Tdssadw.dll
Fermé
setric
-
2 sept. 2008 à 20:49
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 - 3 sept. 2008 à 11:59
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 - 3 sept. 2008 à 11:59
3 réponses
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 299
2 sept. 2008 à 21:05
2 sept. 2008 à 21:05
Salut,
* Télécharge SDFix (par Andy Manchesta) et sauvegarde-le sur ton bureau.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
* Double-clique sur SDFix.exe et choisis Install pour l'extraire dans son dossier sur le bureau.
* Redémarre le PC en mode sans échec :
https://www.malekal.com/demarrer-windows-mode-sans-echec/
* Choisis ton compte.
Déroule la liste des instructions ci-dessous :
* Ouvre le dossier SDFix qui vient d'être créé sur le bureau et double-clique sur RunThis.bat pour lancer le script.
* Appuie sur Y pour commencer le nettoyage.
* Quand il te le demandera, appuie sur une touche pour redémarrer le PC.
* Ton système sera plus long à redémarrer car l'outil va continuer à s'exécuter et supprimer des fichiers.
* Après le chargement du bureau, l'outil aura terminé et affichera Finished.
* Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton bureau.
* Le rapport SDFix s'ouvrira et il sera enregistré dans le dossier SDFix sous le nom Report.txt.
* Enfin, copie/colle le rapport du fichier Report.txt.
* Télécharge SDFix (par Andy Manchesta) et sauvegarde-le sur ton bureau.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
* Double-clique sur SDFix.exe et choisis Install pour l'extraire dans son dossier sur le bureau.
* Redémarre le PC en mode sans échec :
https://www.malekal.com/demarrer-windows-mode-sans-echec/
* Choisis ton compte.
Déroule la liste des instructions ci-dessous :
* Ouvre le dossier SDFix qui vient d'être créé sur le bureau et double-clique sur RunThis.bat pour lancer le script.
* Appuie sur Y pour commencer le nettoyage.
* Quand il te le demandera, appuie sur une touche pour redémarrer le PC.
* Ton système sera plus long à redémarrer car l'outil va continuer à s'exécuter et supprimer des fichiers.
* Après le chargement du bureau, l'outil aura terminé et affichera Finished.
* Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton bureau.
* Le rapport SDFix s'ouvrira et il sera enregistré dans le dossier SDFix sous le nom Report.txt.
* Enfin, copie/colle le rapport du fichier Report.txt.
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 299
3 sept. 2008 à 04:20
3 sept. 2008 à 04:20
Malekal est un très bon site.
tdssadw.dll fait partie d'un rootkit à la mode en moment et SDFix le supprime. Peux-tu poster le rapport ?
Je te conseille de faire un scan avec MBAM, de supprimer tout ce qu'il trouve et de poster le rapport généré :
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm
tdssadw.dll fait partie d'un rootkit à la mode en moment et SDFix le supprime. Peux-tu poster le rapport ?
Je te conseille de faire un scan avec MBAM, de supprimer tout ce qu'il trouve et de poster le rapport généré :
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm
Destrio5
Voici le rapport SDFix
[b]SDFix: Version 1.220 [/b]
Run by Administrateur on 2008-09-02 at 20:22
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\EAXF.EXE - Deleted
C:\WINDOWS\rodqgpvldbv.dll - Deleted
C:\WINDOWS\system32\drivers\tdssserv.sys - Deleted
C:\WINDOWS\system32\tdssadw.dll - Deleted
C:\WINDOWS\system32\tdssl.dll - Deleted
C:\WINDOWS\system32\tdsslog.dll - Deleted
C:\WINDOWS\system32\tdssmain.dll - Deleted
C:\WINDOWS\system32\tdssservers.dat - Deleted
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-02 20:39:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv]
"start"=dword:00000001
"type"=dword:00000001
"imagepath"=str(2):"\systemroot\system32\drivers\TDSSserv.sys"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDSSserv]
"start"=dword:00000001
"type"=dword:00000001
"imagepath"=str(2):"\systemroot\system32\drivers\TDSSserv.sys"
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000000e8
"TracesSuccessful"=dword:00000010
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"="E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"
"D:\\LogicielsM‚dia\\Azureus\\Azureus.exe"="D:\\LogicielsM‚dia\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"D:\\LogicielsM‚dia\\Nero 8\\Nero Home\\NeroHome.exe"="D:\\LogicielsM‚dia\\Nero 8\\Nero Home\\NeroHome.exe:*:Enabled:Nero Home"
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\French\\setup.exe"="C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\French\\setup.exe:*:Enabled:Programme d'installation de Kaspersky Anti-Virus 7.0"
"E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"="E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"D:\\LogicielsM‚dia\\BitTorrent\\bittorrent.exe"="D:\\LogicielsM‚dia\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"D:\\LogicielsM‚dia\\iTunes\\iTunes.exe"="D:\\LogicielsM‚dia\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"D:\\LogicielsM‚dia\\Skype\\Phone\\Skype.exe"="D:\\LogicielsM‚dia\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"="C:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe:*:Enabled:javaw"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
[b]Remaining Files [/b]:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Sat 31 May 2008 0 A..H. --- "C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\tw7.tmp"
Tue 22 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 2 Sep 2008 65,536 A..H. --- "C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Microsoft\Outlook\~Outlook.pst.tmp"
[b]Finished![/b]
Voici le rapport MBAM-scan rapide [est-ce un anti-spyware comme spybot]+[est-ce convivial a AV et/ou autre spyware]
Malwarebytes' Anti-Malware 1.26
Version de la base de données: 1106
Windows 5.1.2600 Service Pack 3
2008-09-02 23:15:18
mbam-log-2008-09-02 (23-15-13).txt
Type de recherche: Examen rapide
Eléments examinés: 73407
Temps écoulé: 7 minute(s), 22 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 13
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 36
Fichier(s) infecté(s): 69
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} (Adware.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Documents and Settings\Utilisateur\Application Data\alot (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_0 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_1 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_10 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_11 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_2 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_3 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_4 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_5 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_6 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_7 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_8 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_9 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\configurator (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\products (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_0 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_0\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_1 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_1\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_2 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_2\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_3 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_3\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_5 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_5\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_6 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_6\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\TimerManager (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\ToolbarSearch (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Updater (Adware.BHO) -> No action taken.
Fichier(s) infecté(s):
C:\Documents and Settings\Chantal\Application Data\alot\toolbar.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_0\Button_0.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_0\Button_0.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_1\Button_1.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_1\Button_1.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_10\Button_10.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_10\Button_10.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_11\Button_11.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_11\Button_11.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_2\Button_2.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_2\Button_2.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_3\Button_3.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_3\Button_3.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_4\Button_4.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_4\Button_4.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_5\Button_5.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_5\Button_5.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_6\Button_6.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_6\Button_6.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_7\Button_7.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_7\Button_7.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_8\Button_8.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_8\Button_8.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_9\Button_9.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_9\Button_9.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\configurator\configurator.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\configurator\configurator.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\products\products.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\products\products.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_0\images\alot_icon_35x16.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_1\images\alot_search_24x16.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_2\images\default_282_alot_map_widget_default.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_3\images\default_244_alot_maps_tools.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\cloudy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\default_283_alot_maps_weather.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\foggy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\IMG4CB.tmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\mcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nclear.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\ncloudy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nfoggy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nmcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\npcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nshower.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\pcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\rain.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\shower.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\tstorm.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_5\images\default_225_alot_maps_mrkt_maps.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_6\images\default_452_alot_mrkt_180.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\domains.dat (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\alot_brand.png (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\spinner.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_bottom.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnclose0.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnclose1.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnmin0.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnmin1.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_caption.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_error_bg.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_error_close.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_error_icon.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\TimerManager\TimerManager.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\TimerManager\TimerManager.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\ToolbarSearch\ToolbarSearch.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\ToolbarSearch\ToolbarSearch.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Updater\Updater.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Updater\Updater.xml.backup (Adware.BHO) -> No action taken.
C:\WINDOWS\system32\tdssserf.dll (Trojan.Agent) -> No action taken.
Dois-je garder SDFix - kaspersky me demande de faire quelques chose avec ces ''trajan''
Comment enlever MyWebSearch..
Merci encore
Voici le rapport SDFix
[b]SDFix: Version 1.220 [/b]
Run by Administrateur on 2008-09-02 at 20:22
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\EAXF.EXE - Deleted
C:\WINDOWS\rodqgpvldbv.dll - Deleted
C:\WINDOWS\system32\drivers\tdssserv.sys - Deleted
C:\WINDOWS\system32\tdssadw.dll - Deleted
C:\WINDOWS\system32\tdssl.dll - Deleted
C:\WINDOWS\system32\tdsslog.dll - Deleted
C:\WINDOWS\system32\tdssmain.dll - Deleted
C:\WINDOWS\system32\tdssservers.dat - Deleted
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-02 20:39:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv]
"start"=dword:00000001
"type"=dword:00000001
"imagepath"=str(2):"\systemroot\system32\drivers\TDSSserv.sys"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDSSserv]
"start"=dword:00000001
"type"=dword:00000001
"imagepath"=str(2):"\systemroot\system32\drivers\TDSSserv.sys"
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000000e8
"TracesSuccessful"=dword:00000010
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"="E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"
"D:\\LogicielsM‚dia\\Azureus\\Azureus.exe"="D:\\LogicielsM‚dia\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"D:\\LogicielsM‚dia\\Nero 8\\Nero Home\\NeroHome.exe"="D:\\LogicielsM‚dia\\Nero 8\\Nero Home\\NeroHome.exe:*:Enabled:Nero Home"
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\French\\setup.exe"="C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\French\\setup.exe:*:Enabled:Programme d'installation de Kaspersky Anti-Virus 7.0"
"E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"="E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"D:\\LogicielsM‚dia\\BitTorrent\\bittorrent.exe"="D:\\LogicielsM‚dia\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"D:\\LogicielsM‚dia\\iTunes\\iTunes.exe"="D:\\LogicielsM‚dia\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"D:\\LogicielsM‚dia\\Skype\\Phone\\Skype.exe"="D:\\LogicielsM‚dia\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"="C:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe:*:Enabled:javaw"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
[b]Remaining Files [/b]:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Sat 31 May 2008 0 A..H. --- "C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\tw7.tmp"
Tue 22 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 2 Sep 2008 65,536 A..H. --- "C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Microsoft\Outlook\~Outlook.pst.tmp"
[b]Finished![/b]
Voici le rapport MBAM-scan rapide [est-ce un anti-spyware comme spybot]+[est-ce convivial a AV et/ou autre spyware]
Malwarebytes' Anti-Malware 1.26
Version de la base de données: 1106
Windows 5.1.2600 Service Pack 3
2008-09-02 23:15:18
mbam-log-2008-09-02 (23-15-13).txt
Type de recherche: Examen rapide
Eléments examinés: 73407
Temps écoulé: 7 minute(s), 22 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 13
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 36
Fichier(s) infecté(s): 69
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} (Adware.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Documents and Settings\Utilisateur\Application Data\alot (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_0 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_1 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_10 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_11 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_2 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_3 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_4 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_5 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_6 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_7 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_8 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_9 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\configurator (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\products (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_0 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_0\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_1 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_1\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_2 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_2\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_3 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_3\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_5 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_5\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_6 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_6\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\TimerManager (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\ToolbarSearch (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Updater (Adware.BHO) -> No action taken.
Fichier(s) infecté(s):
C:\Documents and Settings\Chantal\Application Data\alot\toolbar.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_0\Button_0.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_0\Button_0.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_1\Button_1.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_1\Button_1.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_10\Button_10.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_10\Button_10.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_11\Button_11.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_11\Button_11.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_2\Button_2.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_2\Button_2.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_3\Button_3.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_3\Button_3.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_4\Button_4.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_4\Button_4.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_5\Button_5.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_5\Button_5.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_6\Button_6.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_6\Button_6.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_7\Button_7.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_7\Button_7.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_8\Button_8.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_8\Button_8.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_9\Button_9.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_9\Button_9.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\configurator\configurator.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\configurator\configurator.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\products\products.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\products\products.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_0\images\alot_icon_35x16.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_1\images\alot_search_24x16.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_2\images\default_282_alot_map_widget_default.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_3\images\default_244_alot_maps_tools.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\cloudy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\default_283_alot_maps_weather.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\foggy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\IMG4CB.tmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\mcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nclear.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\ncloudy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nfoggy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nmcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\npcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nshower.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\pcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\rain.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\shower.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\tstorm.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_5\images\default_225_alot_maps_mrkt_maps.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_6\images\default_452_alot_mrkt_180.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\domains.dat (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\alot_brand.png (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\spinner.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_bottom.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnclose0.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnclose1.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnmin0.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnmin1.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_caption.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_error_bg.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_error_close.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_error_icon.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\TimerManager\TimerManager.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\TimerManager\TimerManager.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\ToolbarSearch\ToolbarSearch.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\ToolbarSearch\ToolbarSearch.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Updater\Updater.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Updater\Updater.xml.backup (Adware.BHO) -> No action taken.
C:\WINDOWS\system32\tdssserf.dll (Trojan.Agent) -> No action taken.
Dois-je garder SDFix - kaspersky me demande de faire quelques chose avec ces ''trajan''
Comment enlever MyWebSearch..
Merci encore
Destrio5
Voici le rapport SDFix
[b]SDFix: Version 1.220 [/b]
Run by Administrateur on 2008-09-02 at 20:22
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\EAXF.EXE - Deleted
C:\WINDOWS\rodqgpvldbv.dll - Deleted
C:\WINDOWS\system32\drivers\tdssserv.sys - Deleted
C:\WINDOWS\system32\tdssadw.dll - Deleted
C:\WINDOWS\system32\tdssl.dll - Deleted
C:\WINDOWS\system32\tdsslog.dll - Deleted
C:\WINDOWS\system32\tdssmain.dll - Deleted
C:\WINDOWS\system32\tdssservers.dat - Deleted
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-02 20:39:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv]
"start"=dword:00000001
"type"=dword:00000001
"imagepath"=str(2):"\systemroot\system32\drivers\TDSSserv.sys"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDSSserv]
"start"=dword:00000001
"type"=dword:00000001
"imagepath"=str(2):"\systemroot\system32\drivers\TDSSserv.sys"
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000000e8
"TracesSuccessful"=dword:00000010
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"="E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"
"D:\\LogicielsM‚dia\\Azureus\\Azureus.exe"="D:\\LogicielsM‚dia\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"D:\\LogicielsM‚dia\\Nero 8\\Nero Home\\NeroHome.exe"="D:\\LogicielsM‚dia\\Nero 8\\Nero Home\\NeroHome.exe:*:Enabled:Nero Home"
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\French\\setup.exe"="C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\French\\setup.exe:*:Enabled:Programme d'installation de Kaspersky Anti-Virus 7.0"
"E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"="E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"D:\\LogicielsM‚dia\\BitTorrent\\bittorrent.exe"="D:\\LogicielsM‚dia\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"D:\\LogicielsM‚dia\\iTunes\\iTunes.exe"="D:\\LogicielsM‚dia\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"D:\\LogicielsM‚dia\\Skype\\Phone\\Skype.exe"="D:\\LogicielsM‚dia\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"="C:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe:*:Enabled:javaw"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
[b]Remaining Files [/b]:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Sat 31 May 2008 0 A..H. --- "C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\tw7.tmp"
Tue 22 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 2 Sep 2008 65,536 A..H. --- "C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Microsoft\Outlook\~Outlook.pst.tmp"
[b]Finished![/b]
Voici le rapport MBAM-scan rapide [est-ce un anti-spyware comme spybot]+[est-ce convivial a AV et/ou autre spyware]
Malwarebytes' Anti-Malware 1.26
Version de la base de données: 1106
Windows 5.1.2600 Service Pack 3
2008-09-02 23:15:18
mbam-log-2008-09-02 (23-15-13).txt
Type de recherche: Examen rapide
Eléments examinés: 73407
Temps écoulé: 7 minute(s), 22 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 13
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 36
Fichier(s) infecté(s): 69
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} (Adware.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Documents and Settings\Utilisateur\Application Data\alot (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_0 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_1 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_10 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_11 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_2 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_3 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_4 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_5 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_6 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_7 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_8 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_9 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\configurator (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\products (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_0 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_0\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_1 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_1\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_2 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_2\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_3 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_3\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_5 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_5\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_6 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_6\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\TimerManager (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\ToolbarSearch (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Updater (Adware.BHO) -> No action taken.
Fichier(s) infecté(s):
C:\Documents and Settings\Chantal\Application Data\alot\toolbar.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_0\Button_0.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_0\Button_0.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_1\Button_1.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_1\Button_1.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_10\Button_10.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_10\Button_10.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_11\Button_11.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_11\Button_11.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_2\Button_2.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_2\Button_2.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_3\Button_3.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_3\Button_3.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_4\Button_4.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_4\Button_4.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_5\Button_5.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_5\Button_5.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_6\Button_6.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_6\Button_6.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_7\Button_7.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_7\Button_7.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_8\Button_8.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_8\Button_8.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_9\Button_9.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_9\Button_9.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\configurator\configurator.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\configurator\configurator.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\products\products.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\products\products.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_0\images\alot_icon_35x16.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_1\images\alot_search_24x16.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_2\images\default_282_alot_map_widget_default.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_3\images\default_244_alot_maps_tools.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\cloudy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\default_283_alot_maps_weather.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\foggy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\IMG4CB.tmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\mcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nclear.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\ncloudy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nfoggy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nmcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\npcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nshower.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\pcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\rain.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\shower.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\tstorm.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_5\images\default_225_alot_maps_mrkt_maps.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_6\images\default_452_alot_mrkt_180.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\domains.dat (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\alot_brand.png (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\spinner.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_bottom.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnclose0.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnclose1.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnmin0.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnmin1.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_caption.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_error_bg.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_error_close.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_error_icon.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\TimerManager\TimerManager.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\TimerManager\TimerManager.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\ToolbarSearch\ToolbarSearch.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\ToolbarSearch\ToolbarSearch.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Updater\Updater.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Updater\Updater.xml.backup (Adware.BHO) -> No action taken.
C:\WINDOWS\system32\tdssserf.dll (Trojan.Agent) -> No action taken.
Dois-je garder SDFix - kaspersky me demande de faire quelques chose avec ces ''trajan''
Comment enlever MyWebSearch..
Merci encore
Voici le rapport SDFix
[b]SDFix: Version 1.220 [/b]
Run by Administrateur on 2008-09-02 at 20:22
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\WINDOWS\EAXF.EXE - Deleted
C:\WINDOWS\rodqgpvldbv.dll - Deleted
C:\WINDOWS\system32\drivers\tdssserv.sys - Deleted
C:\WINDOWS\system32\tdssadw.dll - Deleted
C:\WINDOWS\system32\tdssl.dll - Deleted
C:\WINDOWS\system32\tdsslog.dll - Deleted
C:\WINDOWS\system32\tdssmain.dll - Deleted
C:\WINDOWS\system32\tdssservers.dat - Deleted
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-02 20:39:01
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv]
"start"=dword:00000001
"type"=dword:00000001
"imagepath"=str(2):"\systemroot\system32\drivers\TDSSserv.sys"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDSSserv]
"start"=dword:00000001
"type"=dword:00000001
"imagepath"=str(2):"\systemroot\system32\drivers\TDSSserv.sys"
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000000e8
"TracesSuccessful"=dword:00000010
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"="E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"
"D:\\LogicielsM‚dia\\Azureus\\Azureus.exe"="D:\\LogicielsM‚dia\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"D:\\LogicielsM‚dia\\Nero 8\\Nero Home\\NeroHome.exe"="D:\\LogicielsM‚dia\\Nero 8\\Nero Home\\NeroHome.exe:*:Enabled:Nero Home"
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\French\\setup.exe"="C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\French\\setup.exe:*:Enabled:Programme d'installation de Kaspersky Anti-Virus 7.0"
"E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"="E:\\Logiciels Entretien\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"D:\\LogicielsM‚dia\\BitTorrent\\bittorrent.exe"="D:\\LogicielsM‚dia\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"D:\\LogicielsM‚dia\\iTunes\\iTunes.exe"="D:\\LogicielsM‚dia\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"D:\\LogicielsM‚dia\\Skype\\Phone\\Skype.exe"="D:\\LogicielsM‚dia\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe"="C:\\Program Files\\Hewlett-Packard\\Toolbox\\jre\\bin\\javaw.exe:*:Enabled:javaw"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
[b]Remaining Files [/b]:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Sat 31 May 2008 0 A..H. --- "C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\tw7.tmp"
Tue 22 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 2 Sep 2008 65,536 A..H. --- "C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Microsoft\Outlook\~Outlook.pst.tmp"
[b]Finished![/b]
Voici le rapport MBAM-scan rapide [est-ce un anti-spyware comme spybot]+[est-ce convivial a AV et/ou autre spyware]
Malwarebytes' Anti-Malware 1.26
Version de la base de données: 1106
Windows 5.1.2600 Service Pack 3
2008-09-02 23:15:18
mbam-log-2008-09-02 (23-15-13).txt
Type de recherche: Examen rapide
Eléments examinés: 73407
Temps écoulé: 7 minute(s), 22 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 13
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 36
Fichier(s) infecté(s): 69
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5aa2ba46-9913-4dc7-9620-69ab0fa17ae7} (Adware.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> No action taken.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
C:\Documents and Settings\Utilisateur\Application Data\alot (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_0 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_1 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_10 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_11 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_2 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_3 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_4 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_5 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_6 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_7 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_8 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_9 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\configurator (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\products (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_0 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_0\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_1 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_1\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_2 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_2\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_3 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_3\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_5 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_5\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_6 (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_6\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\TimerManager (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\ToolbarSearch (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Updater (Adware.BHO) -> No action taken.
Fichier(s) infecté(s):
C:\Documents and Settings\Chantal\Application Data\alot\toolbar.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_0\Button_0.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_0\Button_0.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_1\Button_1.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_1\Button_1.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_10\Button_10.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_10\Button_10.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_11\Button_11.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_11\Button_11.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_2\Button_2.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_2\Button_2.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_3\Button_3.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_3\Button_3.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_4\Button_4.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_4\Button_4.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_5\Button_5.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_5\Button_5.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_6\Button_6.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_6\Button_6.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_7\Button_7.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_7\Button_7.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_8\Button_8.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_8\Button_8.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_9\Button_9.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Button_9\Button_9.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\configurator\configurator.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\configurator\configurator.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\products\products.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\products\products.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_0\images\alot_icon_35x16.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_1\images\alot_search_24x16.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_2\images\default_282_alot_map_widget_default.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_3\images\default_244_alot_maps_tools.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\cloudy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\default_283_alot_maps_weather.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\foggy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\IMG4CB.tmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\mcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nclear.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\ncloudy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nfoggy.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nmcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\npcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\nshower.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\pcloud.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\rain.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\shower.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_4\images\tstorm.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_5\images\default_225_alot_maps_mrkt_maps.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Button_6\images\default_452_alot_mrkt_180.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\domains.dat (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\alot_brand.png (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\spinner.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_bottom.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnclose0.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnclose1.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnmin0.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_btnmin1.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_caption.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_error_bg.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_error_close.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Resources\Shared\images\widget_error_icon.bmp (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\TimerManager\TimerManager.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\TimerManager\TimerManager.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\ToolbarSearch\ToolbarSearch.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\ToolbarSearch\ToolbarSearch.xml.backup (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Updater\Updater.xml (Adware.BHO) -> No action taken.
C:\Documents and Settings\Chantal\Application Data\alot\Updater\Updater.xml.backup (Adware.BHO) -> No action taken.
C:\WINDOWS\system32\tdssserf.dll (Trojan.Agent) -> No action taken.
Dois-je garder SDFix - kaspersky me demande de faire quelques chose avec ces ''trajan''
Comment enlever MyWebSearch..
Merci encore
Destrio5
Messages postés
85985
Date d'inscription
dimanche 11 juillet 2010
Statut
Modérateur
Dernière intervention
17 février 2023
10 299
3 sept. 2008 à 11:59
3 sept. 2008 à 11:59
Tu peux supprimer SDFix.
Tu peux cliquer sur Supprimer la sélection pour MBAM.
Tu peux cliquer sur Supprimer la sélection pour MBAM.
3 sept. 2008 à 03:40
Malgré qu'encore maintenant je ne sache ce qui m'as frappé, tu m'as fourni les outils pour l'effacer de mon ordi, enfin, plus rien n'apparait.
Et ce lien www.malekal.com, un bijou pour moi!
Devrais-je garder le program SDfix?
encore merci|