Form1 virus????
Dernière réponse : dans Sécurité
Probleme j ai un virus nommé form1 qui a infecté mon pc !!!! besoin d aide svp merciiii beaucoup
Autres pages sur : form1 virus
Lassé par la pub ? Créez un compte
Un bonjour ?
Quel est son emplacement.
Télécharge Hijackthis (de Merjin).
Dézippe-le dans un dossier ou sur ton Bureau.
Lance l'application (Hijackthis.exe) :
- Choisis l'option "Do a system scan and save a logfile"
- Le Bloc-Notes s'ouvre, poste son contenu :
-> Edition / Sélectionner tout
-> Edition / Copier
-> Clique-Droit / Coller dans ta réponse
AIDE : Tuto en vidéo sur Hijackthis
Quel est son emplacement.
Télécharge Hijackthis (de Merjin).
Dézippe-le dans un dossier ou sur ton Bureau.
Lance l'application (Hijackthis.exe) :
- Choisis l'option "Do a system scan and save a logfile"
- Le Bloc-Notes s'ouvre, poste son contenu :
-> Edition / Sélectionner tout
-> Edition / Copier
-> Clique-Droit / Coller dans ta réponse
AIDE : Tuto en vidéo sur Hijackthis
Bonjour angeldark
Voila :
Logfile of HijackThis v1.99.1
Scan saved at 09:47:17, on 14/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Michtio\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.neo.cx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.carrefour.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.neo.cx/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2F85D76C-0569-466F-A488-493E6BD0E955} - (no file)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [I downloaded pirated Software from P2P ] C:\WINDOWS\system32\Sims 2 Pets.exe
O4 - HKLM\..\Run: [012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678912345678] C:\Program Files\user32.exe
O4 - HKLM\..\Run: [UsefulApplication] C:\WINDOWS\useapp.exe
O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [sqexjnf] c:\windows\system32\sqexjnf.exe sqexjnf
O4 - HKLM\..\Run: [gpvbckay] c:\windows\system32\gpvbckay.exe gpvbckay
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: dem.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour.fr/
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
Voila :
Logfile of HijackThis v1.99.1
Scan saved at 09:47:17, on 14/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Michtio\Bureau\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.neo.cx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.carrefour.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.neo.cx/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2F85D76C-0569-466F-A488-493E6BD0E955} - (no file)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [I downloaded pirated Software from P2P ] C:\WINDOWS\system32\Sims 2 Pets.exe
O4 - HKLM\..\Run: [012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678912345678] C:\Program Files\user32.exe
O4 - HKLM\..\Run: [UsefulApplication] C:\WINDOWS\useapp.exe
O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [sqexjnf] c:\windows\system32\sqexjnf.exe sqexjnf
O4 - HKLM\..\Run: [gpvbckay] c:\windows\system32\gpvbckay.exe gpvbckay
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: dem.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour.fr/
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
Re,
Avant de commencer, lis la licence de Blacklight (F-Secure)
En lisant ce document, tu as pris connaissance et accepté les conditions d'utilisation de ce programme inclus dans Navilog1.zip.
Télécharge maintenant Navilog1.zip (Il Mafioso)
Enregistre-le sur ton Bureau.
Dézippe le contenu de l'archive en faisant un Clique droit sur Navilog1.zip puis en choisissant Tout Extraire.
Double clique sur Navilog1.bat.
Laisse-toi guider par l'utilitaire. Choisis l'option 1 puis valide.
[#ff0000]! N'utilise pas l'option 2, 3 et 4 sans notre accord ![/#f]
Patiente jusqu'à l'apparition de ce message :
"*** Analyse Termine le ..... ***"
Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste-nous son contenu de cette manière :
-> Edition / Sélectionner tout
-> Edition / Copier
-> Clique-Droit / Coller dans ta réponse
NOTE : Le rapport se trouve également ici : C:\fixnavi.txt
Avant de commencer, lis la licence de Blacklight (F-Secure)
En lisant ce document, tu as pris connaissance et accepté les conditions d'utilisation de ce programme inclus dans Navilog1.zip.
Télécharge maintenant Navilog1.zip (Il Mafioso)
Enregistre-le sur ton Bureau.
Dézippe le contenu de l'archive en faisant un Clique droit sur Navilog1.zip puis en choisissant Tout Extraire.
Double clique sur Navilog1.bat.
Laisse-toi guider par l'utilitaire. Choisis l'option 1 puis valide.
[#ff0000]! N'utilise pas l'option 2, 3 et 4 sans notre accord ![/#f]
Patiente jusqu'à l'apparition de ce message :
"*** Analyse Termine le ..... ***"
Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste-nous son contenu de cette manière :
-> Edition / Sélectionner tout
-> Edition / Copier
-> Clique-Droit / Coller dans ta réponse
NOTE : Le rapport se trouve également ici : C:\fixnavi.txt
Search Navipromo version 1.1.5 commencé le 15/04/2007 à 0:42:13,51
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Poster ce rapport sur le forum pour le faire analyser !!!
!!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!
Fix lancé depuis C:\Documents and Settings\Michtio\Bureau\Nouveau dossier
Mise a jour le 13.04.2007 a 20h00 by IL-MAFIOSO
Executé en mode normal
*** Recherche Programmes installes ***
*** Recherche dossiers dans C:\WINDOWS ***
*** Recherche dossiers dans C:\Program Files ***
*** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***
*** Recherche dossiers dans C:\Documents and Settings\Michtio\Application Data ***
*** Recherche avec BlackLight Engine/F-secure ***
BlackLight Engine est un produit de F-secure, pour + d'infos :
http://www.f-secure.com/blacklight/blacklight_help.html
F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
======================================
Copyright 2005-2006 F-Secure Corporation. All rights reserved.
This is a beta version. It will expire on 1st of April, 2007.
Version information: 2.2.1061.
[+] Started on 04/15/07 at 00:42:18.
[+] Initializing ...
[+] Starting scan, press Ctrl-C to abort.
[+] Scanning for hidden items ...................................................................................
[+] Scan complete.
[+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
[+] Exited on 04/15/07 at 00:50:50 (return code = 0).
*** Recherche fichiers ***
C:\WINDOWS\pack.epk trouvé !
C:\WINDOWS\system32\nvs2.inf trouvé !
*** Recherche cles registre ***
Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]
Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]
Recherche Clé Magic Control
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche fichiers connus:
2)Recherche Heuristique :
*
C:\WINDOWS\system32\dmembltsbq.dat trouvé !
**
C:\WINDOWS\system32\dmembltsbq.dat trouvé !
C:\WINDOWS\system32\gpvbckay.dat trouvé !
C:\WINDOWS\system32\sqexjnf.dat trouvé !
***
****
C:\WINDOWS\system32\dmembltsbq_navps.dat trouvé !
C:\WINDOWS\system32\sqexjnf_navps.dat trouvé !
*****
C:\WINDOWS\system32\sqexjnf_nav.dat trouvé !
C:\WINDOWS\system32\dmembltsbq_navup.dat trouvé !
******
*******
********
C:\WINDOWS\system32\dmembltsbq.exe trouvé !
C:\WINDOWS\system32\olabsvc.exe trouvé !
*** Analyse Terminé le 15/04/2007 à 0:52:56,10 ***
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Poster ce rapport sur le forum pour le faire analyser !!!
!!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!
Fix lancé depuis C:\Documents and Settings\Michtio\Bureau\Nouveau dossier
Mise a jour le 13.04.2007 a 20h00 by IL-MAFIOSO
Executé en mode normal
*** Recherche Programmes installes ***
*** Recherche dossiers dans C:\WINDOWS ***
*** Recherche dossiers dans C:\Program Files ***
*** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***
*** Recherche dossiers dans C:\Documents and Settings\Michtio\Application Data ***
*** Recherche avec BlackLight Engine/F-secure ***
BlackLight Engine est un produit de F-secure, pour + d'infos :
http://www.f-secure.com/blacklight/blacklight_help.html
F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
======================================
Copyright 2005-2006 F-Secure Corporation. All rights reserved.
This is a beta version. It will expire on 1st of April, 2007.
Version information: 2.2.1061.
[+] Started on 04/15/07 at 00:42:18.
[+] Initializing ...
[+] Starting scan, press Ctrl-C to abort.
[+] Scanning for hidden items ...................................................................................
[+] Scan complete.
[+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
[+] Exited on 04/15/07 at 00:50:50 (return code = 0).
*** Recherche fichiers ***
C:\WINDOWS\pack.epk trouvé !
C:\WINDOWS\system32\nvs2.inf trouvé !
*** Recherche cles registre ***
Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]
Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]
Recherche Clé Magic Control
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche fichiers connus:
2)Recherche Heuristique :
*
C:\WINDOWS\system32\dmembltsbq.dat trouvé !
**
C:\WINDOWS\system32\dmembltsbq.dat trouvé !
C:\WINDOWS\system32\gpvbckay.dat trouvé !
C:\WINDOWS\system32\sqexjnf.dat trouvé !
***
****
C:\WINDOWS\system32\dmembltsbq_navps.dat trouvé !
C:\WINDOWS\system32\sqexjnf_navps.dat trouvé !
*****
C:\WINDOWS\system32\sqexjnf_nav.dat trouvé !
C:\WINDOWS\system32\dmembltsbq_navup.dat trouvé !
******
*******
********
C:\WINDOWS\system32\dmembltsbq.exe trouvé !
C:\WINDOWS\system32\olabsvc.exe trouvé !
*** Analyse Terminé le 15/04/2007 à 0:52:56,10 ***
Re,
Redémarre en mode sans échec
Double clique sur Navilog1.bat.
Suis les instructions. Choisis ensuite l'option 2 puis valide.
Laisse toi guider et réponds aux questions éventuelles.
[#ff0000]Ton bureau va disparaître, c'est normal ![/#f]
Patiente jusqu'à l'apparition de ce message :
"*** Nettoyage Termine le ..... ***"
Appuie sur une touche comme demandé, le Bloc-notes va s'ouvrir.
Sauvegarde le rapport de manière à le retrouver en mode normal.
Referme le Bloc-notes. Ton bureau va maintenant réapparaître.
Redémarre normalement puis poste le rapport sauvegardé auparavant (C:\cleannavi.txt)
Ainsi qu'un nouveau rapport Hijackthis.
Ferme Internet Explorer puis Démarrer/Panneau de Configuration/Options Internet.
Choisis l'onglet Contenu puis onglet Certificats.
Si tu trouves les programmes suivant (en particulier dans Editeurs approuvés), supprime-les :
electronic-group
egroup
Montorgueil
VIP
"Sunny Day Design Ltd"
Redémarre en mode sans échec
Double clique sur Navilog1.bat.
Suis les instructions. Choisis ensuite l'option 2 puis valide.
Laisse toi guider et réponds aux questions éventuelles.
[#ff0000]Ton bureau va disparaître, c'est normal ![/#f]
Patiente jusqu'à l'apparition de ce message :
"*** Nettoyage Termine le ..... ***"
Appuie sur une touche comme demandé, le Bloc-notes va s'ouvrir.
Sauvegarde le rapport de manière à le retrouver en mode normal.
Referme le Bloc-notes. Ton bureau va maintenant réapparaître.
Redémarre normalement puis poste le rapport sauvegardé auparavant (C:\cleannavi.txt)
Ainsi qu'un nouveau rapport Hijackthis.
Ferme Internet Explorer puis Démarrer/Panneau de Configuration/Options Internet.
Choisis l'onglet Contenu puis onglet Certificats.
Si tu trouves les programmes suivant (en particulier dans Editeurs approuvés), supprime-les :
electronic-group
egroup
Montorgueil
VIP
"Sunny Day Design Ltd"
Voila le rapport Cleannavi
Clean Navipromo version 1.1.5 commencé le 16/04/2007 à 11:08:06,92
Fix lancé depuis C:\Documents and Settings\Michtio\Bureau\Nouveau dossier
Mise a jour le 13.04.2007 a 20h00 by IL-MAFIOSO
Executé en mode sans echec
Mode suppression automatique avec prise en charge résultats Blacklight
*** fsbl1.txt non trouvé ***
(Assurez-vous que Blacklight n'avait rien trouvé lors de la recherche)
*** Suppression dossiers dans C:\WINDOWS ***
*** Suppression dossiers dans C:\Program Files ***
*** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***
*** Suppression dossiers dans C:\Documents and Settings\Michtio\Application Data ***
*** Suppression fichiers ***
C:\WINDOWS\pack.epk supprimé !
C:\WINDOWS\system32\nvs2.inf supprimé !
*** Suppression fichiers temporaires ***
Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\Michtio\Local Settings\Temp effectué !
*** Sauvegarde du registre vers dossier Backupnavi***
sauvegarde du registre realise avec succes !
*** Nettoyage registre ***
Nettoyage registre Ok
*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche fichiers connus:
2)Recherche et Suppression Heuristique :
*
C:\WINDOWS\System32\dmembltsbq.dat trouvé !
Copie C:\WINDOWS\system32\dmembltsbq.dat realise avec succes !
C:\WINDOWS\system32\dmembltsbq.dat supprimé !
**
C:\WINDOWS\System32\gpvbckay.dat trouvé !
Copie C:\WINDOWS\system32\gpvbckay.dat realise avec succes !
C:\WINDOWS\system32\gpvbckay.dat supprimé !
C:\WINDOWS\System32\sqexjnf.dat trouvé !
Copie C:\WINDOWS\system32\sqexjnf.dat realise avec succes !
C:\WINDOWS\system32\sqexjnf.dat supprimé !
***
****
C:\WINDOWS\System32\dmembltsbq_navps.dat trouvé !
Copie C:\WINDOWS\system32\dmembltsbq_navps.dat realise avec succes !
C:\WINDOWS\system32\dmembltsbq_navps.dat supprimé !
C:\WINDOWS\System32\sqexjnf_navps.dat trouvé !
Copie C:\WINDOWS\system32\sqexjnf_navps.dat realise avec succes !
C:\WINDOWS\system32\sqexjnf_navps.dat supprimé !
*****
C:\WINDOWS\System32\sqexjnf_nav.dat trouvé !
Copie C:\WINDOWS\system32\sqexjnf_nav.dat realise avec succes !
C:\WINDOWS\system32\sqexjnf_nav.dat supprimé !
C:\WINDOWS\System32\dmembltsbq_navup.dat trouvé !
Copie C:\WINDOWS\system32\dmembltsbq_navup.dat realise avec succes !
C:\WINDOWS\system32\dmembltsbq_navup.dat supprimé !
******
*******
********
C:\WINDOWS\System32\dmembltsbq.exe trouvé !
Copie C:\WINDOWS\system32\dmembltsbq.exe realise avec succes !
C:\WINDOWS\system32\dmembltsbq.exe supprimé !
C:\WINDOWS\System32\olabsvc.exe trouvé !
Copie C:\WINDOWS\system32\olabsvc.exe realise avec succes !
C:\WINDOWS\system32\olabsvc.exe supprimé !
*** Nettoyage termine le 16/04/2007 à 11:09:54,34 ***
Et voila le rapport hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 11:14:21, on 16/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Michtio\Bureau\Nouveau dossier\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.neo.cx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.carrefour.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.neo.cx/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2F85D76C-0569-466F-A488-493E6BD0E955} - (no file)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [I downloaded pirated Software from P2P ] C:\WINDOWS\system32\Sims 2 Pets.exe
O4 - HKLM\..\Run: [012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678912345678] C:\Program Files\user32.exe
O4 - HKLM\..\Run: [UsefulApplication] C:\WINDOWS\useapp.exe
O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [sqexjnf] c:\windows\system32\sqexjnf.exe sqexjnf
O4 - HKLM\..\Run: [gpvbckay] c:\windows\system32\gpvbckay.exe gpvbckay
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: dem.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour.fr/
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
Clean Navipromo version 1.1.5 commencé le 16/04/2007 à 11:08:06,92
Fix lancé depuis C:\Documents and Settings\Michtio\Bureau\Nouveau dossier
Mise a jour le 13.04.2007 a 20h00 by IL-MAFIOSO
Executé en mode sans echec
Mode suppression automatique avec prise en charge résultats Blacklight
*** fsbl1.txt non trouvé ***
(Assurez-vous que Blacklight n'avait rien trouvé lors de la recherche)
*** Suppression dossiers dans C:\WINDOWS ***
*** Suppression dossiers dans C:\Program Files ***
*** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***
*** Suppression dossiers dans C:\Documents and Settings\Michtio\Application Data ***
*** Suppression fichiers ***
C:\WINDOWS\pack.epk supprimé !
C:\WINDOWS\system32\nvs2.inf supprimé !
*** Suppression fichiers temporaires ***
Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\Michtio\Local Settings\Temp effectué !
*** Sauvegarde du registre vers dossier Backupnavi***
sauvegarde du registre realise avec succes !
*** Nettoyage registre ***
Nettoyage registre Ok
*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche fichiers connus:
2)Recherche et Suppression Heuristique :
*
C:\WINDOWS\System32\dmembltsbq.dat trouvé !
Copie C:\WINDOWS\system32\dmembltsbq.dat realise avec succes !
C:\WINDOWS\system32\dmembltsbq.dat supprimé !
**
C:\WINDOWS\System32\gpvbckay.dat trouvé !
Copie C:\WINDOWS\system32\gpvbckay.dat realise avec succes !
C:\WINDOWS\system32\gpvbckay.dat supprimé !
C:\WINDOWS\System32\sqexjnf.dat trouvé !
Copie C:\WINDOWS\system32\sqexjnf.dat realise avec succes !
C:\WINDOWS\system32\sqexjnf.dat supprimé !
***
****
C:\WINDOWS\System32\dmembltsbq_navps.dat trouvé !
Copie C:\WINDOWS\system32\dmembltsbq_navps.dat realise avec succes !
C:\WINDOWS\system32\dmembltsbq_navps.dat supprimé !
C:\WINDOWS\System32\sqexjnf_navps.dat trouvé !
Copie C:\WINDOWS\system32\sqexjnf_navps.dat realise avec succes !
C:\WINDOWS\system32\sqexjnf_navps.dat supprimé !
*****
C:\WINDOWS\System32\sqexjnf_nav.dat trouvé !
Copie C:\WINDOWS\system32\sqexjnf_nav.dat realise avec succes !
C:\WINDOWS\system32\sqexjnf_nav.dat supprimé !
C:\WINDOWS\System32\dmembltsbq_navup.dat trouvé !
Copie C:\WINDOWS\system32\dmembltsbq_navup.dat realise avec succes !
C:\WINDOWS\system32\dmembltsbq_navup.dat supprimé !
******
*******
********
C:\WINDOWS\System32\dmembltsbq.exe trouvé !
Copie C:\WINDOWS\system32\dmembltsbq.exe realise avec succes !
C:\WINDOWS\system32\dmembltsbq.exe supprimé !
C:\WINDOWS\System32\olabsvc.exe trouvé !
Copie C:\WINDOWS\system32\olabsvc.exe realise avec succes !
C:\WINDOWS\system32\olabsvc.exe supprimé !
*** Nettoyage termine le 16/04/2007 à 11:09:54,34 ***
Et voila le rapport hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 11:14:21, on 16/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Michtio\Bureau\Nouveau dossier\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.neo.cx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.carrefour.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.neo.cx/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2F85D76C-0569-466F-A488-493E6BD0E955} - (no file)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [I downloaded pirated Software from P2P ] C:\WINDOWS\system32\Sims 2 Pets.exe
O4 - HKLM\..\Run: [012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678912345678] C:\Program Files\user32.exe
O4 - HKLM\..\Run: [UsefulApplication] C:\WINDOWS\useapp.exe
O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [sqexjnf] c:\windows\system32\sqexjnf.exe sqexjnf
O4 - HKLM\..\Run: [gpvbckay] c:\windows\system32\gpvbckay.exe gpvbckay
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: dem.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour.fr/
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
Re,
Télécharge Clean.zip (de Malekal),
Décompresse-le sur ton bureau (Clique-Droit/Extraire tout), tu dois obtenir un dossier Clean.
Ouvre le dossier clean, double-clique sur cherche.cmd.
Choisis l'option 1 puis patiente. Poste ensuite le contenu du rapport.
Télécharge Clean.zip (de Malekal),
Décompresse-le sur ton bureau (Clique-Droit/Extraire tout), tu dois obtenir un dossier Clean.
Ouvre le dossier clean, double-clique sur cherche.cmd.
Choisis l'option 1 puis patiente. Poste ensuite le contenu du rapport.
Salut angeldark.J'ai cliquer sur cherche.cmd et il m'ouvre et me referme automatiquement une fenetre.J' ai fait ce que tu m'as demander avec clean.cmd et voici le rapport qu'ils m ont donné.Si ce n'est pas ca que tu veux dis le moi.Merci encore pour tout...
16/04/2007 a 15:46:50,18
*** Recherche des fichiers dans C:
*** Recherche des fichiers dans C:\WINDOWS\
C:\WINDOWS\patcher.exe FOUND
*** Recherche des fichiers dans C:\WINDOWS\system32
*** Recherche des fichiers dans C:\Program Files
"C:\Program Files\Viewpoint\" FOUND
*** Fin du rapport !
16/04/2007 a 15:46:50,18
*** Recherche des fichiers dans C:
*** Recherche des fichiers dans C:\WINDOWS\
C:\WINDOWS\patcher.exe FOUND
*** Recherche des fichiers dans C:\WINDOWS\system32
*** Recherche des fichiers dans C:\Program Files
"C:\Program Files\Viewpoint\" FOUND
*** Fin du rapport !
Re,
Redémarre en mode sans échec
Ouvre le dossier clean, double-clique sur clean.cmd.
Choisis l'option 2 puis patiente.
Redémarre normalement
Poste le rapport clean : C:\rapport_clean.txt
Redémarre en mode sans échec
Ouvre le dossier clean, double-clique sur clean.cmd.
Choisis l'option 2 puis patiente.
Redémarre normalement
Poste le rapport clean : C:\rapport_clean.txt
Re a toi Angeldark,
Voila,
Script execute en mode sans echec
Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec 16/04/2007 a 16:43:23,29
Microsoft Windows XP [version 5.1.2600]
*** Suppression des fichiers dans C:
*** Suppression des fichiers dans C:\WINDOWS\
tentative de suppression de C:\WINDOWS\patcher.exe
*** Suppression des fichiers dans C:\WINDOWS\system32
*** Suppression des fichiers dans C:\Program Files
tentative de suppression de "C:\Program Files\Viewpoint\"
*** Suppression des clefs du registre effectuee..
*** Fin du rapport !
Voila,
Script execute en mode sans echec
Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec 16/04/2007 a 16:43:23,29
Microsoft Windows XP [version 5.1.2600]
*** Suppression des fichiers dans C:
*** Suppression des fichiers dans C:\WINDOWS\
tentative de suppression de C:\WINDOWS\patcher.exe
*** Suppression des fichiers dans C:\WINDOWS\system32
*** Suppression des fichiers dans C:\Program Files
tentative de suppression de "C:\Program Files\Viewpoint\"
*** Suppression des clefs du registre effectuee..
*** Fin du rapport !
Here is,
Logfile of HijackThis v1.99.1
Scan saved at 17:06:08, on 16/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\Dit.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Michtio\Bureau\Nouveau dossier\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.neo.cx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.carrefour.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.neo.cx/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2F85D76C-0569-466F-A488-493E6BD0E955} - (no file)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [I downloaded pirated Software from P2P ] C:\WINDOWS\system32\Sims 2 Pets.exe
O4 - HKLM\..\Run: [012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678912345678] C:\Program Files\user32.exe
O4 - HKLM\..\Run: [UsefulApplication] C:\WINDOWS\useapp.exe
O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [sqexjnf] c:\windows\system32\sqexjnf.exe sqexjnf
O4 - HKLM\..\Run: [gpvbckay] c:\windows\system32\gpvbckay.exe gpvbckay
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: dem.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour.fr/
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
Logfile of HijackThis v1.99.1
Scan saved at 17:06:08, on 16/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\Dit.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Michtio\Bureau\Nouveau dossier\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.neo.cx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.carrefour.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.neo.cx/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2F85D76C-0569-466F-A488-493E6BD0E955} - (no file)
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [I downloaded pirated Software from P2P ] C:\WINDOWS\system32\Sims 2 Pets.exe
O4 - HKLM\..\Run: [012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678912345678] C:\Program Files\user32.exe
O4 - HKLM\..\Run: [UsefulApplication] C:\WINDOWS\useapp.exe
O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [sqexjnf] c:\windows\system32\sqexjnf.exe sqexjnf
O4 - HKLM\..\Run: [gpvbckay] c:\windows\system32\gpvbckay.exe gpvbckay
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: dem.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour.fr/
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
Re,
- Lance Hijackthis ->Do a system scan only
->Coche les lignes ci-dessous :
O2 - BHO: (no name) - {2F85D76C-0569-466F-A488-493E6BD0E955} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O4 - HKLM\..\Run: [I downloaded pirated Software from P2P ] C:\WINDOWS\system32\Sims 2 Pets.exe
O4 - HKLM\..\Run: [012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678912345678] C:\Program Files\user32.exe
O4 - HKLM\..\Run: [UsefulApplication] C:\WINDOWS\useapp.exe
O4 - HKLM\..\Run: [sqexjnf] c:\windows\system32\sqexjnf.exe sqexjnf
O4 - HKLM\..\Run: [gpvbckay] c:\windows\system32\gpvbckay.exe gpvbckay
O4 - Global Startup: dem.exe
Clique sur Fix checked (en bas à gauche)
Télécharge OTMoveIt (d'OldTimer). Sauvegarde-le sur ton Bureau.
Sélectionne TOUS les emplacements en gras ci-dessous :
C:\WINDOWS\system32\Sims 2 Pets.exe
C:\WINDOWS\useapp.exe
C:\Program Files\user32.exe
---> Clique-droit puis Copier
Double-clique sur OTMoveIt.exe afin de le lancer.
Fais un Clique-droit sur le cadre de gauche puis choisis Coller.
Clique maintenant sur [#ff0000]MoveIt![/#f]
[#ff0000]Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.[/#f]
Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport est la date de sa création.
- Lance Hijackthis ->Do a system scan only
->Coche les lignes ci-dessous :
O2 - BHO: (no name) - {2F85D76C-0569-466F-A488-493E6BD0E955} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
O4 - HKLM\..\Run: [I downloaded pirated Software from P2P ] C:\WINDOWS\system32\Sims 2 Pets.exe
O4 - HKLM\..\Run: [012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678912345678] C:\Program Files\user32.exe
O4 - HKLM\..\Run: [UsefulApplication] C:\WINDOWS\useapp.exe
O4 - HKLM\..\Run: [sqexjnf] c:\windows\system32\sqexjnf.exe sqexjnf
O4 - HKLM\..\Run: [gpvbckay] c:\windows\system32\gpvbckay.exe gpvbckay
O4 - Global Startup: dem.exe
Clique sur Fix checked (en bas à gauche)
Télécharge OTMoveIt (d'OldTimer). Sauvegarde-le sur ton Bureau.
Sélectionne TOUS les emplacements en gras ci-dessous :
C:\WINDOWS\system32\Sims 2 Pets.exe
C:\WINDOWS\useapp.exe
C:\Program Files\user32.exe
---> Clique-droit puis Copier
Double-clique sur OTMoveIt.exe afin de le lancer.
Fais un Clique-droit sur le cadre de gauche puis choisis Coller.
Clique maintenant sur [#ff0000]MoveIt![/#f]
[#ff0000]Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.[/#f]
Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport est la date de sa création.
ah!!! premier problème !!!! J'ai tout fait et quand j'ai fais move it avec otmoveit et ils me disent qu'ils ne peuvent creer le fichier C:\_OTmoveit\Movedfiles\04162007_173136.log et ils me mettent dans la colonne de droite
C:\WINDOWS\system32\Sims 2 Pets.exe not found
C:\WINDOWS\useapp.exe not found
C:\Program Files\user32.exe not found
Created on 04/16/2007 17:34:43
C:\WINDOWS\system32\Sims 2 Pets.exe not found
C:\WINDOWS\useapp.exe not found
C:\Program Files\user32.exe not found
Created on 04/16/2007 17:34:43
Logfile of HijackThis v1.99.1
Scan saved at 00:13:17, on 17/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Documents and Settings\Michtio\Bureau\Nouveau dossier\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.neo.cx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.carrefour.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.neo.cx/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour.fr/
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
Scan saved at 00:13:17, on 17/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Documents and Settings\Michtio\Bureau\Nouveau dossier\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.neo.cx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.carrefour.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.neo.cx/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour.fr/
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
Ton pc se comporte mieux ?
Télécharge puis installe AVG Anti-Spyware (AVG AS)
Fais les mises à jour mais ne lance pas de scan pour le moment.
AIDE : Tuto sur AVG Anti-Spyware (Malekal)
Redémarre en mode sans échec
Relance AVG AS :
- Choisis l'onglet "Analyse"
- Puis l'onglet "Paramètres"
- Sous la question "Comment réagir ?", clique sur "Actions recommandées" et choisis "Quarantaine"
- Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"
[#ff0000]Si un fichier est infecté en fin d'analyse, clique sur "Appliquer toutes les actions"[/#f]
Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous"
Enregistre ce fichier texte sur ton bureau.
Redémarre normalement
Poste le rapport AVG AS ainsi qu'un rapport Hijackthis.
Télécharge puis installe AVG Anti-Spyware (AVG AS)
Fais les mises à jour mais ne lance pas de scan pour le moment.
AIDE : Tuto sur AVG Anti-Spyware (Malekal)
Redémarre en mode sans échec
Relance AVG AS :
- Choisis l'onglet "Analyse"
- Puis l'onglet "Paramètres"
- Sous la question "Comment réagir ?", clique sur "Actions recommandées" et choisis "Quarantaine"
- Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"
[#ff0000]Si un fichier est infecté en fin d'analyse, clique sur "Appliquer toutes les actions"[/#f]
Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous"
Enregistre ce fichier texte sur ton bureau.
Redémarre normalement
Poste le rapport AVG AS ainsi qu'un rapport Hijackthis.
Re,
Oui un peu mieu mais c'est pas encore ca je crois
Rapport AVG AS
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 21:58:54 17/04/2007
+ Résultat de l'analyse:
C:\System Volume Information\_restore{B9E2A72D-1A55-435B-94E6-503D13FAC150}\RP983\A0360862.exe -> Backdoor.Skinymes.a : Nettoyé.
D:\Dossier Théo\téléchargement\Spyware[1].Doctor.v4.0.0.2613-TBE.rar/run.exe -> Downloader.Zlob.awk : Nettoyé.
C:\Program Files\Pinnacle\Nouveau dossier\Hollywood FX 5.1\FX 5.1\keygen.exe -> Downloader.Zlob.bnv : Nettoyé.
C:\Program Files\Pinnacle\Nouveau dossier\Pinnacle_Studio_9.3.5_MultiLanguage + Hollywood Fx 5.1 Plus Extra Packs.zip/Hollywood FX 5.1/FX 5.1/keygen.exe -> Downloader.Zlob.bnv : Nettoyé.
C:\Documents and Settings\Michtio\Bureau\Nouveau dossier\Hijackthis\backups\backup-20070416-172944-529-dem.exe -> Hijacker.StartPage.ans : Nettoyé.
C:\System Volume Information\_restore{B9E2A72D-1A55-435B-94E6-503D13FAC150}\RP1046\A0480142.exe -> Hijacker.StartPage.ans : Nettoyé.
C:\System Volume Information\_restore{B9E2A72D-1A55-435B-94E6-503D13FAC150}\RP1003\A0398477.exe -> Logger.Small.db : Nettoyé.
:mozilla.500:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.163:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.72:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.95:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.96:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.100:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.99:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.212:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.214:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.186:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.187:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.188:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.189:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.339:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.162:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.38:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@atdmt[1].txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.101:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.39:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.84:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.374:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.323:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.324:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.325:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.326:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.327:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.328:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.79:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.80:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.81:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@doubleclick[2].txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.41:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.6:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.398:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.399:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.400:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.175:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.218:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.219:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.220:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.222:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.337:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.47:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.490:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.68:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.357:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.358:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.375:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Information : Nettoyé.
:mozilla.226:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.227:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.228:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.229:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.492:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.493:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.494:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.495:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.448:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Masterstats : Nettoyé.
:mozilla.62:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Masterstats : Nettoyé.
:mozilla.129:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.15:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.78:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.433:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Netflame : Nettoyé.
:mozilla.320:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Paypal : Nettoyé.
:mozilla.373:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Revenue : Nettoyé.
:mozilla.155:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.156:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.157:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.158:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.159:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.160:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.314:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.10:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.116:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.117:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.118:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.119:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.11:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.120:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.12:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.16:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.17:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.18:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.8:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.9:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\Orel\Cookies\orel@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.348:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.349:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.407:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Toplist : Nettoyé.
:mozilla.60:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.61:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.62:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.89:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.364:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Valueclick : Nettoyé.
:mozilla.36:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Valueclick : Nettoyé.
:mozilla.141:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.142:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.143:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.144:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.145:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.38:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\aj7axb3h.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.48:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.55:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.56:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Catherine\Cookies\catherine@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Orel\Cookies\orel@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.23:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.27:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.461:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.445:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
:mozilla.12:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.13:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.14:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.15:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.17:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.21:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.97:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.98:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
C:\WINDOWS\hosts -> Trojan.Qhost.io : Nettoyé.
C:\WINDOWS\hosts.sam -> Trojan.Qhost.io : Nettoyé.
C:\WINDOWS\system32\hosts -> Trojan.Qhost.io : Nettoyé.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\4L610BON\teller2[1].htm -> Trojan.Small : Nettoyé.
Fin du rapport
Rapport HIJACKTHIS
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 21:58:54 17/04/2007
+ Résultat de l'analyse:
C:\System Volume Information\_restore{B9E2A72D-1A55-435B-94E6-503D13FAC150}\RP983\A0360862.exe -> Backdoor.Skinymes.a : Nettoyé.
D:\Dossier Théo\téléchargement\Spyware[1].Doctor.v4.0.0.2613-TBE.rar/run.exe -> Downloader.Zlob.awk : Nettoyé.
C:\Program Files\Pinnacle\Nouveau dossier\Hollywood FX 5.1\FX 5.1\keygen.exe -> Downloader.Zlob.bnv : Nettoyé.
C:\Program Files\Pinnacle\Nouveau dossier\Pinnacle_Studio_9.3.5_MultiLanguage + Hollywood Fx 5.1 Plus Extra Packs.zip/Hollywood FX 5.1/FX 5.1/keygen.exe -> Downloader.Zlob.bnv : Nettoyé.
C:\Documents and Settings\Michtio\Bureau\Nouveau dossier\Hijackthis\backups\backup-20070416-172944-529-dem.exe -> Hijacker.StartPage.ans : Nettoyé.
C:\System Volume Information\_restore{B9E2A72D-1A55-435B-94E6-503D13FAC150}\RP1046\A0480142.exe -> Hijacker.StartPage.ans : Nettoyé.
C:\System Volume Information\_restore{B9E2A72D-1A55-435B-94E6-503D13FAC150}\RP1003\A0398477.exe -> Logger.Small.db : Nettoyé.
:mozilla.500:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.163:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.72:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.95:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.96:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.100:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.99:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.212:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.214:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.186:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.187:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.188:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.189:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.339:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.162:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.38:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@atdmt[1].txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.101:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.39:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.84:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.374:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.323:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.324:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.325:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.326:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.327:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.328:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.79:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.80:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.81:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@doubleclick[2].txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.41:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.6:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.398:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.399:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.400:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.175:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.218:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.219:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.220:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.222:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.337:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.47:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.490:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.68:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.357:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.358:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.375:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Information : Nettoyé.
:mozilla.226:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.227:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.228:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.229:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.492:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.493:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.494:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.495:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.448:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Masterstats : Nettoyé.
:mozilla.62:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Masterstats : Nettoyé.
:mozilla.129:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.15:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.78:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.433:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Netflame : Nettoyé.
:mozilla.320:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Paypal : Nettoyé.
:mozilla.373:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Revenue : Nettoyé.
:mozilla.155:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.156:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.157:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.158:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.159:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.160:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.314:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.10:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.116:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.117:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.118:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.119:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.11:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.120:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.12:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.16:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.17:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.18:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.8:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.9:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\Orel\Cookies\orel@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.348:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.349:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.407:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Toplist : Nettoyé.
:mozilla.60:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.61:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.62:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.89:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.364:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Valueclick : Nettoyé.
:mozilla.36:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Valueclick : Nettoyé.
:mozilla.141:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.142:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.143:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.144:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.145:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.38:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\aj7axb3h.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.48:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.55:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.56:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Catherine\Cookies\catherine@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Orel\Cookies\orel@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.23:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.27:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.461:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.445:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
:mozilla.12:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.13:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.14:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.15:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.17:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.21:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.97:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.98:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
C:\WINDOWS\hosts -> Trojan.Qhost.io : Nettoyé.
C:\WINDOWS\hosts.sam -> Trojan.Qhost.io : Nettoyé.
C:\WINDOWS\system32\hosts -> Trojan.Qhost.io : Nettoyé.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\4L610BON\teller2[1].htm -> Trojan.Small : Nettoyé.
Fin du rapport
Oui un peu mieu mais c'est pas encore ca je crois
Rapport AVG AS
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 21:58:54 17/04/2007
+ Résultat de l'analyse:
C:\System Volume Information\_restore{B9E2A72D-1A55-435B-94E6-503D13FAC150}\RP983\A0360862.exe -> Backdoor.Skinymes.a : Nettoyé.
D:\Dossier Théo\téléchargement\Spyware[1].Doctor.v4.0.0.2613-TBE.rar/run.exe -> Downloader.Zlob.awk : Nettoyé.
C:\Program Files\Pinnacle\Nouveau dossier\Hollywood FX 5.1\FX 5.1\keygen.exe -> Downloader.Zlob.bnv : Nettoyé.
C:\Program Files\Pinnacle\Nouveau dossier\Pinnacle_Studio_9.3.5_MultiLanguage + Hollywood Fx 5.1 Plus Extra Packs.zip/Hollywood FX 5.1/FX 5.1/keygen.exe -> Downloader.Zlob.bnv : Nettoyé.
C:\Documents and Settings\Michtio\Bureau\Nouveau dossier\Hijackthis\backups\backup-20070416-172944-529-dem.exe -> Hijacker.StartPage.ans : Nettoyé.
C:\System Volume Information\_restore{B9E2A72D-1A55-435B-94E6-503D13FAC150}\RP1046\A0480142.exe -> Hijacker.StartPage.ans : Nettoyé.
C:\System Volume Information\_restore{B9E2A72D-1A55-435B-94E6-503D13FAC150}\RP1003\A0398477.exe -> Logger.Small.db : Nettoyé.
:mozilla.500:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.163:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.72:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.95:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.96:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.100:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.99:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.212:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.214:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.186:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.187:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.188:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.189:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.339:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.162:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.38:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@atdmt[1].txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.101:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.39:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.84:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.374:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.323:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.324:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.325:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.326:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.327:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.328:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.79:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.80:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.81:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@doubleclick[2].txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.41:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.6:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.398:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.399:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.400:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.175:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.218:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.219:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.220:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.222:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.337:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.47:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.490:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.68:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.357:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.358:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.375:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Information : Nettoyé.
:mozilla.226:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.227:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.228:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.229:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.492:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.493:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.494:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.495:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.448:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Masterstats : Nettoyé.
:mozilla.62:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Masterstats : Nettoyé.
:mozilla.129:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.15:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.78:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.433:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Netflame : Nettoyé.
:mozilla.320:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Paypal : Nettoyé.
:mozilla.373:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Revenue : Nettoyé.
:mozilla.155:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.156:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.157:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.158:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.159:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.160:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.314:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.10:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.116:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.117:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.118:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.119:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.11:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.120:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.12:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.16:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.17:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.18:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.8:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.9:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\Orel\Cookies\orel@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.348:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.349:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.407:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Toplist : Nettoyé.
:mozilla.60:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.61:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.62:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.89:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.364:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Valueclick : Nettoyé.
:mozilla.36:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Valueclick : Nettoyé.
:mozilla.141:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.142:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.143:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.144:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.145:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.38:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\aj7axb3h.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.48:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.55:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.56:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Catherine\Cookies\catherine@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Orel\Cookies\orel@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.23:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.27:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.461:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.445:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
:mozilla.12:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.13:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.14:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.15:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.17:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.21:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.97:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.98:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
C:\WINDOWS\hosts -> Trojan.Qhost.io : Nettoyé.
C:\WINDOWS\hosts.sam -> Trojan.Qhost.io : Nettoyé.
C:\WINDOWS\system32\hosts -> Trojan.Qhost.io : Nettoyé.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\4L610BON\teller2[1].htm -> Trojan.Small : Nettoyé.
Fin du rapport
Rapport HIJACKTHIS
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 21:58:54 17/04/2007
+ Résultat de l'analyse:
C:\System Volume Information\_restore{B9E2A72D-1A55-435B-94E6-503D13FAC150}\RP983\A0360862.exe -> Backdoor.Skinymes.a : Nettoyé.
D:\Dossier Théo\téléchargement\Spyware[1].Doctor.v4.0.0.2613-TBE.rar/run.exe -> Downloader.Zlob.awk : Nettoyé.
C:\Program Files\Pinnacle\Nouveau dossier\Hollywood FX 5.1\FX 5.1\keygen.exe -> Downloader.Zlob.bnv : Nettoyé.
C:\Program Files\Pinnacle\Nouveau dossier\Pinnacle_Studio_9.3.5_MultiLanguage + Hollywood Fx 5.1 Plus Extra Packs.zip/Hollywood FX 5.1/FX 5.1/keygen.exe -> Downloader.Zlob.bnv : Nettoyé.
C:\Documents and Settings\Michtio\Bureau\Nouveau dossier\Hijackthis\backups\backup-20070416-172944-529-dem.exe -> Hijacker.StartPage.ans : Nettoyé.
C:\System Volume Information\_restore{B9E2A72D-1A55-435B-94E6-503D13FAC150}\RP1046\A0480142.exe -> Hijacker.StartPage.ans : Nettoyé.
C:\System Volume Information\_restore{B9E2A72D-1A55-435B-94E6-503D13FAC150}\RP1003\A0398477.exe -> Logger.Small.db : Nettoyé.
:mozilla.500:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.163:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.72:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.95:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.96:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.100:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.99:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.212:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.214:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.186:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.187:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.188:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.189:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.339:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.162:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.38:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@atdmt[1].txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.101:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.39:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.84:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.374:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.323:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.324:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.325:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.326:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.327:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.328:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.79:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.80:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.81:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@doubleclick[2].txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.41:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.6:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.398:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.399:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.400:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.175:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.218:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.219:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.220:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.222:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.337:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.47:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.490:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.68:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.357:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.358:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.375:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Information : Nettoyé.
:mozilla.226:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.227:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.228:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.229:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.492:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.493:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.494:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.495:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Live : Nettoyé.
:mozilla.448:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Masterstats : Nettoyé.
:mozilla.62:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Masterstats : Nettoyé.
:mozilla.129:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.15:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.78:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.433:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Netflame : Nettoyé.
:mozilla.320:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Paypal : Nettoyé.
:mozilla.373:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Revenue : Nettoyé.
:mozilla.155:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.156:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.157:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.158:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.159:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.160:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.314:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.10:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.116:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.117:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.118:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.119:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.11:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.120:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.12:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.16:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.17:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.18:C:\Documents and Settings\Michtio\Application Data\Mozilla\Firefox\Profiles\deaaaxck.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.8:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.9:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\Orel\Cookies\orel@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.348:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.349:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.407:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Toplist : Nettoyé.
:mozilla.60:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.61:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.62:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.89:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.364:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Valueclick : Nettoyé.
:mozilla.36:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Valueclick : Nettoyé.
:mozilla.141:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.142:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.143:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.144:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.145:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.38:C:\Documents and Settings\Catherine\Application Data\Mozilla\Firefox\Profiles\aj7axb3h.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.48:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.55:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.56:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Assa!\Cookies\assa!@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Catherine\Cookies\catherine@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Orel\Cookies\orel@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.23:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.27:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.461:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.445:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
:mozilla.12:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.13:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.14:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.15:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.17:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.21:C:\Documents and Settings\Assa!\Application Data\Mozilla\Firefox\Profiles\m67oisyz.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.97:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.98:C:\Documents and Settings\Orel\Application Data\Mozilla\Firefox\Profiles\n3i5hns1.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
C:\WINDOWS\hosts -> Trojan.Qhost.io : Nettoyé.
C:\WINDOWS\hosts.sam -> Trojan.Qhost.io : Nettoyé.
C:\WINDOWS\system32\hosts -> Trojan.Qhost.io : Nettoyé.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\4L610BON\teller2[1].htm -> Trojan.Small : Nettoyé.
Fin du rapport
Oupssssssssssss Désolé
le voila
Logfile of HijackThis v1.99.1
Scan saved at 22:03:15, on 17/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\wudfhost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Michtio\Bureau\Nouveau dossier\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.neo.cx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.carrefour.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.neo.cx/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour.fr/
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
le voila
Logfile of HijackThis v1.99.1
Scan saved at 22:03:15, on 17/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\wudfhost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Michtio\Bureau\Nouveau dossier\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.neo.cx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.carrefour.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.neo.cx/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Autoconfigurateur WiFi Neuf] C:\Program Files\Neuf\Kit\WiFi\9wifi.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour.fr/
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
Lassé par la pub ? Créez un compte