de l'aide pour encore et encore winantivirus et ses compagnons merci !! | |
» Liste des Forums » Virus, troyens, etc... » Discussion |
| |
|


- Logfile of HijackThis v1.99.1
- Scan saved at 19:48:22, on 03/03/2007
- Platform: Windows XP SP2 (WinNT 5.01.2600)
- MSIE: Internet Explorer v7.00 (7.00.6000.16414)
- Running processes:
- C:\WINDOWS\System32\smss.exe
- C:\WINDOWS\system32\winlogon.exe
- C:\WINDOWS\system32\services.exe
- C:\WINDOWS\system32\lsass.exe
- C:\WINDOWS\system32\Ati2evxx.exe
- C:\WINDOWS\system32\svchost.exe
- C:\WINDOWS\System32\svchost.exe
- C:\WINDOWS\system32\spoolsv.exe
- C:\WINDOWS\system32\Ati2evxx.exe
- C:\WINDOWS\Explorer.EXE
- C:\WINDOWS\System32\FTRTSVC.exe
- C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
- C:\WINDOWS\system32\svchost.exe
- C:\WINDOWS\system32\ctfmon.exe
- C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
- C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
- C:\WINDOWS\SOUNDMAN.EXE
- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
- C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
- C:\WINDOWS\system32\LVCOMSX.EXE
- C:\Program Files\Logitech\Video\LogiTray.exe
- C:\Program Files\QuickTime\qttask.exe
- C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
- C:\Program Files\Logitech\iTouch\iTouch.exe
- C:\Program Files\SPAMfighter\SFAgent.exe
- C:\Program Files\Logitech\Video\FxSvr2.exe
- C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
- C:\PROGRA~1\Wanadoo\ComComp.exe
- C:\Program Files\Samsung\Digimax Viewer 1.0\DigimaxViewer.exe
- C:\PROGRA~1\Wanadoo\Toaster.exe
- C:\PROGRA~1\Wanadoo\Inactivity.exe
- C:\PROGRA~1\Wanadoo\PollingModule.exe
- C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
- C:\Program Files\Smart Link\IMTrans\IMTrans.exe
- C:\PROGRA~1\Wanadoo\Watch.exe
- C:\Program Files\Windows Defender\MsMpEng.exe
- C:\Program Files\Windows Defender\MSASCui.exe
- c:\program files\internet explorer\iexplore.exe
- C:\Program Files\Windows Media Player\wmplayer.exe
- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
- C:\DOCUME~1\Tony\LOCALS~1\Temp\Répertoire temporaire 4 pour hijackthis.zip\HijackThis.exe
- R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
- R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
- R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
- R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
- R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
- R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
- O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar.02.5000.1021\fr\msntb.dll
- O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
- O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
- O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
- O4 - HKLM\..\Run: [VirusKeeper] C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
- O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
- O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
- O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
- O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\ebbryupd.dll",setvm
- O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -masquer
- O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
- O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
- O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
- O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
- O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
- O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
- O9 - Extra button: PokerFROnline - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\POKERF~1\client.exe
- O9 - Extra button: Betway.com Poker - {4CBB5C71-1BA0-49ca-93CD-159AF8AA0CC9} - C:\Program Files\BetwayMPP\MPPoker.exe
- O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
- O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
- O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\WINDOWS\system32\shdocvw.dll
- O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
- O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
- O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/2.0.1.11/cfweb_activex.camfrogweb.com-advanced-2.0.1.11_instmodule.exe
- O16 - DPF: {2472DCCC-68CE-49DA-AA81-E7E6D83C1DFA} - http://acces.blonde.com/package/op/PackageHtmlCab.CAB
- O16 - DPF: {FD40EC41-D860-4579-8BA4-52671A45C71C} (AxHtChat Class) - http://images.goa.com/it/Woo2/fr/chat/nPaxChat.cab
- O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
- O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
- O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
- O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
- O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
- O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
- O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\Intel 32\IDriverT.exe
- O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


- ---------------------------------------------------------
- AVG Anti-Spyware - Rapport d'analyse
- ---------------------------------------------------------
- + Créé à: 20:34:48 03/03/2007
- + Résultat de l'analyse:
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP473\A0120389.exe -> Adware.180Solutions : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP429\A0114574.exe -> Adware.Altnet : Ignoré.
- C:\Documents and Settings\Tony\Bureau\fichiers reçus\Everest_Poker.net.exe -> Adware.Casino : Ignoré.
- C:\Documents and Settings\Tony\Bureau\fichiers reçus\Poker770.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP406\A0113345.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP424\A0114244.old -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP424\A0114261.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP429\A0114485.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP429\A0114562.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP430\A0114610.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP430\A0114634.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP432\A0114672.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP433\A0114736.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP433\A0114754.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP438\A0114894.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP441\A0116034.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP441\A0116056.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP444\A0117309.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP444\A0118326.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP445\A0118347.exe -> Adware.Casino : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP445\A0118358.exe -> Adware.Casino : Ignoré.
- C:\WINDOWS\Poker 770 setup.exe -> Adware.Casino : Ignoré.
- HKLM\SOFTWARE\Classes\CLSID\{43F7497C-7687-4DEA-A057-F21BD81BC896} -> Adware.Generic : Ignoré.
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{43F7497C-7687-4DEA-A057-F21BD81BC896} -> Adware.Generic : Ignoré.
- HKU\S-1-5-21-1935655697-1500820517-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{43F7497C-7687-4DEA-A057-F21BD81BC896} -> Adware.Generic : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP487\A0126296.dll -> Adware.Virtumonde : Ignoré.
- C:\WINDOWS\system32\__delete_on_reboot__e_f_c_d_c_a_b_._d_l_l_ -> Adware.Virtumonde : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP474\A0120609.exe -> Adware.WinFixer : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP474\A0120627.exe -> Adware.WinFixer : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP474\A0120623.exe -> Not-A-Virus.Downloader.Win32.WinFixer.m : Ignoré.
- C:\WINDOWS\Downloaded Program Files\UDC6V_0001_D19M0709NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.m : Ignoré.
- C:\Documents and Settings\Tony\Cookies\tony@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Ignoré.
- C:\Documents and Settings\Tony\Cookies\tony@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignoré.
- C:\Documents and Settings\Tony\Cookies\tony@findwhat[1].txt -> TrackingCookie.Findwhat : Ignoré.
- C:\Documents and Settings\Tony\Cookies\tony@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignoré.
- C:\Documents and Settings\Tony\Cookies\tony@overture[1].txt -> TrackingCookie.Overture : Ignoré.
- C:\Documents and Settings\Tony\Cookies\tony@realmedia[1].txt -> TrackingCookie.Realmedia : Ignoré.
- C:\Documents and Settings\Tony\Cookies\tony@weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
- C:\System Volume Information\_restore{661F2BC8-1B52-4FB4-AFE5-8AC4F8EA4AFC}\RP486\A0126116.dll -> Trojan.Agent.acl : Ignoré.
- C:\WINDOWS\Downloaded Program Files\PackageHtml.dll -> Trojan.Dialer.qu : Ignoré.
- Fin du rapport


- Logfile of HijackThis v1.99.1
- Scan saved at 12:55:38, on 04/03/2007
- Platform: Windows XP SP2 (WinNT 5.01.2600)
- MSIE: Internet Explorer v7.00 (7.00.6000.16414)
- Running processes:
- C:\WINDOWS\System32\smss.exe
- C:\WINDOWS\system32\winlogon.exe
- C:\WINDOWS\system32\services.exe
- C:\WINDOWS\system32\lsass.exe
- C:\WINDOWS\system32\Ati2evxx.exe
- C:\WINDOWS\system32\svchost.exe
- C:\Program Files\Windows Defender\MsMpEng.exe
- C:\WINDOWS\System32\svchost.exe
- C:\WINDOWS\system32\spoolsv.exe
- C:\WINDOWS\system32\Ati2evxx.exe
- C:\WINDOWS\Explorer.EXE
- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
- C:\WINDOWS\System32\FTRTSVC.exe
- C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
- C:\WINDOWS\system32\svchost.exe
- C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
- C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
- C:\WINDOWS\SOUNDMAN.EXE
- C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
- C:\Program Files\Logitech\iTouch\iTouch.exe
- C:\Program Files\SPAMfighter\SFAgent.exe
- C:\Program Files\Windows Defender\MSASCui.exe
- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
- C:\WINDOWS\system32\ctfmon.exe
- C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
- C:\PROGRA~1\Wanadoo\ComComp.exe
- C:\PROGRA~1\Wanadoo\Toaster.exe
- C:\PROGRA~1\Wanadoo\Inactivity.exe
- C:\PROGRA~1\Wanadoo\PollingModule.exe
- C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
- C:\PROGRA~1\Wanadoo\Watch.exe
- C:\Program Files\Poker 770\casino.exe
- C:\Program Files\BetwayMPP\MPPoker.exe
- c:\program files\internet explorer\iexplore.exe
- C:\WINDOWS\system32\wuauclt.exe
- C:\PROGRA~1\MICROS~4\OFFICE11\OUTLOOK.EXE
- C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
- C:\DOCUME~1\Tony\LOCALS~1\Temp\Répertoire temporaire 6 pour hijackthis.zip\HijackThis.exe
- R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
- R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
- R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
- R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
- R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
- R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
- O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar.02.5000.1021\fr\msntb.dll
- O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
- O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
- O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
- O4 - HKLM\..\Run: [VirusKeeper] C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
- O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
- O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
- O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
- O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -masquer
- O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
- O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
- O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
- O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
- O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
- O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
- O9 - Extra button: PokerFROnline - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\POKERF~1\client.exe
- O9 - Extra button: Betway.com Poker - {4CBB5C71-1BA0-49ca-93CD-159AF8AA0CC9} - C:\Program Files\BetwayMPP\MPPoker.exe
- O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
- O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
- O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\WINDOWS\system32\shdocvw.dll
- O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
- O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
- O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/2.0.1.11/cfweb_activex.camfrogweb.com-advanced-2.0.1.11_instmodule.exe
- O16 - DPF: {FD40EC41-D860-4579-8BA4-52671A45C71C} (AxHtChat Class) - http://images.goa.com/it/Woo2/fr/chat/nPaxChat.cab
- O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
- O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
- O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
- O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
- O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
- O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
- O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\Intel 32\IDriverT.exe
- O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


- Logfile of HijackThis v1.99.1
- Scan saved at 16:07:12, on 04/03/2007
- Platform: Windows XP SP2 (WinNT 5.01.2600)
- MSIE: Internet Explorer v7.00 (7.00.6000.16414)
- Running processes:
- C:\WINDOWS\System32\smss.exe
- C:\WINDOWS\system32\winlogon.exe
- C:\WINDOWS\system32\services.exe
- C:\WINDOWS\system32\lsass.exe
- C:\WINDOWS\system32\Ati2evxx.exe
- C:\WINDOWS\system32\svchost.exe
- C:\Program Files\Windows Defender\MsMpEng.exe
- C:\WINDOWS\System32\svchost.exe
- C:\WINDOWS\system32\spoolsv.exe
- C:\WINDOWS\system32\Ati2evxx.exe
- C:\WINDOWS\Explorer.EXE
- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
- C:\WINDOWS\System32\FTRTSVC.exe
- C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
- C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
- C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
- C:\WINDOWS\SOUNDMAN.EXE
- C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
- C:\Program Files\Logitech\iTouch\iTouch.exe
- C:\Program Files\SPAMfighter\SFAgent.exe
- C:\Program Files\Windows Defender\MSASCui.exe
- C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
- C:\WINDOWS\system32\ctfmon.exe
- C:\WINDOWS\system32\svchost.exe
- C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
- C:\PROGRA~1\Wanadoo\ComComp.exe
- C:\PROGRA~1\Wanadoo\Toaster.exe
- C:\PROGRA~1\Wanadoo\Inactivity.exe
- C:\PROGRA~1\Wanadoo\PollingModule.exe
- C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
- c:\program files\internet explorer\iexplore.exe
- C:\DOCUME~1\Tony\LOCALS~1\Temp\Répertoire temporaire 8 pour hijackthis.zip\HijackThis.exe
- R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orange.fr/
- R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
- R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
- R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
- O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
- O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
- O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
- O4 - HKLM\..\Run: [VirusKeeper] C:\Program Files\AxBx\VirusKeeper 2007 Pro\VirusKeeper.exe
- O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
- O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
- O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
- O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -masquer
- O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
- O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
- O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
- O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
- O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
- O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
- O9 - Extra button: PokerFROnline - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\POKERF~1\client.exe
- O9 - Extra button: Betway.com Poker - {4CBB5C71-1BA0-49ca-93CD-159AF8AA0CC9} - C:\Program Files\BetwayMPP\MPPoker.exe
- O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
- O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
- O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
- O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
- O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/2.0.1.11/cfweb_activex.camfrogweb.com-advanced-2.0.1.11_instmodule.exe
- O16 - DPF: {FD40EC41-D860-4579-8BA4-52671A45C71C} (AxHtChat Class) - http://images.goa.com/it/Woo2/fr/chat/nPaxChat.cab
- O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
- O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
- O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
- O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
- O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
- O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
- O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\Intel 32\IDriverT.exe
- O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe


- Search Navipromo version 1.0.5 commencé le 05/03/2007 à 10:47:59,07
- !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
- !!! Poster ce rapport sur le forum pour le faire analyser !!!
- !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!
- Fix lancé depuis C:\Documents and Settings\Tony\Local Settings\Temporary Internet Files\Content.IE52982TK\navilog1[1]
- Mise a jour le 03.03.2007 a 23h00 by IL-MAFIOSO
- Executé en mode normal
- *** Recherche Programmes installes ***
- *** Recherche dossiers dans C:\WINDOWS ***
- *** Recherche dossiers dans C:\Program Files ***
- *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***
- *** Recherche dossiers dans C:\Documents and Settings\Tony\Application Data ***
- *** Recherche avec BlackLight Engine/F-secure ***
- BlackLight Engine est un produit de F-secure, pour + d'infos :
- http://www.f-secure.com/blacklight/blacklight_help.html
- F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
- ======================================
- Copyright 2005-2006 F-Secure Corporation. All rights reserved.
- This is a beta version. It will expire on 1st of April, 2007.
- Version information: 2.2.1055.
- [+] Started on 03/05/07 at 10:48:01.
- [+] Initializing ...
- [+] Starting scan, press Ctrl-C to abort.
- [+] Scanning for hidden items .....................................................................................
- [+] Scan complete.
- [+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
- [+] Exited on 03/05/07 at 10:56:47 (return code = 0).
- *** Recherche fichiers ***
- C:\WINDOWS\pack.epk trouvé !
- *** Recherche cles registre ***
- Recharche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]
- Recharche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]
- Recherche Clé Magic Control
- *** Module de recherche complémentaire ***
- (recherche fichiers spécifiques)
- 1)Recherche nouveaux fichiers connus:
- 2)Recherche Heuristique :
- *
- **
- ***
- ****
- *** Analyse Terminé le 05/03/2007 à 10:56:59,93 ***




