharger/
http://free.grisoft.com/doc/download-free-anti-spyware/us/frt/0

Tuto :
http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html

->Relance AVG AS -> "Analyse" ->"Paramètres"

Sous la question "Comment réagir ?" :

-> clique sur "Actions recommandées" et choisis "Quarantaines"
-> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"

Si un fichier est infecté en fin d'analyse

->Clique sur "Appliquer toutes les actions "

->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".

->Enregistre ce fichier texte sur ton bureau ensuite colle le rapport ici
_____________________

colle le rapport d'un scan en ligne
avec un des suivants:

bitdefender en ligne :
http://www.bitdefender.fr/scan_fr/scan8/ie.html

Panda en ligne :
http://pandasoftware.fr

Kaspersky en ligne
https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
0
Storm40f Messages postés 2 Statut Membre
 
merci
voilà le resultat du scan avec Panda et un nouveau log Hijack apres passage de AVG sur tout le disque.

;***********************************************************************************************************************************************************************************
ANALYSIS: 2008-03-26 23:38:20
PROTECTIONS: 0
MALWARE: 75
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.casalemedia.com/]
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.casalemedia.com/]
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@doubleclick[1].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.doubleclick.net/]
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.atdmt.com/]
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@atdmt[2].txt
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@tradedoubler[2].txt
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.tradedoubler.com/]
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@tradedoubler[1].txt
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.tradedoubler.com/]
00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.tradedoubler.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.247realmedia.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.247realmedia.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@247realmedia[2].txt
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.247realmedia.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.247realmedia.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.247realmedia.com/]
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.247realmedia.com/]
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@fastclick[1].txt
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@fastclick[2].txt
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.fastclick.net/]
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.tribalfusion.com/]
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@tribalfusion[1].txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@tribalfusion[2].txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@tribalfusion[3].txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@tribalfusion[5].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.mediaplex.com/]
00147814 Cookie/AspinallsOnlineCasino TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@pacificpoker[1].txt
00149046 Cookie/Casinotropez TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@casinotropez[2].txt
00160284 Cookie/Findwhat TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@findwhat[1].txt
00167430 Cookie/myaffiliateprogram TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[www.myaffiliateprogram.com/]
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.com.com/]
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@com[1].txt
00167647 Cookie/Yadro TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@yadro[1].txt
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@xiti[1].txt
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.xiti.com/]
00167709 Cookie/fe.lea.lycos TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@fe.lea.lycos[1].txt
00167709 Cookie/fe.lea.lycos TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.fe.lea.lycos.fr/]
00167709 Cookie/fe.lea.lycos TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.fe.lea.lycos.fr/]
00167724 Cookie/HotLog TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@hotlog[1].txt
00167747 Cookie/Azjmp TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@azjmp[4].txt
00167747 Cookie/Azjmp TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@azjmp[5].txt
00167747 Cookie/Azjmp TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@azjmp[6].txt
00167747 Cookie/Azjmp TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@azjmp[3].txt
00167747 Cookie/Azjmp TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@azjmp[2].txt
00167747 Cookie/Azjmp TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@azjmp[1].txt
00167749 Cookie/Toplist TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.toplist.cz/]
00167749 Cookie/Toplist TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@toplist[1].txt
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.statcounter.com/]
00168048 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.perf.overture.com/]
00168048 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@perf.overture[1].txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@ad.yieldmanager[1].txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[ad.yieldmanager.com/]
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[ad.yieldmanager.com/]
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.apmebf.com/]
00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.burstnet.com/]
00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@burstnet[1].txt
00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.burstnet.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@serving-sys[1].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.serving-sys.com/]
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.serving-sys.com/]
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@bs.serving-sys[2].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.bs.serving-sys.com/]
00168102 Cookie/Falkag TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@as1.falkag[2].txt
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.weborama.fr/]
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@weborama[2].txt
00168106 Cookie/Weborama TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.weborama.fr/]
00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@adtech[2].txt
00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.adtech.de/]
00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.adtech.de/]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[3].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.server.iad.liveperson.net/hc/54443728]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.server.iad.liveperson.net/hc/54443728]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.server.iad.liveperson.net/]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[8].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[7].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[6].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[5].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[4].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[9].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[2].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[1].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[16].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[15].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[10].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[11].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[12].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@server.iad.liveperson[13].txt
00168116 Cookie/Comclick TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.fl01.ct2.comclick.com/]
00168116 Cookie/Comclick TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@fl01.ct2.comclick[1].txt
00168116 Cookie/Comclick TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[fl01.ct2.comclick.com/]
00168116 Cookie/Comclick TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[fl01.ct2.comclick.com/]
00168116 Cookie/Comclick TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.fl01.ct2.comclick.com/]
00168116 Cookie/Comclick TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.fl01.ct2.comclick.com/]
00168116 Cookie/Comclick TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[fl01.ct2.comclick.com/]
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.advertising.com/]
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.advertising.com/]
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@advertising[2].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@advertising[4].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@advertising[3].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@advertising[1].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.advertising.com/]
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.advertising.com/]
00170087 Cookie/Hbmediapro TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.adopt.hbmediapro.com/]
00170087 Cookie/Hbmediapro TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@adopt.hbmediapro[2].txt
00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[statse.webtrendslive.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.ads.pointroll.com/]
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.ads.pointroll.com/]
00170549 Cookie/FortuneCity TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.fortunecity.com/]
00170549 Cookie/FortuneCity TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@fortunecity[2].txt
00170549 Cookie/FortuneCity TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.fortunecity.com/]
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.overture.com/]
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.overture.com/]
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@overture[2].txt
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.overture.com/]
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.questionmarket.com/]
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@questionmarket[2].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.questionmarket.com/]
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@zedo[2].txt
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@zedo[1].txt
00172449 Cookie/MetriWeb TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.metriweb.be/]
00172483 Cookie/888 TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@888[1].txt
00172484 Cookie/Cassava TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@cassava[1].txt
00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.bluestreak.com/]
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.adrevolver.com/]
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.adrevolver.com/]
00187950 Cookie/bravenetA TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@bravenet[1].txt
00249100 Cookie/Cgi-bin TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@cgi-bin[3].txt
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.smartadserver.com/]
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.smartadserver.com/]
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@smartadserver[2].txt
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.smartadserver.com/]
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Application Data\Mozilla\Firefox\Profiles\m6j0h6jw.default\cookies.txt[.smartadserver.com/]
00286736 Cookie/Cgi-bin TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@cgi-bin[1].txt
00293517 Cookie/AdDynamix TrackingCookie No 0 Yes No C:\Documents and Settings\Nicolas\Cookies\nicolas@ads.addynamix[2].txt
00363038 Adware/Yazzle Adware No 0 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\setar-101[1].0000
00363038 Adware/Yazzle Adware No 0 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\setar-101[1].0000
00363046 Adware/MediaTickets Adware No 1 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\dohinst-103[1].0000
00363046 Adware/MediaTickets Adware No 1 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\dohinst-103[1].0000
00379780 Adware/Yazzle Adware No 0 No No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\128[1].net[YazzleBundle-1122.exe]
00379781 Adware/Yazzle Adware No 0 No No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\128[1].net[YazzleBundle-1122.exe][â– ++\Yazzle1122OinAdmin.exe]
00392623 Adware/ActiveSearch Adware No 0 No No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\128[1].net[²ÜÇ\Services.dll]
00392623 Adware/ActiveSearch Adware No 0 No No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\129[1].net[²ÜÇ\Services.dll]
00392623 Adware/ActiveSearch Adware No 0 No No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UZLKJORT\122[1].net[²ÜÇ\Services.dll]
00392623 Adware/ActiveSearch Adware No 0 No No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\136[1].net[²ÜÇ\Services.dll]
00507855 Adware/WebHancer Adware No 0 No No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\129[1].net[webhdll.dll]
00508019 Adware/WebHancer Adware No 0 No No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\129[1].net[whAgent.exe]
00508096 Adware/WebHancer Adware No 0 No No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\129[1].net[whiehlpr.dll]
00514601 Adware/Maxifiles Adware No 1 No No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UZLKJORT\122[1].net[Installeur.exe]
00523835 Adware/WebHancer Adware No 0 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\129[1].net
00526090 Adware/DeluxeComunications Adware No 0 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\136[1].net
00526091 Adware/DeluxeComunications Adware No 0 No No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\136[1].net[install.exe]
00532132 Adware/WebHancer Adware No 0 No No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\129[1].net[whInstaller.exe]
00538449 Adware/Maxifiles Adware No 1 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UZLKJORT\122[1].net
00547025 Adware/Yazzle Adware No 0 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\128[1].net
01185375 Application/Psexec.A HackTools No 0 Yes No C:\WINDOWS\PSEXESVC.EXE
01297040 Adware/Winpopup Adware No 0 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\122[1].net
01736788 Trj/Downloader.OZB Virus/Trojan No 0 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\WXMB8LEN\vasya[1]
01742617 Generic Trojan Virus/Trojan No 0 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\css4[1]
01789981 Trj/Agent.GJD Virus/Trojan No 1 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\m[1].exe
01789981 Trj/Agent.GJD Virus/Trojan No 1 Yes No C:\1C.tmp
02216583 Generic Malware Virus/Trojan No 0 No No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\dohinst-103[1].0000[Doh.exe]
02216583 Generic Malware Virus/Trojan No 0 No No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\dohinst-103[1].0000[Doh.exe]
02253432 Trj/Downloader.MDW Virus/Trojan No 1 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\143[1].net
02894085 Trj/Spammer.AFJ Virus/Trojan Yes 2 Yes No C:\NETHLPR.EXE
02894166 Trj/Torpig.GG Virus/Trojan No 0 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\serv2[1].txt
02894166 Trj/Torpig.GG Virus/Trojan No 0 Yes No C:\14.tmp
02896391 Trj/Agent.HVV Virus/Trojan No 0 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\serv1[1].txt
02899394 Trj/Agent.HYX Virus/Trojan No 0 Yes No C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\d[1].exe
;===================================================================================================================================================================================
SUSPECTS
Location
;===================================================================================================================================================================================
;===================================================================================================================================================================================




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:41, on 2008-03-26
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DeltTray.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Tall Emu\Online Armor\oaui.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\outils\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [DeltTray] DeltTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [FileZilla Server Interface] "C:\Program Files\FileZilla Server\FileZilla Server Interface.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) - https://static.impots.gouv.fr/abos/securite/xenroll.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{649B4C5F-ECB1-4510-9586-E1BC059B6CF7}: NameServer = 212.151.137.170 212.151.136.246
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: mljihij - mljihij.dll (file missing)
O20 - Winlogon Notify: partnershipreg - C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\partnership.dll (file missing)
O20 - Winlogon Notify: ssqpo - C:\WINDOWS\System32\ssqpo.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Unknown owner - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
ok on s'est mal compris, je t'ai demandé de mettre avg antispyware et non avg antivirus...

scan avec
MalwareByte's Anti-Malware et vire ce qui est trouvé et colle le rapport

https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
_____________

Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O20 - Winlogon Notify: mljihij - mljihij.dll (file missing)
O20 - Winlogon Notify: partnershipreg - C:\Documents and Settings\All Users.WINDOWS\Documents\Settings\partnership.dll (file missing)
O20 - Winlogon Notify: ssqpo - C:\WINDOWS\System32\ssqpo.dll (file missing)

______________

utilise pour supprimer tes traces

CCLEANER: (lance un nettoyage et répare 3 fois le registre) sans installer la barre yahoo

https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

____________

télécharge OTMoveIt
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau. Ou sur https://www.luanagames.com/index.fr.html
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

Citation :

C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\setar-101[1].0000
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\setar-101[1].0000
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\dohinst-103[1].0000
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\dohinst-103[1].0000
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\128[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\128[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\128[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\129[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UZLKJORT\122[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\136[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\129[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\129[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\129[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UZLKJORT\122[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\129[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\136[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\136[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\129[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UZLKJORT\122[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\128[1].net
C:\WINDOWS\PSEXESVC.EXE
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\122[1].net
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\WXMB8LEN\vasya[1]
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\css4[1]
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\m[1].exe
C:\1C.tmp
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\UJMBMLYN\dohinst-103[1].0000[Doh.exe]
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\dohinst-103[1].0000[Doh.exe]
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\143[1].net
C:\NETHLPR.EXE
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\serv2[1].txt
C:\14.tmp
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\serv1[1].txt
C:\Documents and Settings\Nicolas\Local Settings\Temporary Internet Files\Content.IE5\XBKGG2WL\d[1].exe

clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

___________________

Mettre a jour java:
https://www.malekal.com/maintenir-java-adobe-reader-et-le-player-flash-a-jour/
__________________
mettre a jour adobe:
https://get2.adobe.com/reader/otherversions/
________________
pour l'instant navigue puisque ton windows n'est pas a jour avec firefox ou opera et non internet explorer:
http://www.mozilla-europe.org/fr/products/firefox/
https://www.01net.com/telecharger/windows/Internet/navigateur/fiches/61.html
­
________________
recolle un rapport hijakchits et dis tes soucis actuels
0