SPYWARES

Résolu
Bonjour,
depuis quelques mois, mon PC et plein de spywares. Sur internet à chaque navigation des fenêtres de publicité s'ouvrent. Plusieurs alertes ont été données par windows en analysant mon PC, disant que des logiciels espions parvenaient à des données personnelles pour des fins malhonnêtes... et en me proposant Spyware-secure, ce qui n'a rien arrangé, au contraire. J'ai essayé certains logiciels anti-spywares que j'ai trouvé sur ce site, Spyware-Blaster, Spybot - Search & Destroy, Spyware Terminator et Ad-aware. Ces logiciels sont mis à jour, pourtant, les alertes sont toujours fréquentes, et je vous appelle à l'aide !!!
Merci
Configuration: Windows XP
Firefox 3.0.1

28 réponses

Résumé de la discussion

Spyware persiste sur un PC équipé de Windows XP et Firefox 3.0.1, avec des fenêtres publicitaires qui s’ouvrent systématiquement lors de la navigation et des alertes signalant des atteintes à la vie privée. Plusieurs outils anti-spyware ont été utilisés, tels Spyware-Blaster, Spybot S&D, Spyware Terminator et Ad-Aware, mais les alertes persistent malgré leurs mises à jour et la promesse de nettoyage est insuffisante. Des réponses fournissent des procédures détaillées, notamment la désactivation de TeaTimer dans Spybot, l’exécution d’outils comme Navilog1 puis HijackThis, puis la réalisation de rapports et des scans complémentaires avec MBAM et Java. Pour la suite, une vigilance régulière et des mises à jour de Java et des outils de sécurité sont recommandées afin de prévenir les rechutes.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut,

    Important : Désactive TeaTimer, le résident de Spybot, il va gêner la désinfection en empêchant la modification des BHO.

    ---> Démarre Spybot, clique sur Mode, coche Mode avancé
    ---> A gauche, clique sur Outils, puis sur Résident
    ---> Décoche la case devant Résident "TeaTimer" :
    http://apu.mabul.org/up/5/apu-5-gpdx9e06cwz2dypom2q7n6nc.jpg
    ---> Quitte Spybot

    Note : Je te conseille de ne pas le réactiver, il a été incapable d'empêcher l'infection de ton PC.

    - Télécharge Navilog1 (de IL-MAFIOSO) et enregistre-le sur le bureau :
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    - Double-clique sur Navilog1.exe afin de lancer l'installation

    - Si le fix ne lance pas automatiquement après son installation, double-clique sur Navilog1 présent sur le bureau

    - Appuie sur F ou f puis valide par Entrée

    - Appuie sur une touche de ton clavier à chaque fois que cela est demandé, tu arriveras au menu des options

    - Choisis l'option 1 et appuie sur la touche Entrée pour valider ton choix

    - Patiente jusqu'au message : *** Analyse Termine le ..... ***

    - Le scan fini, le bloc-notes contenant le rapport sera affiché, poste le contenu de ce rapport dans ta prochaine réponse

    - Si le résultat du scan ne s'affiche pas, tu le trouveras dans C:\fixnavi.txt

    N'utilise pas l'option 2, 3 et 4 sans notre accord, des fichiers légitimes peuvent être inclus dans ce scan.
    1. Modérateur
      ---> Désinstalle Navilog1

      - Télécharge HijackThis V 2.02 (HijackThis Installer) :
      http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

      - Fais un double-clic sur HJTInstall.exe afin de lancer l'installation

      - Clique sur Install ensuite sur I Accept

      - Clique sur Do a scan system and save log file

      - Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
      1. Modérateur
        ---> Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
        https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

        * Lance l'installation du programme en exécutant le fichier téléchargé.
        * Double-clique maintenant sur le raccourci de Toolbar-S&D.
        * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
        * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
        * Poste le rapport généré. (C:\TB.txt)
        1. Modérateur
          ---> Désinstalle ToolBar S&D

          ---> Fais un scan rapide avec MBAM, supprime tout ce qu'il trouve et poste le rapport :
          http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm
          1. Modérateur
            ---> Relance HijackThis et choisis Do a system scan only

            ---> Coche les cases qui sont devant les lignes suivantes :

            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076

            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60076

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076

            R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)

            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

            O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

            O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

            O8 - Extra context menu item: Crawler Search - tbr:iemenu

            O21 - SSODL: Java - {44343277-704E-4B9C-A442-F36114959926} - java32.dll (file missing)

            ---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.

            ---> Redémarre ton PC et poste un nouveau rapport HijackThis
            1. Modérateur
              ---> Désinstalle HijackThis

              ---> Télécharge CCleaner (N'installe pas la Yahoo Toolbar) :
              https://www.ccleaner.com/ccleaner/download

              ---> Lance-le. Va dans "Options" puis "Avancé", tu décoches la case "Effacer uniquement les fichiers etc...". Tu vas dans "Nettoyeur", tu fais "Analyse". Une fois terminé, tu lances le nettoyage. Puis tu vas dans "Registre", tu fais "Chercher des erreurs". Une fois terminé, tu répares toutes les erreurs sans sauvegarder la base de registre.

              ---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger :
              http://www.infos-du-net.com/forum/272480-11-desactiver-activer-restauration-systeme

              ---> Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème :
              https://www.vulgarisation-informatique.com/creer-point-restauration.php

              ---> Mets à jour Windows avec Windows Update :
              http://v4.windowsupdate.microsoft.com/fr/default.asp
              1. Si tu veux te débarasser des fenetres intempestives installe le plug in add block plus, ca t'empechera déjà d'avoir une pollution visuelle. Pour ce qui est de la suppression des spywares regarde ce lien pas mal documenté : https://www.clubic.com/article-18235-1-spyware-les-eviter-sen-debarrasser.html
                1. Au temps pour moi Destrio5 a l'air de toucher un peu plus que moi :-) Je suis sur qu'il trouvera, bon courage !
              2. En réponse à Destrio5, pardon, je ne suis jamais allé dans le mode avancé de Spybot, mais la case "TeaTimer" je ne la trouve pas dans "outils", et la case "Resident" étais déjà cochée...
                1. Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 12:12:04, on 29/08/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                  C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                  C:\WINDOWS\System32\FTRTSVC.exe
                  C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\RealVNC\VNC4\WinVNC4.exe
                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                  C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                  C:\Program Files\QuickTime\qttask.exe
                  C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                  C:\Program Files\CyberLink\PowerCinema\PCMService.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\PROGRA~1\Wanadoo\ComComp.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                  C:\PROGRA~1\Wanadoo\Toaster.exe
                  C:\PROGRA~1\Wanadoo\Inactivity.exe
                  C:\PROGRA~1\Wanadoo\PollingModule.exe
                  C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                  C:\PROGRA~1\Wanadoo\Watch.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
                  C:\Program Files\Windows Live\Messenger\usnsvc.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60076
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fimg%2ffr%2ffr-fr%2fdivertissement%2fcelebrites%2fgalery%2fwentworth02.jpg%3f
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O3 - Toolbar: Barre d'outils &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
                  O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                  O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
                  O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                  O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
                  O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                  O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                  O8 - Extra context menu item: Crawler Search - tbr:iemenu
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                  O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                  O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                  O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                  O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
                  O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{0CF65C47-C75A-48C7-9250-6EB6A4286E38}: NameServer = 80.10.246.1 81.253.149.2
                  O17 - HKLM\System\CS1\Services\Tcpip\..\{0CF65C47-C75A-48C7-9250-6EB6A4286E38}: NameServer = 80.10.246.1 81.253.149.2
                  O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
                  O21 - SSODL: Java - {44343277-704E-4B9C-A442-F36114959926} - java32.dll (file missing)
                  O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                  O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                  O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
                  O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
                  1. -----------\\ ToolBar S&D 1.1.6 XP/Vista

                    Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
                    X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 2800+ )
                    BIOS : BIOS Date: 09/06/04 16:51:42 Ver: 08.00.10
                    USER : isabelle ( Administrator )
                    BOOT : Normal boot
                    Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)

                    "C:\ToolBar SD" ( MAJ : 27-08-2008|23:35 )
                    Option : [1] ( 29/08/2008|12:16 )

                    -----------\\ Recherche de Fichiers / Dossiers ...

                    C:\Program Files\Crawler
                    C:\Program Files\Crawler\adrkeys.dat
                    C:\Program Files\Crawler\Cache
                    C:\Program Files\Crawler\COMMON_FF.dat
                    C:\Program Files\Crawler\confirm.dat
                    C:\Program Files\Crawler\ctbcomm.dll
                    C:\Program Files\Crawler\ctbr.dll
                    C:\Program Files\Crawler\CTConf.dat
                    C:\Program Files\Crawler\CTipsDef.dll
                    C:\Program Files\Crawler\CToolbar.exe
                    C:\Program Files\Crawler\CUpdate.exe
                    C:\Program Files\Crawler\Download
                    C:\Program Files\Crawler\firefox
                    C:\Program Files\Crawler\Languages
                    C:\Program Files\Crawler\lookfor.dat
                    C:\Program Files\Crawler\majorse.dat
                    C:\Program Files\Crawler\rootmenu.dat
                    C:\Program Files\Crawler\services.dat
                    C:\Program Files\Crawler\STWSGLanguageAct
                    C:\Program Files\Crawler\STWSG_FF.dat
                    C:\Program Files\Crawler\TBR5LanguageAct
                    C:\Program Files\Crawler\Update
                    C:\Program Files\Crawler\WebSecurityGuard.dll
                    C:\Program Files\Crawler\WSGData
                    C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Barre d'outils Crawler
                    C:\DOCUME~1\isabelle\Cookies\isabelle@dnl.crawler[1].txt
                    C:\DOCUME~1\isabelle\Cookies\isabelle@h.starware[1].txt
                    C:\DOCUME~1\isabelle\Cookies\isabelle@try.starware[2].txt

                    -----------\\ [..\Internet Explorer\Main]

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                    "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                    "Start Page"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fimg%2ffr%2ffr-fr%2fdivertissement%2fcelebrites%2fgalery%2fwentworth02.jpg%3f"
                    "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                    "Search Bar"="http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60076"

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                    "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                    "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                    "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                    "Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
                    "SearchAssistant"="http://www.crawler.com/search/ie.aspx?tb_id=60076"
                    "CustomizeSearch"="http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076"

                    --------------------\\ Recherche d'autres infections

                    Aucune autre infection trouvée !

                    -----------\\ Fin du rapport a 12:17:49,50
                    1. -----------\\ ToolBar S&D 1.1.6 XP/Vista

                      Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
                      X86-based PC ( Uniprocessor Free : AMD Sempron(tm) 2800+ )
                      BIOS : BIOS Date: 09/06/04 16:51:42 Ver: 08.00.10
                      USER : isabelle ( Administrator )
                      BOOT : Normal boot
                      Antivirus : Avira AntiVir PersonalEdition 8.0.1.27 (Activated)

                      "C:\ToolBar SD" ( MAJ : 27-08-2008|23:35 )
                      Option : [2] ( 29/08/2008|12:35 )

                      -----------\\ SUPPRESSION

                      Supprime! - C:\Program Files\Crawler\adrkeys.dat
                      Supprime! - C:\Program Files\Crawler\Cache
                      Supprime! - C:\Program Files\Crawler\COMMON_FF.dat
                      Supprime! - C:\Program Files\Crawler\confirm.dat
                      Supprime! - C:\Program Files\Crawler\ctbcomm.dll
                      Supprime! - C:\Program Files\Crawler\ctbr.dll
                      Supprime! - C:\Program Files\Crawler\CTConf.dat
                      Supprime! - C:\Program Files\Crawler\CTipsDef.dll
                      Supprime! - C:\Program Files\Crawler\CToolbar.exe
                      Supprime! - C:\Program Files\Crawler\CUpdate.exe
                      Supprime! - C:\Program Files\Crawler\Download
                      Supprime! - C:\Program Files\Crawler\firefox
                      Supprime! - C:\Program Files\Crawler\Languages
                      Supprime! - C:\Program Files\Crawler\lookfor.dat
                      Supprime! - C:\Program Files\Crawler\majorse.dat
                      Supprime! - C:\Program Files\Crawler\rootmenu.dat
                      Supprime! - C:\Program Files\Crawler\services.dat
                      Supprime! - C:\Program Files\Crawler\STWSGLanguageAct
                      Supprime! - C:\Program Files\Crawler\STWSG_FF.dat
                      Supprime! - C:\Program Files\Crawler\TBR5LanguageAct
                      Supprime! - C:\Program Files\Crawler\Update
                      Supprime! - C:\Program Files\Crawler\WebSecurityGuard.dll
                      Supprime! - C:\Program Files\Crawler\WSGData
                      Supprime! - C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Barre d'outils Crawler
                      Supprime! - C:\DOCUME~1\isabelle\Cookies\isabelle@dnl.crawler[1].txt
                      Supprime! - C:\DOCUME~1\isabelle\Cookies\isabelle@h.starware[1].txt
                      Supprime! - C:\DOCUME~1\isabelle\Cookies\isabelle@try.starware[2].txt
                      Supprime! - C:\Program Files\Crawler

                      -----------\\ Recherche de Fichiers / Dossiers ...

                      -----------\\ [..\Internet Explorer\Main]

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                      "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                      "Start Page"="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fimg%2ffr%2ffr-fr%2fdivertissement%2fcelebrites%2fgalery%2fwentworth02.jpg%3f"
                      "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                      "Search Bar"="http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60076"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                      "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                      "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                      "Start Page"="https://www.msn.com/fr-fr/"
                      "SearchAssistant"="http://www.crawler.com/search/ie.aspx?tb_id=60076"
                      "CustomizeSearch"="http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076"

                      --------------------\\ Recherche d'autres infections

                      Aucune autre infection trouvée !

                      -----------\\ Fin du rapport a 12:36:47,65
                      1. Malwarebytes' Anti-Malware 1.25
                        Version de la base de données: 1094
                        Windows 5.1.2600 Service Pack 2

                        13:06:51 29/08/2008
                        mbam-log-08-29-2008 (13-06-51).txt

                        Type de recherche: Examen rapide
                        Eléments examinés: 51124
                        Temps écoulé: 8 minute(s), 28 second(s)

                        Processus mémoire infecté(s): 0
                        Module(s) mémoire infecté(s): 0
                        Clé(s) du Registre infectée(s): 0
                        Valeur(s) du Registre infectée(s): 0
                        Elément(s) de données du Registre infecté(s): 0
                        Dossier(s) infecté(s): 0
                        Fichier(s) infecté(s): 0

                        Processus mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Module(s) mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Clé(s) du Registre infectée(s):
                        (Aucun élément nuisible détecté)

                        Valeur(s) du Registre infectée(s):
                        (Aucun élément nuisible détecté)

                        Elément(s) de données du Registre infecté(s):
                        (Aucun élément nuisible détecté)

                        Dossier(s) infecté(s):
                        (Aucun élément nuisible détecté)

                        Fichier(s) infecté(s):
                        (Aucun élément nuisible détecté)
                        1. Avira AntiVir Personal
                          Report file date: vendredi 29 août 2008 13:13

                          Scanning for 1581048 virus strains and unwanted programs.

                          Licensed to: Avira AntiVir PersonalEdition Classic
                          Serial number: 0000149996-ADJIE-0001
                          Platform: Windows XP
                          Windows version: (Service Pack 2) [5.1.2600]
                          Boot mode: Normally booted
                          Username: SYSTEM
                          Computer name: BOURD-8543D3698

                          Version information:
                          BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
                          AVSCAN.EXE : 8.1.4.7 315649 Bytes 17/07/2008 17:58:23
                          AVSCAN.DLL : 8.1.4.0 40705 Bytes 17/07/2008 17:58:23
                          LUKE.DLL : 8.1.4.5 164097 Bytes 17/07/2008 17:58:24
                          LUKERES.DLL : 8.1.4.0 12033 Bytes 17/07/2008 17:58:24
                          ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 15:46:19
                          ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 18:16:46
                          ANTIVIR2.VDF : 7.0.6.60 2802176 Bytes 24/08/2008 15:46:08
                          ANTIVIR3.VDF : 7.0.6.88 171520 Bytes 28/08/2008 15:40:52
                          Engineversion : 8.1.1.23
                          AEVDF.DLL : 8.1.0.5 102772 Bytes 20/04/2008 19:10:55
                          AESCRIPT.DLL : 8.1.0.68 315770 Bytes 18/08/2008 18:13:45
                          AESCN.DLL : 8.1.0.23 119156 Bytes 17/07/2008 17:58:24
                          AERDL.DLL : 8.1.0.20 418165 Bytes 26/04/2008 11:37:04
                          AEPACK.DLL : 8.1.2.1 364917 Bytes 17/07/2008 17:58:24
                          AEOFFICE.DLL : 8.1.0.22 192890 Bytes 18/08/2008 18:13:43
                          AEHEUR.DLL : 8.1.0.50 1388918 Bytes 18/08/2008 18:13:41
                          AEHELP.DLL : 8.1.0.15 115063 Bytes 30/05/2008 18:03:05
                          AEGEN.DLL : 8.1.0.36 315764 Bytes 18/08/2008 18:13:35
                          AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 19:45:42
                          AECORE.DLL : 8.1.1.8 172406 Bytes 31/07/2008 19:45:41
                          AEBB.DLL : 8.1.0.1 53617 Bytes 17/07/2008 17:58:24
                          AVWINLL.DLL : 1.0.0.12 15105 Bytes 17/07/2008 17:58:23
                          AVPREF.DLL : 8.0.2.0 38657 Bytes 17/07/2008 17:58:23
                          AVREP.DLL : 8.0.0.2 98344 Bytes 31/07/2008 19:45:40
                          AVREG.DLL : 8.0.0.1 33537 Bytes 17/07/2008 17:58:23
                          AVARKT.DLL : 1.0.0.23 307457 Bytes 20/04/2008 19:10:54
                          AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 17/07/2008 17:58:23
                          SQLITE3.DLL : 3.3.17.1 339968 Bytes 20/04/2008 19:10:55
                          SMTPLIB.DLL : 1.2.0.23 28929 Bytes 17/07/2008 17:58:24
                          NETNT.DLL : 8.0.0.1 7937 Bytes 20/04/2008 19:10:55
                          RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 17/07/2008 17:58:21
                          RCTEXT.DLL : 8.0.52.0 86273 Bytes 17/07/2008 17:58:21

                          Configuration settings for the scan:
                          Jobname..........................: Complete system scan
                          Configuration file...............: c:\program files\antivir personaledition classic\sysscan.avp
                          Logging..........................: low
                          Primary action...................: interactive
                          Secondary action.................: ignore
                          Scan master boot sector..........: off
                          Scan boot sector.................: on
                          Boot sectors.....................: C:, D:,
                          Process scan.....................: on
                          Scan registry....................: on
                          Search for rootkits..............: off
                          Scan all files...................: Intelligent file selection
                          Scan archives....................: on
                          Recursion depth..................: 20
                          Smart extensions.................: on
                          Macro heuristic..................: on
                          File heuristic...................: medium

                          Start of the scan: vendredi 29 août 2008 13:13

                          The scan of running processes will be started
                          Scan process 'avscan.exe' - '1' Module(s) have been scanned
                          Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                          Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                          Scan process 'firefox.exe' - '1' Module(s) have been scanned
                          Scan process 'mbam.exe' - '1' Module(s) have been scanned
                          Scan process 'Watch.exe' - '1' Module(s) have been scanned
                          Scan process 'ALERTM~1.EXE' - '1' Module(s) have been scanned
                          Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
                          Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
                          Scan process 'Toaster.exe' - '1' Module(s) have been scanned
                          Scan process 'ComComp.exe' - '1' Module(s) have been scanned
                          Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
                          Scan process 'jucheck.exe' - '1' Module(s) have been scanned
                          Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
                          Scan process 'hpqgalry.exe' - '1' Module(s) have been scanned
                          Scan process 'NkbMonitor.exe' - '1' Module(s) have been scanned
                          Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
                          Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                          Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
                          Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                          Scan process 'PCMService.exe' - '1' Module(s) have been scanned
                          Scan process 'jusched.exe' - '1' Module(s) have been scanned
                          Scan process 'qttask.exe' - '1' Module(s) have been scanned
                          Scan process 'hpcmpmgr.exe' - '1' Module(s) have been scanned
                          Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
                          Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                          Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
                          Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
                          Scan process 'alg.exe' - '1' Module(s) have been scanned
                          Scan process 'winvnc4.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'SMAgent.exe' - '1' Module(s) have been scanned
                          Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
                          Scan process 'avguard.exe' - '1' Module(s) have been scanned
                          Scan process 'sched.exe' - '1' Module(s) have been scanned
                          Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                          Scan process 'aawservice.exe' - '1' Module(s) have been scanned
                          Scan process 'explorer.exe' - '1' Module(s) have been scanned
                          Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'svchost.exe' - '1' Module(s) have been scanned
                          Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                          Scan process 'lsass.exe' - '1' Module(s) have been scanned
                          Scan process 'services.exe' - '1' Module(s) have been scanned
                          Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                          Scan process 'csrss.exe' - '1' Module(s) have been scanned
                          Scan process 'smss.exe' - '1' Module(s) have been scanned
                          51 processes with 51 modules were scanned

                          Start scanning boot sectors:
                          Boot sector 'C:\'
                          [INFO] No virus was found!
                          Boot sector 'D:\'
                          [INFO] No virus was found!

                          Starting to scan the registry.
                          The registry was scanned ( '61' files ).

                          Starting the file scan:

                          Begin scan in 'C:\' <windows>
                          C:\hiberfil.sys
                          [WARNING] The file could not be opened!
                          C:\pagefile.sys
                          [WARNING] The file could not be opened!
                          Begin scan in 'D:\' <utile>

                          End of the scan: vendredi 29 août 2008 14:13
                          Used time: 1:00:37 Hour(s)

                          The scan has been done completely.

                          6337 Scanning directories
                          219244 Files were scanned
                          0 viruses and/or unwanted programs were found
                          0 Files were classified as suspicious:
                          0 files were deleted
                          0 files were repaired
                          0 files were moved to quarantine
                          0 files were renamed
                          2 Files cannot be scanned
                          219242 Files not concerned
                          1209 Archives were scanned
                          2 Warnings
                          0 Notes
                          • 1
                          • 2