Tom's Guide > Forum > Sécurité - Virus > fenetres web intempestives
Mot :    Pseudo :           
 

Bonjour a tous

J'ai des fenetres web intempestives qui s'ouvrent regulierement quand mon pc est sur le net

Voila mon fichier scan

Logfile of HijackThis v1.99.1
Scan saved at 13:51:04, on 18/04/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\vmmon32.exe
C:\WINDOWS\system32\internat.exe
C:\Program Files\Marvell\Mrv8000x.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
O2 - BHO: (no name) - {DBCF40FC-2B8D-4EB2-9230-0C47184519EA} - C:\WINDOWS\java\CLASSES\idsktuil.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Printer] C:\WINDOWS\system32\vmmon32.exe
O4 - HKLM\..\RunServices: [Printer] C:\WINDOWS\system32\vmmon32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Printer] C:\WINDOWS\system32\vmmon32.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\WINDOWS\java\CLASSES\idsktuil.dll,CreateProtectProc
O4 - Startup: Marvell Libertas Client Configuration Manager.lnk = C:\Program Files\Marvell\Mrv8000x.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.ya [...] st0401.cab
O20 - Winlogon Notify: idsktuil - C:\WINDOWS\java\CLASSES\idsktuil.dll
O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\mvpsl9771.dll (file missing)
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\NEDEAPI.DLL (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Debug Config System - Unknown owner - C:\WINDOWS\system32\lrsys.exe (file missing)
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe


merci pour votre aide

Robin

Liens sponsorisés
Inscrivez-vous ou connectez-vous pour masquer ceci.

Bonjour,

Il y a une infection Vundo.

Télécharge VundoFix.exe (par Atribune) sur ton Bureau.

  • Double-clique VundoFix.exe afin de le lancer
  • Clique sur le bouton Scan for Vundo
  • Lorsque le scan est complété, clique sur le bouton Remove Vundo
  • Une invite te demandera si tu veux supprimer les fichiers, clique YES
  • Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
  • Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK
  • Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse


Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".


Message édité par Angeldark le 18-04-2007 à 14:26:51
------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Merci pour ton aide Angeldark

Voila le rapport Vundo

VundoFix V6.3.19

Checking Java version...

Sun Java not detected
Scan started at 15:08:43 18/04/2007

Listing files found while scanning....

C:\Documents and settings\Standard\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
C:\Documents and settings\Standard\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
C:\WINDOWS\java\CLASSES\idsktuil.dll
C:\WINDOWS\java\CLASSES\liutksdi.bak1
C:\WINDOWS\java\CLASSES\liutksdi.bak2
C:\WINDOWS\java\CLASSES\liutksdi.ini
C:\WINDOWS\SYSTEM32\cbhywkcd.dll
C:\WINDOWS\SYSTEM32\efcdcde.dll
C:\WINDOWS\SYSTEM32\konphege.dll
C:\WINDOWS\SYSTEM32\lfhbcgrw.dll
C:\WINDOWS\system32\NEDEAPI.DLL
C:\WINDOWS\SYSTEM32\pmnnmli.dll
C:\WINDOWS\SYSTEM32\wpiklmcs.exe
C:\WINDOWS\SYSTEM32\yadymsks.dll

Beginning removal...

Attempting to delete C:\Documents and settings\Standard\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
C:\Documents and settings\Standard\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt Has been deleted!

Attempting to delete C:\Documents and settings\Standard\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
C:\Documents and settings\Standard\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt Has been deleted!

Attempting to delete C:\WINDOWS\java\CLASSES\idsktuil.dll
C:\WINDOWS\java\CLASSES\idsktuil.dll Could not be deleted.

Attempting to delete C:\WINDOWS\java\CLASSES\liutksdi.bak1
C:\WINDOWS\java\CLASSES\liutksdi.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\java\CLASSES\liutksdi.bak2
C:\WINDOWS\java\CLASSES\liutksdi.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\java\CLASSES\liutksdi.ini
C:\WINDOWS\java\CLASSES\liutksdi.ini Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\cbhywkcd.dll
C:\WINDOWS\SYSTEM32\cbhywkcd.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\efcdcde.dll
C:\WINDOWS\SYSTEM32\efcdcde.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\konphege.dll
C:\WINDOWS\SYSTEM32\konphege.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\lfhbcgrw.dll
C:\WINDOWS\SYSTEM32\lfhbcgrw.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\pmnnmli.dll
C:\WINDOWS\SYSTEM32\pmnnmli.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\wpiklmcs.exe
C:\WINDOWS\SYSTEM32\wpiklmcs.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\yadymsks.dll
C:\WINDOWS\SYSTEM32\yadymsks.dll Has been deleted!

Performing Repairs to the registry.
Done!



VundoFix V6.3.19

Checking Java version...

Sun Java not detected
Scan started at 15:08:43 18/04/2007

Listing files found while scanning....

C:\Documents and settings\Standard\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
C:\Documents and settings\Standard\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
C:\WINDOWS\java\CLASSES\idsktuil.dll
C:\WINDOWS\java\CLASSES\liutksdi.bak1
C:\WINDOWS\java\CLASSES\liutksdi.bak2
C:\WINDOWS\java\CLASSES\liutksdi.ini
C:\WINDOWS\SYSTEM32\cbhywkcd.dll
C:\WINDOWS\SYSTEM32\efcdcde.dll
C:\WINDOWS\SYSTEM32\konphege.dll
C:\WINDOWS\SYSTEM32\lfhbcgrw.dll
C:\WINDOWS\system32\NEDEAPI.DLL
C:\WINDOWS\SYSTEM32\pmnnmli.dll
C:\WINDOWS\SYSTEM32\wpiklmcs.exe
C:\WINDOWS\SYSTEM32\yadymsks.dll

Beginning removal...

Attempting to delete C:\Documents and settings\Standard\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
C:\Documents and settings\Standard\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt Has been deleted!

Attempting to delete C:\Documents and settings\Standard\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
C:\Documents and settings\Standard\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt Has been deleted!

Attempting to delete C:\WINDOWS\java\CLASSES\idsktuil.dll
C:\WINDOWS\java\CLASSES\idsktuil.dll Could not be deleted.

Attempting to delete C:\WINDOWS\java\CLASSES\liutksdi.bak1
C:\WINDOWS\java\CLASSES\liutksdi.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\java\CLASSES\liutksdi.bak2
C:\WINDOWS\java\CLASSES\liutksdi.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\java\CLASSES\liutksdi.ini
C:\WINDOWS\java\CLASSES\liutksdi.ini Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\cbhywkcd.dll
C:\WINDOWS\SYSTEM32\cbhywkcd.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\efcdcde.dll
C:\WINDOWS\SYSTEM32\efcdcde.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\konphege.dll
C:\WINDOWS\SYSTEM32\konphege.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\lfhbcgrw.dll
C:\WINDOWS\SYSTEM32\lfhbcgrw.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\pmnnmli.dll
C:\WINDOWS\SYSTEM32\pmnnmli.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\wpiklmcs.exe
C:\WINDOWS\SYSTEM32\wpiklmcs.exe Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\yadymsks.dll
C:\WINDOWS\SYSTEM32\yadymsks.dll Has been deleted!

Performing Repairs to the registry.
Done!


voila le rapport Hijackthis

Logfile of HijackThis v1.99.1
Scan saved at 15:26:04, on 18/04/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\vmmon32.exe
C:\WINDOWS\system32\internat.exe
C:\Program Files\Marvell\Mrv8000x.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
O2 - BHO: (no name) - {6C6CED4D-A87C-4E1D-BF1D-C0C81741DE44} - C:\WINDOWS\java\CLASSES\idsktuil.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Printer] C:\WINDOWS\system32\vmmon32.exe
O4 - HKLM\..\RunServices: [Printer] C:\WINDOWS\system32\vmmon32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Printer] C:\WINDOWS\system32\vmmon32.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\WINDOWS\java\CLASSES\idsktuil.dll,CreateProtectProc
O4 - Startup: Marvell Libertas Client Configuration Manager.lnk = C:\Program Files\Marvell\Mrv8000x.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.ya [...] st0401.cab
O20 - Winlogon Notify: idsktuil - C:\WINDOWS\java\CLASSES\idsktuil.dll
O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\mvpsl9771.dll (file missing)
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\NEDEAPI.DLL (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Debug Config System - Unknown owner - C:\WINDOWS\system32\lrsys.exe (file missing)
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe



Bon j'ai toujours des fenetres qui s'affichent
Vundofix a t il bien fait son boulot car il m'a dit qu'il ne pouvez pas supprimer des fichiers !! au boot rien de special
peut etre que je dois faire cela en etant sous un compte admin , je suis sous win 2000 pro

merci pour l'aide

Répondre à atavachron31

Tu as regardé la note ?

Citation :

Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

ok Angeldark !

j'ai bien fait ce qu'il fallait mais au reboot Vundofix ne c'est pas lance ,
l'erreur que j'ai lors du move des fichiers c'est impossible d'importer le fichier vundofix.reg

Voila !

Répondre à atavachron31

On va utiliser Combofix avant de continuer.

  • Télécharge combofix.exe (par sUBs) sur ton Bureau
  • Double clique combofix.exe.
  • Tape sur la touche Y (Yes) pour démarrer le scan.
  • Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.


NOTE : Le rapport se trouve également ici : C:\Combofix.txt

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

probleme , Combofix me balance une erreur lorsque je le lance , probleme de path (c'est une fenetre dos ) !!!

Répondre à atavachron31

Oui, mais Combofix a été modifiée depuis.
Tu peux faire un screen de l'erreur ?

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

apres reboot , pareil meme erreur !

Répondre à atavachron31

Reposte un rapport Hijackthis.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Logfile of HijackThis v1.99.1
Scan saved at 17:54:43, on 18/04/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\internat.exe
C:\WINDOWS\system32\vmmon32.exe
C:\Program Files\Marvell\Mrv8000x.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Printer] C:\WINDOWS\system32\vmmon32.exe
O4 - HKLM\..\RunServices: [Printer] C:\WINDOWS\system32\vmmon32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Printer] C:\WINDOWS\system32\vmmon32.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\WINDOWS\java\CLASSES\idsktuil.dll,CreateProtectProc
O4 - Startup: Marvell Libertas Client Configuration Manager.lnk = C:\Program Files\Marvell\Mrv8000x.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.ya [...] st0401.cab
O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\mvpsl9771.dll (file missing)
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\NEDEAPI.DLL (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Debug Config System - Unknown owner - C:\WINDOWS\system32\lrsys.exe (file missing)
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe

Répondre à atavachron31

Tu es aidé sur un autre forum ?

Prière d'imprimer ces instructions, ou de les coller dans un fichier texte, pour lecture durant ce fix. Regarde bien la note au bas, avant de débuter.

Télécharge Look2Me-Destroyer.exe (par Atribune) sur ton Bureau.

  • Ferme toutes les fenêtres actives avant de passer à l'étape suivante.
  • Double-clique Look2Me-Destroyer.exe afin de lancer l'outil.
  • Coche Run this program as a task
  • Un message s'affichera, te disant ceci : "Look2Me-Destroyer will close and re-open in approximately 1 minute". Clique OK
  • Il se relancera après la minute, puis clique sur le bouton Scan for L2M; les icônes de ton Bureau vont disparaître : c'est normal.
  • Lorsque le scan termine, clique sur le bouton Remove L2M
  • Un message Done Scanning apparaîtra, clique OK.
  • Un nouveau message s'affichera : Done removing infected files! Look2Me-Destroyer will now shutdown your computer; clique OK.
  • Ton PC va maintenant s'éteindre.
  • Démarre ton PC normalement.
  • Colle le rapport généré (Look2Me-Destroyer.txt), situé sur le Bureau, ainsi qu'un nouveau rapport HijackThis! dans ta prochaine réponse.


** Si Look2Me-Destroyer ne se relance pas automatiquement après la minute, redémarre et essaie à nouveau.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

non ,

je vais appliquer a la lettre tes instructions

Répondre à atavachron31

bon en fait j'ai beau attendre ca ne se lance pas apres avoir coche la case

Répondre à atavachron31

On va passer SDFix avant.

Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
Double clique sur SDFix.exe et choisis Install pour l'extraire sur le Bureau.

Redémarre en mode sans échec

  • Ouvre le dossier SDFix qui vient d'être créé à la racine de ton dique dur (C:) et double clique sur RunThis.bat pour lancer le script.
  • Appuie sur Y pour commencer le processus de nettoyage.
  • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
  • Appuie sur une touche pour redémarrer le PC.
  • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
  • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
  • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
  • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
  • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

voila , par contre au relancement du syteme je n'ai pas vu la boite finished ! , quand j'ai relance le systeme je suis revenu en mode normal , ai je bien fait ? , ou alors il fallait de nouveau se mettre en mode sans echec

voila le rapport de de SDFix:
SDFix: Version 1.79

Run by Standard - mer. 18/04/2007 - 22:26:51,38

Microsoft Windows 2000 [Version 5.00.2195]

Running From: C:\DOCUME~1\Standard\Bureau\SDFix

Safe Mode:
Checking Services:

Name:
Debug Config System

ImagePath:
"C:\WINDOWS\system32\lrsys.exe"




Restoring Windows Registry Values
Restoring Windows Default Hosts File


le rapport de Hijackthis :
Logfile of HijackThis v1.99.1
Scan saved at 22:37:53, on 18/04/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\internat.exe
C:\Program Files\Marvell\Mrv8000x.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\WINDOWS\java\CLASSES\idsktuil.dll,CreateProtectProc
O4 - Startup: Marvell Libertas Client Configuration Manager.lnk = C:\Program Files\Marvell\Mrv8000x.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.ya [...] st0401.cab
O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\mvpsl9771.dll (file missing)
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\NEDEAPI.DLL (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Debug Config System - Unknown owner - C:\WINDOWS\system32\lrsys.exe (file missing)
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe



Répondre à atavachron31

Tu peux retenter Look2meDestroyer ?

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

nada ,puis apres j'ai redemarre le pc et retente toujours pareil , ne se lance pas !

Répondre à atavachron31

Fais ceci en attendant mon retour.

Télécharge puis installe AVG Anti-Spyware (AVG AS)
Fais les mises à jour mais ne lance pas de scan pour le moment.
AIDE : Tuto sur AVG Anti-Spyware (Malekal)

Redémarre en mode sans échec

Relance AVG AS :
- Choisis l'onglet "Analyse"
- Puis l'onglet "Paramètres"
- Sous la question "Comment réagir ?", clique sur "Actions recommandées" et choisis "Quarantaine"
- Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"

Si un fichier est infecté en fin d'analyse, clique sur "Appliquer toutes les actions"

Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous"
Enregistre ce fichier texte sur ton bureau.

Redémarre normalement
Poste le rapport AVG AS ainsi qu'un rapport Hijackthis.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

c en cours
et je crois qu'on tiens le bon bout ;-)

Répondre à atavachron31

voila le rapport de AVG spyware :
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 23:58:21 18/04/2007

+ Résultat de l'analyse:



C:\WINDOWS\icont.exe -> Adware.AdURL : Nettoyé et sauvegardé (mise en quarantaine).
HKU\.DEFAULT\Software\Effective-i -> Adware.EffectiveBrandToolbar : Erreur lors du nettoyage.
HKU\.DEFAULT\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Erreur lors du nettoyage.
HKU\.DEFAULT\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Erreur lors du nettoyage.
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\8J26CJ89\Installer[1].exe -> Adware.Look2Me : Nettoyé et sauvegardé (mise en quarantaine).
C:\Installer3.exe -> Adware.Look2Me : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\SYSTEM32\RBOCURS.DLL -> Adware.Look2Me : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\SYSTEM32\guard.tmp -> Adware.Look2Me : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\SYSTEM32\mv84l9lq1.dll -> Adware.Look2Me : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\SYSTEM32\sj2res.dll -> Adware.Look2Me : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\SYSTEM32\sxns.dll -> Adware.Look2Me : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\SYSTEM32\viscript.dll -> Adware.Look2Me : Nettoyé et sauvegardé (mise en quarantaine).
C:\warebundlenewer.exe -> Adware.Look2Me : Nettoyé et sauvegardé (mise en quarantaine).
C:\VundoFix Backups\wpiklmcs.exe.bad -> Adware.Searchcolor : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\VSToolbar\VSToolBar.dll -> Adware.Searchcolours : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\8J26CJ89\deskbar[1].exe -> Adware.Softomate : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\Deskbar -> Adware.Softomate : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\Deskbar\inst.bat -> Adware.Softomate : Nettoyé et sauvegardé (mise en quarantaine).
C:\deskbar.exe -> Adware.Softomate : Nettoyé et sauvegardé (mise en quarantaine).
C:\deskbar3.exe -> Adware.Softomate : Nettoyé et sauvegardé (mise en quarantaine).
C:\ucmoreiex.exe/IUCMORE.DLL -> Adware.Ucmore : Nettoyé et sauvegardé (mise en quarantaine).
C:\ucmoreiex.exe/UCMTSAIE.DLL -> Adware.Ucmore : Nettoyé et sauvegardé (mise en quarantaine).
C:\ucmoreiex.exe/empty_00000001 -> Adware.Ucmore : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\MNC3YF45\drsmartload195a[1].exe -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\VundoFix Backups\pmnnmli.dll.bad -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\SYSTEM32\qaz -> Downloader.Ftp.cb : Nettoyé et sauvegardé (mise en quarantaine).
:mozilla.72:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.42:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Cpvfeed : Nettoyé.
:mozilla.43:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Cpvfeed : Nettoyé.
:mozilla.44:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Cpvfeed : Nettoyé.
:mozilla.45:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Cpvfeed : Nettoyé.
:mozilla.74:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.67:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.68:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.80:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.81:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.82:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.41:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.38:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Paypal : Nettoyé.
:mozilla.51:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.52:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.53:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.54:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.55:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.33:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.34:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.35:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.10:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.11:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.12:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.13:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.14:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.15:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.16:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.7:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.8:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.9:C:\Documents and Settings\Standard\Application Data\Mozilla\Firefox\Profiles\8w7i25k6.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\8J26CJ89\teller2[1].htm -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\teller2.chk -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).


Fin du rapport



et le rapport de HiJackThis :
Logfile of HijackThis v1.99.1
Scan saved at 00:11:49, on 19/04/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\internat.exe
C:\Program Files\Marvell\Mrv8000x.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\WINDOWS\java\CLASSES\idsktuil.dll,CreateProtectProc
O4 - Startup: Marvell Libertas Client Configuration Manager.lnk = C:\Program Files\Marvell\Mrv8000x.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.ya [...] st0401.cab
O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\mvpsl9771.dll (file missing)
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\NEDEAPI.DLL (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Debug Config System - Unknown owner - C:\WINDOWS\system32\lrsys.exe (file missing)
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe



Répondre à atavachron31

Bonsoir atavachron 31,
Si après tous cela rien n'y fait alors je suppose que tu as un rootkit, pour vérifier vas sur ce lien www.f-secure.com/blacklight/try_blacklight.html et accept en bas de page puis télécharge l'exe et places le dans le dossier Windows (pas d'installation, juste un éxécutable) n'hesites pas à consulter cette page avant d'utliser (il ne fonctionne que 15 j, bien suffisant pour faire ce que tu veux) http://www.f-secure.com/blacklight [...] help.html.
Et tiens nous au courant ;)


Message édité par Wam381 le 19-04-2007 à 02:11:04
Répondre à Wam381

Oui je vous tiens au courant Messieurs

Aujourd'hui je ne pourrais pas m'occuper de ce probleme , je verrais ca demain mais hier soir apres avoir passe le pc avec AVGSpyware ca semble aller mieux , plus de fenetres web intempestives et ceci pendant plusieurs minutes
A suivre demain

Répondre à atavachron31

Tu peux retenter Look2meDestroyer ou Combofix ?

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Voila j'ai retente Look2me rien ne se lance , puis redemarrer et ressaie , nada
Sinon depuis que j'ai passe AvgSpyware , je n'ai plus de fenetres web intempestives ,
une precision AvgSpyware tourne en tache de fond

Voila

Répondre à atavachron31

Reposte un rapport Hijackthis.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

voilou le rapport HiJackThis

Logfile of HijackThis v1.99.1
Scan saved at 17:53:27, on 20/04/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\internat.exe
C:\Program Files\Marvell\Mrv8000x.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\WINDOWS\java\CLASSES\idsktuil.dll,CreateProtectProc
O4 - Startup: Marvell Libertas Client Configuration Manager.lnk = C:\Program Files\Marvell\Mrv8000x.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.ya [...] st0401.cab
O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\mvpsl9771.dll (file missing)
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\NEDEAPI.DLL (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Debug Config System - Unknown owner - C:\WINDOWS\system32\lrsys.exe (file missing)
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe

Répondre à atavachron31

Re,

- Lance Hijackthis ->Do a system scan only
->Coche les lignes ci-dessous :

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - (no file)
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\WINDOWS\java\CLASSES\idsktuil.dll,CreateProtectProc
O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\mvpsl9771.dll (file missing)
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\NEDEAPI.DLL (file missing)
O23 - Service: Debug Config System - Unknown owner - C:\WINDOWS\system32\lrsys.exe (file missing)

Clique sur Fix checked (en bas à gauche)

----------
-> Démarrer
-> Exécuter...
Tape Services.msc puis valide
Double clique sur Debug Config System
Type de démarrage : "Désactiver"
Clique en bas sur "Arrêter"
Valide les changements.
-----
Ouvre Hijackthis puis:
-> Open the Misc Tools Section
-> Delete an NT Service
Tape Debug Config System puis valide.
----------

Télécharge OTMoveIt (d'OldTimer). Sauvegarde-le sur ton Bureau.
Sélectionne TOUS les emplacements en gras ci-dessous :

C:\WINDOWS\java\CLASSES\idsktuil.dll
C:\WINDOWS\system32\lrsys.exe


---> Clique-droit puis Copier

Double-clique sur OTMoveIt.exe afin de le lancer.
Fais un Clique-droit sur le cadre de gauche puis choisis Coller.
Clique maintenant sur MoveIt!

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.


Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport est la date de sa création.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

une fois que j'ai fait HiJackThis scan only , coche , et fixed il me demande de rebooter , dois je faire avant de poursuivre le reste ?

Répondre à atavachron31

-----
Ouvre Hijackthis puis:
-> Open the Misc Tools Section
-> Delete an NT Service
Tape Debug Config System puis valide.
----------

Quand je fais cette partie il me dit : "impossible de supprimer ce service , etes vous sur de ce nom , ce service ne tourne peut etre pas "

!!!!

Répondre à atavachron31

avec OTMoveIt il a bien fait son boulot apparement mais il m'a dit qu'il ne pouvait creer le fichier log !

Répondre à atavachron31

Reposte un rapport Hijackthis.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Logfile of HijackThis v1.99.1
Scan saved at 19:21:45, on 20/04/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\internat.exe
C:\Program Files\Marvell\Mrv8000x.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Marvell Libertas Client Configuration Manager.lnk = C:\Program Files\Marvell\Mrv8000x.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.ya [...] st0401.cab
O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\mvpsl9771.dll (file missing)
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\NEDEAPI.DLL (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe

Répondre à atavachron31

Pourquoi ?
car maintenant j'en ai un , je suis derriere une freebox
mais a l'epoque ou ce pc a ete infecte il etait san parefeu

Répondre à atavachron31

Alors installe le SP2 de Windows.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

ah ok
Je suis sous Windows 200 Pro service pack 4 , je dois mettre a jour mon service pack tu crois ?

Répondre à atavachron31

J'avais pas vu ;)
Reposte un dernier rapport Hijackthis.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

le revoila

Logfile of HijackThis v1.99.1
Scan saved at 22:47:48, on 20/04/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\internat.exe
C:\Program Files\Marvell\Mrv8000x.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Marvell Libertas Client Configuration Manager.lnk = C:\Program Files\Marvell\Mrv8000x.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.ya [...] st0401.cab
O20 - Winlogon Notify: Setup - C:\WINDOWS\system32\mvpsl9771.dll (file missing)
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\NEDEAPI.DLL (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe

Répondre à atavachron31

Re,

Toujours des restes de Look2me.

  • Télécharge SpySweeper (de Webroot, version d'essai de 14 jours) :


-Clique sur "Télécharger la version test".
-Installe le programme en choississant "installation standard".
-Accepte le redémarrage
-L'option de le mettre à jour s'affichera, acceptes la mise à jour
-Lorsque les mises à jour seront installées, dans colonne de gauche clique sur l'onglet Options puis analyse.
-Sous Eléments à analyser et Autres options coche toutes les cases.
-Ferme SpySweeper

La suite étant faite en mode sans échec, imprime ou copie/colle dans un fichier texte les instructions suivantes

  • Redémarre en mode sans échec : au redémarrage, tapotes immédiatement la touche F8, tu verras un écran avec choix de démarrages apparaître. Utilisant les flèches du clavier, choisis "Mode Sans Échec" et valide avec "Entrée". Choisis ton compte usuel, et non Administrateur.


  • Démarre SpySweeper

-Clique Analyser sur la gauche puis sur Démarrer l'analyse.
-Quand le scan est terminé, clique sur Suivant.
-Assure-toi que tous les éléments trouvés sont tous cochés, puis clic sur Suivant.
-Tous les éléments cochés seront alors mis en quarantaine.
-Dans "Récapitulatif", sélectionne en bas Afficher le journal de session puis Enregistrer dans un fichier afin de sauvegarder le rapport.

  • Redémarre normalement


  • Désinstalle SpySweeper à partir de ajout/suppression de programme sauf si tu veux continuer l'évaluation pendant 15 jours.


  • Copie/colle le rapport de SpySweeper ici

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

00:18: Removal process completed. Elapsed time 00:00:45
00:17: Warning: Failed to delete profile shadow file "c:\WINDOWS\TEMP\SST70.tmp". Reason: Le fichier spécifié est introuvable
00:17: Warning: Failed to delete profile shadow file ".log". Reason: Le fichier spécifié est introuvable
00:17: Quarantining All Traces: desktop bar
00:17: Quarantining All Traces: findthewebsiteyouneed hijack
00:17: Quarantining All Traces: effective-i toolbar
00:17: Quarantining All Traces: vs toolbar
00:17: Quarantining All Traces: trojan-rbot-csc
00:17: Quarantining All Traces: virtumonde
00:17: Quarantining All Traces: look2me
00:17: Removal process initiated
00:16: Traces Found: 16
00:16: Full Sweep has completed. Elapsed time 00:51:27
00:15: C:\Documents and Settings\Standard\Application Data\SearchToolbarCorp (1 subtraces) (ID = 2147532253)
00:15: HKLM\software\microsoft\juan\ (ID = 2156653)
00:15: File Sweep Complete, Elapsed Time: 00:49:01
00:10: Warning: Stream read error
00:10: Warning: Stream read error
00:10: Warning: Stream read error
00:10: Warning: Stream read error
00:09: Warning: Stream read error
00:09: Warning: Access violation at address 00401D58 in module 'SpySweeper.exe'. Read of address 7EBC000C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:09: Warning: Access violation at address 0058C2B4 in


Message édité par atavachron31 le 21-04-2007 à 00:51:59
Répondre à atavachron31

ahhh je viens de voir que tout le rapport SpySweeper n'est pas dans le message precedent (il ne passe pas en entier )
je colle ici la fin du rapport

00:07: Warning: Access violation at address 0058C2B4 in module 'SpySweeper.exe'. Read of address 0000038C
00:04: Warning: Failed to access drive D:
00:00: C:\VundoFix Backups\efcdcde.dll.bad (ID = 458925)
00:00: C:\Program Files\VSToolbar (ID = 2147550726)
00:00: Found Adware: vs toolbar
23:56: Warning: Failed to open file "c:\documents and settings\standard\local settings\application data\microsoft\windows\usrclass.dat.log". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:56: Warning: Failed to open file "c:\documents and settings\standard\local settings\application data\microsoft\windows\usrclass.dat". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:56: Warning: Failed to open file "c:\documents and settings\standard\ntuser.dat". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:56: Warning: Failed to open file "c:\documents and settings\standard\ntuser.dat.log". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:55: Warning: Failed to open file "c:\program files\webroot\spy sweeper\settings.dat". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:39: Warning: Failed to open file "c:\windows\system32\config\default". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:39: Warning: Failed to open file "c:\windows\system32\config\software". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:39: Warning: Failed to open file "c:\windows\system32\config\system". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:39: Warning: Failed to open file "c:\windows\system32\config\sam.log". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:39: Warning: Failed to open file "c:\windows\system32\config\sam". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:39: Warning: Failed to open file "c:\windows\system32\config\system.alt". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:39: Warning: Failed to open file "c:\windows\system32\config\security.log". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:39: Warning: Failed to open file "c:\windows\system32\config\security". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:39: Warning: Failed to open file "c:\windows\system32\config\default.log". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:39: Warning: Failed to open file "c:\windows\system32\config\software.log". Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus
23:27: C:\deskbar_e31.exe (ID = 392257)
23:26: Warning: Failed to open file "c:\pagefile.sys". Accès refusé
23:26: Starting File Sweep
23:26: Warning: Failed to access drive A:
23:26: Cookie Sweep Complete, Elapsed Time: 00:00:00
23:26: Starting Cookie Sweep
23:26: Registry Sweep Complete, Elapsed Time:00:00:30
23:26: HKU\WRSS_Profile_S-1-5-21-329068152-688789844-1708537768-500\software\microsoft\windows\currentversion\run\ || printer (ID = 1237079)
23:26: Found Trojan Horse: trojan-rbot-csc
23:26: HKLM\software\classes\clsid\{67c55a8d-e808-4caa-9ea7-f77102de0bb6}\ (ID = 2161051)
23:26: HKLM\software\microsoft\uniqdata\ (ID = 1997747)
23:26: Found Adware: virtumonde
23:26: HKLM\software\classes\dbtb00001.deskbarenabler.1\ (ID = 1595846)
23:26: HKLM\software\classes\dbtb00001.deskbarenabler\ (ID = 1595842)
23:26: HKCR\dbtb00001.deskbarenabler.1\ (ID = 1595711)
23:26: HKCR\dbtb00001.deskbarenabler\ (ID = 1595707)
23:26: Found Adware: desktop bar
23:26: HKU\.default\software\microsoft\internet explorer\search\searchassistant explorer\main\ || default_search_url (ID = 555438)
23:26: Found Adware: findthewebsiteyouneed hijack
23:26: HKU\.default\software\maxthon\plugin\toolbar\{44be0690-5429-47f0-85bb-3ffd8020233e}\ (ID = 125650)
23:26: Found Adware: effective-i toolbar
23:26: Starting Registry Sweep
23:26: Memory Sweep Complete, Elapsed Time: 00:01:37
23:24: Starting Memory Sweep
23:24: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\setup\ || dllname (ID = 1139665)
23:24: Found Adware: look2me
23:24: Sweep initiated using definitions version 899
23:24: Spy Sweeper 5.0.7.1608 started
23:24: | Start of Session, vendredi 20 avril 2007 |
********
23:24: | End of Session, vendredi 20 avril 2007 |
Keylogger Shield: Off
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
23:23: Shield States
23:23: Spyware Definitions: 899
23:23: Spy Sweeper 5.0.7.1608 started
23:22: Program Version 5.0.7.1608 Using Spyware Definitions 899
Keylogger Shield: Off
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
23:13: Shield States
Keylogger Shield: Off
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
23:08: Shield States
23:08: Spyware Definitions: 734
23:08: Spy Sweeper 5.0.7.1608 started
23:08: Spy Sweeper 5.0.7.1608 started
23:08: | Start of Session, vendredi 20 avril 2007 |
********

Répondre à atavachron31

Tu peux reposter un rapport Hijackthis ?

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Logfile of HijackThis v1.99.1
Scan saved at 12:22:32, on 21/04/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\internat.exe
C:\Program Files\Marvell\Mrv8000x.exe
C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Marvell Libertas Client Configuration Manager.lnk = C:\Program Files\Marvell\Mrv8000x.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.ya [...] st0401.cab
O20 - Winlogon Notify: Setup - C:\WINDOWS\
O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\NEDEAPI.DLL (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe

Répondre à atavachron31

Re,

Fixe cette ligne :
O20 - Winlogon Notify: Setup - C:\WINDOWS\

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark
Page Précédente
1 2
Tom's Guide > Forum > Sécurité - Virus > fenetres web intempestives
Aller à :

Il y a 2586 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.

Attention

Vous allez répondre sur un sujet resté inactif pendant plus de 6 mois.
Assurez-vous d'apporter des éléments nouveaux à la discussion avant de poursuivre.

Répondre Annuler
Liens