Pbr virus merci de votre aide
Dernière réponse : dans Sécurité
Salut à tous,
je pense avoir un petit problème (surement dû à un virus). J'ai une erreur, après ouverture de session, de nvsvcd.exe qui est obligé de se fermer. De plus ma carte son devient innaccessible.
Ci-dessous mon log Hitjackthis:
Logfile of HijackThis v1.99.1
Scan saved at 11:18:46, on 28/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMOne\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\MySQL\bin\mysqld-nt.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Fichiers communs\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\taskswitch.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Western Digital Technologies\WD Win98 SE USB Disk Driver, v1.00.09\WD_SRT.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Skype\toolbars\Skype for Outlook\Skype4OL.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\gguillier\Mes documents\Logiciels\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - C:\PROGRA~1\COPERN~2\COPERN~1.DLL
R3 - URLSearchHook: (no name) - {83B79436-C1A7-427B-B40D-689E9CC71FAE} - C:\PROGRA~1\COPERN~1\COPERN~3.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: Acronis Popup Blocker - {E24AD748-155E-4254-B674-4EDF86E7E1DF} - (no file)
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Copernic Desktop Search - {C5F7A735-70F1-477F-8C36-6FF3C736017B} - C:\Program Files\Copernic Desktop Search\CopernicDesktopSearchIntegration977.dll
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\PROGRA~1\COPERN~2\COPERN~1.DLL
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [.nvsvcb] C:\WINDOWS\system32\smssb.exe /u
O4 - HKLM\..\Run: [WD_SRT] "C:\Program Files\Western Digital Technologies\WD Win98 SE USB Disk Driver, v1.00.09\WD_SRT.EXE"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\RunOnce: [InstallShieldSetup] C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\8\INTEL3~1\IDriver.exe /reboot{BD57EA4D-026E-4F08-9B93-080E282B81FE} /z
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Chercher avec Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.rdl/INTEGRATION_MENU_SEARCHEXT
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\COMOne\Logiciel Bluetooth\btsendto_ie_ctx.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?a61b22407d764ca69cb645a06fd9c16
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?a61b22407d764ca69cb645a06fd9c16
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~2\COPERN~1.EXE
O9 - Extra 'Tools' menuitem: Démarrer Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~2\COPERN~1.EXE
O9 - Extra button: Acronis Pop-up Blocker - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Acronis Pop-up Blocker - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~2\COPERN~1.EXE
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\COMOne\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\COMOne\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267....
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavweb...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Cont...
O16 - DPF: {6DB731A3-B074-4118-8B1C-32511C65D836} (FotovistaPhotoUploader.ctrFpu) - http://www.mypixmania.com/fr/fr/tools/activex/fpu.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdown...
O16 - DPF: {D96D2F74-0B74-47D2-964F-B67E9F69F1CD} (CongnamulMap4Asp Control) - http://asp.congnamul.com/AspActiveX/CongnamulMap4Asp_V1...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = CARLIPA.local
O17 - HKLM\Software\..\Telephony: DomainName = CARLIPA.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = CARLIPA.local
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Google\Google Desktop Search\Plugins\gdSkype\skype4com.dll (file missing)
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: MCPClient - C:\Program Files\Fichiers communs\Stardock\mcpstub.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\COMOne\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MySQL - Unknown owner - C:\MySQL\bin\mysqld-nt".exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Cisco Systems, Inc. STC Agent (STCAgent) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: Windows Log - Unknown owner - C:\WINDOWS\system32\nvsvcd.exe
Merci de me dire ce que vous en pensez.
@+
je pense avoir un petit problème (surement dû à un virus). J'ai une erreur, après ouverture de session, de nvsvcd.exe qui est obligé de se fermer. De plus ma carte son devient innaccessible.
Ci-dessous mon log Hitjackthis:
Logfile of HijackThis v1.99.1
Scan saved at 11:18:46, on 28/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMOne\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\MySQL\bin\mysqld-nt.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Fichiers communs\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\taskswitch.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Western Digital Technologies\WD Win98 SE USB Disk Driver, v1.00.09\WD_SRT.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Skype\toolbars\Skype for Outlook\Skype4OL.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\gguillier\Mes documents\Logiciels\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - C:\PROGRA~1\COPERN~2\COPERN~1.DLL
R3 - URLSearchHook: (no name) - {83B79436-C1A7-427B-B40D-689E9CC71FAE} - C:\PROGRA~1\COPERN~1\COPERN~3.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: Acronis Popup Blocker - {E24AD748-155E-4254-B674-4EDF86E7E1DF} - (no file)
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Copernic Desktop Search - {C5F7A735-70F1-477F-8C36-6FF3C736017B} - C:\Program Files\Copernic Desktop Search\CopernicDesktopSearchIntegration977.dll
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\PROGRA~1\COPERN~2\COPERN~1.DLL
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [.nvsvcb] C:\WINDOWS\system32\smssb.exe /u
O4 - HKLM\..\Run: [WD_SRT] "C:\Program Files\Western Digital Technologies\WD Win98 SE USB Disk Driver, v1.00.09\WD_SRT.EXE"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\RunOnce: [InstallShieldSetup] C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\8\INTEL3~1\IDriver.exe /reboot{BD57EA4D-026E-4F08-9B93-080E282B81FE} /z
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Chercher avec Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.rdl/INTEGRATION_MENU_SEARCHEXT
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\COMOne\Logiciel Bluetooth\btsendto_ie_ctx.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?a61b22407d764ca69cb645a06fd9c16
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?a61b22407d764ca69cb645a06fd9c16
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~2\COPERN~1.EXE
O9 - Extra 'Tools' menuitem: Démarrer Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~2\COPERN~1.EXE
O9 - Extra button: Acronis Pop-up Blocker - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Acronis Pop-up Blocker - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~2\COPERN~1.EXE
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\COMOne\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\COMOne\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267....
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavweb...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Cont...
O16 - DPF: {6DB731A3-B074-4118-8B1C-32511C65D836} (FotovistaPhotoUploader.ctrFpu) - http://www.mypixmania.com/fr/fr/tools/activex/fpu.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdown...
O16 - DPF: {D96D2F74-0B74-47D2-964F-B67E9F69F1CD} (CongnamulMap4Asp Control) - http://asp.congnamul.com/AspActiveX/CongnamulMap4Asp_V1...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = CARLIPA.local
O17 - HKLM\Software\..\Telephony: DomainName = CARLIPA.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = CARLIPA.local
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Google\Google Desktop Search\Plugins\gdSkype\skype4com.dll (file missing)
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: MCPClient - C:\Program Files\Fichiers communs\Stardock\mcpstub.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\COMOne\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MySQL - Unknown owner - C:\MySQL\bin\mysqld-nt".exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Cisco Systems, Inc. STC Agent (STCAgent) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: Windows Log - Unknown owner - C:\WINDOWS\system32\nvsvcd.exe
Merci de me dire ce que vous en pensez.
@+
Autres pages sur : pbr virus merci aide
Lassé par la pub ? Créez un compte
Ok je viens de voir deux trojan fais ceci:
2/Ewido
Telecharge ewido sur ce site:
Ewido-Anti-Malware
Fais les mise a jour puis redemarre en mode sans echec fais un scan , appuie sur Apply all actions pour supprimer les menaces et post le rapport .
2/ Poster le log Hijackthis:
2/Ewido
Telecharge ewido sur ce site:
Ewido-Anti-Malware
Fais les mise a jour puis redemarre en mode sans echec fais un scan , appuie sur Apply all actions pour supprimer les menaces et post le rapport .
2/ Poster le log Hijackthis:
Merci de ton aide. J'ai fait ce que tu m'as dit et voici le rapport Ewido :
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 17:59:52 28/08/2006
+ Scan result:
C:\Program Files\Fichiers communs\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined).
C:\WINDOWS\system32\netf.dll -> Backdoor.IRCBot.nw : Cleaned with backup (quarantined).
C:\WINDOWS\system32\nvsvcd.exe -> Backdoor.IRCBot.nw : Cleaned with backup (quarantined).
:mozilla.388:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.389:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.390:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.391:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.12:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.13:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.14:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.15:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.16:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.220:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.23:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.24:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.25:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.26:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.27:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.28:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.303:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.318:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.522:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\gguillier\Cookies\gguillier@hertz.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\gguillier\Cookies\gguillier@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\gguillier\Cookies\gguillier@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.118:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.119:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.120:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.245:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.410:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.471:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.500:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.523:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.530:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.547:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.551:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.563:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.574:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.609:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.628:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.64:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.65:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.53:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.55:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.56:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.57:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.58:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.206:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.127:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.538:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.539:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.419:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.227:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.228:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.620:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.621:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.622:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.143:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.302:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.30:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.71:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
:mozilla.368:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.369:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.137:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.141:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.188:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.189:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.190:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.191:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.192:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.193:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.194:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.195:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.519:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.520:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.411:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned.
:mozilla.42:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.43:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\gguillier\Cookies\gguillier@paypopup[2].txt -> TrackingCookie.Paypopup : Cleaned.
:mozilla.415:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.416:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.417:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.418:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.204:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.205:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.413:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.507:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.508:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.254:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.255:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.256:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.257:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.258:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.78:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.79:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.80:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.88:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.89:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.90:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.261:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.262:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.443:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.445:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.440:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.44:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.48:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.49:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.50:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.367:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.447:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.448:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.449:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.450:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.451:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.452:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.132:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.133:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.374:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.433:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.499:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.518:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.114:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.115:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.116:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\gguillier\Cookies\gguillier@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.250:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.251:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
::Report end
Et voici le nveau Hitjack This :
Logfile of HijackThis v1.99.1
Scan saved at 18:19:20, on 28/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMOne\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\MySQL\bin\mysqld-nt.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Fichiers communs\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\taskswitch.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Western Digital Technologies\WD Win98 SE USB Disk Driver, v1.00.09\WD_SRT.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Skype\toolbars\Skype for Outlook\Skype4OL.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\gguillier\Mes documents\Logiciels\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - C:\PROGRA~1\COPERN~2\COPERN~1.DLL
R3 - URLSearchHook: (no name) - {83B79436-C1A7-427B-B40D-689E9CC71FAE} - C:\PROGRA~1\COPERN~1\COPERN~3.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: Acronis Popup Blocker - {E24AD748-155E-4254-B674-4EDF86E7E1DF} - (no file)
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Copernic Desktop Search - {C5F7A735-70F1-477F-8C36-6FF3C736017B} - C:\Program Files\Copernic Desktop Search\CopernicDesktopSearchIntegration977.dll
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\PROGRA~1\COPERN~2\COPERN~1.DLL
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [.nvsvcb] C:\WINDOWS\system32\smssb.exe /u
O4 - HKLM\..\Run: [WD_SRT] "C:\Program Files\Western Digital Technologies\WD Win98 SE USB Disk Driver, v1.00.09\WD_SRT.EXE"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Chercher avec Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.rdl/INTEGRATION_MENU_SEARCHEXT
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\COMOne\Logiciel Bluetooth\btsendto_ie_ctx.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?a61b22407d764ca69cb645a06fd9c16
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?a61b22407d764ca69cb645a06fd9c16
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~2\COPERN~1.EXE
O9 - Extra 'Tools' menuitem: Démarrer Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~2\COPERN~1.EXE
O9 - Extra button: Acronis Pop-up Blocker - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Acronis Pop-up Blocker - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~2\COPERN~1.EXE
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\COMOne\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\COMOne\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267....
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavweb...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Cont...
O16 - DPF: {6DB731A3-B074-4118-8B1C-32511C65D836} (FotovistaPhotoUploader.ctrFpu) - http://www.mypixmania.com/fr/fr/tools/activex/fpu.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdown...
O16 - DPF: {D96D2F74-0B74-47D2-964F-B67E9F69F1CD} (CongnamulMap4Asp Control) - http://asp.congnamul.com/AspActiveX/CongnamulMap4Asp_V1...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = CARLIPA.local
O17 - HKLM\Software\..\Telephony: DomainName = CARLIPA.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = CARLIPA.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = CARLIPA.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = CARLIPA.local
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Google\Google Desktop Search\Plugins\gdSkype\skype4com.dll (file missing)
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: MCPClient - C:\Program Files\Fichiers communs\Stardock\mcpstub.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\COMOne\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MySQL - Unknown owner - C:\MySQL\bin\mysqld-nt".exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Cisco Systems, Inc. STC Agent (STCAgent) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: Windows Log - Unknown owner - C:\WINDOWS\system32\nvsvcd.exe (file missing)
Merci encore
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 17:59:52 28/08/2006
+ Scan result:
C:\Program Files\Fichiers communs\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined).
C:\WINDOWS\system32\netf.dll -> Backdoor.IRCBot.nw : Cleaned with backup (quarantined).
C:\WINDOWS\system32\nvsvcd.exe -> Backdoor.IRCBot.nw : Cleaned with backup (quarantined).
:mozilla.388:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.389:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.390:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.391:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.12:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.13:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.14:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.15:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.16:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.220:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.23:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.24:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.25:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.26:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.27:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.28:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.303:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.318:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.522:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\gguillier\Cookies\gguillier@hertz.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\gguillier\Cookies\gguillier@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\gguillier\Cookies\gguillier@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.118:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.119:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.120:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.245:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.410:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.471:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.500:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.523:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.530:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.547:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.551:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.563:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.574:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.609:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.628:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.64:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.65:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.53:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.55:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.56:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.57:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.58:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.206:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.127:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.538:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.539:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.419:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.227:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.228:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.620:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.621:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.622:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.143:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.302:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.30:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.71:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
:mozilla.368:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.369:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.137:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.141:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.188:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.189:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.190:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.191:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.192:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.193:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.194:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.195:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.519:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.520:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.411:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned.
:mozilla.42:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.43:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\gguillier\Cookies\gguillier@paypopup[2].txt -> TrackingCookie.Paypopup : Cleaned.
:mozilla.415:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.416:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.417:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.418:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.204:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.205:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.413:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.507:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.508:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.254:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.255:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.256:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.257:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.258:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.78:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.79:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.80:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.88:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.89:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.90:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.261:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.262:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.443:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.445:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.440:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.44:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.48:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.49:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.50:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.367:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.447:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.448:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.449:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.450:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.451:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.452:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.132:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.133:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.374:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.433:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.499:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.518:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.114:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.115:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.116:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\gguillier\Cookies\gguillier@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.250:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.251:C:\Documents and Settings\gguillier\Application Data\Mozilla\Firefox\Profiles\rnetx3f0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
::Report end
Et voici le nveau Hitjack This :
Logfile of HijackThis v1.99.1
Scan saved at 18:19:20, on 28/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMOne\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\MySQL\bin\mysqld-nt.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Fichiers communs\Stardock\SDMCP.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\taskswitch.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Western Digital Technologies\WD Win98 SE USB Disk Driver, v1.00.09\WD_SRT.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Skype\toolbars\Skype for Outlook\Skype4OL.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\gguillier\Mes documents\Logiciels\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {BE89472C-B803-4D1D-9A9A-0A63660E0FE3} - C:\PROGRA~1\COPERN~2\COPERN~1.DLL
R3 - URLSearchHook: (no name) - {83B79436-C1A7-427B-B40D-689E9CC71FAE} - C:\PROGRA~1\COPERN~1\COPERN~3.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Barre d'outils MSN Search Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: Acronis Popup Blocker - {E24AD748-155E-4254-B674-4EDF86E7E1DF} - (no file)
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Copernic Desktop Search - {C5F7A735-70F1-477F-8C36-6FF3C736017B} - C:\Program Files\Copernic Desktop Search\CopernicDesktopSearchIntegration977.dll
O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - C:\PROGRA~1\COPERN~2\COPERN~1.DLL
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [.nvsvcb] C:\WINDOWS\system32\smssb.exe /u
O4 - HKLM\..\Run: [WD_SRT] "C:\Program Files\Western Digital Technologies\WD Win98 SE USB Disk Driver, v1.00.09\WD_SRT.EXE"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll/search.htm
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Chercher avec Copernic Agent - res://C:\Program Files\Copernic Agent\CopernicAgentExt.rdl/INTEGRATION_MENU_SEARCHEXT
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\COMOne\Logiciel Bluetooth\btsendto_ie_ctx.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/229?a61b22407d764ca69cb645a06fd9c16
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1105\fr-fr\msntabres.dll/230?a61b22407d764ca69cb645a06fd9c16
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~2\COPERN~1.EXE
O9 - Extra 'Tools' menuitem: Démarrer Copernic Agent - {193B17B0-7C9F-4D5B-AEAB-8D3605EFC084} - C:\PROGRA~1\COPERN~2\COPERN~1.EXE
O9 - Extra button: Acronis Pop-up Blocker - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Acronis Pop-up Blocker - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Copernic Agent - {688DC797-DC11-46A7-9F1B-445F4F58CE6E} - C:\PROGRA~1\COPERN~2\COPERN~1.EXE
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\COMOne\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\COMOne\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267....
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavweb...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Cont...
O16 - DPF: {6DB731A3-B074-4118-8B1C-32511C65D836} (FotovistaPhotoUploader.ctrFpu) - http://www.mypixmania.com/fr/fr/tools/activex/fpu.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClie...
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdown...
O16 - DPF: {D96D2F74-0B74-47D2-964F-B67E9F69F1CD} (CongnamulMap4Asp Control) - http://asp.congnamul.com/AspActiveX/CongnamulMap4Asp_V1...
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = CARLIPA.local
O17 - HKLM\Software\..\Telephony: DomainName = CARLIPA.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = CARLIPA.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = CARLIPA.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = CARLIPA.local
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Google\Google Desktop Search\Plugins\gdSkype\skype4com.dll (file missing)
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: MCPClient - C:\Program Files\Fichiers communs\Stardock\mcpstub.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\COMOne\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MySQL - Unknown owner - C:\MySQL\bin\mysqld-nt".exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Cisco Systems, Inc. STC Agent (STCAgent) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\SSL VPN Client\agent.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: Windows Log - Unknown owner - C:\WINDOWS\system32\nvsvcd.exe (file missing)
Merci encore
Bonjour,
La procédure est longue et en partie en mode sans échec,
imprime ou mets dans un fichier texte les instructions.
Les manipulations sont à faire sans interruption et dans l'ordre.
Si tu ne comprends pas quelque chose, demande des explications avant de commencer.
Télécharge:
Ccleaner
Installe le dans un répertoire dédié.
Lors de l'installation décoche: "Ajouter la Barre d'Outils Yahoo! Ccleaner"
Aide sur Ccleaner de Rub_Mic
Redémarre en mode sans échec
Ferme TOUS les fenêtres ouvertes (sauf Hijackthis)
et les logiciels de protection en temps réel (antivirus...)
- Lance Hijackthis ->Do a system scan only
->Coche les lignes ci-dessous :
O4 - HKLM\..\Run: [.nvsvcb] C:\WINDOWS\system32\smssb.exe /u
O23 - Service: Windows Log - Unknown owner - C:\WINDOWS\system32\nvsvcd.exe (file missing)
Clique sur Fix checked (en bas à gauche)
----------
-> Démarrer
-> Exécuter...
Tape Services.msc puis valide
Double clique sur " Windows Log "
Type de démarrage : " Désactiver "
Clique en bas sur " Arrêter "
Valide les changements.
-----
Ouvre Hijackthis puis:
-> Open the Misc Tools Section
-> Delete an NT Service
Tape " Windows Log " puis valide.
----------
- Assure toi d'avoir accès aux dossiers/fichiers cachés
-> Démarrer
-> Panneau de configuration
-> Options des Dossiers, onglet Affichage :
. Clique sur Afficher les dossiers cachés
. Décoche Masquer les extensions des fichiers dont le type est connu
. Décoche Masquer les fichiers protégés du système d'exploitation
- Suppime ces fichiers et/ou dossiers s'ils existent encore :
C:\WINDOWS\system32\smssb.exe
C:\WINDOWS\system32\nvsvcd.exe
- Lance un nettoyage Ccleaner :
Clique sur le bouton "Analyse" puis "Lancer le Néttoyage"
Redémarre normalement.
- Poste un nouveau rapport Hijackthis.
- Fais un scan en ligne Kaspersky :
. Scan la zone critique
. Sauvegarde puis colle le rapport en fin d'analyse
Aide pour le scan en ligne.
NOTES :
- Si ce message apparaît :
"La licence de Kaspersky On-line Scanner est périmée"
Vas dans Ajout/Suppression de programmes pour désinstaller l'Online Scanner
Retente ensuite le scan.
- Si tu n'arrive toujours pas à utiliser le scan en ligne, fait un scan en ligne Panda
. /!\ Lorsqu'il te faudra entrée ton adresse e-mail, clique sur I don't accept (en bas)
. Poste le rapport en fin d'analyse
. Si tu as Avast! désactive-le.
La procédure est longue et en partie en mode sans échec,
imprime ou mets dans un fichier texte les instructions.
Les manipulations sont à faire sans interruption et dans l'ordre.
Si tu ne comprends pas quelque chose, demande des explications avant de commencer.
Télécharge:
Ccleaner
Installe le dans un répertoire dédié.
Lors de l'installation décoche: "Ajouter la Barre d'Outils Yahoo! Ccleaner"
Aide sur Ccleaner de Rub_Mic
Redémarre en mode sans échec
Ferme TOUS les fenêtres ouvertes (sauf Hijackthis)
et les logiciels de protection en temps réel (antivirus...)
- Lance Hijackthis ->Do a system scan only
->Coche les lignes ci-dessous :
O4 - HKLM\..\Run: [.nvsvcb] C:\WINDOWS\system32\smssb.exe /u
O23 - Service: Windows Log - Unknown owner - C:\WINDOWS\system32\nvsvcd.exe (file missing)
Clique sur Fix checked (en bas à gauche)
----------
-> Démarrer
-> Exécuter...
Tape Services.msc puis valide
Double clique sur " Windows Log "
Type de démarrage : " Désactiver "
Clique en bas sur " Arrêter "
Valide les changements.
-----
Ouvre Hijackthis puis:
-> Open the Misc Tools Section
-> Delete an NT Service
Tape " Windows Log " puis valide.
----------
- Assure toi d'avoir accès aux dossiers/fichiers cachés
-> Démarrer
-> Panneau de configuration
-> Options des Dossiers, onglet Affichage :
. Clique sur Afficher les dossiers cachés
. Décoche Masquer les extensions des fichiers dont le type est connu
. Décoche Masquer les fichiers protégés du système d'exploitation
- Suppime ces fichiers et/ou dossiers s'ils existent encore :
C:\WINDOWS\system32\smssb.exe
C:\WINDOWS\system32\nvsvcd.exe
- Lance un nettoyage Ccleaner :
Clique sur le bouton "Analyse" puis "Lancer le Néttoyage"
Redémarre normalement.
- Poste un nouveau rapport Hijackthis.
- Fais un scan en ligne Kaspersky :
. Scan la zone critique
. Sauvegarde puis colle le rapport en fin d'analyse
Aide pour le scan en ligne.
NOTES :
- Si ce message apparaît :
"La licence de Kaspersky On-line Scanner est périmée"
Vas dans Ajout/Suppression de programmes pour désinstaller l'Online Scanner
Retente ensuite le scan.
- Si tu n'arrive toujours pas à utiliser le scan en ligne, fait un scan en ligne Panda
. /!\ Lorsqu'il te faudra entrée ton adresse e-mail, clique sur I don't accept (en bas)
. Poste le rapport en fin d'analyse
. Si tu as Avast! désactive-le.
Lassé par la pub ? Créez un compte
- Contenus similaires :
Tags :
- ForumPop ups et virus aide pour debutant
- ForumVirus aide trojan.agent trojan.downloader
- ForumVirus aide
- ForumVirus aide comment les elimines
- ForumVirus worm autorun.cxl aide
- ForumAide virus sur mn ordinateur
- ForumAide virus, ordinateur qui rame
- ForumAide pour le virus w32 jeefo
- ForumAide virus
- ForumAide virus dans system32 services.exe
- Voir plus