Fenêtres CiD intempestives
Résolu
Frank34
Messages postés
11
Statut
Membre
-
Destrio5 Messages postés 99820 Date d'inscription Statut Modérateur Dernière intervention -
Destrio5 Messages postés 99820 Date d'inscription Statut Modérateur Dernière intervention -
Bonjour,
Voilà depuis quelques mois j'ai un problème lorsque je navigue sur internet. Des fenêtres appelées CiD apparaissent constament, ce qui est très embêtant. Puisque je ne suis pas très bon en informatique, j'aimerais que quelqu'un qui sait comment supprimer pour de bon ces fenêtres me guide afin que je puisse m'en débarasser un fois pour toute.
Merci
Voilà depuis quelques mois j'ai un problème lorsque je navigue sur internet. Des fenêtres appelées CiD apparaissent constament, ce qui est très embêtant. Puisque je ne suis pas très bon en informatique, j'aimerais que quelqu'un qui sait comment supprimer pour de bon ces fenêtres me guide afin que je puisse m'en débarasser un fois pour toute.
Merci
A voir également:
- Fenêtres CiD intempestives
- Fermer toutes les fenetres windows - Guide
- Live cid skype - Forum Skype et Microsoft Teams
- Afficher toutes les fenetres ouvertes windows 11 - Guide
- Mon clavier n'écrit plus et ouvre des fenetres ✓ - Forum Clavier
- Ouvrir deux fenetres windows - Guide
21 réponses
Salut,
---> Télécharge Lop S&D sur ton Bureau
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
---> Double-clique dessus pour lancer l'installation
---> Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
---> Séléctionne la langue souhaitée, puis choisis l'option 1 (Recherche)
---> Patiente jusqu'à la fin du scan
---> Poste le rapport généré (C:\lopR.txt)
(Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)
Si tu as un problème pour utiliser Lop S&D, regarde dans le tutorial :
http://bibou0007.com/outils-specifiques-f78/tutorial-lop-sd-t956.htm#11431
---> Télécharge Lop S&D sur ton Bureau
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
---> Double-clique dessus pour lancer l'installation
---> Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
---> Séléctionne la langue souhaitée, puis choisis l'option 1 (Recherche)
---> Patiente jusqu'à la fin du scan
---> Poste le rapport généré (C:\lopR.txt)
(Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)
Si tu as un problème pour utiliser Lop S&D, regarde dans le tutorial :
http://bibou0007.com/outils-specifiques-f78/tutorial-lop-sd-t956.htm#11431
Voilà le rapport:
--------------------\\ Lop S&D 4.2.2-9 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Mario ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 2008-08-14 | 11:45:30 ]
[ MAJ : 13-08-2008 | 21:02 ]
--------------------\\ Listing des dossiers dans APPLIC~1
[2008-07-27|10:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2007-06-29|14:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[2007-01-13|15:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2006-05-17|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[2008-04-12|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[2008-05-27|22:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[2006-12-29|12:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macromedia
[2008-03-07|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
[2007-03-03|15:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
[2008-08-12|13:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative
[2007-03-03|15:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2007-01-26|12:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[2007-10-14|12:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[2008-03-07|16:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SiteAdvisor
[2008-06-29|07:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[2006-12-29|14:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TechSmith
[2006-05-17|15:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[2008-04-28|13:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[2006-05-17|10:59] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[2006-05-17|15:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[2007-03-22|21:05] C:\DOCUME~1\LOCALS~1\APPLIC~1\McAfee
[2007-03-21|10:35] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[2008-03-07|17:10] C:\DOCUME~1\LOCALS~1\APPLIC~1\SiteAdvisor
[2007-07-21|11:39] C:\DOCUME~1\Mario\APPLIC~1\.BitTornado
[2008-02-09|09:18] C:\DOCUME~1\Mario\APPLIC~1\Adobe
[2008-07-27|09:58] C:\DOCUME~1\Mario\APPLIC~1\AdobeUM
[2006-05-17|15:45] C:\DOCUME~1\Mario\APPLIC~1\Ahead
[2007-01-13|21:10] C:\DOCUME~1\Mario\APPLIC~1\Apple Computer
[2008-02-18|21:39] C:\DOCUME~1\Mario\APPLIC~1\BitTorrent
[2006-05-17|10:59] C:\DOCUME~1\Mario\APPLIC~1\desktop.ini
[2007-04-29|07:54] C:\DOCUME~1\Mario\APPLIC~1\dm.ini
[2008-08-12|13:24] C:\DOCUME~1\Mario\APPLIC~1\FORDKINDOOZE
[2008-01-03|15:19] C:\DOCUME~1\Mario\APPLIC~1\Google
[2007-04-27|11:57] C:\DOCUME~1\Mario\APPLIC~1\Help
[2007-11-24|18:40] C:\DOCUME~1\Mario\APPLIC~1\ICQ Toolbar
[2006-05-17|15:19] C:\DOCUME~1\Mario\APPLIC~1\Identities
[2007-03-03|15:44] C:\DOCUME~1\Mario\APPLIC~1\Lavasoft
[2008-08-13|05:20] C:\DOCUME~1\Mario\APPLIC~1\LimeWire
[2006-12-29|12:47] C:\DOCUME~1\Mario\APPLIC~1\Macromedia
[2008-03-07|16:55] C:\DOCUME~1\Mario\APPLIC~1\McAfee
[2006-10-18|12:44] C:\DOCUME~1\Mario\APPLIC~1\Microsoft
[2007-11-24|18:35] C:\DOCUME~1\Mario\APPLIC~1\Mozilla
[2007-04-26|15:40] C:\DOCUME~1\Mario\APPLIC~1\NCH Swift Sound
[2008-06-24|10:46] C:\DOCUME~1\Mario\APPLIC~1\SiteAdvisor
[2006-06-29|00:37] C:\DOCUME~1\Mario\APPLIC~1\Sun
[2006-06-10|22:45] C:\DOCUME~1\Mario\APPLIC~1\teamspeak2
[2006-07-17|15:47] C:\DOCUME~1\Mario\APPLIC~1\Ventrilo
[2006-05-17|15:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[2008-08-14 11:00][--ah-----] C:\WINDOWS\tasks\A7050ACD906ABB15.job
[2008-03-07 17:08][--a------] C:\WINDOWS\tasks\McDefragTask.job
[2008-03-07 17:08][--a------] C:\WINDOWS\tasks\McQcTask.job
[2008-07-26 07:05][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008-08-14 11:02][--ah-----] C:\WINDOWS\tasks\SA.DAT
[2004-08-05 08:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
( A7050ACD906ABB15.job )=( c:\docume~1\mario\applic~1\fordki~1\Itchplatformfunk.exe )
--------------------\\ Listing des dossiers dans C:\Program Files
[2006-05-17|15:25] C:\Program Files\Adobe
[2006-05-17|15:44] C:\Program Files\Ahead
[2008-05-24|16:00] C:\Program Files\Apple Software Update
[2008-08-14|10:39] C:\Program Files\EA GAMES
[2006-11-09|18:11] C:\Program Files\EACOM
[2008-07-27|10:00] C:\Program Files\Fichiers communs
[2008-04-12|11:21] C:\Program Files\Google
[2007-11-24|18:36] C:\Program Files\InstallShield Installation Information
[2008-08-13|20:36] C:\Program Files\Internet Explorer
[2008-08-03|15:50] C:\Program Files\iPod
[2008-08-03|15:50] C:\Program Files\iTunes
[2008-07-18|08:06] C:\Program Files\Java
[2008-05-27|22:28] C:\Program Files\Lavasoft
[2008-05-14|22:02] C:\Program Files\LimeWire
[2006-12-29|12:42] C:\Program Files\Macromedia
[2007-06-20|19:34] C:\Program Files\Maxis
[2008-07-14|17:39] C:\Program Files\McAfee
[2008-03-07|17:07] C:\Program Files\McAfee.com
[2008-08-14|10:45] C:\Program Files\Messenger
[2007-05-18|13:15] C:\Program Files\M‚t‚oM‚dia
[2006-05-17|15:13] C:\Program Files\microsoft frontpage
[2006-12-07|13:10] C:\Program Files\Microsoft IntelliType Pro
[2006-05-19|23:01] C:\Program Files\Microsoft Office
[2008-04-28|14:12] C:\Program Files\Microsoft SQL Server Compact Edition
[2006-05-19|23:01] C:\Program Files\Microsoft.NET
[2007-08-11|09:46] C:\Program Files\Might and Magic VI
[2006-05-17|15:10] C:\Program Files\Movie Maker
[2008-08-14|11:19] C:\Program Files\Mozilla Firefox
[2007-07-21|12:11] C:\Program Files\MSN
[2006-05-18|09:16] C:\Program Files\MSN Apps
[2006-05-17|15:09] C:\Program Files\MSN Gaming Zone
[2006-05-17|15:10] C:\Program Files\NetMeeting
[2006-05-17|15:09] C:\Program Files\Online Services
[2007-06-13|07:21] C:\Program Files\Outlook Express
[2008-07-12|09:53] C:\Program Files\QuickTime
[2006-05-17|15:11] C:\Program Files\Services en ligne
[2008-05-21|15:38] C:\Program Files\SiteAdvisor
[2006-05-17|15:19] C:\Program Files\Uninstall Information
[2008-04-29|22:26] C:\Program Files\Windows Live
[2007-02-11|17:40] C:\Program Files\Windows Media Connect 2
[2007-02-11|17:40] C:\Program Files\Windows Media Player
[2006-05-17|15:08] C:\Program Files\Windows NT
[2006-05-17|15:11] C:\Program Files\WindowsUpdate
[2006-09-28|15:38] C:\Program Files\WinRAR
[2006-05-17|15:13] C:\Program Files\xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[2008-07-27|10:00] C:\Program Files\Fichiers communs\Adobe
[2006-05-17|15:43] C:\Program Files\Fichiers communs\Ahead
[2007-06-29|14:30] C:\Program Files\Fichiers communs\Apple
[2006-09-15|07:38] C:\Program Files\Fichiers communs\Blizzard Entertainment
[2006-05-19|23:01] C:\Program Files\Fichiers communs\DESIGNER
[2006-06-27|10:22] C:\Program Files\Fichiers communs\DirectX
[2006-12-29|12:41] C:\Program Files\Fichiers communs\InstallShield
[2006-12-02|11:09] C:\Program Files\Fichiers communs\Java
[2006-12-29|12:43] C:\Program Files\Fichiers communs\Macromedia
[2008-03-07|17:08] C:\Program Files\Fichiers communs\McAfee
[2008-06-09|21:26] C:\Program Files\Fichiers communs\Microsoft Shared
[2006-05-17|15:10] C:\Program Files\Fichiers communs\MSSoap
[2006-05-17|11:00] C:\Program Files\Fichiers communs\ODBC
[2006-05-17|15:10] C:\Program Files\Fichiers communs\Services
[2006-05-17|10:59] C:\Program Files\Fichiers communs\SpeechEngines
[2007-06-13|07:21] C:\Program Files\Fichiers communs\System
[2008-04-28|14:02] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[2008-05-27|22:26] C:\Program Files\Fichiers communs\Wise Installation Wizard
--------------------\\ Process
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative\flag active.exe
C:\DOCUME~1\Mario\APPLIC~1\fordki~1
C:\DOCUME~1\Mario\APPLIC~1\fordki~1\ghjitjdk.exe
C:\DOCUME~1\Mario\APPLIC~1\fordki~1\Itch platform funk.exe
C:\DOCUME~1\Mario\APPLIC~1\fordki~1\lbiycauu.exe
C:\DOCUME~1\Mario\APPLIC~1\fordki~1\ping close.exe
C:\DOCUME~1\Mario\APPLIC~1\fordki~1\Software Mix Fast Dumb.exe
C:\WINDOWS\Tasks\A7050ACD906ABB15.job
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"debugmeow"="C:\\DOCUME~1\\Mario\\APPLIC~1\\FORDKI~1\\ping close.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"stupid creative poll axis"="C:\\Documents and Settings\\All Users\\Application Data\\Memo save stupid creative\\flag active.exe"
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-14 11:47:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 302
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:1934][D:32]-> C:\DOCUME~1\Mario\LOCALS~1\Temp
[F:38][D:0]-> C:\DOCUME~1\Mario\Cookies
[F:447][D:16]-> C:\DOCUME~1\Mario\LOCALS~1\TEMPOR~1\content.IE5
--------------------\\ Fin du rapport a 11:48:26.65
--------------------\\ Lop S&D 4.2.2-9 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Mario ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 2008-08-14 | 11:45:30 ]
[ MAJ : 13-08-2008 | 21:02 ]
--------------------\\ Listing des dossiers dans APPLIC~1
[2008-07-27|10:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2007-06-29|14:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[2007-01-13|15:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2006-05-17|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[2008-04-12|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[2008-05-27|22:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[2006-12-29|12:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macromedia
[2008-03-07|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
[2007-03-03|15:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
[2008-08-12|13:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative
[2007-03-03|15:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2007-01-26|12:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[2007-10-14|12:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[2008-03-07|16:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SiteAdvisor
[2008-06-29|07:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[2006-12-29|14:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TechSmith
[2006-05-17|15:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[2008-04-28|13:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[2006-05-17|10:59] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[2006-05-17|15:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[2007-03-22|21:05] C:\DOCUME~1\LOCALS~1\APPLIC~1\McAfee
[2007-03-21|10:35] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[2008-03-07|17:10] C:\DOCUME~1\LOCALS~1\APPLIC~1\SiteAdvisor
[2007-07-21|11:39] C:\DOCUME~1\Mario\APPLIC~1\.BitTornado
[2008-02-09|09:18] C:\DOCUME~1\Mario\APPLIC~1\Adobe
[2008-07-27|09:58] C:\DOCUME~1\Mario\APPLIC~1\AdobeUM
[2006-05-17|15:45] C:\DOCUME~1\Mario\APPLIC~1\Ahead
[2007-01-13|21:10] C:\DOCUME~1\Mario\APPLIC~1\Apple Computer
[2008-02-18|21:39] C:\DOCUME~1\Mario\APPLIC~1\BitTorrent
[2006-05-17|10:59] C:\DOCUME~1\Mario\APPLIC~1\desktop.ini
[2007-04-29|07:54] C:\DOCUME~1\Mario\APPLIC~1\dm.ini
[2008-08-12|13:24] C:\DOCUME~1\Mario\APPLIC~1\FORDKINDOOZE
[2008-01-03|15:19] C:\DOCUME~1\Mario\APPLIC~1\Google
[2007-04-27|11:57] C:\DOCUME~1\Mario\APPLIC~1\Help
[2007-11-24|18:40] C:\DOCUME~1\Mario\APPLIC~1\ICQ Toolbar
[2006-05-17|15:19] C:\DOCUME~1\Mario\APPLIC~1\Identities
[2007-03-03|15:44] C:\DOCUME~1\Mario\APPLIC~1\Lavasoft
[2008-08-13|05:20] C:\DOCUME~1\Mario\APPLIC~1\LimeWire
[2006-12-29|12:47] C:\DOCUME~1\Mario\APPLIC~1\Macromedia
[2008-03-07|16:55] C:\DOCUME~1\Mario\APPLIC~1\McAfee
[2006-10-18|12:44] C:\DOCUME~1\Mario\APPLIC~1\Microsoft
[2007-11-24|18:35] C:\DOCUME~1\Mario\APPLIC~1\Mozilla
[2007-04-26|15:40] C:\DOCUME~1\Mario\APPLIC~1\NCH Swift Sound
[2008-06-24|10:46] C:\DOCUME~1\Mario\APPLIC~1\SiteAdvisor
[2006-06-29|00:37] C:\DOCUME~1\Mario\APPLIC~1\Sun
[2006-06-10|22:45] C:\DOCUME~1\Mario\APPLIC~1\teamspeak2
[2006-07-17|15:47] C:\DOCUME~1\Mario\APPLIC~1\Ventrilo
[2006-05-17|15:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[2008-08-14 11:00][--ah-----] C:\WINDOWS\tasks\A7050ACD906ABB15.job
[2008-03-07 17:08][--a------] C:\WINDOWS\tasks\McDefragTask.job
[2008-03-07 17:08][--a------] C:\WINDOWS\tasks\McQcTask.job
[2008-07-26 07:05][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008-08-14 11:02][--ah-----] C:\WINDOWS\tasks\SA.DAT
[2004-08-05 08:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
( A7050ACD906ABB15.job )=( c:\docume~1\mario\applic~1\fordki~1\Itchplatformfunk.exe )
--------------------\\ Listing des dossiers dans C:\Program Files
[2006-05-17|15:25] C:\Program Files\Adobe
[2006-05-17|15:44] C:\Program Files\Ahead
[2008-05-24|16:00] C:\Program Files\Apple Software Update
[2008-08-14|10:39] C:\Program Files\EA GAMES
[2006-11-09|18:11] C:\Program Files\EACOM
[2008-07-27|10:00] C:\Program Files\Fichiers communs
[2008-04-12|11:21] C:\Program Files\Google
[2007-11-24|18:36] C:\Program Files\InstallShield Installation Information
[2008-08-13|20:36] C:\Program Files\Internet Explorer
[2008-08-03|15:50] C:\Program Files\iPod
[2008-08-03|15:50] C:\Program Files\iTunes
[2008-07-18|08:06] C:\Program Files\Java
[2008-05-27|22:28] C:\Program Files\Lavasoft
[2008-05-14|22:02] C:\Program Files\LimeWire
[2006-12-29|12:42] C:\Program Files\Macromedia
[2007-06-20|19:34] C:\Program Files\Maxis
[2008-07-14|17:39] C:\Program Files\McAfee
[2008-03-07|17:07] C:\Program Files\McAfee.com
[2008-08-14|10:45] C:\Program Files\Messenger
[2007-05-18|13:15] C:\Program Files\M‚t‚oM‚dia
[2006-05-17|15:13] C:\Program Files\microsoft frontpage
[2006-12-07|13:10] C:\Program Files\Microsoft IntelliType Pro
[2006-05-19|23:01] C:\Program Files\Microsoft Office
[2008-04-28|14:12] C:\Program Files\Microsoft SQL Server Compact Edition
[2006-05-19|23:01] C:\Program Files\Microsoft.NET
[2007-08-11|09:46] C:\Program Files\Might and Magic VI
[2006-05-17|15:10] C:\Program Files\Movie Maker
[2008-08-14|11:19] C:\Program Files\Mozilla Firefox
[2007-07-21|12:11] C:\Program Files\MSN
[2006-05-18|09:16] C:\Program Files\MSN Apps
[2006-05-17|15:09] C:\Program Files\MSN Gaming Zone
[2006-05-17|15:10] C:\Program Files\NetMeeting
[2006-05-17|15:09] C:\Program Files\Online Services
[2007-06-13|07:21] C:\Program Files\Outlook Express
[2008-07-12|09:53] C:\Program Files\QuickTime
[2006-05-17|15:11] C:\Program Files\Services en ligne
[2008-05-21|15:38] C:\Program Files\SiteAdvisor
[2006-05-17|15:19] C:\Program Files\Uninstall Information
[2008-04-29|22:26] C:\Program Files\Windows Live
[2007-02-11|17:40] C:\Program Files\Windows Media Connect 2
[2007-02-11|17:40] C:\Program Files\Windows Media Player
[2006-05-17|15:08] C:\Program Files\Windows NT
[2006-05-17|15:11] C:\Program Files\WindowsUpdate
[2006-09-28|15:38] C:\Program Files\WinRAR
[2006-05-17|15:13] C:\Program Files\xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[2008-07-27|10:00] C:\Program Files\Fichiers communs\Adobe
[2006-05-17|15:43] C:\Program Files\Fichiers communs\Ahead
[2007-06-29|14:30] C:\Program Files\Fichiers communs\Apple
[2006-09-15|07:38] C:\Program Files\Fichiers communs\Blizzard Entertainment
[2006-05-19|23:01] C:\Program Files\Fichiers communs\DESIGNER
[2006-06-27|10:22] C:\Program Files\Fichiers communs\DirectX
[2006-12-29|12:41] C:\Program Files\Fichiers communs\InstallShield
[2006-12-02|11:09] C:\Program Files\Fichiers communs\Java
[2006-12-29|12:43] C:\Program Files\Fichiers communs\Macromedia
[2008-03-07|17:08] C:\Program Files\Fichiers communs\McAfee
[2008-06-09|21:26] C:\Program Files\Fichiers communs\Microsoft Shared
[2006-05-17|15:10] C:\Program Files\Fichiers communs\MSSoap
[2006-05-17|11:00] C:\Program Files\Fichiers communs\ODBC
[2006-05-17|15:10] C:\Program Files\Fichiers communs\Services
[2006-05-17|10:59] C:\Program Files\Fichiers communs\SpeechEngines
[2007-06-13|07:21] C:\Program Files\Fichiers communs\System
[2008-04-28|14:02] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[2008-05-27|22:26] C:\Program Files\Fichiers communs\Wise Installation Wizard
--------------------\\ Process
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative\flag active.exe
C:\DOCUME~1\Mario\APPLIC~1\fordki~1
C:\DOCUME~1\Mario\APPLIC~1\fordki~1\ghjitjdk.exe
C:\DOCUME~1\Mario\APPLIC~1\fordki~1\Itch platform funk.exe
C:\DOCUME~1\Mario\APPLIC~1\fordki~1\lbiycauu.exe
C:\DOCUME~1\Mario\APPLIC~1\fordki~1\ping close.exe
C:\DOCUME~1\Mario\APPLIC~1\fordki~1\Software Mix Fast Dumb.exe
C:\WINDOWS\Tasks\A7050ACD906ABB15.job
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"debugmeow"="C:\\DOCUME~1\\Mario\\APPLIC~1\\FORDKI~1\\ping close.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"stupid creative poll axis"="C:\\Documents and Settings\\All Users\\Application Data\\Memo save stupid creative\\flag active.exe"
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-14 11:47:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 302
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:1934][D:32]-> C:\DOCUME~1\Mario\LOCALS~1\Temp
[F:38][D:0]-> C:\DOCUME~1\Mario\Cookies
[F:447][D:16]-> C:\DOCUME~1\Mario\LOCALS~1\TEMPOR~1\content.IE5
--------------------\\ Fin du rapport a 11:48:26.65
---> Relance Lop S&D
---> Choisis cette fois-ci l'option 2 (Suppression)
---> Ne ferme pas la fenêtre lors de la suppression !
---> Poste le rapport généré (C:\lopR.txt)
(Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)
---> Choisis cette fois-ci l'option 2 (Suppression)
---> Ne ferme pas la fenêtre lors de la suppression !
---> Poste le rapport généré (C:\lopR.txt)
(Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet Fichier, Nouvelle tâche, tape explorer.exe et valide)
Voilà le rapport:
--------------------\\ Lop S&D 4.2.2-9 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Mario ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 2008-08-14 | 11:57:45 ]
[ MAJ : 13-08-2008 | 21:02 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Echec ! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative\flag active.exe
Supprime! - C:\DOCUME~1\Mario\APPLIC~1\fordki~1\ghjitjdk.exe
Supprime! - C:\DOCUME~1\Mario\APPLIC~1\fordki~1\Itch platform funk.exe
Supprime! - C:\DOCUME~1\Mario\APPLIC~1\fordki~1\lbiycauu.exe
Supprime! - C:\DOCUME~1\Mario\APPLIC~1\fordki~1\ping close.exe
Supprime! - C:\DOCUME~1\Mario\APPLIC~1\fordki~1\Software Mix Fast Dumb.exe
Supprime! - C:\WINDOWS\Tasks\A7050ACD906ABB15.job
Echec ! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative
Supprime! - C:\DOCUME~1\Mario\APPLIC~1\fordki~1
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ DEUXIEME PASSAGE
Echec ! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative\flag active.exe
Echec ! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[2008-07-27|10:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2007-06-29|14:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[2007-01-13|15:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2006-05-17|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[2008-04-12|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[2008-05-27|22:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[2006-12-29|12:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macromedia
[2008-03-07|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
[2007-03-03|15:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
[2008-08-12|13:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative
[2007-03-03|15:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2007-01-26|12:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[2007-10-14|12:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[2008-03-07|16:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SiteAdvisor
[2008-06-29|07:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[2006-12-29|14:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TechSmith
[2006-05-17|15:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[2008-04-28|13:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[2006-05-17|10:59] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[2006-05-17|15:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[2007-03-22|21:05] C:\DOCUME~1\LOCALS~1\APPLIC~1\McAfee
[2007-03-21|10:35] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[2008-03-07|17:10] C:\DOCUME~1\LOCALS~1\APPLIC~1\SiteAdvisor
[2007-07-21|11:39] C:\DOCUME~1\Mario\APPLIC~1\.BitTornado
[2008-02-09|09:18] C:\DOCUME~1\Mario\APPLIC~1\Adobe
[2008-07-27|09:58] C:\DOCUME~1\Mario\APPLIC~1\AdobeUM
[2006-05-17|15:45] C:\DOCUME~1\Mario\APPLIC~1\Ahead
[2007-01-13|21:10] C:\DOCUME~1\Mario\APPLIC~1\Apple Computer
[2008-02-18|21:39] C:\DOCUME~1\Mario\APPLIC~1\BitTorrent
[2006-05-17|10:59] C:\DOCUME~1\Mario\APPLIC~1\desktop.ini
[2007-04-29|07:54] C:\DOCUME~1\Mario\APPLIC~1\dm.ini
[2008-01-03|15:19] C:\DOCUME~1\Mario\APPLIC~1\Google
[2007-04-27|11:57] C:\DOCUME~1\Mario\APPLIC~1\Help
[2007-11-24|18:40] C:\DOCUME~1\Mario\APPLIC~1\ICQ Toolbar
[2006-05-17|15:19] C:\DOCUME~1\Mario\APPLIC~1\Identities
[2007-03-03|15:44] C:\DOCUME~1\Mario\APPLIC~1\Lavasoft
[2008-08-13|05:20] C:\DOCUME~1\Mario\APPLIC~1\LimeWire
[2006-12-29|12:47] C:\DOCUME~1\Mario\APPLIC~1\Macromedia
[2008-03-07|16:55] C:\DOCUME~1\Mario\APPLIC~1\McAfee
[2006-10-18|12:44] C:\DOCUME~1\Mario\APPLIC~1\Microsoft
[2007-11-24|18:35] C:\DOCUME~1\Mario\APPLIC~1\Mozilla
[2007-04-26|15:40] C:\DOCUME~1\Mario\APPLIC~1\NCH Swift Sound
[2008-06-24|10:46] C:\DOCUME~1\Mario\APPLIC~1\SiteAdvisor
[2006-06-29|00:37] C:\DOCUME~1\Mario\APPLIC~1\Sun
[2006-06-10|22:45] C:\DOCUME~1\Mario\APPLIC~1\teamspeak2
[2006-07-17|15:47] C:\DOCUME~1\Mario\APPLIC~1\Ventrilo
[2006-05-17|15:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[2008-03-07 17:08][--a------] C:\WINDOWS\tasks\McDefragTask.job
[2008-03-07 17:08][--a------] C:\WINDOWS\tasks\McQcTask.job
[2008-07-26 07:05][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008-08-14 11:02][--ah-----] C:\WINDOWS\tasks\SA.DAT
[2004-08-05 08:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[2006-05-17|15:25] C:\Program Files\Adobe
[2006-05-17|15:44] C:\Program Files\Ahead
[2008-05-24|16:00] C:\Program Files\Apple Software Update
[2008-08-14|10:39] C:\Program Files\EA GAMES
[2006-11-09|18:11] C:\Program Files\EACOM
[2008-07-27|10:00] C:\Program Files\Fichiers communs
[2008-04-12|11:21] C:\Program Files\Google
[2007-11-24|18:36] C:\Program Files\InstallShield Installation Information
[2008-08-13|20:36] C:\Program Files\Internet Explorer
[2008-08-03|15:50] C:\Program Files\iPod
[2008-08-03|15:50] C:\Program Files\iTunes
[2008-07-18|08:06] C:\Program Files\Java
[2008-05-27|22:28] C:\Program Files\Lavasoft
[2008-05-14|22:02] C:\Program Files\LimeWire
[2006-12-29|12:42] C:\Program Files\Macromedia
[2007-06-20|19:34] C:\Program Files\Maxis
[2008-07-14|17:39] C:\Program Files\McAfee
[2008-03-07|17:07] C:\Program Files\McAfee.com
[2008-08-14|10:45] C:\Program Files\Messenger
[2007-05-18|13:15] C:\Program Files\M‚t‚oM‚dia
[2006-05-17|15:13] C:\Program Files\microsoft frontpage
[2006-12-07|13:10] C:\Program Files\Microsoft IntelliType Pro
[2006-05-19|23:01] C:\Program Files\Microsoft Office
[2008-04-28|14:12] C:\Program Files\Microsoft SQL Server Compact Edition
[2006-05-19|23:01] C:\Program Files\Microsoft.NET
[2007-08-11|09:46] C:\Program Files\Might and Magic VI
[2006-05-17|15:10] C:\Program Files\Movie Maker
[2008-08-14|11:19] C:\Program Files\Mozilla Firefox
[2007-07-21|12:11] C:\Program Files\MSN
[2006-05-18|09:16] C:\Program Files\MSN Apps
[2006-05-17|15:09] C:\Program Files\MSN Gaming Zone
[2006-05-17|15:10] C:\Program Files\NetMeeting
[2006-05-17|15:09] C:\Program Files\Online Services
[2007-06-13|07:21] C:\Program Files\Outlook Express
[2008-07-12|09:53] C:\Program Files\QuickTime
[2006-05-17|15:11] C:\Program Files\Services en ligne
[2008-05-21|15:38] C:\Program Files\SiteAdvisor
[2006-05-17|15:19] C:\Program Files\Uninstall Information
[2008-04-29|22:26] C:\Program Files\Windows Live
[2007-02-11|17:40] C:\Program Files\Windows Media Connect 2
[2007-02-11|17:40] C:\Program Files\Windows Media Player
[2006-05-17|15:08] C:\Program Files\Windows NT
[2006-05-17|15:11] C:\Program Files\WindowsUpdate
[2006-09-28|15:38] C:\Program Files\WinRAR
[2006-05-17|15:13] C:\Program Files\xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[2008-07-27|10:00] C:\Program Files\Fichiers communs\Adobe
[2006-05-17|15:43] C:\Program Files\Fichiers communs\Ahead
[2007-06-29|14:30] C:\Program Files\Fichiers communs\Apple
[2006-09-15|07:38] C:\Program Files\Fichiers communs\Blizzard Entertainment
[2006-05-19|23:01] C:\Program Files\Fichiers communs\DESIGNER
[2006-06-27|10:22] C:\Program Files\Fichiers communs\DirectX
[2006-12-29|12:41] C:\Program Files\Fichiers communs\InstallShield
[2006-12-02|11:09] C:\Program Files\Fichiers communs\Java
[2006-12-29|12:43] C:\Program Files\Fichiers communs\Macromedia
[2008-03-07|17:08] C:\Program Files\Fichiers communs\McAfee
[2008-06-09|21:26] C:\Program Files\Fichiers communs\Microsoft Shared
[2006-05-17|15:10] C:\Program Files\Fichiers communs\MSSoap
[2006-05-17|11:00] C:\Program Files\Fichiers communs\ODBC
[2006-05-17|15:10] C:\Program Files\Fichiers communs\Services
[2006-05-17|10:59] C:\Program Files\Fichiers communs\SpeechEngines
[2007-06-13|07:21] C:\Program Files\Fichiers communs\System
[2008-04-28|14:02] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[2008-05-27|22:26] C:\Program Files\Fichiers communs\Wise Installation Wizard
--------------------\\ Process
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative\flag active.exe
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-14 11:59:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 302
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:1934][D:32]-> C:\DOCUME~1\Mario\LOCALS~1\Temp
[F:38][D:0]-> C:\DOCUME~1\Mario\Cookies
[F:467][D:16]-> C:\DOCUME~1\Mario\LOCALS~1\TEMPOR~1\content.IE5
--------------------\\ Fin du rapport a 12:00:45.81
--------------------\\ Lop S&D 4.2.2-9 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Mario ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 2008-08-14 | 11:57:45 ]
[ MAJ : 13-08-2008 | 21:02 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Echec ! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative\flag active.exe
Supprime! - C:\DOCUME~1\Mario\APPLIC~1\fordki~1\ghjitjdk.exe
Supprime! - C:\DOCUME~1\Mario\APPLIC~1\fordki~1\Itch platform funk.exe
Supprime! - C:\DOCUME~1\Mario\APPLIC~1\fordki~1\lbiycauu.exe
Supprime! - C:\DOCUME~1\Mario\APPLIC~1\fordki~1\ping close.exe
Supprime! - C:\DOCUME~1\Mario\APPLIC~1\fordki~1\Software Mix Fast Dumb.exe
Supprime! - C:\WINDOWS\Tasks\A7050ACD906ABB15.job
Echec ! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative
Supprime! - C:\DOCUME~1\Mario\APPLIC~1\fordki~1
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ DEUXIEME PASSAGE
Echec ! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative\flag active.exe
Echec ! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[2008-07-27|10:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2007-06-29|14:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[2007-01-13|15:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2006-05-17|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[2008-04-12|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[2008-05-27|22:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[2006-12-29|12:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macromedia
[2008-03-07|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
[2007-03-03|15:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
[2008-08-12|13:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative
[2007-03-03|15:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2007-01-26|12:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[2007-10-14|12:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[2008-03-07|16:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SiteAdvisor
[2008-06-29|07:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[2006-12-29|14:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TechSmith
[2006-05-17|15:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[2008-04-28|13:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[2006-05-17|10:59] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[2006-05-17|15:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[2007-03-22|21:05] C:\DOCUME~1\LOCALS~1\APPLIC~1\McAfee
[2007-03-21|10:35] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[2008-03-07|17:10] C:\DOCUME~1\LOCALS~1\APPLIC~1\SiteAdvisor
[2007-07-21|11:39] C:\DOCUME~1\Mario\APPLIC~1\.BitTornado
[2008-02-09|09:18] C:\DOCUME~1\Mario\APPLIC~1\Adobe
[2008-07-27|09:58] C:\DOCUME~1\Mario\APPLIC~1\AdobeUM
[2006-05-17|15:45] C:\DOCUME~1\Mario\APPLIC~1\Ahead
[2007-01-13|21:10] C:\DOCUME~1\Mario\APPLIC~1\Apple Computer
[2008-02-18|21:39] C:\DOCUME~1\Mario\APPLIC~1\BitTorrent
[2006-05-17|10:59] C:\DOCUME~1\Mario\APPLIC~1\desktop.ini
[2007-04-29|07:54] C:\DOCUME~1\Mario\APPLIC~1\dm.ini
[2008-01-03|15:19] C:\DOCUME~1\Mario\APPLIC~1\Google
[2007-04-27|11:57] C:\DOCUME~1\Mario\APPLIC~1\Help
[2007-11-24|18:40] C:\DOCUME~1\Mario\APPLIC~1\ICQ Toolbar
[2006-05-17|15:19] C:\DOCUME~1\Mario\APPLIC~1\Identities
[2007-03-03|15:44] C:\DOCUME~1\Mario\APPLIC~1\Lavasoft
[2008-08-13|05:20] C:\DOCUME~1\Mario\APPLIC~1\LimeWire
[2006-12-29|12:47] C:\DOCUME~1\Mario\APPLIC~1\Macromedia
[2008-03-07|16:55] C:\DOCUME~1\Mario\APPLIC~1\McAfee
[2006-10-18|12:44] C:\DOCUME~1\Mario\APPLIC~1\Microsoft
[2007-11-24|18:35] C:\DOCUME~1\Mario\APPLIC~1\Mozilla
[2007-04-26|15:40] C:\DOCUME~1\Mario\APPLIC~1\NCH Swift Sound
[2008-06-24|10:46] C:\DOCUME~1\Mario\APPLIC~1\SiteAdvisor
[2006-06-29|00:37] C:\DOCUME~1\Mario\APPLIC~1\Sun
[2006-06-10|22:45] C:\DOCUME~1\Mario\APPLIC~1\teamspeak2
[2006-07-17|15:47] C:\DOCUME~1\Mario\APPLIC~1\Ventrilo
[2006-05-17|15:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[2008-03-07 17:08][--a------] C:\WINDOWS\tasks\McDefragTask.job
[2008-03-07 17:08][--a------] C:\WINDOWS\tasks\McQcTask.job
[2008-07-26 07:05][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008-08-14 11:02][--ah-----] C:\WINDOWS\tasks\SA.DAT
[2004-08-05 08:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[2006-05-17|15:25] C:\Program Files\Adobe
[2006-05-17|15:44] C:\Program Files\Ahead
[2008-05-24|16:00] C:\Program Files\Apple Software Update
[2008-08-14|10:39] C:\Program Files\EA GAMES
[2006-11-09|18:11] C:\Program Files\EACOM
[2008-07-27|10:00] C:\Program Files\Fichiers communs
[2008-04-12|11:21] C:\Program Files\Google
[2007-11-24|18:36] C:\Program Files\InstallShield Installation Information
[2008-08-13|20:36] C:\Program Files\Internet Explorer
[2008-08-03|15:50] C:\Program Files\iPod
[2008-08-03|15:50] C:\Program Files\iTunes
[2008-07-18|08:06] C:\Program Files\Java
[2008-05-27|22:28] C:\Program Files\Lavasoft
[2008-05-14|22:02] C:\Program Files\LimeWire
[2006-12-29|12:42] C:\Program Files\Macromedia
[2007-06-20|19:34] C:\Program Files\Maxis
[2008-07-14|17:39] C:\Program Files\McAfee
[2008-03-07|17:07] C:\Program Files\McAfee.com
[2008-08-14|10:45] C:\Program Files\Messenger
[2007-05-18|13:15] C:\Program Files\M‚t‚oM‚dia
[2006-05-17|15:13] C:\Program Files\microsoft frontpage
[2006-12-07|13:10] C:\Program Files\Microsoft IntelliType Pro
[2006-05-19|23:01] C:\Program Files\Microsoft Office
[2008-04-28|14:12] C:\Program Files\Microsoft SQL Server Compact Edition
[2006-05-19|23:01] C:\Program Files\Microsoft.NET
[2007-08-11|09:46] C:\Program Files\Might and Magic VI
[2006-05-17|15:10] C:\Program Files\Movie Maker
[2008-08-14|11:19] C:\Program Files\Mozilla Firefox
[2007-07-21|12:11] C:\Program Files\MSN
[2006-05-18|09:16] C:\Program Files\MSN Apps
[2006-05-17|15:09] C:\Program Files\MSN Gaming Zone
[2006-05-17|15:10] C:\Program Files\NetMeeting
[2006-05-17|15:09] C:\Program Files\Online Services
[2007-06-13|07:21] C:\Program Files\Outlook Express
[2008-07-12|09:53] C:\Program Files\QuickTime
[2006-05-17|15:11] C:\Program Files\Services en ligne
[2008-05-21|15:38] C:\Program Files\SiteAdvisor
[2006-05-17|15:19] C:\Program Files\Uninstall Information
[2008-04-29|22:26] C:\Program Files\Windows Live
[2007-02-11|17:40] C:\Program Files\Windows Media Connect 2
[2007-02-11|17:40] C:\Program Files\Windows Media Player
[2006-05-17|15:08] C:\Program Files\Windows NT
[2006-05-17|15:11] C:\Program Files\WindowsUpdate
[2006-09-28|15:38] C:\Program Files\WinRAR
[2006-05-17|15:13] C:\Program Files\xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[2008-07-27|10:00] C:\Program Files\Fichiers communs\Adobe
[2006-05-17|15:43] C:\Program Files\Fichiers communs\Ahead
[2007-06-29|14:30] C:\Program Files\Fichiers communs\Apple
[2006-09-15|07:38] C:\Program Files\Fichiers communs\Blizzard Entertainment
[2006-05-19|23:01] C:\Program Files\Fichiers communs\DESIGNER
[2006-06-27|10:22] C:\Program Files\Fichiers communs\DirectX
[2006-12-29|12:41] C:\Program Files\Fichiers communs\InstallShield
[2006-12-02|11:09] C:\Program Files\Fichiers communs\Java
[2006-12-29|12:43] C:\Program Files\Fichiers communs\Macromedia
[2008-03-07|17:08] C:\Program Files\Fichiers communs\McAfee
[2008-06-09|21:26] C:\Program Files\Fichiers communs\Microsoft Shared
[2006-05-17|15:10] C:\Program Files\Fichiers communs\MSSoap
[2006-05-17|11:00] C:\Program Files\Fichiers communs\ODBC
[2006-05-17|15:10] C:\Program Files\Fichiers communs\Services
[2006-05-17|10:59] C:\Program Files\Fichiers communs\SpeechEngines
[2007-06-13|07:21] C:\Program Files\Fichiers communs\System
[2008-04-28|14:02] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[2008-05-27|22:26] C:\Program Files\Fichiers communs\Wise Installation Wizard
--------------------\\ Process
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative
C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative\flag active.exe
--------------------\\ Verification du Registre
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-14 11:59:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 302
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:1934][D:32]-> C:\DOCUME~1\Mario\LOCALS~1\Temp
[F:38][D:0]-> C:\DOCUME~1\Mario\Cookies
[F:467][D:16]-> C:\DOCUME~1\Mario\LOCALS~1\TEMPOR~1\content.IE5
--------------------\\ Fin du rapport a 12:00:45.81
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Voilà j'ai redémarré mon ordinateur, refait l.option 2 sur LoP et voilà le rapport:
--------------------\\ Lop S&D 4.2.2-9 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Mario ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 2008-08-14 | 12:10:12 ]
[ MAJ : 13-08-2008 | 21:02 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative\flag active.exe
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[2008-07-27|10:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2007-06-29|14:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[2007-01-13|15:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2006-05-17|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[2008-04-12|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[2008-05-27|22:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[2006-12-29|12:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macromedia
[2008-03-07|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
[2007-03-03|15:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
[2007-03-03|15:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2007-01-26|12:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[2007-10-14|12:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[2008-03-07|16:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SiteAdvisor
[2008-06-29|07:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[2006-12-29|14:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TechSmith
[2006-05-17|15:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[2008-04-28|13:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[2006-05-17|10:59] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[2006-05-17|15:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[2007-03-22|21:05] C:\DOCUME~1\LOCALS~1\APPLIC~1\McAfee
[2007-03-21|10:35] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[2008-03-07|17:10] C:\DOCUME~1\LOCALS~1\APPLIC~1\SiteAdvisor
[2007-07-21|11:39] C:\DOCUME~1\Mario\APPLIC~1\.BitTornado
[2008-02-09|09:18] C:\DOCUME~1\Mario\APPLIC~1\Adobe
[2008-07-27|09:58] C:\DOCUME~1\Mario\APPLIC~1\AdobeUM
[2006-05-17|15:45] C:\DOCUME~1\Mario\APPLIC~1\Ahead
[2007-01-13|21:10] C:\DOCUME~1\Mario\APPLIC~1\Apple Computer
[2008-02-18|21:39] C:\DOCUME~1\Mario\APPLIC~1\BitTorrent
[2006-05-17|10:59] C:\DOCUME~1\Mario\APPLIC~1\desktop.ini
[2007-04-29|07:54] C:\DOCUME~1\Mario\APPLIC~1\dm.ini
[2008-01-03|15:19] C:\DOCUME~1\Mario\APPLIC~1\Google
[2007-04-27|11:57] C:\DOCUME~1\Mario\APPLIC~1\Help
[2007-11-24|18:40] C:\DOCUME~1\Mario\APPLIC~1\ICQ Toolbar
[2006-05-17|15:19] C:\DOCUME~1\Mario\APPLIC~1\Identities
[2007-03-03|15:44] C:\DOCUME~1\Mario\APPLIC~1\Lavasoft
[2008-08-13|05:20] C:\DOCUME~1\Mario\APPLIC~1\LimeWire
[2006-12-29|12:47] C:\DOCUME~1\Mario\APPLIC~1\Macromedia
[2008-03-07|16:55] C:\DOCUME~1\Mario\APPLIC~1\McAfee
[2006-10-18|12:44] C:\DOCUME~1\Mario\APPLIC~1\Microsoft
[2007-11-24|18:35] C:\DOCUME~1\Mario\APPLIC~1\Mozilla
[2007-04-26|15:40] C:\DOCUME~1\Mario\APPLIC~1\NCH Swift Sound
[2008-06-24|10:46] C:\DOCUME~1\Mario\APPLIC~1\SiteAdvisor
[2006-06-29|00:37] C:\DOCUME~1\Mario\APPLIC~1\Sun
[2006-06-10|22:45] C:\DOCUME~1\Mario\APPLIC~1\teamspeak2
[2006-07-17|15:47] C:\DOCUME~1\Mario\APPLIC~1\Ventrilo
[2006-05-17|15:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[2008-03-07 17:08][--a------] C:\WINDOWS\tasks\McDefragTask.job
[2008-03-07 17:08][--a------] C:\WINDOWS\tasks\McQcTask.job
[2008-07-26 07:05][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008-08-14 12:09][--ah-----] C:\WINDOWS\tasks\SA.DAT
[2004-08-05 08:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[2006-05-17|15:25] C:\Program Files\Adobe
[2006-05-17|15:44] C:\Program Files\Ahead
[2008-05-24|16:00] C:\Program Files\Apple Software Update
[2008-08-14|10:39] C:\Program Files\EA GAMES
[2006-11-09|18:11] C:\Program Files\EACOM
[2008-07-27|10:00] C:\Program Files\Fichiers communs
[2008-04-12|11:21] C:\Program Files\Google
[2007-11-24|18:36] C:\Program Files\InstallShield Installation Information
[2008-08-13|20:36] C:\Program Files\Internet Explorer
[2008-08-03|15:50] C:\Program Files\iPod
[2008-08-03|15:50] C:\Program Files\iTunes
[2008-07-18|08:06] C:\Program Files\Java
[2008-05-27|22:28] C:\Program Files\Lavasoft
[2008-05-14|22:02] C:\Program Files\LimeWire
[2006-12-29|12:42] C:\Program Files\Macromedia
[2007-06-20|19:34] C:\Program Files\Maxis
[2008-07-14|17:39] C:\Program Files\McAfee
[2008-03-07|17:07] C:\Program Files\McAfee.com
[2008-08-14|10:45] C:\Program Files\Messenger
[2007-05-18|13:15] C:\Program Files\M‚t‚oM‚dia
[2006-05-17|15:13] C:\Program Files\microsoft frontpage
[2006-12-07|13:10] C:\Program Files\Microsoft IntelliType Pro
[2006-05-19|23:01] C:\Program Files\Microsoft Office
[2008-04-28|14:12] C:\Program Files\Microsoft SQL Server Compact Edition
[2006-05-19|23:01] C:\Program Files\Microsoft.NET
[2007-08-11|09:46] C:\Program Files\Might and Magic VI
[2006-05-17|15:10] C:\Program Files\Movie Maker
[2008-08-14|11:19] C:\Program Files\Mozilla Firefox
[2007-07-21|12:11] C:\Program Files\MSN
[2006-05-18|09:16] C:\Program Files\MSN Apps
[2006-05-17|15:09] C:\Program Files\MSN Gaming Zone
[2006-05-17|15:10] C:\Program Files\NetMeeting
[2006-05-17|15:09] C:\Program Files\Online Services
[2007-06-13|07:21] C:\Program Files\Outlook Express
[2008-07-12|09:53] C:\Program Files\QuickTime
[2006-05-17|15:11] C:\Program Files\Services en ligne
[2008-05-21|15:38] C:\Program Files\SiteAdvisor
[2006-05-17|15:19] C:\Program Files\Uninstall Information
[2008-04-29|22:26] C:\Program Files\Windows Live
[2007-02-11|17:40] C:\Program Files\Windows Media Connect 2
[2007-02-11|17:40] C:\Program Files\Windows Media Player
[2006-05-17|15:08] C:\Program Files\Windows NT
[2006-05-17|15:11] C:\Program Files\WindowsUpdate
[2006-09-28|15:38] C:\Program Files\WinRAR
[2006-05-17|15:13] C:\Program Files\xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[2008-07-27|10:00] C:\Program Files\Fichiers communs\Adobe
[2006-05-17|15:43] C:\Program Files\Fichiers communs\Ahead
[2007-06-29|14:30] C:\Program Files\Fichiers communs\Apple
[2006-09-15|07:38] C:\Program Files\Fichiers communs\Blizzard Entertainment
[2006-05-19|23:01] C:\Program Files\Fichiers communs\DESIGNER
[2006-06-27|10:22] C:\Program Files\Fichiers communs\DirectX
[2006-12-29|12:41] C:\Program Files\Fichiers communs\InstallShield
[2006-12-02|11:09] C:\Program Files\Fichiers communs\Java
[2006-12-29|12:43] C:\Program Files\Fichiers communs\Macromedia
[2008-03-07|17:08] C:\Program Files\Fichiers communs\McAfee
[2008-06-09|21:26] C:\Program Files\Fichiers communs\Microsoft Shared
[2006-05-17|15:10] C:\Program Files\Fichiers communs\MSSoap
[2006-05-17|11:00] C:\Program Files\Fichiers communs\ODBC
[2006-05-17|15:10] C:\Program Files\Fichiers communs\Services
[2006-05-17|10:59] C:\Program Files\Fichiers communs\SpeechEngines
[2007-06-13|07:21] C:\Program Files\Fichiers communs\System
[2008-04-28|14:02] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[2008-05-27|22:26] C:\Program Files\Fichiers communs\Wise Installation Wizard
--------------------\\ Process
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-14 12:11:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 302
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:1934][D:32]-> C:\DOCUME~1\Mario\LOCALS~1\Temp
[F:38][D:0]-> C:\DOCUME~1\Mario\Cookies
[F:488][D:16]-> C:\DOCUME~1\Mario\LOCALS~1\TEMPOR~1\content.IE5
--------------------\\ Fin du rapport a 12:13:37.56
--------------------\\ Lop S&D 4.2.2-9 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Mario ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 2008-08-14 | 12:10:12 ]
[ MAJ : 13-08-2008 | 21:02 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative\flag active.exe
Supprime! - C:\DOCUME~1\ALLUSE~1\APPLIC~1\Memo save stupid creative
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans APPLIC~1
[2008-07-27|10:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[2007-06-29|14:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[2007-01-13|15:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[2006-05-17|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[2008-04-12|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[2008-05-27|22:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[2006-12-29|12:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Macromedia
[2008-03-07|17:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee
[2007-03-03|15:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\McAfee.com
[2007-03-03|15:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[2007-01-26|12:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NVIDIA
[2007-10-14|12:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QTSBandwidthCache
[2008-03-07|16:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SiteAdvisor
[2008-06-29|07:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[2006-12-29|14:48] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TechSmith
[2006-05-17|15:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[2008-04-28|13:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[2006-05-17|10:59] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[2006-05-17|15:13] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
[2007-03-22|21:05] C:\DOCUME~1\LOCALS~1\APPLIC~1\McAfee
[2007-03-21|10:35] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[2008-03-07|17:10] C:\DOCUME~1\LOCALS~1\APPLIC~1\SiteAdvisor
[2007-07-21|11:39] C:\DOCUME~1\Mario\APPLIC~1\.BitTornado
[2008-02-09|09:18] C:\DOCUME~1\Mario\APPLIC~1\Adobe
[2008-07-27|09:58] C:\DOCUME~1\Mario\APPLIC~1\AdobeUM
[2006-05-17|15:45] C:\DOCUME~1\Mario\APPLIC~1\Ahead
[2007-01-13|21:10] C:\DOCUME~1\Mario\APPLIC~1\Apple Computer
[2008-02-18|21:39] C:\DOCUME~1\Mario\APPLIC~1\BitTorrent
[2006-05-17|10:59] C:\DOCUME~1\Mario\APPLIC~1\desktop.ini
[2007-04-29|07:54] C:\DOCUME~1\Mario\APPLIC~1\dm.ini
[2008-01-03|15:19] C:\DOCUME~1\Mario\APPLIC~1\Google
[2007-04-27|11:57] C:\DOCUME~1\Mario\APPLIC~1\Help
[2007-11-24|18:40] C:\DOCUME~1\Mario\APPLIC~1\ICQ Toolbar
[2006-05-17|15:19] C:\DOCUME~1\Mario\APPLIC~1\Identities
[2007-03-03|15:44] C:\DOCUME~1\Mario\APPLIC~1\Lavasoft
[2008-08-13|05:20] C:\DOCUME~1\Mario\APPLIC~1\LimeWire
[2006-12-29|12:47] C:\DOCUME~1\Mario\APPLIC~1\Macromedia
[2008-03-07|16:55] C:\DOCUME~1\Mario\APPLIC~1\McAfee
[2006-10-18|12:44] C:\DOCUME~1\Mario\APPLIC~1\Microsoft
[2007-11-24|18:35] C:\DOCUME~1\Mario\APPLIC~1\Mozilla
[2007-04-26|15:40] C:\DOCUME~1\Mario\APPLIC~1\NCH Swift Sound
[2008-06-24|10:46] C:\DOCUME~1\Mario\APPLIC~1\SiteAdvisor
[2006-06-29|00:37] C:\DOCUME~1\Mario\APPLIC~1\Sun
[2006-06-10|22:45] C:\DOCUME~1\Mario\APPLIC~1\teamspeak2
[2006-07-17|15:47] C:\DOCUME~1\Mario\APPLIC~1\Ventrilo
[2006-05-17|15:13] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks
[2008-03-07 17:08][--a------] C:\WINDOWS\tasks\McDefragTask.job
[2008-03-07 17:08][--a------] C:\WINDOWS\tasks\McQcTask.job
[2008-07-26 07:05][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008-08-14 12:09][--ah-----] C:\WINDOWS\tasks\SA.DAT
[2004-08-05 08:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing des dossiers dans C:\Program Files
[2006-05-17|15:25] C:\Program Files\Adobe
[2006-05-17|15:44] C:\Program Files\Ahead
[2008-05-24|16:00] C:\Program Files\Apple Software Update
[2008-08-14|10:39] C:\Program Files\EA GAMES
[2006-11-09|18:11] C:\Program Files\EACOM
[2008-07-27|10:00] C:\Program Files\Fichiers communs
[2008-04-12|11:21] C:\Program Files\Google
[2007-11-24|18:36] C:\Program Files\InstallShield Installation Information
[2008-08-13|20:36] C:\Program Files\Internet Explorer
[2008-08-03|15:50] C:\Program Files\iPod
[2008-08-03|15:50] C:\Program Files\iTunes
[2008-07-18|08:06] C:\Program Files\Java
[2008-05-27|22:28] C:\Program Files\Lavasoft
[2008-05-14|22:02] C:\Program Files\LimeWire
[2006-12-29|12:42] C:\Program Files\Macromedia
[2007-06-20|19:34] C:\Program Files\Maxis
[2008-07-14|17:39] C:\Program Files\McAfee
[2008-03-07|17:07] C:\Program Files\McAfee.com
[2008-08-14|10:45] C:\Program Files\Messenger
[2007-05-18|13:15] C:\Program Files\M‚t‚oM‚dia
[2006-05-17|15:13] C:\Program Files\microsoft frontpage
[2006-12-07|13:10] C:\Program Files\Microsoft IntelliType Pro
[2006-05-19|23:01] C:\Program Files\Microsoft Office
[2008-04-28|14:12] C:\Program Files\Microsoft SQL Server Compact Edition
[2006-05-19|23:01] C:\Program Files\Microsoft.NET
[2007-08-11|09:46] C:\Program Files\Might and Magic VI
[2006-05-17|15:10] C:\Program Files\Movie Maker
[2008-08-14|11:19] C:\Program Files\Mozilla Firefox
[2007-07-21|12:11] C:\Program Files\MSN
[2006-05-18|09:16] C:\Program Files\MSN Apps
[2006-05-17|15:09] C:\Program Files\MSN Gaming Zone
[2006-05-17|15:10] C:\Program Files\NetMeeting
[2006-05-17|15:09] C:\Program Files\Online Services
[2007-06-13|07:21] C:\Program Files\Outlook Express
[2008-07-12|09:53] C:\Program Files\QuickTime
[2006-05-17|15:11] C:\Program Files\Services en ligne
[2008-05-21|15:38] C:\Program Files\SiteAdvisor
[2006-05-17|15:19] C:\Program Files\Uninstall Information
[2008-04-29|22:26] C:\Program Files\Windows Live
[2007-02-11|17:40] C:\Program Files\Windows Media Connect 2
[2007-02-11|17:40] C:\Program Files\Windows Media Player
[2006-05-17|15:08] C:\Program Files\Windows NT
[2006-05-17|15:11] C:\Program Files\WindowsUpdate
[2006-09-28|15:38] C:\Program Files\WinRAR
[2006-05-17|15:13] C:\Program Files\xerox
--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs
[2008-07-27|10:00] C:\Program Files\Fichiers communs\Adobe
[2006-05-17|15:43] C:\Program Files\Fichiers communs\Ahead
[2007-06-29|14:30] C:\Program Files\Fichiers communs\Apple
[2006-09-15|07:38] C:\Program Files\Fichiers communs\Blizzard Entertainment
[2006-05-19|23:01] C:\Program Files\Fichiers communs\DESIGNER
[2006-06-27|10:22] C:\Program Files\Fichiers communs\DirectX
[2006-12-29|12:41] C:\Program Files\Fichiers communs\InstallShield
[2006-12-02|11:09] C:\Program Files\Fichiers communs\Java
[2006-12-29|12:43] C:\Program Files\Fichiers communs\Macromedia
[2008-03-07|17:08] C:\Program Files\Fichiers communs\McAfee
[2008-06-09|21:26] C:\Program Files\Fichiers communs\Microsoft Shared
[2006-05-17|15:10] C:\Program Files\Fichiers communs\MSSoap
[2006-05-17|11:00] C:\Program Files\Fichiers communs\ODBC
[2006-05-17|15:10] C:\Program Files\Fichiers communs\Services
[2006-05-17|10:59] C:\Program Files\Fichiers communs\SpeechEngines
[2007-06-13|07:21] C:\Program Files\Fichiers communs\System
[2008-04-28|14:02] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[2008-05-27|22:26] C:\Program Files\Fichiers communs\Wise Installation Wizard
--------------------\\ Process
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-14 12:11:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 302
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
[F:1934][D:32]-> C:\DOCUME~1\Mario\LOCALS~1\Temp
[F:38][D:0]-> C:\DOCUME~1\Mario\Cookies
[F:488][D:16]-> C:\DOCUME~1\Mario\LOCALS~1\TEMPOR~1\content.IE5
--------------------\\ Fin du rapport a 12:13:37.56
Tu peux désinstaller Lop S&D.
Fais ceci pour vérifier que tu n'aies pas d'autres infections :
- Télécharge et installe MalwareByte's Anti-Malware :
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm
- Mets-le à jour
- Redémarre en mode sans échec (Recommandé) :
https://www.malekal.com/demarrer-windows-mode-sans-echec/
- Choisis ta session habituelle
- Fais un scan complet avec MalwareByte's Anti-Malware
- Supprime tout ce que le logiciel trouve, enregistre le rapport
- Redémarre en mode normal et poste le rapport ici
Tutorial :
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Fais ceci pour vérifier que tu n'aies pas d'autres infections :
- Télécharge et installe MalwareByte's Anti-Malware :
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm
- Mets-le à jour
- Redémarre en mode sans échec (Recommandé) :
https://www.malekal.com/demarrer-windows-mode-sans-echec/
- Choisis ta session habituelle
- Fais un scan complet avec MalwareByte's Anti-Malware
- Supprime tout ce que le logiciel trouve, enregistre le rapport
- Redémarre en mode normal et poste le rapport ici
Tutorial :
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Voilà le rapport de Malware:
Malwarebytes' Anti-Malware 1.24
Version de la base de données: 1052
Windows 5.1.2600 Service Pack 2
13:52:47 2008-08-14
mbam-log-8-14-2008 (13-52-47).txt
Type de recherche: Examen complet (A:\|C:\|D:\|E:\|)
Eléments examinés: 93742
Temps écoulé: 1 hour(s), 18 minute(s), 7 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 20
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
Malwarebytes' Anti-Malware 1.24
Version de la base de données: 1052
Windows 5.1.2600 Service Pack 2
13:52:47 2008-08-14
mbam-log-8-14-2008 (13-52-47).txt
Type de recherche: Examen complet (A:\|C:\|D:\|E:\|)
Eléments examinés: 93742
Temps écoulé: 1 hour(s), 18 minute(s), 7 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 20
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2eff3cf7-99c1-4c29-bc2b-68e057e22340} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{a6573479-9075-4a65-98a6-19fd29cf7374} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
---> Relance MBAM, va dans Quarantaine et supprime tout
---> Fais ceci :
- Télécharge HijackThis V 2.02 (HijackThis Installer) :
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
- Fais un double-clic sur HJTInstall.exe afin de lancer l'installation
- Clique sur Install ensuite sur I Accept
- Clique sur Do a scan system and save log file
- Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
---> Fais ceci :
- Télécharge HijackThis V 2.02 (HijackThis Installer) :
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
- Fais un double-clic sur HJTInstall.exe afin de lancer l'installation
- Clique sur Install ensuite sur I Accept
- Clique sur Do a scan system and save log file
- Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
Voilà le rapport:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:28:23, on 2008-08-14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MétéoMédia\MétéoIMédia\WeatherEye.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://ici.radio-canada.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MétéoIMédia] C:\Program Files\MétéoMédia\MétéoIMédia\WeatherEye
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Search - ?p=ZJxdm037YYCA
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://unfuretparmitantdautre.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Service SiteAdvisor (SiteAdvisor Service) - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (file missing)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:28:23, on 2008-08-14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MétéoMédia\MétéoIMédia\WeatherEye.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://ici.radio-canada.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MétéoIMédia] C:\Program Files\MétéoMédia\MétéoIMédia\WeatherEye
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Search - ?p=ZJxdm037YYCA
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://unfuretparmitantdautre.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Service SiteAdvisor (SiteAdvisor Service) - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (file missing)
---> Relance HijackThis et choisis Do a system scan only
---> Coche les cases qui sont devant les lignes suivantes :
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Search - ?p=ZJxdm037YYCA
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.
---> Redémarre le PC et poste un nouveau rapport HijackThis
---> Coche les cases qui sont devant les lignes suivantes :
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Search - ?p=ZJxdm037YYCA
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.
---> Redémarre le PC et poste un nouveau rapport HijackThis
Voilà le nouveau rapport:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:47:38, on 2008-08-14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MétéoMédia\MétéoIMédia\WeatherEye.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://ici.radio-canada.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MétéoIMédia] C:\Program Files\MétéoMédia\MétéoIMédia\WeatherEye
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://unfuretparmitantdautre.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Service SiteAdvisor (SiteAdvisor Service) - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (file missing)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:47:38, on 2008-08-14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MétéoMédia\MétéoIMédia\WeatherEye.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://ici.radio-canada.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MétéoIMédia] C:\Program Files\MétéoMédia\MétéoIMédia\WeatherEye
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://unfuretparmitantdautre.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: My Web Search Service (MyWebSearchService) - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Service SiteAdvisor (SiteAdvisor Service) - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (file missing)
Il y a encore une trace.
---> Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
---> Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
Voilà le rapport:
-----------\\ ToolBar S&D 1.0.9 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Mario ] [ "C:\Toolbar SD" ] [ Selection : 1 ]
[ 2008-08-14 | 14:56:44.90 ]
[ MAJ : 13-08-2008 | 14:08 ]
-----------\\ Recherche de Fichiers / Dossiers ...
[Service] MyWebSearchService
\...\{635abd67-4fe9-1b23-4f01-e679fa7484c1} - (ytoolbar)
-----------\\ Extensions
(Mario) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Mario) - {635abd67-4fe9-1b23-4f01-e679fa7484c1} => ytoolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://ici.radio-canada.ca/"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src={referrer:source?}"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"SearchAssistant"="http://www.crawler.com/search/ie.aspx?tb_id=60327"
"CustomizeSearch"="http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327"
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
-----------\\ Fin du rapport a 14:58:24.39
-----------\\ ToolBar S&D 1.0.9 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Mario ] [ "C:\Toolbar SD" ] [ Selection : 1 ]
[ 2008-08-14 | 14:56:44.90 ]
[ MAJ : 13-08-2008 | 14:08 ]
-----------\\ Recherche de Fichiers / Dossiers ...
[Service] MyWebSearchService
\...\{635abd67-4fe9-1b23-4f01-e679fa7484c1} - (ytoolbar)
-----------\\ Extensions
(Mario) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Mario) - {635abd67-4fe9-1b23-4f01-e679fa7484c1} => ytoolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://ici.radio-canada.ca/"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src={referrer:source?}"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"SearchAssistant"="http://www.crawler.com/search/ie.aspx?tb_id=60327"
"CustomizeSearch"="http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327"
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
-----------\\ Fin du rapport a 14:58:24.39
Voilà le rapport:
-----------\\ ToolBar S&D 1.0.9 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Mario ] [ "C:\Toolbar SD" ] [ Selection : 2 ]
[ 2008-08-14 | 15:04:34.03 ]
[ MAJ : 13-08-2008 | 14:08 ]
-----------\\ SUPPRESSION
Supprime! - [Service] MyWebSearchService
Supprime! - C:\DOCUME~1\Mario\APPLIC~1\Mozilla\Firefox\Profiles\LBU3X6~1.DEF\EXTENS~1\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ Extensions
(Mario) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://ici.radio-canada.ca/"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src={referrer:source?}"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"SearchAssistant"="http://www.crawler.com/search/ie.aspx?tb_id=60327"
"CustomizeSearch"="http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327"
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
-----------\\ Fin du rapport a 15:05:51.35
-----------\\ ToolBar S&D 1.0.9 XP/Vista
[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Mario ] [ "C:\Toolbar SD" ] [ Selection : 2 ]
[ 2008-08-14 | 15:04:34.03 ]
[ MAJ : 13-08-2008 | 14:08 ]
-----------\\ SUPPRESSION
Supprime! - [Service] MyWebSearchService
Supprime! - C:\DOCUME~1\Mario\APPLIC~1\Mozilla\Firefox\Profiles\LBU3X6~1.DEF\EXTENS~1\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ Extensions
(Mario) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://ici.radio-canada.ca/"
"Search Page"="https://www.google.com/?gws_rd=ssl"
"Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
"SearchMigratedDefaultURL"="https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src={referrer:source?}"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
"SearchAssistant"="http://www.crawler.com/search/ie.aspx?tb_id=60327"
"CustomizeSearch"="http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327"
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
-----------\\ Fin du rapport a 15:05:51.35
Voilà le rapport:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:19:30, on 2008-08-14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MétéoMédia\MétéoIMédia\WeatherEye.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://ici.radio-canada.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MétéoIMédia] C:\Program Files\MétéoMédia\MétéoIMédia\WeatherEye
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://unfuretparmitantdautre.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Service SiteAdvisor (SiteAdvisor Service) - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (file missing)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:19:30, on 2008-08-14
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MétéoMédia\MétéoIMédia\WeatherEye.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://ici.radio-canada.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MétéoIMédia] C:\Program Files\MétéoMédia\MétéoIMédia\WeatherEye
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://unfuretparmitantdautre.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Service SiteAdvisor (SiteAdvisor Service) - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (file missing)