[virus] pb de fenêtres pub
RésoluJe solicite votre aide car je suis ennuyée par des fenetres pub qui s'ouvrent constament qd je navigue sur le web du genre spyware etc...
c'est pénible et ça ralentit fortement mon pc.
J'utilise windows xp, avast! et firefox.
J'ai lu qqs messages et j'ai lancé hijack this, en voici le rapport :
Logfile of HijackThis v1.99.1
Scan saved at 15:27:39, on 02/06/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Asseray\LOCALS~1\Temp\Rar$EX00.391\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [YeppStudioAgent] C:\Program Files\Samsung\SamsungMediaStudio4.1\SamsungMediaStudioAgent.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .htm: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1215A302-DDA0-4BB9-87EA-24BF321828B0}: NameServer = 212.151.136.242 212.151.137.170
O17 - HKLM\System\CS1\Services\Tcpip\..\{1215A302-DDA0-4BB9-87EA-24BF321828B0}: NameServer = 212.151.136.242 212.151.137.170
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
J'espère que vous pourrez m'aider et je vous en remercie d'avance !
Configuration: Windows XP Firefox 2.0.0.4
30 réponses
Des fenêtres publicitaires s'ouvrent constamment lors de la navigation sur Internet sous Windows XP avec Firefox, et sont perçues comme des spyware, ralentissant fortement le PC. Des mesures proposées incluent le démarrage en mode sans échec, l’utilisation d’outils comme HijackThis, puis des scans avec AVG Anti-Spyware pour identifier les éléments malveillants. Plusieurs méthodes de suppression et de nettoyage ont été discutées, notamment rapports Navilog et procédures guidées par des tutoriels, ainsi que des conseils sur les paramètres de sécurité et les mises à jour. D'autres échanges recommandent l'installation d'un pare-feu et la mise à jour du système pour prévenir les récurrences publicitaires, en combinant vigilance navigateur, suppression des programmes indésirables et mises à jour régulières.
-
salut mag594,
belle journée n´est-ce pas?!
tu n´as apparament rencontré aucun probleme, cool!!
bon week end a toi
@+
-
je viens de suivre tes conseils,
merci beaucoup ! -
re,
tu n´as pas de par feu :
telecharge et instal ceci :
https://kerio.probb.fr/t4-tlcharger-sunbelt-kerio-personal-firewall
tutorial :
https://kerio.probb.fr/t1-tuto-pour-kerio-4-2
je voie que tu as spybot et son tea timer pour le completer telecharge ceci:
http://www.brightfort.com/spywareblaster.html
mets le a jours et click sur enable all protection
c´est un résident avec des signatures de spyware connus
il faudra juste le mettre a jour de temps en temps car la version gratuite ne le fait pas automatiquement
telecharge aussi le service pack 2 sur le site de microsoft...
Voila pour un début
N´hesite pas si tu rencontre des difficultés
@+
-
il a l'air d'aller bien en fait :-)
Les fenêtres n'apparaissent plus...je suis tranquille!
Je te remercie beaucoup d'avoir passer du temps à m'aider, c'est vraiment très sympa !
Comment je peux eviter ce genre de désagréments? afin d'éviter ce genre d'harcelement par la suite?
Merci encore !
ps : problème résolu ! j'aurais bien aimé récapituler la solution, mais en fait j'ai pas compris grand chose lol ! -
re,
ok tout ca me parais ok,
comment va ton pc?
-
Rapport blacklight:
06/07/07 20:11:51 [Info]: BlackLight Engine 1.0.61 initialized
06/07/07 20:11:51 [Info]: OS: 5.1 build 2600 (Service Pack 1)
06/07/07 20:11:51 [Note]: 7019 4
06/07/07 20:11:51 [Note]: 7005 0
06/07/07 20:11:57 [Note]: 7006 0
06/07/07 20:11:57 [Note]: 7011 1536
06/07/07 20:11:57 [Note]: 7026 0
06/07/07 20:11:57 [Note]: 7026 0
06/07/07 20:12:09 [Note]: FSRAW library version 1.7.1021
06/07/07 20:43:37 [Note]: 7007 0 -
re,
tu as bien tout supprimé?
on va verifier un truc :
Va sur ce lien et télécharge Blacklight(de F-Secure) :
< https://www.f-secure.com/en > et sauvegarde le sur ton Bureau
Consulte le tuto de Malekal_morte ici :
< https://www.malekal.com/tutorial-f-secure-blacklight/ >
Tu suis le tuto pour la phase 1 (scan) et tu postes le rapport de blacklight dans ta réponse.
@+
-
Voici le rapport, il est long, je ne crois pas que ce soit bon signe!
Ad-Aware SE Build 1.06r1
Logfile Created on:jeudi 7 juin 2007 17:42:08
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R174 04.06.2007
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Alexa(TAC index:5):3 total references
Tracking Cookie(TAC index:3):24 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
07-06-2007 17:42:08 - Scan started. (Full System Scan)
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 624
ThreadCreationTime : 05-06-2007 05:57:23
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 684
ThreadCreationTime : 05-06-2007 05:57:37
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 708
ThreadCreationTime : 05-06-2007 05:57:38
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 752
ThreadCreationTime : 05-06-2007 05:57:38
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Applications Services et Contrôleur
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 764
ThreadCreationTime : 05-06-2007 05:57:38
BasePriority : Normal
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [ati2evxx.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 916
ThreadCreationTime : 05-06-2007 05:57:38
BasePriority : Normal
FileVersion : 6.14.10.4111
ProductVersion : 6.14.10.4111
ProductName : ATI External Event Utility for WindowsNT and Windows9X
CompanyName : ATI Technologies Inc.
FileDescription : ATI External Event Utility EXE Module
InternalName : ATI2EVXX.EXE
LegalCopyright : Copyright © 1999-2004 ATI Technologies Inc.
OriginalFilename : ATI2EVXX.EXE
#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 956
ThreadCreationTime : 05-06-2007 05:57:38
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1064
ThreadCreationTime : 05-06-2007 05:57:38
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1200
ThreadCreationTime : 05-06-2007 05:57:38
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1232
ThreadCreationTime : 05-06-2007 05:57:38
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:11 [aswupdsv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 1384
ThreadCreationTime : 05-06-2007 05:57:39
BasePriority : Normal
FileVersion : 4, 7, 997, 0
ProductVersion : 4, 7, 0, 0
ProductName : avast! Antivirus
CompanyName : ALWIL Software
FileDescription : avast! Antivirus updating service
InternalName : aswUpdSv.exe
LegalCopyright : Copyright (c) 2007 ALWIL Software
OriginalFilename : aswUpdSv.exe
#:12 [ashserv.exe]
FilePath : C:\Program Files\Alwil Software\Avast4\
ProcessID : 1468
ThreadCreationTime : 05-06-2007 05:57:39
BasePriority : High
FileVersion : 4, 7, 997, 0
ProductVersion : 4, 7, 0, 0
ProductName : avast! Antivirus
CompanyName : ALWIL Software
FileDescription : avast! antivirus service
InternalName : aswServ
LegalCopyright : Copyright (c) 2007 ALWIL Software
OriginalFilename : aswServ.exe
#:13 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1744
ThreadCreationTime : 05-06-2007 05:57:43
BasePriority : Normal
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:14 [ati2evxx.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1364
ThreadCreationTime : 05-06-2007 05:57:45
BasePriority : Normal
FileVersion : 6.14.10.4111
ProductVersion : 6.14.10.4111
ProductName : ATI External Event Utility for WindowsNT and Windows9X
CompanyName : ATI Technologies Inc.
FileDescription : ATI External Event Utility EXE Module
InternalName : ATI2EVXX.EXE
LegalCopyright : Copyright © 1999-2004 ATI Technologies Inc.
OriginalFilename : ATI2EVXX.EXE
#:15 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 1536
ThreadCreationTime : 05-06-2007 05:57:45
BasePriority : Normal
FileVersion : 6.00.2800.1221 (xpsp2.030511-1403)
ProductVersion : 6.00.2800.1221
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Explorateur Windows
InternalName : explorer
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : EXPLORER.EXE
#:16 [rundll32.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1700
ThreadCreationTime : 05-06-2007 05:57:47
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Exécuter une DLL en tant qu'application
InternalName : rundll
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : RUNDLL.EXE
#:17 [agrsmmsg.exe]
FilePath : C:\WINDOWS\
ProcessID : 1708
ThreadCreationTime : 05-06-2007 05:57:47
BasePriority : Normal
FileVersion : 2.1.30 2.1.30 05/23/2003 10:43:49
ProductVersion : 2.1.30 2.1.30 05/23/2003 10:43:49
ProductName : Agere SoftModem Messaging Applet
CompanyName : Agere Systems
FileDescription : SoftModem Messaging Applet
InternalName : smdmstat.exe
LegalCopyright : Copyright © Agere Systems 1998-2000
OriginalFilename : smdmstat.exe
#:18 [ashdisp.exe]
FilePath : C:\PROGRA~1\ALWILS~1\Avast4\
ProcessID : 872
ThreadCreationTime : 05-06-2007 05:57:47
BasePriority : Normal
FileVersion : 4, 7, 997, 0
ProductVersion : 4, 7, 0, 0
ProductName : avast! Antivirus
CompanyName : ALWIL Software
FileDescription : avast! service GUI component
InternalName : aswDisp
LegalCopyright : Copyright (c) 2007 ALWIL Software
OriginalFilename : aswDisp.exe
#:19 [atiptaxx.exe]
FilePath : C:\Program Files\ATI Technologies\ATI Control Panel\
ProcessID : 1800
ThreadCreationTime : 05-06-2007 05:57:47
BasePriority : Normal
FileVersion : 6.14.10.5137
ProductVersion : 6.14.10.5137
ProductName : ATI Desktop Component
CompanyName : ATI Technologies, Inc.
FileDescription : ATI Desktop Control Panel
InternalName : Atiptaxx.exe
LegalCopyright : Copyright (C) 1998-2004 ATI Technologies Inc.
OriginalFilename : Atiptaxx.exe
#:20 [jusched.exe]
FilePath : C:\Program Files\Java\jre1.5.0_09\bin\
ProcessID : 1824
ThreadCreationTime : 05-06-2007 05:57:47
BasePriority : Normal
#:21 [avgas.exe]
FilePath : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\
ProcessID : 1956
ThreadCreationTime : 05-06-2007 05:57:53
BasePriority : Normal
FileVersion : 7, 5, 0, 50
ProductVersion : 7, 5, 0, 50
ProductName : AVG Anti-Spyware
CompanyName : Anti-Malware Development a.s.
FileDescription : AVG Anti-Spyware
InternalName : AVG Anti-Spyware
LegalCopyright : Copyright © 2006 Anti-Malware Development a.s.
OriginalFilename : avgas.exe
#:22 [ctfmon.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1976
ThreadCreationTime : 05-06-2007 05:57:53
BasePriority : Normal
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE
#:23 [wincinemamgr.exe]
FilePath : C:\Program Files\InterVideo\Common\Bin\
ProcessID : 2000
ThreadCreationTime : 05-06-2007 05:57:54
BasePriority : Normal
FileVersion : 1.7.1
ProductVersion : 1, 7, 1, 0
ProductName : WinCinema Manager for InterVideo WinCinema products
CompanyName : InterVideo Inc.
FileDescription : WinCinema Manager
InternalName : WinCinema Manager
LegalCopyright : Copyright 1999-2003 InterVideo, Inc. All rights reserved.
OriginalFilename : WinCinemaMgr.EXE
#:24 [guard.exe]
FilePath : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\
ProcessID : 688
ThreadCreationTime : 05-06-2007 05:58:51
BasePriority : Normal
FileVersion : 7, 5, 0, 47
ProductVersion : 7, 5, 0, 47
ProductName : AVG Anti-Spyware
CompanyName : Anti-Malware Development a.s.
FileDescription : AVG Anti-Spyware guard
InternalName : AVG Anti-Spyware guard
LegalCopyright : Copyright © 2006 Anti-Malware Development a.s.
OriginalFilename : guard.exe
#:25 [cdac11ba.exe]
FilePath : C:\WINDOWS\System32\drivers\
ProcessID : 768
ThreadCreationTime : 05-06-2007 05:58:51
BasePriority : Normal
FileVersion : 4.20.0
ProductVersion : 4.20.0 Windows NT 2002/07/15
ProductName : SafeCast Windows NT
CompanyName : Macrovision
FileDescription : Macrovision RTS Service
InternalName : CDANTSRV
LegalCopyright : Copyright (c) 1998-2002 Macrovision Corp.
OriginalFilename : CDANTSRV.EXE
Comments : StringFileInfo: U.S. English
#:26 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1028
ThreadCreationTime : 05-06-2007 05:58:51
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:27 [wdfmgr.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1336
ThreadCreationTime : 05-06-2007 05:58:56
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: dnsrv(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe
#:28 [wuauclt.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1844
ThreadCreationTime : 05-06-2007 06:00:05
BasePriority : Normal
#:29 [jucheck.exe]
FilePath : C:\Program Files\Java\jre1.5.0_09\bin\
ProcessID : 340
ThreadCreationTime : 05-06-2007 06:02:48
BasePriority : Normal
FileVersion : 5.0.90.3
ProductVersion : 5.0.90.3
ProductName : Java(TM) 2 Platform Standard Edition 5.0 Update 9
CompanyName : Sun Microsystems, Inc.
FileDescription : Java(TM) Update Checker
InternalName : Java(TM) Update Checker
LegalCopyright : Copyright © 2004
OriginalFilename : jucheck.exe
#:30 [msnmsgr.exe]
FilePath : C:\Program Files\MSN Messenger\
ProcessID : 3628
ThreadCreationTime : 05-06-2007 11:10:42
BasePriority : Normal
FileVersion : 8.1.0178.00
ProductVersion : 8.1.0178
ProductName : Messenger
CompanyName : Microsoft Corporation
FileDescription : Messenger
InternalName : msnmsgr.exe
LegalCopyright : Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFilename : msnmsgr.exe
#:31 [usnsvc.exe]
FilePath : C:\Program Files\MSN Messenger\
ProcessID : 2652
ThreadCreationTime : 05-06-2007 11:11:18
BasePriority : Normal
FileVersion : 8.1.0178.00
ProductVersion : 8.1.0178
ProductName : Messenger
CompanyName : Microsoft Corporation
FileDescription : Messenger Sharing USN Journal Reader Service
InternalName : usnsvc.exe
LegalCopyright : Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFilename : usnsvc.exe
#:32 [azureus.exe]
FilePath : C:\Documents and Settings\Asseray\Mes documents\mes programmes\azureus\
ProcessID : 2016
ThreadCreationTime : 05-06-2007 18:56:48
BasePriority : Normal
#:33 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 3128
ThreadCreationTime : 06-06-2007 17:45:56
BasePriority : Normal
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : IEXPLORE.EXE
#:34 [livecall.exe]
FilePath : C:\Program Files\MSN Messenger\
ProcessID : 3344
ThreadCreationTime : 06-06-2007 21:26:24
BasePriority : Normal
FileVersion : 1.1.161.0
ProductVersion : 1.1.161.0
ProductName : Windows Live Call
CompanyName : Microsoft Corporation
FileDescription : Windows Live Call
InternalName : livecall
LegalCopyright : Copyright © 2006 Microsoft Corporation. All rights reserved.
OriginalFilename : livecall.exe
#:35 [thunderbird.exe]
FilePath : C:\Program Files\Mozilla Thunderbird\
ProcessID : 1804
ThreadCreationTime : 07-06-2007 05:53:05
BasePriority : Normal
#:36 [realsched.exe]
FilePath : C:\Program Files\Fichiers communs\Real\Update_OB\
ProcessID : 3564
ThreadCreationTime : 07-06-2007 05:58:00
BasePriority : Normal
FileVersion : 0.1.0.3208
ProductVersion : 0.1.0.3208
ProductName : RealPlayer (32-bit)
CompanyName : RealNetworks, Inc.
FileDescription : RealNetworks Scheduler
InternalName : schedapp
LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
LegalTrademarks : RealAudio(tm) is a trademark of RealNetworks, Inc.
OriginalFilename : realsched.exe
#:37 [firefox.exe]
FilePath : C:\Program Files\Mozilla Firefox\
ProcessID : 396
ThreadCreationTime : 07-06-2007 06:06:01
BasePriority : Normal
#:38 [acrord32.exe]
FilePath : C:\Program Files\Adobe\Acrobat 7.0\Reader\
ProcessID : 2120
ThreadCreationTime : 07-06-2007 15:25:02
BasePriority : Normal
FileVersion : 7.0.5.2005092300
ProductVersion : 7.0.5.2005092300
ProductName : Adobe Reader
CompanyName : Adobe Systems Incorporated
FileDescription : Adobe Reader 7.0
LegalCopyright : Copyright 1984-2005 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename : AcroRd32.exe
#:39 [ad-aware.exe]
FilePath : C:\DOCUME~1\Asseray\MESDOC~1\MESPRO~1\FENETR~1\AD-AWA~1\
ProcessID : 2320
ThreadCreationTime : 07-06-2007 15:41:21
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
#:40 [hh.exe]
FilePath : C:\WINDOWS\
ProcessID : 612
ThreadCreationTime : 07-06-2007 15:41:22
BasePriority : Normal
FileVersion : 5.2.3790.315 (srv03_gdr.050421-1728)
ProductVersion : 5.2.3790.315
ProductName : HTML Help
CompanyName : Microsoft Corporation
FileDescription : Microsoft® HTML Help Executable
InternalName : HH 1.41
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : HH.exe
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Alexa Object Recognized!
Type : RegValue
Data :
TAC Rating : 5
Category : Data Miner
Comment : "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
Rootkey : HKEY_USERS
Object : .DEFAULT\software\microsoft\internet explorer\extensions\cmdmapping
Value : {c95fe080-8f5d-11d2-a20b-00aa003c157a}
Alexa Object Recognized!
Type : RegValue
Data :
TAC Rating : 5
Category : Data Miner
Comment : "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
Rootkey : HKEY_USERS
Object : S-1-5-18\software\microsoft\internet explorer\extensions\cmdmapping
Value : {c95fe080-8f5d-11d2-a20b-00aa003c157a}
Alexa Object Recognized!
Type : RegValue
Data :
TAC Rating : 5
Category : Data Miner
Comment : "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
Rootkey : HKEY_USERS
Object : S-1-5-21-1757981266-1532298954-839522115-1005\software\microsoft\internet explorer\extensions\cmdmapping
Value : {c95fe080-8f5d-11d2-a20b-00aa003c157a}
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 3
Objects found so far: 3
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 3
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@estat[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:17
Value : Cookie:asseray@estat.com/
Expires : 07-03-2017 20:11:36
LastSync : Hits:17
UseCount : 0
Hits : 17
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@smartadserver[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:11
Value : Cookie:asseray@smartadserver.com/
Expires : 13-03-2027 23:08:16
LastSync : Hits:11
UseCount : 0
Hits : 11
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@statcounter[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:14
Value : Cookie:asseray@statcounter.com/
Expires : 19-05-2012 22:26:16
LastSync : Hits:14
UseCount : 0
Hits : 14
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@www.smartadserver[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:27
Value : Cookie:asseray@www.smartadserver.com/
Expires : 16-05-2027 22:26:16
LastSync : Hits:27
UseCount : 0
Hits : 27
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@adtech[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:15
Value : Cookie:asseray@adtech.de/
Expires : 08-03-2017 00:30:00
LastSync : Hits:15
UseCount : 0
Hits : 15
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@advertising[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:5
Value : Cookie:asseray@advertising.com/
Expires : 08-05-2012 23:11:42
LastSync : Hits:5
UseCount : 0
Hits : 5
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@weborama[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:112
Value : Cookie:asseray@weborama.fr/
Expires : 07-09-2007 09:14:02
LastSync : Hits:112
UseCount : 0
Hits : 112
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@as1.falkag[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:asseray@as1.falkag.de/
Expires : 23-05-2007 12:52:56
LastSync : Hits:3
UseCount : 0
Hits : 3
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@ads.pointroll[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:15
Value : Cookie:asseray@ads.pointroll.com/
Expires : 01-01-2010 02:00:00
LastSync : Hits:15
UseCount : 0
Hits : 15
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@tradedoubler[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:20
Value : Cookie:asseray@tradedoubler.com/
Expires : 27-05-2027 19:38:42
LastSync : Hits:20
UseCount : 0
Hits : 20
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@fastclick[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:6
Value : Cookie:asseray@fastclick.net/
Expires : 20-04-2009 19:29:22
LastSync : Hits:6
UseCount : 0
Hits : 6
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@atdmt[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:7
Value : Cookie:asseray@atdmt.com/
Expires : 03-06-2012 02:00:00
LastSync : Hits:7
UseCount : 0
Hits : 7
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@questionmarket[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:7
Value : Cookie:asseray@questionmarket.com/
Expires : 01-05-2008 16:12:32
LastSync : Hits:7
UseCount : 0
Hits : 7
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@doubleclick[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:3
Value : Cookie:asseray@doubleclick.net/
Expires : 06-06-2007 20:01:24
LastSync : Hits:3
UseCount : 0
Hits : 3
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@msnportal.112.2o7[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:asseray@msnportal.112.2o7.net/
Expires : 03-06-2012 13:15:28
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@www.poweradvertising[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:asseray@www.poweradvertising.com/
Expires : 30-04-2008 10:22:44
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@media.fastclick[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:asseray@media.fastclick.net/
Expires : 21-04-2007 20:35:34
LastSync : Hits:2
UseCount : 0
Hits : 2
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@bluestreak[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:6
Value : Cookie:asseray@bluestreak.com/
Expires : 03-06-2017 03:44:58
LastSync : Hits:6
UseCount : 0
Hits : 6
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@bs.serving-sys[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:asseray@bs.serving-sys.com/
Expires : 01-01-2038
LastSync : Hits:1
UseCount : 0
Hits : 1
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@stat.dealtime[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:2
Value : Cookie:asseray@stat.dealtime.com/
Expires : 10-03-2009 13:52:38
LastSync : Hits:2
UseCount : 0
Hits : 2
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@adserver.aol[2].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:4
Value : Cookie:asseray@adserver.aol.fr/
Expires : 17-03-2017 21:21:32
LastSync : Hits:4
UseCount : 0
Hits : 4
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@serving-sys[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:5
Value : Cookie:asseray@serving-sys.com/
Expires : 01-01-2038
LastSync : Hits:5
UseCount : 0
Hits : 5
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@mediaplex[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:5
Value : Cookie:asseray@mediaplex.com/
Expires : 22-06-2009 02:00:00
LastSync : Hits:5
UseCount : 0
Hits : 5
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : asseray@stats1.reliablestats[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:11
Value : Cookie:asseray@stats1.reliablestats.com/
Expires : 15-07-2007 09:58:48
LastSync : Hits:11
UseCount : 0
Hits : 11
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 24
Objects found so far: 27
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 27
Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 27
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 27
17:52:36 Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:10:27.828
Objects scanned:132759
Objects identified:27
Objects ignored:0
New critical objects:27 -
salut mag,
fais ubn scan avec ceci pour verifier :
https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/11643.html
@+
-
en effet, je viens de le supprimer...c'est suffisant tu crois?
-
salut mag,
il semblerais que le theme que tu as telechargé soit infecté, il a été supprimé, enfin une partie au moins...
enleve le, tu utilise theme xp ou un truc du genre?
@+
-
port bitdefender :
BitDefender Online Scanner
Rapport d'analyse généré à: Wed, Jun 06, 2007 - 20:40:43
Voie d'analyse: C:\;D:\;E:\;F:\;G:\;H:\;I:\;
Statistiques
Temps
00:50:39
Fichiers
176388
Directoires
3593
Secteurs de boot
2
Archives
13875
Paquets programmes
6529
Résultats
Virus identifiés
2
Fichiers infectés
2
Fichiers suspects
0
Avertissements
0
Désinfectés
0
Fichiers effacés
2
nfo sur les moteurs
Définition virus
512224
Version des moteurs
AVCORE v1.0 (build 2409) (i386) (May 9 2007 18:01:21)
Analyse des plugins
14
Archive des plugins
38
Unpack des plugins
6
E-mail plugins
6
Système plugins
1
Paramètres d'analyse
première action
Désinfecté
Seconde Action
supprimé
Heuristique
Oui
Acceptez les avertissements
Oui
Extensions analysées
*;
Excludez les extensions
Analyse d'emails
Oui
analyse des Archives
Oui
Analyser paquets programmes
Oui
Analyse des fichiers
Oui
Analyse de boot
Oui
fichier analysé
Statut
C:\WINDOWS\Resources\Themes\74.exe=>wise0018
Détecté avec: Application.Adware.NewDotNet.B.Dropper
C:\WINDOWS\Resources\Themes\74.exe=>wise0018
Supprimé
C:\WINDOWS\Resources\Themes\74.exe
Echec de la mise à jour
C:\WINDOWS\Resources\Themes\74.exe=>wise0020=>(CAB Sfx r)=>VVSN.exe
Infecté par: Generic.Adw.SaveNow.56AD4696
C:\WINDOWS\Resources\Themes\74.exe=>wise0020=>(CAB Sfx r)=>VVSN.exe
Echec de la désinfection
C:\WINDOWS\Resources\Themes\74.exe=>wise0020=>(CAB Sfx r)=>VVSN.exe
Supprimé
C:\WINDOWS\Resources\Themes\74.exe=>wise0020=>(CAB Sfx r)
Echec de la mise à jour
rapport hijackthis:
kLogfile of HijackThis v1.99.1
Scan saved at 20:57:21, on 06/06/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\Asseray\Mes documents\mes programmes\azureus\Azureus.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MOZILLA.ORG\MOZILLA\MOZILLA.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Asseray\LOCALS~1\Temp\Rar$EX00.359\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [YeppStudioAgent] C:\Program Files\Samsung\SamsungMediaStudio4.1\SamsungMediaStudioAgent.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .htm: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1215A302-DDA0-4BB9-87EA-24BF321828B0}: NameServer = 212.151.137.166 212.151.136.242
O17 - HKLM\System\CS1\Services\Tcpip\..\{1215A302-DDA0-4BB9-87EA-24BF321828B0}: NameServer = 212.151.137.166 212.151.136.242
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
Voili voilou -
salut mag,
j´aurais voulue voir l´autre partie du rapport avec les chemins et savoir si ils avait été supprimés, y te les a supprimé?
remet un hijack this stp...
@+
-
BitDefender Online Scanner - Rapport virus en temps réel
Généré à: Wed, Jun 06, 2007 - 12:31:25
Info d'analyse
Fichiers scannés
179764
Infectés Fichiers
2
Voilà...encore infecté ! snif...
Virus Détectés
Application.Adware.NewDotNet.B.Dropper
1
Generic.Adw.SaveNow.56AD4696
1 -
re,
tu l´as internet explorer...
tu peux pas le faire sur firefox...
@+
-
Hello,
il exige une installation d'internet explorer...Est ce vraiment indispensable?
cf : Internet Explorer 4 ou supérieur est requis pour le fonctionnement de l'analyse en ligne. -
re,
lance plutot celui la :
https://www.bitdefender.fr/
et copie colle le résultat ici
* En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
* Dans la nouvelle fenêtre, clique sur I agree
* La fenêtre change encore, clique sur Click here to scan
* Les signatures se chargent, etc.
tuto en image
http://pageperso.aol.fr/rginformatique/mapage/defender.htm
post le rapport.
@+
-
Petit probleme : il n'y a pas de rapport comme d'habitude.
J'ai lancé le scan...il a repéré quelques infections et des anomalies sécurités. J'ai cliqué sur nettoyé et il a supprimé les fichiers.
Dois je le lancer à nouveau pour voir si tout est correct? -
salut mag594,
bon c´est ok avg avait bien marché alors,
le fix wareout aussi a fonctionné, il a viré les lignes 017 du hijack this ;-)
maintenant ca me parait ok mais on va quand meme passer un scan en ligne pour s´en assurer, c´est long mais c´est la vie...
https://www.trendmicro.com/en_us/forHome/products/housecall.html
poste le rapport...
@+
-
oups, j'avais posté le mauvais rapport :
voici le rapport AVG :
Créé à: 00:16:23 04/06/2007
+ Résultat de l'analyse:
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Nettoyé.
C:\Program Files\themexp\NNWDAB638.EXE -> Adware.NewDotNet : Nettoyé.
:mozilla.677:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.678:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.679:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.100:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.38:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.427:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.720:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.86:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.95:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.323:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.324:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.331:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.721:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.722:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.749:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.750:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.751:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.752:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.753:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.754:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.755:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.8:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.17:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.18:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@adtech[2].txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.10:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.11:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.36:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.37:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.38:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.39:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.40:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.9:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@advertising[1].txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.358:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.15:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.658:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.147:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@bluestreak[2].txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.765:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Clickhype : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@ad1.clickhype[1].txt -> TrackingCookie.Clickhype : Nettoyé.
:mozilla.548:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.549:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.550:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.830:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Coremetrics : Nettoyé.
:mozilla.642:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Cpvfeed : Nettoyé.
:mozilla.643:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Cpvfeed : Nettoyé.
:mozilla.644:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Cpvfeed : Nettoyé.
:mozilla.645:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Cpvfeed : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@stat.dealtime[2].txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.16:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.22:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.19:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@estat[2].txt -> TrackingCookie.Estat : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@as1.falkag[1].txt -> TrackingCookie.Falkag : Nettoyé.
:mozilla.339:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@fastclick[2].txt -> TrackingCookie.Fastclick : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@media.fastclick[2].txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.383:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.594:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.682:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.867:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.868:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.898:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.237:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.238:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.151:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.152:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.33:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.34:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.84:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Netflame : Nettoyé.
:mozilla.265:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.266:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.267:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.41:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.42:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.236:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Paypal : Nettoyé.
:mozilla.75:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Paypal : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.723:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Qksrv : Nettoyé.
:mozilla.724:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Qksrv : Nettoyé.
:mozilla.659:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Questionmarket : Nettoyé.
:mozilla.660:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Questionmarket : Nettoyé.
:mozilla.661:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Questionmarket : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@questionmarket[2].txt -> TrackingCookie.Questionmarket : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@real[1].txt -> TrackingCookie.Real : Nettoyé.
:mozilla.46:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Realmedia : Nettoyé.
:mozilla.161:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.164:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.165:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.166:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.170:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.171:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.172:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.173:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.174:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.175:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.176:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.177:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.178:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.179:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.180:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.181:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.182:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.183:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.184:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.185:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.186:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.187:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.188:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.466:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.467:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.468:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.469:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.470:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.471:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@serving-sys[1].txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.67:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.68:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.881:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.882:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.47:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Skype : Nettoyé.
:mozilla.70:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Skype : Nettoyé.
:mozilla.824:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Skype : Nettoyé.
:mozilla.825:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Skype : Nettoyé.
:mozilla.826:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Skype : Nettoyé.
:mozilla.827:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Skype : Nettoyé.
:mozilla.828:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Skype : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@skype[1].txt -> TrackingCookie.Skype : Nettoyé.
:mozilla.48:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.76:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.77:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.78:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.80:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.81:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.82:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.83:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.7:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Specificclick : Nettoyé.
:mozilla.809:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Specificclick : Nettoyé.
:mozilla.810:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Specificclick : Nettoyé.
:mozilla.811:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Specificclick : Nettoyé.
:mozilla.812:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Specificclick : Nettoyé.
:mozilla.571:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.573:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.574:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.575:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.576:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.577:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.578:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.579:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.580:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@statcounter[2].txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.445:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Tacoda : Nettoyé.
:mozilla.446:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Tacoda : Nettoyé.
:mozilla.447:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Tacoda : Nettoyé.
:mozilla.448:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Tacoda : Nettoyé.
:mozilla.74:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.75:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.76:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.77:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.50:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Trafficmp : Nettoyé.
:mozilla.51:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Tribalfusion : Nettoyé.
:mozilla.725:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Tribalfusion : Nettoyé.
:mozilla.843:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Vegasred : Nettoyé.
:mozilla.10:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Web-stat : Nettoyé.
:mozilla.11:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Web-stat : Nettoyé.
:mozilla.8:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Web-stat : Nettoyé.
:mozilla.141:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.144:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.145:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.146:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.939:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Asseray\Cookies\asseray@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.760:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Yadro : Nettoyé.
:mozilla.155:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.156:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.157:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.158:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.63:C:\Documents and Settings\Asseray\Application Data\Mozilla\Profiles\default\o7wh6sty.slt\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.346:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
:mozilla.347:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
:mozilla.348:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
:mozilla.349:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
:mozilla.350:C:\Documents and Settings\Asseray\Application Data\Mozilla\Firefox\Profiles\wp5tprep.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
Fin du rapport
Le rapport du FIX :
Fixwareout Last edited 5/15/2007
Post this report in the forums please
...
»»»»»Prerun check
»»»»»
»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
....
....
»»»»» Misc files.
....
»»»»» Checking for older varients.
....
Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.
Click browse, find the file then click submit.
http://www.virustotal.com/flash/index_en.html
Or https://virusscan.jotti.org/
»»»»» Other
»»»»» Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd"
"AGRSMMSG"="AGRSMMSG.exe"
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"TkBellExe"="\"C:\\Program Files\\Fichiers communs\\Real\\Update_OB\\realsched.exe\" -osboot"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""
"YeppStudioAgent"="C:\\Program Files\\Samsung\\SamsungMediaStudio4.1\\SamsungMediaStudioAgent.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\ctfmon.exe"
"Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
....
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»
et enfin le rapport de Hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 22:54:06, on 04/06/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\DOCUME~1\Asseray\LOCALS~1\Temp\Rar$EX00.016\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [YeppStudioAgent] C:\Program Files\Samsung\SamsungMediaStudio4.1\SamsungMediaStudioAgent.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .htm: C:\Program Files\Netscape\Netscape Browser\PLUGINS\npTrident.dll
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
Bon courage, pour moi c'est du chinois lol !
- 1
- 2