Configuration :
18-05-2009 à 09h29
Bonjour,
mon scan avec
malwarebytes n'a rien donné,
résultats avec
ad-aware :
Logfile created: 16/05/2009 13:31:58
Lavasoft Ad-Aware version: 8.0.4
Extended engine version: 8.1
User performing scan: joe
*********************** Definitions database information ***********************
Lavasoft definition file: 148.31
Extended engine definition file: 8.1
******************************** Scan results: *********************************
Scan profile name: Analyse complète (ID: full)
Objects scanned: 138513
Objects detected: 53
Type Detected
==========================
Processes.......: 0
Registry entries: 0
Hostfile entries: 0
Files...........: 0
Folders.........: 0
LSPs............: 0
Cookies.........: 53
Browser hijacks.: 0
MRU objects.....: 0
Removed items:
Description: *2o7* Family Name: Cookies Clean status: Success Item ID: 408943 Family ID: 0
Description: *atdmt* Family Name: Cookies Clean status: Success Item ID: 408910 Family ID: 0
Description: *doubleclick* Family Name: Cookies Clean status: Success Item ID: 408875 Family ID: 0
Description: *weborama* Family Name: Cookies Clean status: Success Item ID: 408955 Family ID: 0
Description: *adserver* Family Name: Cookies Clean status: Success Item ID: 408737 Family ID: 0
Description: *adserv* Family Name: Cookies Clean status: Success Item ID: 408921 Family ID: 0
Description: *adserve* Family Name: Cookies Clean status: Success Item ID: 409020 Family ID: 0
Description: *statcounter* Family Name: Cookies Clean status: Success Item ID: 409185 Family ID: 0
Description: *tradedoubler* Family Name: Cookies Clean status: Success Item ID: 408964 Family ID: 0
Description: *doubleclick* Family Name: Cookies Clean status: Success Item ID: 408875 Family ID: 0
Description: *estat* Family Name: Cookies Clean status: Success Item ID: 408873 Family ID: 0
Description: *specificclick* Family Name: Cookies Clean status: Success Item ID: 408807 Family ID: 0
Description: *weborama* Family Name: Cookies Clean status: Success Item ID: 408955 Family ID: 0
Description: *adserver* Family Name: Cookies Clean status: Success Item ID: 408737 Family ID: 0
Description: *adserv* Family Name: Cookies Clean status: Success Item ID: 408921 Family ID: 0
Description: *adserve* Family Name: Cookies Clean status: Success Item ID: 409020 Family ID: 0
Description: *advertis* Family Name: Cookies Clean status: Success Item ID: 408918 Family ID: 0
Description: *advertising* Family Name: Cookies Clean status: Success Item ID: 409017 Family ID: 0
Description: *bs.serving-sys* Family Name: Cookies Clean status: Success Item ID: 408902 Family ID: 0
Description: *serving-sys* Family Name: Cookies Clean status: Success Item ID: 409130 Family ID: 0
Description: *2o7* Family Name: Cookies Clean status: Success Item ID: 408943 Family ID: 0
Description: *bluestreak* Family Name: Cookies Clean status: Success Item ID: 408904 Family ID: 0
Description: *apmebf* Family Name: Cookies Clean status: Success Item ID: 409163 Family ID: 0
Description: *mediaplex* Family Name: Cookies Clean status: Success Item ID: 408991 Family ID: 0
Description: *atdmt* Family Name: Cookies Clean status: Success Item ID: 408910 Family ID: 0
Description: *real* Family Name: Cookies Clean status: Success Item ID: 408817 Family ID: 0
Description: *247realmedia* Family Name: Cookies Clean status: Success Item ID: 408945 Family ID: 0
Description: *realmedia* Family Name: Cookies Clean status: Success Item ID: 409139 Family ID: 0
Description: *adviva* Family Name: Cookies Clean status: Success Item ID: 409016 Family ID: 0
Description: *adtech* Family Name: Cookies Clean status: Success Item ID: 409018 Family ID: 0
Description: *ad.yieldmanager* Family Name: Cookies Clean status: Success Item ID: 409172 Family ID: 0
Description: *fastclick* Family Name: Cookies Clean status: Success Item ID: 408869 Family ID: 0
Description: *tacoda* Family Name: Cookies Clean status: Success Item ID: 409123 Family ID: 0
Description: *adrevolver* Family Name: Cookies Clean status: Success Item ID: 408932 Family ID: 0
Description: *media.adrevolver* Family Name: Cookies Clean status: Success Item ID: 409144 Family ID: 0
Description: *wunderloop* Family Name: Cookies Clean status: Success Item ID: 599639 Family ID: 0
Description: *tradedoubler* Family Name: Cookies Clean status: Success Item ID: 408964 Family ID: 0
Description: *hitbox* Family Name: Cookies Clean status: Success Item ID: 408858 Family ID: 0
Description: *.hitbox* Family Name: Cookies Clean status: Success Item ID: 409072 Family ID: 0
Description: *.lycos* Family Name: Cookies Clean status: Success Item ID: 408930 Family ID: 0
Description: *.comclick* Family Name: Cookies Clean status: Success Item ID: 409086 Family ID: 0
Description: *statcounter* Family Name: Cookies Clean status: Success Item ID: 409185 Family ID: 0
Description: *adbureau* Family Name: Cookies Clean status: Success Item ID: 409027 Family ID: 0
Description: stat.dealtime* Family Name: Cookies Clean status: Success Item ID: 409126 Family ID: 0
Description: *dealtime* Family Name: Cookies Clean status: Success Item ID: 409235 Family ID: 0
Description: *kelkoo* Family Name: Cookies Clean status: Success Item ID: 408851 Family ID: 0
Description: *statse.webtrends* Family Name: Cookies Clean status: Success Item ID: 408803 Family ID: 0
Description: *webtrendslive* Family Name: Cookies Clean status: Success Item ID: 408954 Family ID: 0
Description: *.webtrendslive* Family Name: Cookies Clean status: Success Item ID: 409033 Family ID: 0
Description: *statse.webtrendslive* Family Name: Cookies Clean status: Success Item ID: 409269 Family ID: 0
Description: *webtrends* Family Name: Cookies Clean status: Success Item ID: 599640 Family ID: 0
Description: *questionmarket* Family Name: Cookies Clean status: Success Item ID: 408819 Family ID: 0
Description: *adbrite* Family Name: Cookies Clean status: Success Item ID: 409218 Family ID: 0
Scan and cleaning complete: Finished correctly after 2360 seconds
*********************************** Settings ***********************************
Scan profile:
ID: full, enabled:1, value: Analyse complète
ID: scancriticalareas, enabled:1, value: true
ID: scanrunningapps, enabled:1, value: true
ID: scanregistry, enabled:1, value: true
ID: scanlsp, enabled:1, value: true
ID: scanads, enabled:1, value: true
ID: scanhostsfile, enabled:1, value: true
ID: scanmru, enabled:1, value: true
ID: scanbrowserhijacks, enabled:1, value: true
ID: scantrackingcookies, enabled:1, value: true
ID: closebrowsers, enabled:1, value: false
ID: folderstoscan, enabled:1, value: C:\,D:\
ID: scanrootkits, enabled:1, value: true
ID: usespywareheuristics, enabled:1, value: true
ID: extendedengine, enabled:0, value: true
ID: useheuristics, enabled:0, value: true
ID: heuristicslevel, enabled:0, value: mild, domain: medium,mild,strict
ID: filescanningoptions, enabled:1
ID: archives, enabled:1, value: true
ID: onlyexecutables, enabled:1, value: false
ID: skiplargerthan, enabled:1, value: 20480
Scan global:
ID: global, enabled:1
ID: addtocontextmenu, enabled:1, value: true
ID: playsoundoninfection, enabled:1, value: false
ID: soundfile, enabled:0, value: *to be filled in automatically*\alert.wav
Scheduled scan settings:
<Empty>
Update settings:
ID: updates, enabled:1
ID: launchthreatworksafterscan, enabled:1, value: normal, domain: normal,off,silently
ID: displaystatus, enabled:1, value: false
ID: deffiles, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall
ID: autodetectproxy, enabled:1, value: false
ID: useautoconfigscript, enabled:1, value: false
ID: autoconfigurl, enabled:0, value:
ID: useproxy, enabled:1, value: false
ID: proxyserver, enabled:0, value:
ID: softwareupdates, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall
ID: licenseandinfo, enabled:1, value: downloadandinstall, domain: dontcheck,downloadandinstall
ID: schedules, enabled:1, value: true
ID: updatedaily, enabled:1, value: Daily
ID: time, enabled:1, value: Sun Feb 22 21:53:00 2009
ID: frequency, enabled:1, value: daily, domain: daily,monthly,once,systemstart,weekly
ID: weekdays, enabled:1
ID: monday, enabled:1, value: false
ID: tuesday, enabled:1, value: false
ID: wednesday, enabled:1, value: false
ID: thursday, enabled:1, value: false
ID: friday, enabled:1, value: false
ID: saturday, enabled:1, value: false
ID: sunday, enabled:1, value: false
ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31
ID: scanprofile, enabled:1, value:
ID: auto_deal_with_infections, enabled:1, value: false
ID: updateweekly, enabled:1, value: Weekly
ID: time, enabled:1, value: Sun Feb 22 21:53:00 2009
ID: frequency, enabled:1, value: weekly, domain: daily,monthly,once,systemstart,weekly
ID: weekdays, enabled:1
ID: monday, enabled:1, value: true
ID: tuesday, enabled:1, value: false
ID: wednesday, enabled:1, value: false
ID: thursday, enabled:1, value: false
ID: friday, enabled:1, value: false
ID: saturday, enabled:1, value: false
ID: sunday, enabled:1, value: true
ID: monthly, enabled:1, value: 1, minvalue: 1, maxvalue: 31
ID: scanprofile, enabled:1, value:
ID: auto_deal_with_infections, enabled:1, value: false
Appearance settings:
ID: appearance, enabled:1
ID: skin, enabled:1, value: default.egl, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Resource
ID: showtrayicon, enabled:1, value: true
ID: language, enabled:1, value: fr, reglocation: HKEY_LOCAL_MACHINE\SOFTWARE\Lavasoft\Ad-Aware\Language
Realtime protection settings:
ID: realtime, enabled:1
ID: processprotection, enabled:1, value: true
ID: registryprotection, enabled:0, value: false
ID: networkprotection, enabled:0, value: false
ID: loadatstartup, enabled:1, value: true
ID: usespywareheuristics, enabled:0, value: false
ID: extendedengine, enabled:0, value: false
ID: useheuristics, enabled:0, value: false
ID: heuristicslevel, enabled:0, value: mild, domain: medium,mild,strict
ID: infomessages, enabled:1, value: display, domain: display,dontnotify,onlyimportant
****************************** System information ******************************
Computer name: NOM-BBACE4CAFDD
Processor name: Genuine Intel(R) CPU T2300 @ 1.66GHz
Processor identifier: x86 Family 6 Model 14 Stepping 8
Raw info: processorarchitecture 0, processortype 586, processorlevel 6, processor revision 3592, number of processors 2
Physical memory available: 385232896 bytes
Physical memory total: 1071755264 bytes
Virtual memory available: 2008834048 bytes
Virtual memory total: 2147352576 bytes
Memory load: 64%
Microsoft
Windows XP Home Edition Service Pack 3 (build 2600)
Windows startup mode:
Running processes:
PID: 816 name: \SystemRoot\System32\smss.exe owner: SYSTEM domain: AUTORITE NT
PID: 868 name: \??\C:\WINDOWS\system32\csrss.exe owner: SYSTEM domain: AUTORITE NT
PID: 892 name: \??\C:\WINDOWS\system32\winlogon.exe owner: SYSTEM domain: AUTORITE NT
PID: 936 name: C:\WINDOWS\system32\services.exe owner: SYSTEM domain: AUTORITE NT
PID: 948 name: C:\WINDOWS\system32\lsass.exe owner: SYSTEM domain: AUTORITE NT
PID: 1120 name: C:\WINDOWS\system32\svchost.exe owner: SYSTEM domain: AUTORITE NT
PID: 1188 name: C:\WINDOWS\system32\svchost.exe owner: SERVICE RÉSEAU domain: AUTORITE NT
PID: 1228 name: C:\WINDOWS\System32\svchost.exe owner: SYSTEM domain: AUTORITE NT
PID: 1324 name: C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe owner: SYSTEM domain: AUTORITE NT
PID: 1376 name: C:\WINDOWS\system32\svchost.exe owner: SERVICE RÉSEAU domain: AUTORITE NT
PID: 1428 name: C:\WINDOWS\system32\svchost.exe owner: SERVICE LOCAL domain: AUTORITE NT
PID: 1960 name: C:\WINDOWS\system32\spoolsv.exe owner: SYSTEM domain: AUTORITE NT
PID: 2036 name: C:\WINDOWS\system32\svchost.exe owner: SERVICE LOCAL domain: AUTORITE NT
PID: 204 name: C:\WINDOWS\eHome\ehRecvr.exe owner: SYSTEM domain: AUTORITE NT
PID: 224 name: C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe owner: SYSTEM domain: AUTORITE NT
PID: 292 name: C:\Program Files\Intel\Wireless\Bin\EvtEng.exe owner: SYSTEM domain: AUTORITE NT
PID: 576 name: C:\WINDOWS\Explorer.EXE owner: joe domain: NOM-BBACE4CAFDD
PID: 592 name: C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe owner: SYSTEM domain: AUTORITE NT
PID: 432 name: C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe owner: SYSTEM domain: AUTORITE NT
PID: 800 name: C:\WINDOWS\system32\nvsvc32.exe owner: SYSTEM domain: AUTORITE NT
PID: 844 name: C:\WINDOWS\system32\IoctlSvc.exe owner: SYSTEM domain: AUTORITE NT
PID: 112 name: C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe owner: SYSTEM domain: AUTORITE NT
PID: 1184 name: C:\WINDOWS\system32\svchost.exe owner: SERVICE LOCAL domain: AUTORITE NT
PID: 1480 name: C:\WINDOWS\system32\svchost.exe owner: SYSTEM domain: AUTORITE NT
PID: 1832 name: C:\Program Files\Sony\VAIO Event Service\VESMgr.exe owner: SYSTEM domain: AUTORITE NT
PID: 1728 name: C:\Program Files\Apoint\Apoint.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 1308 name: C:\WINDOWS\ehome\ehtray.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 516 name: C:\Program Files\Sony\VAIO Power Management\SPMgr.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 452 name: C:\Program Files\Sony\ISB Utility\ISBMgr.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 1760 name: C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 1768 name: C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe owner: SYSTEM domain: AUTORITE NT
PID: 1716 name: C:\WINDOWS\ehome\mcrdsvc.exe owner: SERVICE LOCAL domain: AUTORITE NT
PID: 1912 name: C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 2088 name: C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 2132 name: C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 2492 name: C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 2844 name: C:\WINDOWS\system32\wbem\wmiprvse.exe owner: SYSTEM domain: AUTORITE NT
PID: 2860 name: C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 2928 name: C:\Program Files\Apoint\Apntex.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 2964 name: C:\Program Files\Picasa2\PicasaMediaDetector.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 3044 name: C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe owner: SYSTEM domain: AUTORITE NT
PID: 3364 name: C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe owner: SYSTEM domain: AUTORITE NT
PID: 3648 name: C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 3096 name: C:\WINDOWS\eHome\ehmsas.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 3972 name: C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 4016 name: C:\WINDOWS\System32\alg.exe owner: SERVICE LOCAL domain: AUTORITE NT
PID: 3008 name: C:\Program Files\Windows Live\Mail\wlmail.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 3808 name: C:\Program Files\Windows Live\Contacts\wlcomm.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 2824 name: C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 3520 name: C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe owner: SYSTEM domain: AUTORITE NT
PID: 3916 name: C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe owner: joe domain: NOM-BBACE4CAFDD
PID: 288 name: C:\WINDOWS\system32\wbem\unsecapp.exe owner: SYSTEM domain: AUTORITE NT
PID: 772 name: C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe owner: joe domain: NOM-BBACE4CAFDD
Startup items:
Name: CTFMON.EXE
imagepath: C:\WINDOWS\system32\CTFMON.EXE
Name: PostBootReminder
imagepath: {7849596a-48ea-486e-8937-a2a3009f31a9}
Name: CDBurn
imagepath: {fbeb8a05-beee-4442-804e-409d6c4515e9}
Name: WebCheck
imagepath: {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
Name: SysTray
imagepath: {35CEC8A3-2BE6-11D2-8773-92E220524153}
Name: WPDShServiceObj
imagepath: {AAA288BA-9A4C-45B0-95D7-94D524869DB5}
Name: {438755C2-A8BA-11D1-B96B-00A0C90312E1}
imagepath: Pré-chargeur Browseui
Name: {8C7461EF-2B13-11d2-BE35-3078302C2030}
imagepath: Démon de cache des catégories de composant
Name: NvCplDaemon
imagepath: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
Name: Apoint
imagepath: C:\Program Files\Apoint\Apoint.exe
Name: ehTray
imagepath: C:\WINDOWS\ehome\ehtray.exe
Name: VAIOCameraUtility
imagepath: "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
Name: SonyPowerCfg
imagepath: C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
Name: ISBMgr.exe
imagepath: C:\Program Files\Sony\ISB Utility\ISBMgr.exe
Name: Switcher.exe
imagepath: C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
Name: Adobe Reader Speed Launcher
imagepath: "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
Name: VAIO Update 3
imagepath: "C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe" /Stationary
Avec
a-squared, j'ai :
backdoor.win32 Agent!IK
trojan Win32 Agent!IK
Worm.MSIL!IK
IM-worm32.sumon!IK
(impossible de copier lé résultat)
---
josiane