Aide Matos : popeye7280 et 11 utilisateurs inconnus

 Mot :   Pseudo :  
 
Bas de page
Auteur
 Sujet :

Command.exe immposible a suppr

 
n°448262
vis4r
Posté le 24-12-2007 à 20:41:44  profilanswer
 

Bonsoir, bon reveillon à tous ceux que ca concerne :D
 
Je vous explique mon probleme, j'ai un processus jugé mauvais par hijackthis, qui s'appelle "command.exe" et il m'est impossible de le supprimé !  
Voila mon log :  
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:48:55, on 24/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Visar\Menu Démarrer\Programmes\Démarrage\ctfmon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [fc0fce39] rundll32.exe "C:\WINDOWS\system32\iwxhkrdx.dll",b
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: ctfmon.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: ctfmon.exe (User 'Default user')
O4 - Startup: ctfmon.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - d:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - d:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.mail.live.com/mail/w1/ [...] NPUpld.cab
O18 - Protocol: bw+0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 
--
End of file - 16448 bytes
 
 
 
Voilà si quelqu'un aurai une idée!  
 
Je vous remercie d'avance, bonne soirée !

n°448275
hugokboss
Posté le 25-12-2007 à 13:00:47  profilanswer
 

Sais tu ou est situté ce fichier ? si oui telecharge unlocker installe puis apres fais un clik droit sur ce fichier puis unlocker ensuite tuchoisis effacer et tu clique sur debloquer tous les processus voila.
 
Apres deuxieme chose que tu peux faire une procédure de nettoyage complete lance :
 
-spybot avec les mise a jours
-ccleaner avec les dernieres mise a jour
-kasperskyantivirus ou autre
-avg anti spyware ou spyware doctor
 
et apres rvaiment en dernier cas smitfraudfix voila bon courage tiens nous au courant


---------------
"Plus japprend et plus je me rend compte que je ne sais rien"
n°448305
vis4r
Posté le 26-12-2007 à 16:46:15  profilanswer
 

Apparament, il n'est plus la ! Je l'ai trouver dans msconfig, ds l'onglet services et je l'ai decoché !  
 
Je vous remiercie.


---------------
-= V!s4R =-
n°448306
Mr_Jo
Posté le 26-12-2007 à 18:08:10  profilanswer
 

Il faut absolument installer un pare feu:
ou FIREWALL, en voila 2, gratuits et performants :  
Tu as par exemple zone alarm, parefeu gratuit et performant :  
 
    * Téléchargement de ZoneAlarm : http://www.zonelabs.com/store/cont [...] y=&lang=fr  
    * Tutorial de configuration : http://speedweb1.free.fr/frames2.php?page=tuto1  
 
Tu as aussi Kerio Personnal Firewall très bon et gratuit aussi :  
 
    * Téléchargement de Kerio : http://telechargement.zebulon.fr/kerio.html
    * Tutorial de configuration : http://www.vulgarisation-informatique.com/kerio.php  
 
ensuite effectuer la procédure de pré-nettoyage:
http://forum.aideonline.com/aideon [...] 6201_1.htm
 
les lignes 018 correspondent à : Piratage de protocole et de protocoles additionnels
 
Il faut télécharger la dernière version Java:
http://www.java.com/fr/download/windows_manual.jsp
et après l'avoir installée désinstaller l'ancienne par ajout/suppression de programmes


Message édité par Mr_Jo le 26-12-2007 à 18:08:44

---------------
[:mr_jo]
n°448332
synthexe
Anti-Malware Power
Posté le 26-12-2007 à 21:20:33  profilanswer
 

Bonsoir à tous et joyeux noyel :hello:

 

Pour en rajouter une couche :

 

TU N'AS PAS D'ANTIVIRUS !!!!
Télécharge et installe Antivir/Avira


Faire ce que conseille Mr_JO, c'est à dire, installer un firewall au plus vite.
Et tout le reste ...
En plus de ça, ajoute ceci (tu sembles etre infecté par Vundo/Virtumnode) :

 
  • Ferme/Désactive ton antivirus (important), avant de télécharger et lancer Combofix.
  • Télécharge combofix.exe (par sUBs) sur ton Bureau : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Double clique combofix.exe et suis les invites.
  • Ne pas cliquer sur la fenetre de commande de Combofix pendant le scan, cela peut perturber l'outil.
  • Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.


===========================

 

Postes les rapports AVG-AS, Clean option1, Combofix et un nouveau hijackthis.

 

Bonne soirée/nuitée ;)


Message édité par synthexe le 26-12-2007 à 21:20:57

---------------
¤¤ Kaspersky WebScanner ¤¤¤¤¤¤¤ AVG AntiSpyware ¤¤
¤¤¤¤¤¤ CCleaner ¤¤¤¤¤¤
n°448427
vis4r
Posté le 29-12-2007 à 19:02:19  profilanswer
 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:01, on 2007-12-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
D:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\aideonline.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - d:\Program Files\FlashGet\jccatch.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {8A341D0C-0D60-4D67-86D9-14609D219187} - C:\WINDOWS\system32\mljjg.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {A74F3FC3-CC9A-4D4C-AFB5-B56F0CAA445D} - C:\WINDOWS\system32\jkkihij.dll (file missing)
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - d:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "d:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [BMff3cfda5] Rundll32.exe "C:\WINDOWS\system32\vlywgnxc.dll",s
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Tout télécharger avec FlashGet - D:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Télécharger avec FlashGet - D:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - d:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - d:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: bw+0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {8B2615DF-B7B5-4395-A37F-45E679D50D6E} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: jkkihij - jkkihij.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
 
--
End of file - 17554 bytes
 
 
 
====================================================
 
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
 
 + Créé à: 15:25:12 27/12/2007
 
 + Résultat de l'analyse:  
 
 
 
C:\Documents and Settings\Visar\Local Settings\Temp\cmdinst.exe -> Adware.CommAd : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\TXVyYXRp\asappsrv.dll -> Adware.CommAd : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\TXVyYXRp\command.exe -> Adware.CommAd : Nettoyé et sauvegardé (mise en quarantaine).
HKLM\SOFTWARE\Classes\WR -> Adware.Generic : Nettoyé et sauvegardé (mise en quarantaine).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo -> Adware.Generic : Nettoyé et sauvegardé (mise en quarantaine).
D:\Program Files\PpStream Fr\PSNetwork.dll -> Adware.Wsear : Nettoyé et sauvegardé (mise en quarantaine).
D:\Program Files\PpStream Fr\xpsp2\XPSP2Patch.exe.bak -> Backdoor.Hupigon : Nettoyé et sauvegardé (mise en quarantaine).
D:\GBA\Flash_Player_Install.exe -> Downloader.Agent.bks : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\rf1\roblcidr31z.exe -> Downloader.Small.buy : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\Trend Micro\HijackThis\backups\backup-20071222-223134-615.dll -> Not-A-Virus.Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\Online Services\hoqezib83122.dll -> Not-A-Virus.Adware.TTC : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Albina\Bureau\installer_fr.exe -> Not-A-Virus.Downloader.Win32.WinFixer.au : Nettoyé et sauvegardé (mise en quarantaine).
C:\Program Files\Network Monitor\netmon.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Nettoyé et sauvegardé (mise en quarantaine).
:mozilla.247:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.248:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@247realmedia[2].txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.230:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.305:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.306:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.33:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.34:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.35:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.36:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.37:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.38:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.39:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.40:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.41:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.42:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.43:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.44:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.45:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.46:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.47:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.48:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.49:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.50:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.51:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.52:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.538:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.646:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.722:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.914:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.923:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@clubmed.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@msnaccountservices.112.2o7[2].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@notrefamille.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@sfr.122.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.373:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.374:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.375:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@3.adbrite[2].txt -> TrackingCookie.Adbrite : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@adbrite[2].txt -> TrackingCookie.Adbrite : Nettoyé.
C:\Documents and Settings\Visar\Local Settings\Temp\Cookies\visar@adbrite[2].txt -> TrackingCookie.Adbrite : Nettoyé.
C:\Documents and Settings\Visar\Local Settings\Temp\Cookies\visar@ads.adbrite[2].txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.405:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Adrevolver : Nettoyé.
:mozilla.485:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.486:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@adtech[2].txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.418:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.419:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.420:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.421:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.422:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.511:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.25:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\Visar\Cookies\visar@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.17:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.882:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\Visar\Cookies\visar@bluestreak[2].txt -> TrackingCookie.Bluestreak : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@burstnet[2].txt -> TrackingCookie.Burstnet : Nettoyé.
:mozilla.701:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.702:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.703:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.704:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.705:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.467:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Casinotropez : Nettoyé.
:mozilla.468:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Casinotropez : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@promo.casinotropez[2].txt -> TrackingCookie.Casinotropez : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@centrport[1].txt -> TrackingCookie.Centrport : Nettoyé.
:mozilla.447:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.448:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.451:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.359:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Connextra : Nettoyé.
:mozilla.363:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Connextra : Nettoyé.
:mozilla.364:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Connextra : Nettoyé.
:mozilla.365:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Connextra : Nettoyé.
:mozilla.366:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Connextra : Nettoyé.
:mozilla.367:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Connextra : Nettoyé.
:mozilla.368:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Connextra : Nettoyé.
:mozilla.369:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Connextra : Nettoyé.
:mozilla.370:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Connextra : Nettoyé.
:mozilla.371:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Connextra : Nettoyé.
:mozilla.372:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Connextra : Nettoyé.
:mozilla.698:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Connextra : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@connextra[1].txt -> TrackingCookie.Connextra : Nettoyé.
:mozilla.706:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.707:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.708:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.709:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.710:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Dealtime : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@dealtime[1].txt -> TrackingCookie.Dealtime : Nettoyé.
:mozilla.13:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
C:\Documents and Settings\Visar\Cookies\visar@doubleclick[2].txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.711:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Enhance : Nettoyé.
:mozilla.32:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@estat[1].txt -> TrackingCookie.Estat : Nettoyé.
C:\Documents and Settings\Visar\Cookies\visar@estat[1].txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.392:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.393:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Euroclick : Nettoyé.
:mozilla.220:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.221:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.137:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.219:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.336:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.339:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
:mozilla.597:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.600:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.668:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.961:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.962:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.756:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.757:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Imrworldwide : Nettoyé.
:mozilla.664:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Information : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@ivwbox[2].txt -> TrackingCookie.Ivwbox : Nettoyé.
:mozilla.23:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@auto.search.msn[1].txt -> TrackingCookie.Msn : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@ie.search.msn[1].txt -> TrackingCookie.Msn : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@search.msn[1].txt -> TrackingCookie.Msn : Nettoyé.
:mozilla.89:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.90:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
:mozilla.92:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Overture : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@overture[2].txt -> TrackingCookie.Overture : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@perf.overture[1].txt -> TrackingCookie.Overture : Nettoyé.
C:\Documents and Settings\Visar\Cookies\visar@overture[1].txt -> TrackingCookie.Overture : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@ads.planetactive[1].txt -> TrackingCookie.Planetactive : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.969:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Qksrv : Nettoyé.
:mozilla.970:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Qksrv : Nettoyé.
:mozilla.323:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Questionmarket : Nettoyé.
:mozilla.324:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Questionmarket : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@questionmarket[1].txt -> TrackingCookie.Questionmarket : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@realmedia[1].txt -> TrackingCookie.Realmedia : Nettoyé.
:mozilla.663:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Revenue : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@revsci[2].txt -> TrackingCookie.Revsci : Nettoyé.
:mozilla.238:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.239:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.240:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.241:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.242:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.243:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.244:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.639:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.774:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.904:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.905:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.913:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.958:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.973:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.974:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.54:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.55:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.56:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.57:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.58:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.59:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@smartadserver[2].txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.490:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.491:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.492:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.493:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.494:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.495:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.496:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.497:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.498:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.499:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.500:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.501:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.502:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.503:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.504:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.505:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.506:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.507:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.508:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.509:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@statcounter[1].txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.868:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Tacoda : Nettoyé.
:mozilla.869:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Tacoda : Nettoyé.
:mozilla.870:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Tacoda : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@tacoda[1].txt -> TrackingCookie.Tacoda : Nettoyé.
:mozilla.64:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.65:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.66:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.67:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.196:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.197:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.198:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Visar\Cookies\visar@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Visar\Local Settings\Temp\Cookies\visar@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@m.webtrends[2].txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.537:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@count.xhit[2].txt -> TrackingCookie.Xhit : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@yadro[2].txt -> TrackingCookie.Yadro : Nettoyé.
:mozilla.149:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.150:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.151:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.153:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.154:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.155:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.156:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.157:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
C:\Documents and Settings\Albina\Cookies\albina@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.226:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
:mozilla.227:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
:mozilla.228:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
:mozilla.229:C:\Documents and Settings\Albina\Application Data\Mozilla\Firefox\Profiles\xwlvrwiv.default\cookies.txt -> TrackingCookie.Zedo : Nettoyé.
C:\Documents and Settings\Albina\Local Settings\Temp\_PA25\img_369.jpg-albina92600@hotmail.fr.com -> Trojan.Pakes.btu : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Albina\Local Settings\Temp\_PA794\img_369.jpg-albina92600@hotmail.fr.com -> Trojan.Pakes.btu : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Albina\Local Settings\Temp\_PA846\img_369.jpg-albina92600@hotmail.fr.com -> Trojan.Pakes.btu : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\TXVyYXRp\nrpVsrlD.vbs -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\system32\wnsapiicomsv32.exe -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\uninstall_nmon.vbs -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Albina\Menu Démarrer\Programmes\Démarrage\ctfmon.exe -> Trojan.VB.aqt : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\Visar\Menu Démarrer\Programmes\Démarrage\ctfmon.exe -> Trojan.VB.aqt : Nettoyé et sauvegardé (mise en quarantaine).
C:\Recycled\Recycled\ctfmon.exe -> Trojan.VB.aqt : Nettoyé et sauvegardé (mise en quarantaine).
C:\Recycled\ctfmon.exe -> Trojan.VB.aqt : Nettoyé et sauvegardé (mise en quarantaine).
C:\WINDOWS\pss\ctfmon.exeStartup -> Trojan.VB.aqt : Nettoyé et sauvegardé (mise en quarantaine).
D:\Recycled\ctfmon.exe -> Trojan.VB.aqt : Nettoyé et sauvegardé (mise en quarantaine).
 
 
Fin du rapport
 
 
=======================================================
 
 27/12/2007 a 15:45:12,45  
 
*** Recherche des fichiers dans C:  
C:\autorun.inf FOUND  
C:\StubInstaller.exe FOUND  
 
*** Recherche des fichiers dans C:\WINDOWS\  
 
*** Recherche des fichiers dans C:\WINDOWS\system32  
C:\WINDOWS\system32\atmtd.dll._ FOUND  
C:\WINDOWS\system32\mcrh.tmp FOUND  
C:\WINDOWS\system32\atmtd.dll FOUND  
"C:\WINDOWS\Downloaded Program Files\CONFLICT.1" FOUND  
 
*** Recherche des fichiers dans C:\Program Files  
"C:\Program Files\Fichiers communs\Yazzle????OinAdmin.exe" FOUND  
"C:\Program Files\Network Monitor\" FOUND  
"C:\Program Files\Outerinfo" FOUND  
*** Fin du rapport !  
 
 
 
================================================
 
 
 
Combofix a fait apparaitre un ficher zip "catchme" , je ne sais pas quoi en faire.  
Mais depuis tout ce grand nettoyage, j'ai des problèmes:  
-l'ordi est plus lent, mais c'est compréhensible car ZA prend des ressources jusque la libre ^^  
-les pages internet sur firefox ou explorer sont tres lentes a charger, voir ne se chargent pas entièrements!  
-il m'était impossible de poster sur le forum, je suis sur l'ordi portable du papa =S . Lorsque je voulais valider mon message une page blanche apparaisait.  
-Je ne peux pas regarder mes mails depuis explorer, hotmail ne veut pas ouvrir ma boite, enfin certaines fois oui d'autre non ...  
 
 
Bonne soirée a tous !


---------------
-= V!s4R =-
n°448455
Mr_Jo
Posté le 30-12-2007 à 11:34:02  profilanswer
 

Citation :

Mais depuis tout ce grand nettoyage, j'ai des problèmes:


 
Normal, ton PC n'est pas encore nettoyé.
le dossier quarantaine de AVG n'est pas vidé.
le rapport clean indique qu'il faudra passer à l'étape 2
En ce qui concerne Combo,  
attends le retour de synthexe pour continuer , ne bricole pas.
 
Installe l'antivirus comme demandé.
 
installe aussi CCleaner:
http://filehippo.com/download_ccleaner/  (téléchargement sur la partie verte à droite)
nota: lors du nettoyage, onglet applications, décocher Utilitaires car il supprime des mises à jour.
ATF cleaner (ne s'installe pas ) permet de nettoyer rapidement les dossiers temporaires.
 
 
 


---------------
[:mr_jo]
n°448461
synthexe
Anti-Malware Power
Posté le 30-12-2007 à 13:06:05  profilanswer
 

Bonjour :hello:
 
Il manque le rapport de ComboFix, pourrais-je l'avoir stp ?
Rien qu'a la vue du rapport AVG-AS, on peut s'apercevoir que tu étais TRES vérolé ...
Merci pour les précisions sur les symptomes.
 
Poste le rapport de ComboFix stp.
 
Bon dimanche ;)


---------------
¤¤ Kaspersky WebScanner ¤¤¤¤¤¤¤ AVG AntiSpyware ¤¤
¤¤¤¤¤¤ CCleaner ¤¤¤¤¤¤
n°448476
vis4r
Posté le 30-12-2007 à 15:20:27  profilanswer
 

ComboFix 07-12-21.4 - Visar 2007-12-30 15:13:25.2 - NTFSx86
Running from: C:\Documents and Settings\Visar\Bureau\ComboFix.exe
.
 
(((((((((((((((((((((((((((((   Fichiers cr‚‚s 2007-11-28 to 2007-12-30  ))))))))))))))))))))))))))))))))))))
.
 
2007-12-29 19:05 . 2007-12-29 19:05 123 -r-hs---- C:\autorun.inf
2007-12-27 15:45 . 2007-12-27 15:45 2,007,722 --a------ C:\upload_moi_41A63901.tar.gz
2007-12-27 13:35 . 2007-12-27 13:35 <REP> d-------- C:\Program Files\MSXML 6.0
2007-12-27 13:07 . 2007-12-27 13:07 <REP> d-------- C:\Program Files\MSXML 4.0
2007-12-27 12:33 . 2007-07-30 19:19 38,232 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2007-12-27 12:33 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2007-12-27 12:33 . 2007-07-30 19:19 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2007-12-27 12:33 . 2007-07-30 19:18 21,336 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2007-12-27 11:57 . 2007-06-21 21:54 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-12-26 23:17 . 2007-12-26 23:17 <REP> d-------- C:\Documents and Settings\Visar\Application Data\Grisoft
2007-12-26 23:14 . 2007-12-26 23:14 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-26 23:14 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-26 22:47 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-26 22:09 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2007-12-26 22:09 . 2001-08-23 17:04 12,288 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2007-12-26 22:07 . 2007-12-26 22:07 110,656 --a------ C:\WINDOWS\system32\vlywgnxc.dll
2007-12-26 22:07 . 2007-12-30 13:11 26,855 --a------ C:\WINDOWS\BMff3cfda5.xml
2007-12-26 22:07 . 2007-12-30 15:24 22 --a------ C:\WINDOWS\pskt.ini
2007-12-26 14:50 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2007-12-26 14:50 . 2001-08-17 22:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys
2007-12-25 19:45 . 2007-12-26 22:07 1,026,915 ---hs---- C:\WINDOWS\system32\thtkhawc.ini
2007-12-24 15:28 . 2007-12-25 19:44 1,019,102 ---hs---- C:\WINDOWS\system32\xdrkhxwi.ini
2007-12-23 17:14 . 2007-12-23 17:14 143 --a------ C:\WINDOWS\system32\mcrh.tmp
2007-12-23 11:37 . 2007-12-24 15:28 992,776 ---hs---- C:\WINDOWS\system32\pfmsoyct.ini
2007-12-22 22:24 . 2007-12-22 22:24 <REP> d-------- C:\Program Files\Trend Micro
2007-12-22 22:20 . 2007-12-27 15:24 <REP> d-------- C:\WINDOWS\system32\rf1
2007-12-22 22:20 . 2007-12-22 22:20 <REP> d-------- C:\WINDOWS\system32\ey2
2007-12-22 22:20 . 2007-12-22 22:20 <REP> d-------- C:\WINDOWS\system32\ardCo01
2007-12-22 22:20 . 2007-12-22 22:20 <REP> d-------- C:\Temp\cEeer12
2007-12-22 22:13 . 2004-03-09 00:00 609,824 --a------ C:\WINDOWS\system32\COMCTL32.ocx
2007-12-22 22:13 . 2004-03-09 00:00 212,240 --a------ C:\WINDOWS\system32\richtx32.OCX
2007-12-22 22:13 . 2004-03-09 00:00 124,688 --a------ C:\WINDOWS\system32\MSWINSCK.ocx
2007-12-22 15:57 . 2007-12-22 15:57 <REP> d-------- C:\Program Files\SystemRequirementsLab
2007-12-22 15:57 . 2007-12-22 15:57 <REP> d-------- C:\Documents and Settings\Visar\Application Data\SystemRequirementsLab
2007-11-24 11:26 . 2007-11-24 11:26 <REP> d-------- C:\Program Files\iPod
2007-11-17 11:40 . 2007-11-17 11:40 <REP> d-------- C:\Program Files\DivX
2007-11-12 16:18 . 2007-11-12 16:18 <REP> d-------- C:\Documents and Settings\Albina\Application Data\Motive
2007-11-09 19:51 . 2007-11-09 19:51 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MotiveSysIDs
2007-11-09 19:50 . 2005-04-05 16:20 69,632 --a------ C:\WINDOWS\system32\MCCDevice.dll
2007-11-09 19:50 . 2005-03-25 17:27 6,048 --a------ C:\WINDOWS\system32\MCC16.dll
2007-11-09 19:22 . 2007-11-09 19:22 <REP> d-------- C:\WINDOWS\Motive
2007-11-09 19:22 . 2007-11-09 19:22 <REP> d-------- C:\Program Files\Motive
2007-11-09 19:22 . 2007-11-09 19:22 <REP> d-------- C:\Program Files\Fichiers communs\Motive
2007-11-09 19:22 . 2007-11-09 19:22 <REP> d-------- C:\Program Files\Common Files
2007-11-09 19:22 . 2007-11-09 19:22 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Motive
2007-11-09 19:22 . 2003-10-22 09:54 81,920 --a------ C:\WINDOWS\system32\W32n50.dll
2007-11-09 19:22 . 2003-10-22 09:54 17,162 --a------ C:\WINDOWS\system32\Pcandis5.sys
2007-11-09 19:22 . 2003-10-22 09:54 16,848 --a------ C:\WINDOWS\system32\Pcandis4.sys
2007-11-09 19:22 . 2003-10-22 09:54 16,073 --a------ C:\WINDOWS\system32\Pcandis3.vxd
2007-11-09 19:18 . 2007-11-09 19:18 <REP> d-------- C:\Program Files\BroadJump
2007-11-09 19:14 . 2007-11-09 19:51 <REP> d-------- C:\Program Files\Club-Internet
2007-11-09 19:14 . 2002-02-14 03:53 6,345 -ra------ C:\WINDOWS\system32\DevMngr.vxd
 
.
((((((((((((((((((((((((((((((((((   Compte-rendu de Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-29 19:41 --------- d-----w C:\Documents and Settings\Albina\Application Data\OpenOffice.org2
2007-12-27 15:23 --------- d-----w C:\Program Files\PowerArchiver
2007-12-27 14:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-26 22:07 --------- d-----w C:\Program Files\Windows Live Safety Center
2007-12-26 21:51 --------- d-----w C:\Program Files\Java
2007-12-22 21:13 --------- d-----w C:\Program Files\MSN Messenger
2007-11-24 10:21 --------- d-----w C:\Program Files\Apple Software Update
2007-11-15 20:46 --------- d-----w C:\Program Files\DLDIrc
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-07 20:54 --------- d-----w C:\Documents and Settings\Visar\Application Data\Apple Computer
2007-10-28 12:26 0 ----a-w C:\Documents and Settings\Visar\dlditool.exe
2006-04-15 12:16 5 -c--a-w C:\Documents and Settings\Visar\getfile.dat
.
 
(((((((((((((((((((((((((((((((((   Point de chargement Reg   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2006-09-30 10:46]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:55]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-05 13:00 C:\WINDOWS\system32\rundll32.exe]
"QuickTime Task"="D:\Program Files\K-Lite Codec Pack\QuickTime\QTTask.exe" [2007-10-19 20:16]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"ZoneAlarm Client"="d:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]
"BMff3cfda5"="Rundll32.exe" [2004-08-05 13:00 C:\WINDOWS\system32\rundll32.exe]
 
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00]
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^LE COMPAGNON CLUB.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\LE COMPAGNON CLUB.lnk
backup=C:\WINDOWS\pss\LE COMPAGNON CLUB.lnkCommon Startup
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Visar^Menu Démarrer^Programmes^Démarrage^BitTorrent.lnk]
path=C:\Documents and Settings\Visar\Menu Démarrer\Programmes\Démarrage\BitTorrent.lnk
backup=C:\WINDOWS\pss\BitTorrent.lnkStartup
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Visar^Menu Démarrer^Programmes^Démarrage^Club Internet.lnk]
path=C:\Documents and Settings\Visar\Menu Démarrer\Programmes\Démarrage\Club Internet.lnk
backup=C:\WINDOWS\pss\Club Internet.lnkStartup
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Visar^Menu Démarrer^Programmes^Démarrage^ctfmon.exe]
path=C:\Documents and Settings\Visar\Menu Démarrer\Programmes\Démarrage\ctfmon.exe
backup=C:\WINDOWS\pss\ctfmon.exeStartup
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Visar^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.1.lnk]
path=C:\Documents and Settings\Visar\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.1.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.1.lnkStartup
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Visar^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.2.lnk]
path=C:\Documents and Settings\Visar\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.2.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.2.lnkStartup
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Visar^Menu Démarrer^Programmes^Démarrage^Outil de détection de support de Cyber-shot Viewer.lnk]
path=C:\Documents and Settings\Visar\Menu Démarrer\Programmes\Démarrage\Outil de détection de support de Cyber-shot Viewer.lnk
backup=C:\WINDOWS\pss\Outil de détection de support de Cyber-shot Viewer.lnkStartup
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Visar^Menu Démarrer^Programmes^Démarrage^SKYSM.lnk]
path=C:\Documents and Settings\Visar\Menu Démarrer\Programmes\Démarrage\SKYSM.lnk
backup=C:\WINDOWS\pss\SKYSM.lnkStartup
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Visar^Menu Démarrer^Programmes^Démarrage^Stardock ObjectDock.lnk]
path=C:\Documents and Settings\Visar\Menu Démarrer\Programmes\Démarrage\Stardock ObjectDock.lnk
backup=C:\WINDOWS\pss\Stardock ObjectDock.lnkStartup
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Visar^Menu Démarrer^Programmes^Démarrage^Y'z ToolBar.lnk]
path=C:\Documents and Settings\Visar\Menu Démarrer\Programmes\Démarrage\Y'z ToolBar.lnk
backup=C:\WINDOWS\pss\Y'z ToolBar.lnkStartup
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
   d:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe /minimized
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
   D:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
   C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
2003-01-27 17:16 376912 --a------ C:\Program Files\BroadJump\Client Foundation\CFD.exe
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cmaudio]
   RunDll32 cmicnfg.cpl,CMICtrlWnd
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
2004-08-05 13:00 15360 --a------ C:\WINDOWS\system32\ctfmon.exe
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
   d:\Program Files\DAEMON Tools\daemon.exe -lang 1033
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
   C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
   C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe -start
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-11-02 18:36 267048 --a------ D:\Program Files\iTunes\iTunesHelper.exe
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KAVPersonal50]
   C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe /minimize
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanceurEasyBox]
   d:\Program Files\EasyBox\EasyBox.exe -AutoStart
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
2007-01-14 20:00 36864 --a------ C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
2006-10-31 01:03 284184 --a--c--- C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
   C:\Program Files\Logitech\QuickCam10\QuickCam10.exe /hide
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
2006-11-15 22:01 244512 --a--c--- C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
2006-04-21 15:41 438359 --a------ C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
   C:\Program Files\Messenger\msmsgs.exe /background
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
   RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
   nwiz.exe /install
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pando]
   D:\Program Files\Pando Networks\Pando\pando.exe /Minimized
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PKR Pal]
   D:\Program Files\PKR\pkrpal.exe -osboot
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
   D:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe -atboottime
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RocketDock]
2007-03-18 23:05 630784 --a------ C:\Program Files\RocketDock\RocketDock.exe
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StandardInstall]
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
   C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
   C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe  -osboot
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
   C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 -reboot 1
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VC8Player]
   d:\Program Files\Virtual CD v8\System\VC8Play.exe
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Virtual PDF Printer]
   C:\Program Files\Virtual PDF Printer\VirtualPDFPrinter.exe
   
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zone Labs Client]
2007-06-21 21:54 919016 --a------ d:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
 
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PDSched"=2 (0x2)
"PDEngine"=3 (0x3)
"cmdService"=2 (0x2)
"usnjsvc"=3 (0x3)
"AVG Anti-Spyware Guard"=2 (0x2)
 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Cmaudio"=RunDll32 cmicnfg.cpl,CMICtrlWnd
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 
R0 Defrag32b;Defrag32Boot;C:\WINDOWS\system32\drivers\Defrag32b.sys [2005-06-28 09:17]
R2 Defrag32;Defrag32;C:\WINDOWS\system32\drivers\Defrag32.sys [2005-06-28 09:17]
R2 UxTuneUp;Extension de conception TuneUp;C:\WINDOWS\System32\svchost.exe -k netsvcs []
R2 Vcs;Vcs support;C:\WINDOWS\system32\Drivers\Vcs.sys [2004-11-14 13:01]
S3 Camdrv30;Philips ToUcam XS;C:\WINDOWS\system32\Drivers\camdrv30.sys [2001-08-17 23:04]
S3 RivaTuner32;RivaTuner32;C:\Program Files\RivaTuner v2.01\RivaTuner32.sys [2007-04-29 18:05]
S4 PDSched;PDScheduler;"C:\Program Files\Raxco\PerfectDisk\PDSched.exe" [2005-06-28 13:07]
 
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
UxTuneUp
 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\Recycled\ctfmon.exe
\Shell\Open(&O)\command - C:\Recycled\Recycled\ctfmon.exe
 
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(&0)\command - D:\Recycled\ctfmon.exe
 
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-12-29 11:59:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-21 16:24:20 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
 
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-30 15:25:15
Windows 5.1.2600 Service Pack 2 NTFS
 
scanning hidden processes ...
 
scanning hidden autostart entries ...
 
scanning hidden files ...
 
scan completed successfully  
hidden files: 0  
 
**************************************************************************
.
Completion time: 2007-12-30 15:27:04 - machine was rebooted [Visar]
.
2007-12-27 12:46:34 --- E O F ---  
 
 
 
===============================================
 
 
voilà le rapport combofix, je vous remercie pr l'interet que vous portez a mon problème.
 
 
Bon dimanche :D
 
 
PS: problème en partie réglé concernant la navigation sur internet, apparament ZA bloquait les cookies.^^


Message édité par vis4r le 30-12-2007 à 15:24:10

---------------
-= V!s4R =-
n°448549
synthexe
Anti-Malware Power
Posté le 02-01-2008 à 17:26:28  profilanswer
 

Bonsoir :hello:
 
Je n'ai pas le temps de me pencher plus que ca sur le rapport ce soir ... mais je repasserais demain ou vendredi, tu as encore quelques restes ...
 
Bonne année ;)


---------------
¤¤ Kaspersky WebScanner ¤¤¤¤¤¤¤ AVG AntiSpyware ¤¤
¤¤¤¤¤¤ CCleaner ¤¤¤¤¤¤
n°448622
synthexe
Anti-Malware Power
Posté le 04-01-2008 à 12:35:56  profilanswer
 

Bonjour :hello:

 
  • Crée un fichier avec le bloc-note, saisie le contenu de la boite ci-dessous (en gras) :


File::
C:\autorun.inf
C:\WINDOWS\system32\vlywgnxc.dll
C:\WINDOWS\system32\thtkhawc.ini
C:\WINDOWS\system32\xdrkhxwi.ini
C:\WINDOWS\system32\pfmsoyct.ini

 

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BMff3cfda5"=-

 


  • Sauvegarde le fichier avec le nom suivant : CFScript.txt
  • Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture


http://img.photobucket.com/albums/v666/sUBs/CFScript.gif

  • Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
  • Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

Ne touche à rien tant que le scan n'est pas terminé.

  • Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
  • Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt


=================================

 

Rends toi sur ce lien : [color=blue]Virus Total[/color]

  • Clique sur Parcourir
  • Rends toi jusque sur ce fichier si tu le trouves :


D:\Recycled\ctfmon.exe

 
  • Clique sur Envoyer le fichier et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
  • Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
  • Lorsque l'analyse est terminée ("Situation actuelle: terminé" ), clique sur Formaté
  • Une nouvelle fenêtre de ton navigateur va apparaître
  • Clique alors sur cette image : http://perso.orange.fr/-Gof/screen/txtvt.jpg
  • Fais un clic droit sur la page, et choisis Sélectionner tout, puis copier
  • Enfin colle le résultat dans ta prochaine réponse.

Note : Peu importe le résultat, il est important de me communiquer le résultat de toute l'analyse.
Il est possible que tes outils de sécurité réagissent à l'envoi du fichier, en ce cas il te faudra ignorer les alertes.

 

==========================

 
  • Fais un scan en ligne Kaspersky
  • Clique sur Accept
  • Une barre jaune va te demander si tu acceptes d'installer le Kavwebscan_Unicode.cab, installe l'Active X.
  • clique une nouvelle fois sur "Accept"
  • Les bases de mises à jour vont s'installer, patiente un moment
  • Clique sur Next.
  • Clique sur My Computer, le scan se met en route; attends la fin du scan sans fermer la fenêtre sinon il s'arrêtera.


A la fin du scan, si des objets infectés sont découverts, clique sur Save report as... Choisis bureau et nomme le rapport "rapport Kaspersky" et dans le champ d'enregistrement, choisis "fichiers texte" enregistre alors le rapport.

 

Copie/colle l'entièreté du fichier texte ouvert, par clic droit dessus, sélectionner tout/copier.

 

Colle ce rapport dans ta réponse dans ta réponse ainsi qu'un nouveau log Hijackthis.

 

==========================

 

Poste les rapports demandés : ComboFix, VirusTotal et KasperskyOnline.

 

Bonne journée ;)


Message édité par synthexe le 04-01-2008 à 12:37:17

---------------
¤¤ Kaspersky WebScanner ¤¤¤¤¤¤¤ AVG AntiSpyware ¤¤
¤¤¤¤¤¤ CCleaner ¤¤¤¤¤¤
n°448679
vis4r
Posté le 05-01-2008 à 15:32:21  profilanswer
 

Bonjour! Voilà ce que tu m'a demandé :  
 
 
 
 
 
 
==============================================================
 
 
 
 
 
 
ComboFix 08-01-04.1 - Visar 2008-01-05 13:29:17.3 - NTFSx86
Microsoft Windows XP Professionnel  5.1.2600.2.1252.1.1036.18.219 [GMT 1:00]
Running from: C:\Documents and Settings\Visar\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Visar\Bureau\CFScript.txt
 * Created a new restore point
 
FILE
C:\autorun.inf
C:\WINDOWS\system32\pfmsoyct.ini
C:\WINDOWS\system32\thtkhawc.ini
C:\WINDOWS\system32\vlywgnxc.dll
C:\WINDOWS\system32\xdrkhxwi.ini
.
 
((((((((((((((((((((((((((((((((((((   Autres suppressions   ))))))))))))))))))))))))))))))))))))))))))))))))
.
 
C:\autorun.inf
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\pfmsoyct.ini
C:\WINDOWS\system32\thtkhawc.ini
C:\WINDOWS\system32\vlywgnxc.dll
C:\WINDOWS\system32\xdrkhxwi.ini
D:\Autorun.inf
 
.
(((((((((((((((((((((((((((((   Fichiers créés 2007-12-05 to 2008-01-05  ))))))))))))))))))))))))))))))))))))
.
 
2008-01-05 13:27 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-12-27 15:45 . 2007-12-27 15:45 2,007,722 --a------ C:\upload_moi_41A63901.tar.gz
2007-12-27 13:35 . 2007-12-27 13:35 <REP> d-------- C:\Program Files\MSXML 6.0
2007-12-27 13:07 . 2007-12-27 13:07 <REP> d-------- C:\Program Files\MSXML 4.0
2007-12-27 12:33 . 2007-07-30 19:19 38,232 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2007-12-27 12:33 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2007-12-27 12:33 . 2007-07-30 19:19 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2007-12-27 12:33 . 2007-07-30 19:18 21,336 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2007-12-27 11:57 . 2007-06-21 21:54 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2007-12-26 23:17 . 2007-12-26 23:17 <REP> d-------- C:\Documents and Settings\Visar\Application Data\Grisoft
2007-12-26 23:14 . 2007-12-26 23:14 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-26 23:14 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-26 22:47 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-26 22:09 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2007-12-26 22:09 . 2001-08-23 17:04 12,288 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2007-12-26 22:07 . 2008-01-04 23:53 26,865 --a------ C:\WINDOWS\BMff3cfda5.xml
2007-12-26 22:07 . 2008-01-05 13:29 21 --a------ C:\WINDOWS\pskt.ini
2007-12-26 14:50 . 2001-08-17 22:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2007-12-26 14:50 . 2001-08-17 22:02 9,600 --a--c--- C:\WINDOWS\system32\dllcache\hidusb.sys