Problème avec Antivirus 2009...

Bonjour, j'ai un problème avec Antivirus 2009 qui s'ouvre de faÇon intempestive et me demande de faire des mises à jour. De plus, quand j'ouvre internet, google me dit que cette version de Antivirus 2009 est une fausse copie. Je ne sait pas du tout quoi faire pour régler ce problème...
Je vous remercie d'avance.
Configuration: Windows XP
Internet Explorer 6.0

18 réponses

  1. Hi,

    télécharge hijackthis
    -> enregistre la cible sous .... "le bureau"

    -> Fais un double-clic sur "HJTInstall.exe" afin de lancer l'installation

    -> Clique sur Install ensuite sur "I Accept"

    -> Clique sur" Do a scan system and save log file"

    -> Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse

    ->Tuto hijackthis(Merci à Balltrap34)

    Alut.
    0
    1. Bonjour et merci d'avoir répondu aussi vite,

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 6:51:01 PM, on 11/24/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
      C:\PROGRA~1\CA\ETRUST~1\realmon.exe
      C:\WINDOWS\vVX6000.exe
      C:\Program Files\Microsoft IntelliType Pro\itype.exe
      C:\Program Files\Microsoft IntelliPoint\ipoint.exe
      C:\Program Files\QuickTime\QTTask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Program Files\Antivirus 2009\av2009.exe
      C:\Program Files\Southwest Airlines\Ding\Ding.exe
      C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
      C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
      C:\Program Files\CA\eTrust Antivirus\InoRT.exe
      C:\Program Files\CA\eTrust Antivirus\InoTask.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\system32\drivers\KodakCCS.exe
      C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
      C:\Program Files\Microsoft LifeCam\MSCamS32.exe
      C:\WINDOWS\system32\ScsiAccess.EXE
      C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
      R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
      O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
      O2 - BHO: &Research - {037C7B8A-151A-49E6-BAED-CC05FCB50328} - C:\WINDOWS\system32\winsrc.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
      O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
      O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
      O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
      O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
      O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [37522284379178892537510095547503] C:\Program Files\Antivirus 2009\av2009.exe
      O4 - HKCU\..\Run: [ieupdate] "C:\WINDOWS\system32\explorer32.exe"
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
      O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
      O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
      O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUxdm265YYUS
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?b443838b5c1d43eca4708e83929a0ad9
      O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?b443838b5c1d43eca4708e83929a0ad9
      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/MyFunCardsFWBInitialSetup1.0.0.15.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u10-windows-i586-jc.cab&AuthParam=1580987764_a5235be86e79daca0cfb05ddc36bfbcd&ext=.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
      O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
      O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
      O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
      O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
      O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O24 - Desktop Component 0: (no name) - http://www.soarfl.com/images/webview.jpg
      0
  2. Hi,

    Installe - Télécharge SmitfraudFix (de de S!Ri, balltrap34 et moe31)

    Option:1 => Recherche:

    * Double cliquer sur SmitfraudFix.exe

    * Sélectionner 1 et pressez =>Entrée dans le menu pour créer

    un rapport des fichiers responsables de l'infection. Le rapport se trouve à la racine du disque

    système

    C:\rapport.txt

    ==>et colle le rapport génèrer sur le forum.

    *=>Ne pas faire l'option 2 sans un avis d'une personne compétente*<=

    Alut.
    0
    1. Bonjour,

      SmitFraudFix v2.378

      Scan done at 17:44:45.85, Tue 11/25/2008
      Run from C:\Documents and Settings\Pat\Desktop\SmitfraudFix
      OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
      The filesystem type is NTFS
      Fix run in normal mode

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
      C:\PROGRA~1\CA\ETRUST~1\realmon.exe
      C:\WINDOWS\vVX6000.exe
      C:\Program Files\Microsoft IntelliType Pro\itype.exe
      C:\Program Files\Microsoft IntelliPoint\ipoint.exe
      C:\Program Files\QuickTime\QTTask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Program Files\Antivirus 2009\av2009.exe
      C:\Program Files\Southwest Airlines\Ding\Ding.exe
      C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
      C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
      C:\Program Files\CA\eTrust Antivirus\InoRT.exe
      C:\Program Files\CA\eTrust Antivirus\InoTask.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\system32\drivers\KodakCCS.exe
      C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
      C:\Program Files\Microsoft LifeCam\MSCamS32.exe
      C:\WINDOWS\system32\ScsiAccess.EXE
      C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Windows Live Favorites\wlfsync.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Documents and Settings\Pat\Desktop\SmitfraudFix\Policies.exe
      C:\WINDOWS\system32\cmd.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      C:\WINDOWS\system32\ieupdates.exe FOUND !
      C:\WINDOWS\system32\scui.cpl FOUND !
      C:\WINDOWS\system32\winsrc.dll FOUND !

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Pat

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Pat\LOCALS~1\Temp

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Pat\Application Data

      C:\Documents and Settings\Pat\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk FOUND !

      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

      C:\DOCUME~1\Pat\STARTM~1\Antivirus 2009 FOUND !

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Pat\FAVORI~1

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      C:\Program Files\Google\googletoolbar1.dll FOUND !

      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="http://www.soarfl.com/images/webview.jpg"
      "SubscribedURL"="http://www.soarfl.com/images/webview.jpg"
      "FriendlyName"=""

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="My Current Home Page"

      »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
      !!!Attention, following keys are not inevitably infected!!!

      o4Patch
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, following keys are not inevitably infected!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, following keys are not inevitably infected!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
      !!!Attention, following keys are not inevitably infected!!!

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, following keys are not inevitably infected!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» RK

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: 3Com 3C905TX-based Ethernet Adapter (Generic) - Packet Scheduler Miniport
      DNS Server Search Order: 167.206.254.2
      DNS Server Search Order: 167.206.254.1

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{BAE2F39A-5A42-4CCA-AEE0-F6417E30B613}: DhcpNameServer=167.206.254.2 167.206.254.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{BAE2F39A-5A42-4CCA-AEE0-F6417E30B613}: DhcpNameServer=167.206.254.2 167.206.254.1
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{BAE2F39A-5A42-4CCA-AEE0-F6417E30B613}: DhcpNameServer=167.206.254.2 167.206.254.1
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=167.206.254.2 167.206.254.1
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=167.206.254.2 167.206.254.1
      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=167.206.254.2 167.206.254.1

      »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

      »»»»»»»»»»»»»»»»»»»»»»»» End

      Merci encore pour l'aide.
      0
      1. Hi,

        Nettoyage:

        * Redemarrer l'ordinateur en mode sans échec:

        * Double cliquer sur smitfraudix:

        * Sélectionner 2 et pressez Entrée dans le menu pour supprimer les fichiers responsables de l'infection.

        * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et pressez Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection:.

        * Le fix déterminera si le fichier wininet.dll est infecté. A la question: Corriger le fichier infecté ? répondre O (oui) et pressez Entrée pour remplacer le fichier corrompu:.

        * Un redemarrage sera peut être necessaire pour terminer la procedure de nettoyage. Le rapport se trouve à la racine du disque système C:\rapport.txt:

        Option::

        * Pour effacer la liste des sites de confiance et sensibles, sélectionner 3 et pressez Entrée dans le menu.

        * A la question: Réinitialiser la liste des sites de confiance et sensibles ? répondre O (oui) et pressez Entrée afin de restaurer les zones de confiances et sensibles:.

        :FAUX POSITIF::

        process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
        0
        1. Bonjour, je vous envoie le rapport et j'ai aussi effacé la liste des sites sensibles

          SmitFraudFix v2.378

          Scan done at 17:07:43.29, Wed 11/26/2008
          Run from C:\Documents and Settings\Pat\Desktop\SmitfraudFix
          OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
          The filesystem type is NTFS
          Fix run in safe mode

          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
          !!!Attention, following keys are not inevitably infected!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» Killing process

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          127.0.0.1 localhost

          »»»»»»»»»»»»»»»»»»»»»»»» VACFix

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

          S!Ri's WS2Fix: LSP not Found.

          »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

          GenericRenosFix by S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{BAE2F39A-5A42-4CCA-AEE0-F6417E30B613}: DhcpNameServer=167.206.254.2 167.206.254.1
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{BAE2F39A-5A42-4CCA-AEE0-F6417E30B613}: DhcpNameServer=167.206.254.2 167.206.254.1
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{BAE2F39A-5A42-4CCA-AEE0-F6417E30B613}: DhcpNameServer=167.206.254.2 167.206.254.1
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=167.206.254.2 167.206.254.1
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=167.206.254.2 167.206.254.1
          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=167.206.254.2 167.206.254.1

          »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "System"=""

          »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

          Registry Cleaning done.

          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
          !!!Attention, following keys are not inevitably infected!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» End
          0
          1. Hi,

            Refait un hijackthis.

            Alut.
            0
            1. Hi,

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 22:40:52, on 11/26/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
              C:\PROGRA~1\CA\ETRUST~1\realmon.exe
              C:\WINDOWS\vVX6000.exe
              C:\Program Files\Microsoft IntelliType Pro\itype.exe
              C:\Program Files\Microsoft IntelliPoint\ipoint.exe
              C:\Program Files\QuickTime\QTTask.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Skype\Phone\Skype.exe
              C:\Program Files\Southwest Airlines\Ding\Ding.exe
              C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
              C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
              C:\Program Files\CA\eTrust Antivirus\InoRT.exe
              C:\Program Files\CA\eTrust Antivirus\InoTask.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\WINDOWS\system32\drivers\KodakCCS.exe
              C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
              C:\Program Files\Microsoft LifeCam\MSCamS32.exe
              C:\WINDOWS\system32\ScsiAccess.EXE
              C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\WINDOWS\system32\wscntfy.exe
              C:\Program Files\Windows Live\Messenger\usnsvc.exe
              C:\Program Files\Windows Live Favorites\wlfsync.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Windows Live Toolbar\msn_sl.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
              R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
              O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
              O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
              O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
              O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
              O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
              O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
              O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
              O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
              O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
              O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
              O4 - HKCU\..\Run: [37522284379178892537510095547503] C:\Program Files\Antivirus 2009\av2009.exe
              O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
              O4 - Global Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
              O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
              O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
              O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZUxdm265YYUS
              O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
              O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
              O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?b443838b5c1d43eca4708e83929a0ad9
              O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?b443838b5c1d43eca4708e83929a0ad9
              O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/MyFunCardsFWBInitialSetup1.0.0.15.cab
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u10-windows-i586-jc.cab&AuthParam=1580987764_a5235be86e79daca0cfb05ddc36bfbcd&ext=.cab
              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
              O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
              O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
              O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
              O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
              O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
              O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
              O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
              O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
              O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
              0
              1. Hi,

                -Télécharge et installe MalwareByte's Anti-Malware
                Malwarebyte

                - Mets le à jour

                ---
                - Double clique sur le raccourci de MalwareByte's Anti-Malware qui est sur le bureau.
                - Sélectionne Exécuter un examen complet si ce n'est pas déjà fait
                - clique sur Rechercher

                - Une fois le scan terminé, une fenêtre s'ouvre, clique sur sur Ok

                - Si MalwareByte's n'a rien détecté, clique sur Ok Un rapport va apparaître ferme-le.

                - Si MalwareByte's a détecté des infections, clique sur Afficher les résultats ensuite sur Supprimer la sélection

                - Enregistre le rapport sur ton Bureau comme cela il sera plus facile à retrouver, poste ensuite ce rapport.

                Note : Si MalwareByte's a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok
                0
                1. Hi,

                  Malwarebytes' Anti-Malware 1.30
                  Version de la base de données: 1429
                  Windows 5.1.2600 Service Pack 3

                  11/27/2008 11:51:00 AM
                  mbam-log-2008-11-27 (11-51-00).txt

                  Type de recherche: Examen complet (C:\|)
                  Eléments examinés: 90283
                  Temps écoulé: 33 minute(s), 55 second(s)

                  Processus mémoire infecté(s): 1
                  Module(s) mémoire infecté(s): 1
                  Clé(s) du Registre infectée(s): 21
                  Valeur(s) du Registre infectée(s): 6
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 2
                  Fichier(s) infecté(s): 20

                  Processus mémoire infecté(s):
                  C:\Program Files\Antivirus 2009\av2009.exe (Rogue.Antivirus 2009) -> Unloaded process successfully.

                  Module(s) mémoire infecté(s):
                  C:\WINDOWS\system32\winsrc.dll (Trojan.FakeAlert) -> Delete on reboot.

                  Clé(s) du Registre infectée(s):
                  HKEY_CLASSES_ROOT\CLSID\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{037c7b8a-151a-49e6-baed-cc05fcb50328} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.

                  Valeur(s) du Registre infectée(s):
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ieupdate (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\37522284379178892537510095547503 (Rogue.Antivirus 2009) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ADP (Rogue.Multiple) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  C:\Program Files\Antivirus 2009 (Rogue.Antivirus 2009) -> Quarantined and deleted successfully.
                  C:\Program Files\MalwareAlarm (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.

                  Fichier(s) infecté(s):
                  C:\WINDOWS\system32\winsrc.dll (Trojan.FakeAlert) -> Delete on reboot.
                  C:\WINDOWS\system32\explorer32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  C:\Documents and Settings\Pat\Local Settings\Temporary Internet Files\Content.IE5\0P43OPKD\winsystems[2].dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{CA2BE733-B862-423E-9309-D508986C957D}\RP1163\A0108662.cpl (Rogue.XPantivirus) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{CA2BE733-B862-423E-9309-D508986C957D}\RP1163\A0108663.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{CA2BE733-B862-423E-9309-D508986C957D}\RP1163\A0108661.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{CA2BE733-B862-423E-9309-D508986C957D}\RP1164\A0108749.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\ieupdates.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\TDSScfub.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\TDSSnrsr.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\TDSSoeqh.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\TDSSriqp.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\drivers\TDSSpaxt.sys (Trojan.TDSS) -> Quarantined and deleted successfully.
                  C:\WINDOWS\Temp\TDSS1265.tmp (Trojan.TDSS) -> Quarantined and deleted successfully.
                  C:\Program Files\Antivirus 2009\av2009.exe (Rogue.Antivirus 2009) -> Quarantined and deleted successfully.
                  C:\Program Files\MalwareAlarm\MalwareAlarm.lic (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.
                  C:\Program Files\MalwareAlarm\Uninstall.exe (Rogue.Malware.Alarm) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\TDSSosvn.dat (Malware.Trace) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\TDSSfpmp.dll (Rootkit.Agent) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\TDSStkdv.log (Trojan.TDSS) -> Quarantined and deleted successfully.
                  0
                  1. Hi,

                    Refait moi un hijackthis STP.

                    Alut.
                    0
                    1. Hi,

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 10:31:28, on 11/28/2008
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
                      C:\PROGRA~1\CA\ETRUST~1\realmon.exe
                      C:\WINDOWS\vVX6000.exe
                      C:\Program Files\Microsoft IntelliType Pro\itype.exe
                      C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                      C:\Program Files\QuickTime\QTTask.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\Program Files\Java\jre6\bin\jusched.exe
                      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Skype\Phone\Skype.exe
                      C:\Program Files\Southwest Airlines\Ding\Ding.exe
                      C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                      C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
                      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
                      C:\Program Files\CA\eTrust Antivirus\InoRT.exe
                      C:\Program Files\CA\eTrust Antivirus\InoTask.exe
                      C:\Program Files\Java\jre6\bin\jqs.exe
                      C:\WINDOWS\system32\drivers\KodakCCS.exe
                      C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
                      C:\Program Files\Microsoft LifeCam\MSCamS32.exe
                      C:\WINDOWS\system32\ScsiAccess.EXE
                      C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\WINDOWS\system32\wscntfy.exe
                      C:\Program Files\Windows Live\Messenger\usnsvc.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Program Files\Windows Live Toolbar\msn_sl.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;*.local
                      O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
                      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                      O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_1.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
                      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
                      O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
                      O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
                      O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
                      O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
                      O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                      O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
                      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      O4 - Global Startup: DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe
                      O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                      O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
                      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                      O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?b443838b5c1d43eca4708e83929a0ad9
                      O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?b443838b5c1d43eca4708e83929a0ad9
                      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - https://sdlc-esd.oracle.com/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab?GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u10-b92-b/jinstall-6u10-windows-i586-jc.cab&BHost=javadl.sun.com&File=jinstall-6u10-windows-i586-jc.cab&AuthParam=1580987764_a5235be86e79daca0cfb05ddc36bfbcd&ext=.cab
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
                      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: CA License Client (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
                      O23 - Service: CA License Server (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
                      O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoRT.exe
                      O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Antivirus\InoTask.exe
                      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                      O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
                      O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
                      O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
                      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                      0
                      1. Hi,

                        Relance hijack et clique sur "Do a system scan only"
                        Ensuite recherche ces lignes et coches les cases

                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)

                        Ensuite clique sur "Fix checked"
                        =*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*==*=*=*=*=*=*=*=*=*=*=*=*=*=*=**=**==*=*=*=*=*
                        Télécharge toolscleaner sur ton Bureau :

                        toolscleaner

                        * Double-clique sur ToolsCleaner2.exe et laisse le travailler

                        * Clique sur Recherche et laisse le scan se terminer.

                        * Clique sur Suppression pour finaliser.

                        * Tu peux, si tu le souhaites, te servir des Options facultatives.

                        * Clique sur Quitter, pour que le rapport puisse se créer.

                        * Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse

                        =*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*=*==*=*=*=*=*=*=*=*=*=*=*=*=*=*=**=**==*=*=*=*=*

                        Désactive et réactive la Restauration du système :

                        1 Dans la barre des tâches de Windows, clique sur Démarrer.

                        2 Clique avec le bouton droit de la souris sur Poste de travail puis clique sur Propriétés.

                        3 Dans l'onglet Restauration du système, coche "Désactiver la Restauration du système"

                        4 Clique sur Appliquer.

                        5 Ensuite décoche "Désactiver la restauration du systeme"

                        6 clique sur appliquer puis ok

                        7 vas créer un point de restauration dans accessoires----outils systeme----restauration du systeme.
                        0
                        1. Hi,

                          [ Rapport ToolsCleaner version 2.2.6 (par A.Rothstein & dj QUIOU) ]

                          -->- Recherche:

                          C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis: trouvé !
                          C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
                          C:\Documents and Settings\Pat\Desktop\HijackThis.lnk: trouvé !
                          C:\Documents and Settings\Pat\Desktop\SmitFraudFix.exe: trouvé !
                          C:\Documents and Settings\Pat\Desktop\SmitFraudfix: trouvé !
                          C:\Program Files\Trend Micro\HijackThis: trouvé !
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
                          C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

                          ---------------------------------
                          -->- Suppression:

                          C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
                          C:\Documents and Settings\Pat\Desktop\HijackThis.lnk: supprimé !
                          C:\Documents and Settings\Pat\Desktop\SmitFraudFix.exe: supprimé !
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
                          C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
                          C:\Documents and Settings\All Users\Start Menu\Programs\HijackThis: supprimé !
                          C:\Documents and Settings\Pat\Desktop\SmitFraudfix: supprimé !
                          C:\Program Files\Trend Micro\HijackThis: supprimé !

                          Je sent une nette amélioration déjà...
                          0
                          1. Hi,

                            Bonne soirée .

                            Alut.
                            0
                            1. Merci,
                              est-ce que tout est en règle maintenant??
                              0
                              1. Hi,

                                Non tu es encore plus........

                                Oui c'est bon.

                                Alut.
                                0
                                1. Salut y'as des rookti TDSServer dans cet M....E fait combofix

                                  A+
                                  0
                                  1. Voilà le rapport de combofix holligan6 3680 :

                                    ComboFix 08-11-28.03 - Pat 2008-11-29 11:03:29.1 - NTFSx86
                                    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.74 [GMT -5:00]
                                    Running from: c:\documents and settings\Pat\Desktop\ComboFix.exe
                                    * Created a new restore point

                                    [COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
                                    .

                                    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
                                    .

                                    c:\documents and settings\Pat\Application Data\gadcom
                                    c:\documents and settings\Pat\Application Data\gadcom\gadcom.exe
                                    c:\documents and settings\Pat\Local Settings\Temporary Internet Files\fbk.sts
                                    c:\windows\system32\cbXOIcbX.dll
                                    c:\windows\system32\cmfjwjtt.ini
                                    c:\windows\system32\dPI19
                                    c:\windows\system32\dPI19\dPI191065.exe
                                    c:\windows\system32\hyuycftm.dll
                                    c:\windows\system32\iifFvWMf.dll
                                    c:\windows\system32\ljJDwTmJ.dll
                                    c:\windows\system32\pac.txt
                                    c:\windows\system32\prunnet.exe
                                    c:\windows\system32\ttjwjfmc.dll
                                    c:\windows\system32\XbcIOXbc.ini
                                    c:\windows\system32\XbcIOXbc.ini2
                                    c:\windows\system32\ztinez.dll

                                    .
                                    ((((((((((((((((((((((((( Files Created from 2008-10-28 to 2008-11-29 )))))))))))))))))))))))))))))))
                                    .

                                    2008-11-28 18:11 . 2008-11-28 18:11 <DIR> d-------- c:\windows\system32\oca
                                    2008-11-28 18:11 . 2008-11-28 18:11 <DIR> d-------- c:\windows\system32\ns5
                                    2008-11-28 18:11 . 2008-11-28 18:11 <DIR> d-------- c:\windows\system32\LN
                                    2008-11-28 18:11 . 2008-11-28 18:11 <DIR> d-------- c:\windows\system32\jec
                                    2008-11-28 18:11 . 2008-11-28 18:11 <DIR> d-------- c:\windows\system32\DEC
                                    2008-11-28 18:11 . 2008-11-28 18:11 <DIR> d-------- c:\windows\system32\AI
                                    2008-11-28 18:11 . 2008-11-28 18:11 <DIR> d-------- c:\temp\FT62
                                    2008-11-28 18:11 . 2008-11-28 18:11 904,372 --a------ c:\temp\eTIIB90.exe
                                    2008-11-28 18:11 . 2008-11-28 18:11 115,016 --a------ c:\windows\system32\MSINET.OCX
                                    2008-11-27 11:12 . 2008-11-27 11:12 <DIR> d-------- c:\documents and settings\Pat\Application Data\Malwarebytes
                                    2008-11-27 11:11 . 2008-11-27 11:12 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
                                    2008-11-27 11:11 . 2008-11-27 11:11 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
                                    2008-11-27 11:11 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
                                    2008-11-27 11:11 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
                                    2008-11-25 17:44 . 2007-09-05 23:22 289,144 --a------ c:\windows\system32\VCCLSID.exe
                                    2008-11-25 17:44 . 2006-04-27 16:49 288,417 --a------ c:\windows\system32\SrchSTS.exe
                                    2008-11-25 17:44 . 2008-10-01 14:51 87,552 --a------ c:\windows\system32\VACFix.exe
                                    2008-11-25 17:44 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\o4Patch.exe
                                    2008-11-25 17:44 . 2008-05-18 20:40 82,944 --a------ c:\windows\system32\IEDFix.exe
                                    2008-11-25 17:44 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\IEDFix.C.exe
                                    2008-11-25 17:44 . 2008-08-18 11:19 82,432 --a------ c:\windows\system32\404Fix.exe
                                    2008-11-25 17:44 . 2003-06-05 20:13 53,248 --a------ c:\windows\system32\Process.exe
                                    2008-11-25 17:44 . 2004-07-31 17:50 51,200 --a------ c:\windows\system32\dumphive.exe
                                    2008-11-25 17:44 . 2007-10-03 23:36 25,600 --a------ c:\windows\system32\WS2Fix.exe
                                    2008-11-25 17:44 . 2008-11-26 17:07 1,526 --a------ c:\windows\system32\tmp.reg
                                    2008-11-24 18:50 . 2008-11-28 14:00 <DIR> d-------- c:\program files\Trend Micro
                                    2008-11-23 17:02 . 2008-04-13 19:12 221,184 --a------ c:\windows\system32\wmpns.dll
                                    2008-11-23 13:30 . 2008-11-23 13:30 <DIR> d-------- c:\windows\system32\scripting
                                    2008-11-23 13:29 . 2008-11-23 13:29 <DIR> d-------- c:\windows\system32\en
                                    2008-11-23 13:29 . 2008-11-23 13:29 <DIR> d-------- c:\windows\l2schemas
                                    2008-11-22 12:48 . 2008-11-22 12:48 841 --a------ c:\windows\Active Setup Log.BAK
                                    2008-11-21 18:10 . 2008-11-21 19:18 <DIR> d-------- C:\d75bdf71f27ae75b5cf02fbafa40e4d0
                                    2008-11-19 19:21 . 2008-11-19 19:21 <DIR> d-------- c:\windows\Sun
                                    2008-11-19 19:21 . 2008-11-23 01:04 <DIR> d-------- c:\documents and settings\Pat\Application Data\LimeWire
                                    2008-11-19 19:18 . 2008-11-19 19:15 410,976 --a------ c:\windows\system32\deploytk.dll
                                    2008-11-19 19:18 . 2008-11-19 19:15 73,728 --a------ c:\windows\system32\javacpl.cpl
                                    2008-11-19 19:15 . 2008-11-19 19:15 <DIR> d-------- c:\program files\Java
                                    2008-11-12 18:33 . 2008-10-24 06:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
                                    2008-11-02 19:00 . 2008-11-02 19:00 <DIR> d-------- c:\program files\Messenger Plus! Live
                                    2008-11-02 19:00 . 2008-11-02 19:00 <DIR> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
                                    2008-10-31 15:10 . 2008-10-31 15:15 <DIR> d-------- c:\program files\Windows Live
                                    2008-10-31 15:10 . 2008-10-31 15:13 <DIR> d--hsc--- c:\program files\Common Files\WindowsLiveInstaller
                                    2008-10-31 15:09 . 2008-10-31 15:09 <DIR> d-------- c:\documents and settings\All Users\Application Data\WLInstaller

                                    .
                                    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    2008-11-27 16:54 --------- d-----w c:\documents and settings\Pat\Application Data\Skype
                                    2008-11-26 22:02 --------- d-----w c:\program files\Google
                                    2008-11-24 00:15 --------- d-----w c:\documents and settings\Pat\Application Data\skypePM
                                    2008-11-23 23:00 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
                                    2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
                                    2008-10-18 19:52 --------- d-----w c:\program files\iTunes
                                    2008-10-18 19:52 --------- d-----w c:\program files\iPod
                                    2008-10-18 19:52 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
                                    2008-10-18 19:49 --------- d-----w c:\program files\Bonjour
                                    2008-10-18 19:48 --------- d-----w c:\program files\QuickTime
                                    2008-10-18 19:47 --------- d-----w c:\program files\Common Files\Apple
                                    2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
                                    2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
                                    2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
                                    2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
                                    2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
                                    2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
                                    2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
                                    2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
                                    2008-10-16 19:06 268,648 ----a-w c:\windows\system32\mucltui.dll
                                    2008-10-16 19:06 208,744 ----a-w c:\windows\system32\muweb.dll
                                    2008-10-07 01:41 --------- d-----w c:\program files\Apple Software Update
                                    2008-10-01 17:01 32,000 ----a-w c:\windows\system32\drivers\usbaapl.sys
                                    2008-09-30 21:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
                                    2008-09-23 22:46 245,408 ----a-w c:\windows\system32\unicows.dll
                                    2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
                                    2008-09-10 01:14 1,307,648 ----a-w c:\windows\system32\msxml6.dll
                                    2008-09-04 17:15 1,106,944 ----a-w c:\windows\system32\msxml3.dll
                                    2008-08-29 14:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
                                    2008-08-29 13:53 61,440 ----a-w c:\windows\system32\dnssd.dll
                                    2006-08-05 01:00 307,200 ----a-w c:\program files\Uninstall My Web Search.dll
                                    .

                                    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    .
                                    *Note* empty entries & legit default entries are not shown
                                    REGEDIT4

                                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
                                    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
                                    "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
                                    "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-08-12 21741864]

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
                                    "LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 277296]
                                    "Realtime Monitor"="c:\progra~1\CA\ETRUST~1\realmon.exe" [2003-02-13 493024]
                                    "VX6000"="c:\windows\vVX6000.exe" [2006-10-13 994096]
                                    "itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 813912]
                                    "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
                                    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
                                    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
                                    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-19 136600]

                                    c:\documents and settings\All Users\Start Menu\Programs\Startup\
                                    Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
                                    DING!.lnk - c:\program files\Southwest Airlines\Ding\Ding.exe [2005-05-17 462848]
                                    Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2003-12-13 630915]
                                    Kodak software updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe [2003-06-08 16432]

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                                    "AppInit_DLLs"=ztinez.dll

                                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                    "%windir%\\system32\\sessmgr.exe"=
                                    "c:\\Program Files\\Messenger\\msmsgs.exe"=
                                    "c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
                                    "c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
                                    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                    "c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
                                    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                                    "c:\\Program Files\\iTunes\\iTunes.exe"=
                                    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                                    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                                    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=

                                    R2 LogWatch;Event Log Watch;"c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe" [2006-12-18 53248]
                                    R3 ati2mtaa;ati2mtaa;c:\windows\system32\DRIVERS\ati2mtaa.sys [2004-08-04 327040]
                                    R3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\DRIVERS\VX6000Xp.sys [2006-06-29 2383152]
                                    S3 ati2mpaa;ati2mpaa;c:\windows\system32\DRIVERS\ati2mpaa.sys [2005-08-20 281856]
                                    S3 CA_LIC_CLNT;CA License Client;"c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe" [2006-12-18 77824]
                                    S3 CA_LIC_SRVR;CA License Server;"c:\program files\CA\SharedComponents\CA_LIC\lic98rmtd.exe" [2006-12-18 77824]
                                    S4 hpt3xx;hpt3xx; []

                                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{24b457b5-9317-11dd-9e70-0060081d0b9e}]
                                    \Shell\AutoRun\command - E:\setupSNK.exe
                                    .
                                    Contents of the 'Scheduled Tasks' folder

                                    2008-11-16 c:\windows\Tasks\AppleSoftwareUpdate.job
                                    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

                                    2008-11-29 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
                                    - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
                                    .
                                    - - - - ORPHANS REMOVED - - - -

                                    BHO-{1A37B132-2251-488D-8E90-852971CCBED8} - c:\windows\system32\cbXOIcbX.dll
                                    BHO-{af93f183-6f79-4625-84bd-a36f3bf9531a} - c:\windows\system32\ztinez.dll
                                    HKCU-Run-SpySweeper - c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
                                    HKCU-Run-prunnet - c:\windows\system32\prunnet.exe
                                    HKLM-Run-prunnet - c:\windows\system32\prunnet.exe

                                    .
                                    ------- Supplementary Scan -------
                                    .
                                    FireFox -: Profile - c:\documents and settings\Pat\Application Data\Mozilla\Firefox\Profiles\jaxmc14n.default\
                                    .
                                    .
                                    ------- File Associations -------
                                    .
                                    .

                                    **************************************************************************

                                    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                    Rootkit scan 2008-11-29 11:44:10
                                    Windows 5.1.2600 Service Pack 3 NTFS

                                    scanning hidden processes ...

                                    scanning hidden autostart entries ...

                                    scanning hidden files ...

                                    scan completed successfully
                                    hidden files: 0

                                    **************************************************************************
                                    .
                                    ------------------------ Other Running Processes ------------------------
                                    .
                                    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    c:\program files\Bonjour\mDNSResponder.exe
                                    c:\program files\CA\eTrust Antivirus\InoRpc.exe
                                    c:\program files\CA\eTrust Antivirus\InoRT.exe
                                    c:\program files\CA\eTrust Antivirus\InoTask.exe
                                    c:\program files\Java\jre6\bin\jqs.exe
                                    c:\windows\system32\drivers\KodakCCS.exe
                                    c:\program files\Microsoft LifeCam\MSCamS32.exe
                                    c:\windows\system32\ScsiAccess.EXE
                                    c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
                                    c:\windows\system32\wdfmgr.exe
                                    c:\program files\iPod\bin\iPodService.exe
                                    c:\windows\system32\wscntfy.exe
                                    c:\program files\Windows Live\Messenger\usnsvc.exe
                                    .
                                    **************************************************************************
                                    .
                                    Completion time: 2008-11-29 11:50:55 - machine was rebooted
                                    ComboFix-quarantined-files.txt 2008-11-29 16:50:45

                                    Pre-Run: 68,850,585,600 bytes free
                                    Post-Run: 69,282,508,800 bytes free

                                    209 --- E O F --- 2008-11-24 02:03:53
                                    0