re bonsoir...
Me revoici car finalement, après avoir relancé un scan ad aware, 14 infections ont été retrouvées... quelqu'un pour m'aider svp ?
voici le scan logware et après celui de hijack (je précise que hijak lors du scan m'a balancé deux messages d'erreur en anglais que je n'ai pas compris" :
Scan Results
Ad-Aware 2007 Free Edition
Log File Created on:
2008-03-1000:52:11
Using Definitions File:
C:\ProgramData\Lavasoft\Ad-Aware 2007\core.aawdef
Computer name:
PC-DE-SALAH
Name of user performing scan:
SYSTEM
Name of user ordering scan:
Salah
Scan was not completed
• System Information
• File Version Information
• Ad-Aware 2007 Settings
• Extended Ad-Aware 2007 Settings
• Database Information
• Scan Statistics
• Scan Detailed Statistics
• Infections Found
• Listing of running processes
System Information
Number of processors:
1
Processor type:
AMD Athlon(tm) 64 Processor 3000+
Memory Available:
46%
Total Physical Memory:
2145320960 Bytes
Available Physical Memory:
980578304 Bytes
Total Page File Size:
4519059456 Bytes
Available On Page File:
3240697856 Bytes
Total Virtual Memory:
2147352576 Bytes
Available Virtual Memory:
1938251776 Bytes
OS:
Microsoft Windows Vista 6.0 (Build 6000)
[to top]
File Verion Information
File Version
CEAPI.dll 7,0,2,6
aawservice.exe 7,0,2,6
Ad-Aware2007.exe 7.0.2.6
[to top]
Ad-Aware 2007 Settings
Skipping files larger than:
1048576 Bytes
Ignoring infections with lower TAI than:
3
Safe Mode:
False
[to top]
Extended Ad-Aware 2007 Settings
• Unload malicious processes and modules
• Unload Modules
• Let Windows remove files at Start-Up
• Deactivate Ad-Watch
• Re-analyze Scan Result
• Delete Restored Items
• Write Protect System Files
• Create Log file
• Include basic settings
• Include advanced settings
• Include user and computer name
• Environment information
• Running processes
• Running processes and modules
• Include info about ignored objects in log file
• Consider definitions File Outdated after x days
• Proxy URL
• Proxy Port
[to top]
Database Info
Version number:
58
Build Number:
0
Build Date and Time:
2008/03/0609:21:44
[to top]
Scan Statistics
Method:
Smart
Items Scanned:
80405
Infections Detected:
14
Infections Removed:
0
Infections Quarantined:
0
Infections Ignored:
0
[to top]
Scan Detailed Statistics
Type Critical Total
Process Scan 0 0
Registry Scan 0 0
Registry PE Scan 0 0
Hosts Scan 0 0
File Scan 0 0
Folder Scan 0 0
LSP Scan 0 0
ADS Scan 0 0
Cookie Scan 14 14
File Hash Scan 0 0
[to top]
Infections Found
Family Id Name Category TAI
725 Tracking Cookie DataMiner 3
• [600000225] Browser: Firefox Cookie: C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles/x70vy0sx.default\cookies.txt weborama.fr AFFICHE_W /
• [600000408] Browser: Firefox Cookie: C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles/x70vy0sx.default\cookies.txt serving-sys.com E2 /
• [600000408] Browser: Firefox Cookie: C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles/x70vy0sx.default\cookies.txt serving-sys.com D3 /
• [600000408] Browser: Firefox Cookie: C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles/x70vy0sx.default\cookies.txt serving-sys.com C3 /
• [600000408] Browser: Firefox Cookie: C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles/x70vy0sx.default\cookies.txt serving-sys.com B2 /
• [600000408] Browser: Firefox Cookie: C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles/x70vy0sx.default\cookies.txt serving-sys.com A2 /
• [600000408] Browser: Firefox Cookie: C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles/x70vy0sx.default\cookies.txt serving-sys.com U /
• [600000171] Browser: Firefox Cookie: C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles/x70vy0sx.default\cookies.txt bs.serving-sys.com eyeblaster /
• [600000001] Browser: Firefox Cookie: C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles/x70vy0sx.default\cookies.txt smartadserver.com pid /
• [600000001] Browser: Firefox Cookie: C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles/x70vy0sx.default\cookies.txt smartadserver.com pbw /
• [600000001] Browser: Firefox Cookie: C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles/x70vy0sx.default\cookies.txt smartadserver.com pbwmaj /
• [600000001] Browser: Firefox Cookie: C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles/x70vy0sx.default\cookies.txt smartadserver.com TestIfCookieP /
• [600000212] Browser: Firefox Cookie: C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles/x70vy0sx.default\cookies.txt msnportal.112.2o7.net s_vi /
• [600000179] Browser: Firefox Cookie: C:\Users\Salah\AppData\Roaming\Mozilla\Firefox\Profiles/x70vy0sx.default\cookies.txt atdmt.com AA002 /
scan hijack :
Logfile of HijackThis v1.99.1
Scan saved at 01:06:21, on 10/03/2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Logitech\SetPoint\LBTWiz.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Hijack\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Bluetooth Connection Assistant] LBTWIZ.EXE -silent
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra co