Mon pc est infecte du spyware.65 (detecter par l'Antispyware de Microsoft) je n'arrive pas a m'en sortir, j'ai suivi toutes les indications donner a un membre pour le meme probleme mais rien a faire svp de l'aide...
Voici mon log Hitjackthis:
Logfile of HijackThis v1.99.1
Scan saved at 20:33:54, on 14/05/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:WINNTSystem32smss.exe
C:WINNTsystem32winlogon.exe
C:WINNTsystem32services.exe
C:WINNTsystem32lsass.exe
C:WINNTsystem32svchost.exe
C:WINNTSystem32svchost.exe
C:Program FilesFichiers communsSymantec SharedccSetMgr.exe
C:Program FilesFichiers communsSymantec SharedSNDSrvc.exe
C:WINNTExplorer.EXE
C:Program FilesFichiers communsSymantec SharedSPBBCSPBBCSvc.exe
C:Program FilesFichiers communsSymantec SharedccEvtMgr.exe
C:WINNTsystem32spoolsv.exe
C:Program FilesFichiers communsMicrosoft SharedVS7DEBUGMDM.EXE
C:Program FilesCanonMultiPASS4MPSERVIC.EXE
C:Program FilesNorton AntiVirusnavapsvc.exe
C:Program FilesNorton AntiVirusIWPNPFMntor.exe
C:Program FilesNorton AntiVirusAdvToolsNPROTECT.EXE
C:WINNTsystem32nvsvc32.exe
C:WINNTSystem32svchost.exe
C:Program FilesFichiers communsSymantec SharedCCPD-LCsymlcsvc.exe
C:WINNTsystem32ZoneLabsvsmon.exe
C:WINNTSystem32sstray.exe
C:Program FilesCanonMultiPASS4monitr32.exe
C:WINNTSystem32qttask.exe
C:Documents and SettingsMiaraBureaulogiciel sandrinezone alarmZoneAlarmzlclient.exe
C:WINNTcrmh.exe
C:WINNTSystem32RUNDLL32.EXE
C:Program FilesMSN MessengerMsnMsgr.Exe
C:Program FilesInterMuteSpySubtractSpySub.exe
C:WINNTiemu.exe
C:WINNTSystem32wuauclt.exe
C:Program FilesFichiers communsSymantec SharedNMain.exe
C:Program FilesFichiers communsSymantec SharedccApp.exe
C:PROGRA~1NORTON~1navw32.exe
C:Program FilesMozilla Firefoxfirefox.exe
C:Documents and SettingsMiaraBureaulogiciel sandrineANTISPYWARESPY SHOOTERSpy ShooterFlowStarter.exe
C:Program FilesMicrosoft AntiSpywaregcasDtServ.exe
C:Program FilesMicrosoft AntiSpywaregcasServ.exe
C:Documents and SettingsMiaraBureaulogiciel sandrineANTISPYWAREHITJACKthislogicielHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:WINNTjumhq.dll/sp.html#93256
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = res://C:WINNTjumhq.dll/sp.html#93256
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = about:blank
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = res://C:WINNTjumhq.dll/sp.html#93256
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = res://C:WINNTjumhq.dll/sp.html#93256
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = res://C:WINNTjumhq.dll/sp.html#93256
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = res://C:WINNTjumhq.dll/sp.html#93256
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Liens
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: Class - {80C16797-088A-9CEB-4233-4E16FB01F600} - C:WINNTwinet.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:Program FilesNorton AntiVirusNavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:Program FilesNorton AntiVirusNavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINNTSystem32msdxm.ocx
O4 - HKLM..Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINNTsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM..Run: [TCASUTIEXE] TCAUDIAG.exe -off
O4 - HKLM..Run: [NeroFilterCheck] C:WINNTsystem32NeroCheck.exe
O4 - HKLM..Run: [monitr32] C:Program FilesCanonMultiPASS4monitr32.exe
O4 - HKLM..Run: [UserFaultCheck] %systemroot%system32dumprep 0 -u
O4 - HKLM..Run: [SSC_UserPrompt] C:Program FilesFichiers communsSymantec SharedSecurity CenterUsrPrmpt.exe
O4 - HKLM..Run: [Advanced Tools Check] C:PROGRA~1NORTON~1AdvToolsADVCHK.EXE
O4 - HKLM..Run: [Symantec NetDriver Monitor] C:PROGRA~1SYMNET~1SNDMon.exe /Consumer
O4 - HKLM..Run: [QuickTime Task] "C:WINNTSystem32qttask.exe" -atboottime
O4 - HKLM..Run: [Zone Labs Client] "C:Documents and SettingsMiaraBureaulogiciel sandrinezone alarmZoneAlarmzlclient.exe"
O4 - HKLM..Run: [crmh.exe] C:WINNTcrmh.exe
O4 - HKLM..Run: [ccApp] "C:Program FilesFichiers communsSymantec SharedccApp.exe"
O4 - HKLM..RunOnce: [iemu.exe] C:WINNTiemu.exe
O4 - HKCU..Run: [NvMediaCenter] RUNDLL32.EXE C:WINNTsystem32NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU..Run: [MsnMsgr] "C:Program FilesMSN MessengerMsnMsgr.Exe" /background
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:Program FilesAdobeAcrobat 7.0Readerreader_sl.exe
O4 - Global Startup: Spy Shooter 4.5.lnk = C:Documents and SettingsMiaraBureaulogiciel sandrineASSpy ShooterFlowStarter.exe
O4 - Global Startup: SpySubtract.lnk = C:Program FilesInterMuteSpySubtractSpySub.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:PROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {601B418B-E6A6-47FC-A094-07248741CEB3} (Camtronics Medical Systems Web Viewer) - file://D:vwr_dataWebVwr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1108334016816
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:WINNTapiac.exe" /s (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:Program FilesFichiers communsSymantec SharedccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:Program FilesFichiers communsSymantec SharedccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:Program FilesFichiers communsSymantec SharedccSetMgr.exe
O23 - Service: FlowProtectorService - Unknown owner - C:Documents and SettingsMiaraBureaulogiciel sandrineASSpy Shooter4.5.0.1FlowService.exe (file missing)
O23 - Service: MpService - Canon Inc - C:Program FilesCanonMultiPASS4MPSERVIC.EXE
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:Program FilesNorton AntiVirusnavapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:Program FilesNorton AntiVirusIWPNPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:Program FilesNorton AntiVirusAdvToolsNPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:WINNTsystem32nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:Program FilesNorton AntiVirusSAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:PROGRA~1FICHIE~1SYMANT~1SCRIPT~1SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:Program FilesFichiers communsSymantec SharedSNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:Program FilesFichiers communsSymantec SharedSPBBCSPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:Program FilesFichiers communsSymantec SharedCCPD-LCsymlcsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:WINNTsystem32ZoneLabsvsmon.exe
l'analyse de Ad-Aware me donne:
Ad-Aware SE Build 1.05
Logfile Created on:samedi 14 mai 2005 20:34:58
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R45 13.05.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):12 total references.
Possible Browser Hijack attempt(TAC index:3):3 total references.
VX2(TAC index:10):1 total references.
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : Prior to deletion, allow unloading Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic settings in log file
Set : Include additional settings in log file
Set : Include reference summary in log file
Set : Include Alternate Datastream details in log file
Set : Play sound at scan completion if scan locates critical objects
14-05-2005 20:34:58 - Scan started. (Full System Scan)
MRU List Object Recognized!
Location: : softwaremicrosoftdirectdrawmostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1004336348-725345543-1000softwaremicrosoftinternet explorer
Description : last download directory used in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-19softwaremicrosoftmediaplayerpreferences
Description : last playlist loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-20softwaremicrosoftmediaplayerpreferences
Description : last playlist loaded in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1004336348-725345543-1000softwaremicrosoftmicrosoft management consolerecent file list
Description : list of recent snap-ins used in the microsoft management console
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1004336348-725345543-1000softwaremicrosoftsearch assistantacmru
Description : list of recent search terms used with the search assistant
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1004336348-725345543-1000softwaremicrosoftwindowscurrentversionexplorercomdlg32lastvisitedmru
Description : list of recent programs opened
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1004336348-725345543-1000softwaremicrosoftwindowscurrentversionexplorercomdlg32opensavemru
Description : list of recently saved files, stored according to file extension
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1004336348-725345543-1000softwaremicrosoftwindowscurrentversionexplorerrecentdocs
Description : list of recent documents opened
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1004336348-725345543-1000softwaremicrosoftwindowscurrentversionexplorerrunmru
Description : mru list for items opened in start | run
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1004336348-725345543-1000softwaremicrosoftwindows mediawmsdkgeneral
Description : windows media sdk
MRU List Object Recognized!
Location: : S-1-5-21-1801674531-1004336348-725345543-1000softwarewinrardialogedithistoryextrpath
Description : winrar "extract-to" history
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : SystemRootSystem32
ProcessID : 412
ThreadCreationTime : 14-05-2005 17:49:26
BasePriority : Normal
#:2 [csrss.exe]
FilePath : ??C:WINNTsystem32
ProcessID : 468
ThreadCreationTime : 14-05-2005 17:49:28
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : ??C:WINNTsystem32
ProcessID : 492
ThreadCreationTime : 14-05-2005 17:49:29
BasePriority : High
#:4 [services.exe]
FilePath : C:WINNTsystem32
ProcessID : 536
ThreadCreationTime : 14-05-2005 17:49:29
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Applications Services et Contrôleur
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:WINNTsystem32
ProcessID : 548
ThreadCreationTime : 14-05-2005 17:49:29
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:WINNTsystem32
ProcessID : 728
ThreadCreationTime : 14-05-2005 17:49:29
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:WINNTSystem32
ProcessID : 804
ThreadCreationTime : 14-05-2005 17:49:29
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:WINNTSystem32
ProcessID : 928
ThreadCreationTime : 14-05-2005 17:49:29
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:WINNTSystem32
ProcessID : 984
ThreadCreationTime : 14-05-2005 17:49:30
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [ccsetmgr.exe]
FilePath : C:Program FilesFichiers communsSymantec Shared
ProcessID : 1092
ThreadCreationTime : 14-05-2005 17:49:30
BasePriority : Normal
FileVersion : 103.0.3.8
ProductVersion : 103.0.3.8
ProductName : Client and Host Security Platform
CompanyName : Symantec Corporation
FileDescription : Symantec Settings Manager Service
InternalName : ccSetMgr
LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved.
OriginalFilename : ccSetMgr.exe
#:11 [sndsrvc.exe]
FilePath : C:Program FilesFichiers communsSymantec Shared
ProcessID : 1204
ThreadCreationTime : 14-05-2005 17:49:30
BasePriority : Normal
FileVersion : 5.5.1.6
ProductVersion : 5.5
ProductName : Symantec Security Drivers
CompanyName : Symantec Corporation
FileDescription : Network Driver Service
InternalName : SndSrvc
LegalCopyright : Copyright 2002, 2003, 2004 Symantec Corporation
OriginalFilename : SndSrvc.exe
#:12 [explorer.exe]
FilePath : C:WINNT
ProcessID : 1212
ThreadCreationTime : 14-05-2005 17:49:30
BasePriority : Normal
FileVersion : 6.00.2600.0000 (xpclient.010817-1148)
ProductVersion : 6.00.2600.0000
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Explorateur Windows
InternalName : explorer
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : EXPLORER.EXE
#:13 [spbbcsvc.exe]
FilePath : C:Program FilesFichiers communsSymantec SharedSPBBC
ProcessID : 1228
ThreadCreationTime : 14-05-2005 17:49:30
BasePriority : Normal
FileVersion : 1,0,1,47
ProductVersion : 1,0,1,47
ProductName : SPBBC
CompanyName : Symantec Corporation
FileDescription : SPBBC Service
InternalName : SPBBCSvc
LegalCopyright : Copyright © 2004 Symantec Corporation. All rights reserved.
OriginalFilename : SPBBCSvc.exe
#:14 [ccevtmgr.exe]
FilePath : C:Program FilesFichiers communsSymantec Shared
ProcessID : 1364
ThreadCreationTime : 14-05-2005 17:49:32
BasePriority : Normal
FileVersion : 103.0.3.8
ProductVersion : 103.0.3.8
ProductName : Client and Host Security Platform
CompanyName : Symantec Corporation
FileDescription : Symantec Event Manager Service
InternalName : ccEvtMgr
LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved.
OriginalFilename : ccEvtMgr.exe
#:15 [spoolsv.exe]
FilePath : C:WINNTsystem32
ProcessID : 1504
ThreadCreationTime : 14-05-2005 17:49:33
BasePriority : Normal
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:16 [alg.exe]
FilePath : C:WINNTSystem32
ProcessID : 1644
ThreadCreationTime : 14-05-2005 17:49:39
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe
#:17 [mdm.exe]
FilePath : C:Program FilesFichiers communsMicrosoft SharedVS7DEBUG
ProcessID : 1700
ThreadCreationTime : 14-05-2005 17:49:39
BasePriority : Normal
FileVersion : 7.00.9466
ProductVersion : 7.00.9466
ProductName : Microsoft® Visual Studio .NET
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : mdm.exe
#:18 [mpservic.exe]
FilePath : C:Program FilesCanonMultiPASS4
ProcessID : 1716
ThreadCreationTime : 14-05-2005 17:49:39
BasePriority : Normal
FileVersion : 4.00
ProductVersion : 4.00
ProductName : Canon MultiPASS
CompanyName : Canon Inc
FileDescription : Implements the NT service that starts the server.
LegalCopyright : Copyright © 2000 Canon Inc
#:19 [navapsvc.exe]
FilePath : C:Program FilesNorton AntiVirus
ProcessID : 1796
ThreadCreationTime : 14-05-2005 17:49:39
BasePriority : Normal
FileVersion : 11.0.9.16
ProductVersion : 11.0.9
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Auto-Protect Service
InternalName : NAVAPSVC
LegalCopyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright © 2004 Symantec Corporation. All rights reserved.
OriginalFilename : NAVAPSVC.EXE
#:20 [npfmntor.exe]
FilePath : C:Program FilesNorton AntiVirusIWP
ProcessID : 1856
ThreadCreationTime : 14-05-2005 17:49:39
BasePriority : Normal
FileVersion : 11.0.9.16
ProductVersion : 11.0.9
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Firewall Install Monitor
InternalName : NPFMonitor
LegalCopyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright © 2004 Symantec Corporation. All rights reserved.
OriginalFilename : NPFMonitor.EXE
#:21 [nprotect.exe]
FilePath : C:Program FilesNorton AntiVirusAdvTools
ProcessID : 1960
ThreadCreationTime : 14-05-2005 17:49:42
BasePriority : Normal
FileVersion : 16.00.0.22
ProductVersion : 16.00.0.22
ProductName : Norton Utilities
CompanyName : Symantec Corporation
FileDescription : Norton Protection Status
InternalName : NPROTECT
LegalCopyright : Copyright © 2003 Symantec Corporation
LegalTrademarks : Norton Utilities
OriginalFilename : NPROTECT.EXE
#:22 [nvsvc32.exe]
FilePath : C:WINNTsystem32
ProcessID : 1980
ThreadCreationTime : 14-05-2005 17:49:42
BasePriority : Normal
FileVersion : 6.14.10.4523
ProductVersion : 6.14.10.4523
ProductName : NVIDIA Driver Helper Service, Version 45.23
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA Driver Helper Service, Version 45.23
InternalName : NVSVC
LegalCopyright : © NVIDIA Corporation. All rights reserved.
OriginalFilename : nvsvc32.exe
#:23 [svchost.exe]
FilePath : C:WINNTSystem32
ProcessID : 208
ThreadCreationTime : 14-05-2005 17:49:42
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:24 [symlcsvc.exe]
FilePath : C:Program FilesFichiers communsSymantec SharedCCPD-LC
ProcessID : 260
ThreadCreationTime : 14-05-2005 17:49:42
BasePriority : Normal
FileVersion : 1, 8, 54, 534
ProductVersion : 1, 8, 54, 534
ProductName : Symantec Core Component
CompanyName : Symantec Corporation
FileDescription : Symantec Core Component
InternalName : symlcsvc
LegalCopyright : Copyright © 2003
OriginalFilename : symlcsvc.exe
#:25 [wdfmgr.exe]
FilePath : C:WINNTSystem32
ProcessID : 348
ThreadCreationTime : 14-05-2005 17:49:43
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: dnsrv(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe
#:26 [vsmon.exe]
FilePath : C:WINNTsystem32ZoneLabs
ProcessID : 112
ThreadCreationTime : 14-05-2005 17:49:43
BasePriority : Normal
FileVersion : 5.1.033.000
ProductVersion : 5.1.033.000
ProductName : TrueVector Service
CompanyName : Zone Labs Inc.
FileDescription : TrueVector Service
InternalName : vsmon
LegalCopyright : Copyright © 1998-2004, Zone Labs Inc.
OriginalFilename : vsmon.exe
#:27 [sstray.exe]
FilePath : C:WINNTSystem32
ProcessID : 2468
ThreadCreationTime : 14-05-2005 17:50:14
BasePriority : Normal
FileVersion : 1.00.00.0317
ProductVersion : 1.00.00.0317
ProductName : NVIDIA nForce
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA nForce Taskbar Utility
InternalName : SSTray.exe
LegalCopyright : Copyright 2000-2002 NVIDIA Corporation
#:28 [monitr32.exe]
FilePath : C:Program FilesCanonMultiPASS4
ProcessID : 2492
ThreadCreationTime : 14-05-2005 17:50:14
BasePriority : Normal
FileVersion : 4.00
ProductVersion : 4.00
ProductName : Canon MultiPASS
CompanyName : Canon Inc
FileDescription : Status Monitor
LegalCopyright : Copyright © 2000 Canon Inc
OriginalFilename : monitr32.exe
#:29 [qttask.exe]
FilePath : C:WINNTSystem32
ProcessID : 2548
ThreadCreationTime : 14-05-2005 17:50:15
BasePriority : Normal
FileVersion : 6.4
ProductVersion : QuickTime 6.4
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2003
OriginalFilename : QTTask.exe
#:30 [zlclient.exe]
FilePath : C:Documents and SettingsMiaraBureaulogiciel sandrinezone alarmZoneAlarm
ProcessID : 2556
ThreadCreationTime : 14-05-2005 17:50:15
BasePriority : Normal
FileVersion : 5.1.033.000
ProductVersion : 5.1.033.000
ProductName : Zone Labs Client
CompanyName : Zone Labs Inc.
FileDescription : Zone Labs Client
InternalName : zlclient
LegalCopyright : Copyright © 1998-2004, Zone Labs Inc.
OriginalFilename : zlclient.exe
#:31 [crmh.exe]
FilePath : C:WINNT
ProcessID : 2564
ThreadCreationTime : 14-05-2005 17:50:15
BasePriority : Normal
#:32 [rundll32.exe]
FilePath : C:WINNTSystem32
ProcessID : 2572
ThreadCreationTime : 14-05-2005 17:50:15
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Exécuter une DLL en tant qu'application
InternalName : rundll
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : RUNDLL.EXE
#:33 [msnmsgr.exe]
FilePath : C:Program FilesMSN Messenger
ProcessID : 2584
ThreadCreationTime : 14-05-2005 17:50:15
BasePriority : Normal
FileVersion : 6.2.0205
ProductVersion : Version 6.2
ProductName : MSN Messenger
CompanyName : Microsoft Corporation
FileDescription : MSN Messenger
InternalName : msnmsgr
LegalCopyright : Copyright © Microsoft Corporation 1997-2004
LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msnmsgr.exe
#:34 [spysub.exe]
FilePath : C:Program FilesInterMuteSpySubtract
ProcessID : 2648
ThreadCreationTime : 14-05-2005 17:50:16
BasePriority : Normal
FileVersion : 1, 0, 1, 61
ProductVersion : 2.64
ProductName : SpySubtract
CompanyName : InterMute, Inc.
FileDescription : SpySubtract Program EXE
InternalName : SpySub.exe
LegalCopyright : Copyright © 2005 InterMute, Inc. All rights reserved.
OriginalFilename : SpySub.exe
#:35 [iemu.exe]
FilePath : C:WINNT
ProcessID : 3884
ThreadCreationTime : 14-05-2005 17:54:39
BasePriority : Normal
VX2 Object Recognized!
Type : Process
Data : iemu.exe
Category : Malware
Comment : (CSI MATCH)
Object : C:WINNT
Warning! VX2 Object found in memory(C:WINNTiemu.exe)
"C:WINNTiemu.exe"Process terminated successfully
"C:WINNTiemu.exe"Process terminated successfully
#:36 [wuauclt.exe]
FilePath : C:WINNTSystem32
ProcessID : 1104
ThreadCreationTime : 14-05-2005 18:01:23
BasePriority : Normal
FileVersion : 5.4.3790.2182 built by: srv03_rtm(ntvbl04)
ProductVersion : 5.4.3790.2182
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Mises à jour automatiques
InternalName : wuauclt.exe
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : wuauclt.exe
#:37 [nmain.exe]
FilePath : C:Program FilesFichiers communsSymantec Shared
ProcessID : 2024
ThreadCreationTime : 14-05-2005 18:14:37
BasePriority : Normal
FileVersion : 103.0.1.26
ProductVersion : 103.0.1.26
ProductName : Client and Host Security Platform
CompanyName : Symantec Corporation
FileDescription : Symantec Integrator
InternalName : Symantec Integrator
LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved.
OriginalFilename : NMAIN.EXE
#:38 [ccapp.exe]
FilePath : C:Program FilesFichiers communsSymantec Shared
ProcessID : 3624
ThreadCreationTime : 14-05-2005 18:14:39
BasePriority : Normal
FileVersion : 103.0.3.8
ProductVersion : 103.0.3.8
ProductName : Client and Host Security Platform
CompanyName : Symantec Corporation
FileDescription : Symantec User Session
InternalName : ccApp
LegalCopyright : Copyright © 2000-2004 Symantec Corporation. All rights reserved.
OriginalFilename : ccApp.exe
#:39 [navw32.exe]
FilePath : C:PROGRA~1NORTON~1
ProcessID : 552
ThreadCreationTime : 14-05-2005 18:15:02
BasePriority : Normal
FileVersion : 11.0.9.16
ProductVersion : 11.0.9
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Norton AntiVirus Scanner Module
InternalName : Navw32
LegalCopyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright © 2004 Symantec Corporation. All rights reserved.
OriginalFilename : Navw32.exe
#:40 [firefox.exe]
FilePath : C:Program FilesMozilla Firefox
ProcessID : 2764
ThreadCreationTime : 14-05-2005 18:20:09
BasePriority : Normal
#:41 [flowstarter.exe]
FilePath : C:Documents and SettingsMiaraBureaulogiciel sandrineANTISPYWARESPY SHOOTERSpy Shooter
ProcessID : 1820
ThreadCreationTime : 14-05-2005 18:20:46
BasePriority : Normal
#:42 [gcasdtserv.exe]
FilePath : C:Program FilesMicrosoft AntiSpyware
ProcessID : 3028
ThreadCreationTime : 14-05-2005 18:30:35
BasePriority : Normal
FileVersion : 1.00.0509
ProductVersion : 1.00.0509
ProductName : Microsoft AntiSpyware (Beta 1)
CompanyName : Microsoft Corporation
FileDescription : Microsoft AntiSpyware Data Service
InternalName : gcasDtServ
LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved.
LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet is a trademark of Microsoft Corporation.
OriginalFilename : gcasDtServ.exe
#:43 [gcasserv.exe]
FilePath : C:Program FilesMicrosoft AntiSpyware
ProcessID : 2676
ThreadCreationTime : 14-05-2005 18:30:44
BasePriority : Idle
FileVersion : 1.00.0509
ProductVersion : 1.00.0509
ProductName : Microsoft AntiSpyware (Beta 1)
CompanyName : Microsoft Corporation
FileDescription : Microsoft AntiSpyware Service
InternalName : gcasServ
LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved.
LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet is a trademark of Microsoft Corporation.
OriginalFilename : gcasServ.exe
#:44 [ad-aware.exe]
FilePath : C:Documents and SettingsMiaraBureaulogiciel sandrineANTISPYWAREAD-WAREAd-Aware SE Personal
ProcessID : 740
ThreadCreationTime : 14-05-2005 18:34:48
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 1
Objects found so far: 13
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 0
Objects found so far: 13
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 0
Objects found so far: 13
Started tracking cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 0
Objects found so far: 13
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk scan result for C:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 0
Objects found so far: 13
Possible Browser Hijack attempt Object Recognized!
Type : File
Data : Only sex website.url
Category : Misc
Comment : Problematic URL discovered:
http://www.onlysex.ws/
Object : C:Documents and SettingsMiaraFavoris
Possible Browser Hijack attempt Object Recognized!
Type : File
Data : Search the web.url
Category : Misc
Comment : Problematic URL discovered:
http://www.lookfor.cc/
Object : C:Documents and SettingsMiaraFavoris
Possible Browser Hijack attempt Object Recognized!
Type : File
Data : Seven days of free porn.url
Category : Misc
Comment : Problematic URL discovered:
http://www.7days.ws/
Object : C:Documents and SettingsMiaraFavoris
Performing conditional scans..
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New Critical Objects: 0
Objects found so far: 16
20:51:44 Scan Complete
Summary of this scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:16:46.734
Objects scanned:95068
Objects identified:4
Objects ignored:0
New Critical Objects:4
AH L'AIDE JE CRAQUE...