Fenetres qui s'ouvrent seules [Résolu]
Forum Sécurité - Virus : Fenetres qui s'ouvrent seules [Résolu]
Salut,
Je suis comme beaucoup, j'ai des fenetres qui s'ouvrent toutes seules sous firefox.
J'ai déjà télécharger Hijackthis et donc, voilà le rapport:
Logfile of HijackThis v1.99.1
Scan saved at 12:33:40, on 29/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Druide\Antidote\Gestionnaire Antidote.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jerome\Bureau\Scanner.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.free.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Copernic Desktop Search 2 - {968631B6-4729-440D-9BF4-251F5593EC9A} - C:\Program Files\Copernic Desktop Search 2\DesktopSearchBand2526.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [Netcom] "C:\Program Files\Netcom\Netcom.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\PROGRA~1\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Copernic Desktop Search 2] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site with Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://home.free.fr/
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: MSSQL$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe" -sPINNACLESYS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SQLAgent$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlagent.EXE" -i PINNACLESYS (file missing)
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
Merci pour votre aide.
Mitze.
Message édité par Mitze le 30-05-2007 à 21:06:21
Bonjour,
Télécharge BlackLight (de F-Secure); clique sur "I ACCEPT" au bas de la page. Sauvegarde le sur ton Bureau.
Double-clique fsbl.exe et accepte la licence; clique Scan puis Next
Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).
Copie et colle le contenu de ce rapport dans ta prochaine réponse. NE PAS choisir l'option "Rename" de suite : nous devons analyser le rapport, car des fichiers légitimes peuvent être présents, tel wbemtest.exe
Tu peux consulter le tutorial de F-Secure BlackLight : (merci à Malekal)
http://www.malekal.com/tutorial_f- [...] Light.html
Répondre à bob_
Merci, voici le rapport de Blacklight:
05/29/07 15:17:30 [Info]: BlackLight Engine 1.0.61 initialized
05/29/07 15:17:30 [Info]: OS: 5.1 build 2600 (Service Pack 2)
05/29/07 15:17:31 [Note]: 7019 4
05/29/07 15:17:31 [Note]: 7005 0
05/29/07 15:17:34 [Note]: 7006 0
05/29/07 15:17:34 [Note]: 7011 444
05/29/07 15:17:34 [Note]: 7026 0
05/29/07 15:17:34 [Note]: 7026 0
05/29/07 15:17:34 [Note]: 7024 3
05/29/07 15:17:34 [Info]: Hidden process: C:\windows\system32\ffanowbcr.exe
05/29/07 15:17:40 [Note]: FSRAW library version 1.7.1021
05/29/07 15:26:58 [Info]: Hidden file: c:\WINDOWS\system32\ffanowbcr.dat
05/29/07 15:26:58 [Note]: 10002 1
05/29/07 15:26:58 [Info]: Hidden file: C:\windows\system32\ffanowbcr.exe
05/29/07 15:26:58 [Note]: 10002 1
05/29/07 15:26:59 [Info]: Hidden file: c:\WINDOWS\system32\ffanowbcr_nav.dat
05/29/07 15:26:59 [Note]: 10002 1
05/29/07 15:26:59 [Info]: Hidden file: c:\WINDOWS\system32\ffanowbcr_navps.dat
05/29/07 15:26:59 [Note]: 10002 1
05/29/07 15:29:12 [Note]: 2000 1012
05/29/07 15:29:12 [Note]: 2000 1012
OK !! on commence
Télécharge Navilog1.exe (IL-MAFIOSO)
Enregistre-le sur ton Bureau.
Lance l'installation en double cliquant sur navilog.exe.
Une fois l'installation terminée, l'utilitaire s'exécutera automatiquement.
(Si ce n'est pas le cas, double clique sur le raccourci présent sur le Bureau)
Laisse-toi guider par l'utilitaire. Choisis l'option 1 puis valide.
! N'utilise pas l'option 2, 3 et 4 sans notre accord !
Patiente jusqu'à l'apparition de ce message :
"*** Analyse Termine le ..... ***"
Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste-nous son contenu de cette manière :
-> Edition / Sélectionner tout
-> Edition / Copier
-> Clique-Droit / Coller dans ta réponse
NOTE : Le rapport se trouve également ici : C:\fixnavi.txt
Répondre à bob_
Voici le rapport :
Search Navipromo version 2.0.2 commencé le 29/05/2007 à 15:44:33,54
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Poster ce rapport sur le forum pour le faire analyser !!!
!!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!
Fix lancé depuis C:\Program Files\navilog1
Mise a jour le 17.05.2007 a 23h00 by IL-MAFIOSO
Executé en mode normal
*** Recherche Programmes installes ***
WebMediaPlayer
*** Recherche dossiers dans C:\WINDOWS ***
*** Recherche dossiers dans C:\Program Files ***
C:\Program Files\WebMediaPlayer trouvé !
*** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***
*** Recherche dossiers dans C:\Documents and Settings\Jerome\Application Data ***
*** Recherche avec BlackLight Engine/F-secure ***
BlackLight Engine est un produit de F-secure, pour + d'infos :
http://www.f-secure.com/blacklight [...] _help.html
Fichier(s) caché(s) dans C:\WINDOWS\system32 :
c:\WINDOWS\system32\ffanowbcr.dat
C:\windows\system32\ffanowbcr.exe
c:\WINDOWS\system32\ffanowbcr_nav.dat
c:\WINDOWS\system32\ffanowbcr_navps.dat
Processus caché(s) dans C:\WINDOWS\system32 :
C:\windows\system32\ffanowbcr.exe
*** Recherche fichiers ***
C:\DOCUME~1\Jerome\Bureau\WebMediaPlayer.lnk trouvé !
C:\WINDOWS\pack.epk trouvé !
C:\WINDOWS\system32\nvs2.inf trouvé !
*** Recherche cles registre ***
Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]
Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]
Recherche Clé Magic Control
HKEY_CURRENT_USER\Software\Lanconfig trouvé !
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche fichiers connus:
2)Recherche Heuristique :
*
C:\WINDOWS\system32\ffanowbcr.dat trouvé !
**
C:\WINDOWS\system32\ffanowbcr.dat trouvé !
***
****
C:\WINDOWS\system32\ffanowbcr_navps.dat trouvé !
*****
******
*******
********
C:\WINDOWS\system32\ffanowbcr.exe trouvé !
*** Analyse Terminé le 29/05/2007 à 15:58:12,96 ***
Up !
Bonsoir,
Désolé du retard.
Double clique sur le raccourci de Navilog1 présent sur ton Bureau.
Suis les instructions. Choisis ensuite l'option 2 puis valide.
Laisse toi guider et réponds aux questions éventuelles.
L'utilitaire va t'informer qu'il va redémarrer l'ordinateur.
**Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts**
Appuie maintenant sur une touche, comme demandé.
(si ton PC ne redémarre pas automatiquement, fais-le manuellement)
Patiente jusqu'à l'apparition de ce message :
"*** Nettoyage Termine le ..... ***"
Le Bloc-notes va s'ouvrir.
Sauvegarde le rapport de manière à le retrouver.
Referme le Bloc-notes. Ton bureau va maintenant réapparaître.
NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.
Poste le rapport sauvegardé auparavant (C:\cleannavi.txt)
Ainsi qu'un nouveau rapport Hijackthis.
Ferme Internet Explorer puis Démarrer/Panneau de Configuration/Options Internet.
Choisis l'onglet Contenu puis onglet Certificats.
Si tu trouves les programmes suivant (en particulier dans Editeurs approuvés), supprime-les :
electronic-group
egroup
Montorgueil
VIP
"Sunny Day Design Ltd"
Répondre à Angeldark
Bonjour,
Voici les 2 rapports demandés :
Clean Navipromo version 2.0.2 commencé le 30/05/2007 à 6:42:35,59
Fix lancé depuis C:\Program Files\navilog1
Mise a jour le 17.05.2007 a 23h00 by IL-MAFIOSO
Mode suppression automatique avec prise en charge résultats Blacklight
*** Creation backups fichiers trouvés par Blacklight ***
Copie vers "C:\Program Files\navilog1\Backupnavi"
*** Suppression des fichiers trouvés avec Blacklight ***
c:\WINDOWS\system32\ffanowbcr.dat supprimé !
C:\windows\system32\ffanowbcr.exe supprimé !
c:\WINDOWS\system32\ffanowbcr_nav.dat supprimé !
c:\WINDOWS\system32\ffanowbcr_navps.dat supprimé !
** 2ème passage **
C:\WINDOWS\system32\ffanowbcr.exe absent !
C:\WINDOWS\system32\ffanowbcr.dat absent !
C:\WINDOWS\system32\ffanowbcr_nav.dat absent !
C:\WINDOWS\system32\ffanowbcr_navps.dat absent !
C:\WINDOWS\system32\ffanowbcr_navup.dat absent !
C:\WINDOWS\system32\ffanowbcr_navtmp.dat absent !
C:\WINDOWS\system32\ffanowbcr_m2s.xml absent !
C:\WINDOWS\prefetch\ffanowbcr*.pf trouvé !
Copie C:\WINDOWS\prefetch\ffanowbcr*.pf réalise avec succes !
C:\WINDOWS\prefetch\ffanowbcr*.pf supprimé !
*** Suppression dossiers dans C:\WINDOWS ***
*** Suppression dossiers dans C:\Program Files ***
C:\Program Files\WebMediaPlayer ...suppression...
C:\Program Files\WebMediaPlayer supprimé !
*** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***
*** Suppression dossiers dans C:\Documents and Settings\Jerome\Application Data ***
*** Suppression fichiers ***
C:\DOCUME~1\Jerome\Bureau\WebMediaPlayer.lnk supprimé !
C:\WINDOWS\pack.epk supprimé !
C:\WINDOWS\system32\nvs2.inf supprimé !
*** Suppression fichiers temporaires ***
Nettoyage contenu C:\WINDOWS\Temp effectué !
Nettoyage contenu C:\Documents and Settings\Jerome\Local Settings\Temp effectué !
*** Sauvegarde du registre vers dossier Backupnavi***
sauvegarde du registre réalise avec succes !
*** Nettoyage registre ***
Nettoyage registre Ok
*** Traitement Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche fichiers connus:
2)Recherche et Suppression Heuristique :
*
**
***
****
*****
******
*******
********
3)Contrôle présence clés Rootkit dans le registre :
Aucune autre clés présente dans le registre !
*** Nettoyage termine le 30/05/2007 à 6:47:33,64 ***
Logfile of HijackThis v1.99.1
Scan saved at 06:52:42, on 30/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jerome\Bureau\Scanner.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.free.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Copernic Desktop Search 2 - {968631B6-4729-440D-9BF4-251F5593EC9A} - C:\Program Files\Copernic Desktop Search 2\DesktopSearchBand2526.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [Netcom] "C:\Program Files\Netcom\Netcom.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\PROGRA~1\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Copernic Desktop Search 2] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site with Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://home.free.fr/
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: MSSQL$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe" -sPINNACLESYS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SQLAgent$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlagent.EXE" -i PINNACLESYS (file missing)
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
Merci encore.
Re,
Télécharge Clean.zip (de Malekal),
Décompresse-le sur ton bureau (Clique-Droit/Extraire tout), tu dois obtenir un dossier Clean.
Ouvre le dossier clean, double-clique sur clean.cmd.
Choisis l'option 1 puis patiente. Poste ensuite le contenu du rapport.
Répondre à Angeldark
Rapport de Clean :
30/05/2007 a 17:16:15,54
*** Recherche des fichiers dans C:
*** Recherche des fichiers dans C:\WINDOWS\
*** Recherche des fichiers dans C:\WINDOWS\system32
C:\WINDOWS\system32\SpoonUninstall.exe FOUND
*** Recherche des fichiers dans C:\Program Files
*** Fin du rapport !
On a l'air de toucher au but !!
Re,
Télécharge puis installe AVG Anti-Spyware (AVG AS)
Fais les mises à jour mais ne lance pas de scan pour le moment.
AIDE : Tuto sur AVG Anti-Spyware (Malekal)
Redémarre en mode sans échec
Relance AVG AS :
- Choisis l'onglet "Analyse"
- Puis l'onglet "Paramètres"
- Sous la question "Comment réagir ?", clique sur "Actions recommandées" et choisis "Quarantaine"
- Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"
Si un fichier est infecté en fin d'analyse, clique sur "Appliquer toutes les actions"
Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous"
Enregistre ce fichier texte sur ton bureau.
Redémarre normalement.
Poste le rapport AVG AS ainsi qu'un rapport Hijackthis.
Répondre à Angeldark
Et voici 2 nouveaux rapports :
Le premier, de AVG Anti-Spyware
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 20:36:03 30/05/2007
+ Résultat de l'analyse:
C:\Program Files\DAEMON Tools\SetupDTSB.exe -> Adware.SaveNow : Nettoyé.
D:\System Volume Information\_restore{E6B5E9DF-A61F-43CE-BD52-E63581DE2305}\RP464\A0074395.exe -> Dropper.Agent.lu : Nettoyé.
D:\System Volume Information\_restore{E6B5E9DF-A61F-43CE-BD52-E63581DE2305}\RP464\A0071214.exe -> Not-A-Virus.PSWTool.Win32.Dialupass.f : Nettoyé.
D:\System Volume Information\_restore{E6B5E9DF-A61F-43CE-BD52-E63581DE2305}\RP464\A0074288.exe -> Not-A-Virus.PSWTool.Win32.Messen.106 : Nettoyé.
D:\System Volume Information\_restore{E6B5E9DF-A61F-43CE-BD52-E63581DE2305}\RP464\A0074214.exe -> Not-A-Virus.PSWTool.Win32.NetPass.b : Nettoyé.
:mozilla.717:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.718:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.719:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.720:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.721:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.724:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.509:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.510:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.511:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.512:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.513:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.514:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.515:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.516:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.517:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.518:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.519:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.520:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.521:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.522:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.523:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.524:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.525:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.526:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.527:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.528:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.529:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.530:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.531:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.532:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.533:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.534:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.535:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.536:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.613:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.947:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@2o7[2].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\les filles\Cookies\les filles@2o7[2].txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.482:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.483:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.438:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.439:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@adtech[2].txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.493:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.494:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.495:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.496:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.497:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.436:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.575:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\les filles\Cookies\les filles@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.399:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.829:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.830:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.831:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.832:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.833:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.18:C:\Documents and Settings\Beatrice\Application Data\Mozilla\Firefox\Profiles\9760cyci.default\cookies.txt -> TrackingCookie.Com : Nettoyé.
:mozilla.19:C:\Documents and Settings\Beatrice\Application Data\Mozilla\Firefox\Profiles\9760cyci.default\cookies.txt -> TrackingCookie.Com : Nettoyé.
:mozilla.593:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Com : Nettoyé.
:mozilla.616:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.617:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.618:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.921:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.923:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.16:C:\Documents and Settings\Beatrice\Application Data\Mozilla\Firefox\Profiles\9760cyci.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.239:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.269:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.270:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@estat[1].txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.391:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Etracker : Nettoyé.
:mozilla.392:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Etracker : Nettoyé.
:mozilla.394:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Etracker : Nettoyé.
:mozilla.390:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.393:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.486:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Falkag : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@as1.falkag[2].txt -> TrackingCookie.Falkag : Nettoyé.
:mozilla.950:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.953:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.954:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Gemius : Nettoyé.
:mozilla.292:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Goclick : Nettoyé.
:mozilla.293:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Goclick : Nettoyé.
:mozilla.560:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.668:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.746:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.749:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.769:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.800:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.822:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.842:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.895:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.919:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.934:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.196:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.197:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.198:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.759:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.476:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.477:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.294:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Information : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@search.live[1].txt -> TrackingCookie.Live : Nettoyé.
:mozilla.290:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\Beatrice\Cookies\beatrice@stat.onestat[2].txt -> TrackingCookie.Onestat : Nettoyé.
:mozilla.445:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.446:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.447:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.231:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Paypal : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.487:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Quarterserver : Nettoyé.
:mozilla.639:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.640:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.641:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.642:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.643:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Reliablestats : Nettoyé.
:mozilla.569:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.570:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.571:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.572:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.573:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.574:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.32:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.33:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.699:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.702:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@skype[1].txt -> TrackingCookie.Skype : Nettoyé.
:mozilla.17:C:\Documents and Settings\Beatrice\Application Data\Mozilla\Firefox\Profiles\9760cyci.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.405:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.406:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.407:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.408:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.784:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Specificclick : Nettoyé.
:mozilla.785:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Specificclick : Nettoyé.
:mozilla.786:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Specificclick : Nettoyé.
:mozilla.787:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Specificclick : Nettoyé.
:mozilla.53:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.55:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.226:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Toplist : Nettoyé.
:mozilla.272:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.273:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.274:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.275:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.276:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.332:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Valueclick : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@valueclick[2].txt -> TrackingCookie.Valueclick : Nettoyé.
:mozilla.441:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.442:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.443:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\les filles\Cookies\les filles@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.245:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
C:\Documents and Settings\Jerome\Cookies\jerome@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Nettoyé.
:mozilla.409:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.410:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.411:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.412:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.550:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
:mozilla.551:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
:mozilla.552:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
:mozilla.553:C:\Documents and Settings\Jerome\Application Data\Mozilla\Firefox\Profiles\ktta9wau.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
D:\System Volume Information\_restore{E6B5E9DF-A61F-43CE-BD52-E63581DE2305}\RP464\A0071588.exe -> Trojan.IcqSmiley.e : Nettoyé.
D:\System Volume Information\_restore{E6B5E9DF-A61F-43CE-BD52-E63581DE2305}\RP464\A0071423.exe -> Trojan.LdPinch.abn : Nettoyé.
Fin du rapport
Et le deuxième, celui de HijackThis :
Logfile of HijackThis v1.99.1
Scan saved at 20:46:43, on 30/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Druide\Antidote\Gestionnaire Antidote.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jerome\Bureau\Scanner.exe
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\d138a1775812050c324458347919de13\update\update.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.free.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Copernic Desktop Search 2 - {968631B6-4729-440D-9BF4-251F5593EC9A} - C:\Program Files\Copernic Desktop Search 2\DesktopSearchBand2526.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [Netcom] "C:\Program Files\Netcom\Netcom.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\PROGRA~1\Druide\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Copernic Desktop Search 2] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download web site with Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://home.free.fr/
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: MSSQL$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe" -sPINNACLESYS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SQLAgent$PINNACLESYS - Unknown owner - C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlagent.EXE" -i PINNACLESYS (file missing)
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing)
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
A plus
C'est mieux ?
Répondre à Angeldark
Super, y'a plus rien à faire ?
En tous cas merci encore pour tout.
Peut-être à plus, on n'est jamais à l'abri.
Faut-il que je porte plainte sur MWC ? Et dans quel rubrique, enfin, je veux dire à propos de quel logiciel ?
| Citation : Faut-il que je porte plainte sur MWC ? Et dans quel rubrique, enfin, je veux dire à propos de quel logiciel ? |
Dans Autres Infections : Egdaccess.
Répondre à Angeldark
Il y a 2584 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.
