Voila les 2 rapports de suppression, et le scan de smitfraudfix^^
.
======= RAPPORT D'AD-REMOVER 1.1.4.5_Q | UNIQUEMENT XP/VISTA/SEVEN =======
.
Mit à jour par C_XX le 26/08/2009 à 6:37 PM
Contact: AdRemover.contact@gmail.com
Site web:
http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 23:04:44, 04/09/2009 | Mode sans echec | Option: CLEAN
Exécuté de: C:\Program Files\Ad-remover\
Système d'exploitation: Microsoft® Windows XP™ v5.1.2600
Nom du PC: NOM-641695C7437 | Utilisateur actuel: HP_Propri‚taire
.
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
.
.
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\chrome
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\chrome.manifest
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\chrome.manifest.dev
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\install.rdf
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\install.rdf.bak
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\META-INF
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\chrome\ajtoolbar.jar
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\ask.gif
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\ask.src
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\config.dat
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\config.dat.bak
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\contents.rdf
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\defaults\preferences\snipit.js
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\META-INF\manifest.mf
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\META-INF\zigbert.rsa
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}\META-INF\zigbert.sf
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
C:\Program Files\AskBarDis\bar
C:\Program Files\AskBarDis\unins000.dat
C:\Program Files\AskBarDis\unins000.exe
C:\Program Files\AskBarDis\bar\bin
C:\Program Files\AskBarDis\bar\Cache
C:\Program Files\AskBarDis\bar\History
C:\Program Files\AskBarDis\bar\Settings
C:\Program Files\AskBarDis\bar\bin\askBar.dll
C:\Program Files\AskBarDis\bar\bin\askPopStp.dll
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\AskSplash.exe
C:\Program Files\AskBarDis\bar\bin\AskTBApp.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\AskBarDis\bar\bin\psvince.dll
C:\Program Files\AskBarDis\bar\Cache\0486A7A9
C:\Program Files\AskBarDis\bar\Cache\0486AAF5.bin
C:\Program Files\AskBarDis\bar\Cache\0486AD66.bin
C:\Program Files\AskBarDis\bar\Cache\0486AF3A.bin
C:\Program Files\AskBarDis\bar\Cache\0486B12E.bin
C:\Program Files\AskBarDis\bar\Cache\0486B2E4.bin
C:\Program Files\AskBarDis\bar\Cache\0486B4A9.bin
C:\Program Files\AskBarDis\bar\Cache\0486B66E.bin
C:\Program Files\AskBarDis\bar\Cache\files.ini
C:\Program Files\AskBarDis\bar\History\search
C:\Program Files\AskBarDis\bar\Settings\AskLogo.ico
C:\Program Files\AskBarDis\bar\Settings\config.dat
C:\Program Files\AskBarDis\bar\Settings\config.dat.bak
C:\Program Files\AskBarDis\bar\Settings\prevcfg.htm
C:\Program Files\AskBarDis\bar\Settings\prevCfg2.htm
C:\Program Files\AskBarDis
C:\Program Files\EoRezo\EoAdv
C:\Program Files\EoRezo\EoAdv\eoAdv.url
C:\Program Files\EoRezo\EoAdv\tmp
C:\Program Files\EoRezo\EoAdv\tmp\eoRezoBho.dll.247
C:\Program Files\EoRezo
C:\DOCUME~1\HP_PRO~1.NOM\APPLIC~1\Mozilla\Firefox\Profiles\tdogpxei.default\searchplugins\ask.xml
C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll
C:\Documents and Settings\HP_Propri‚taire\Application Data\Eorezo\cmhost.cyp
C:\Documents and Settings\HP_Propri‚taire\Application Data\Eorezo\ConfMedia.cyp
C:\Documents and Settings\HP_Propri‚taire\Application Data\Eorezo\db
C:\Documents and Settings\HP_Propri‚taire\Application Data\Eorezo\eoDesktop
C:\Documents and Settings\HP_Propri‚taire\Application Data\Eorezo\host.cyp
C:\Documents and Settings\HP_Propri‚taire\Application Data\Eorezo\user.cyp
C:\Documents and Settings\HP_Propri‚taire\Application Data\Eorezo\db\cat.cyp
C:\Documents and Settings\HP_Propri‚taire\Application Data\Eorezo\eoDesktop\config.xml
C:\Documents and Settings\HP_Propri‚taire\Application Data\Eorezo\eoDesktop\eoDesktop.html
C:\Documents and Settings\HP_Propri‚taire\Application Data\Eorezo
C:\Documents and Settings\HP_Propri‚taire\Application Data\ItsLabel\ItsTV
C:\Documents and Settings\HP_Propri‚taire\Application Data\ItsLabel\ItsTV\itsTV.xml
C:\Documents and Settings\HP_Propri‚taire\Application Data\ItsLabel
C:\DOCUME~1\HP_PRO~1.NOM\Cookies\hp_propri‚taire@casinoking-net[1].txt
C:\DOCUME~1\HP_PRO~1.NOM\Cookies\hp_propri‚taire@casinoking-net[3].txt
C:\Documents and Settings\AlExAnDrE\Cookies\alexandre@empirepoker[1].txt
C:\Documents and Settings\AlExAnDrE\Cookies\alexandre@partygaming.122.2o7[1].txt
C:\Documents and Settings\AlExAnDrE\Cookies\alexandre@partypoker[1].txt
C:\Documents and Settings\AlExAnDrE\Cookies\alexandre@rotator.its.adjuggler[2].txt
C:\Documents and Settings\Charlotte\Cookies\charlotte@pacificpoker[1].txt
C:\Documents and Settings\Charlotte\Cookies\charlotte@rotator.its.adjuggler[2].txt
C:\Documents and Settings\DANIEL\Cookies\daniel@rotator.its.adjuggler[2].txt
C:\Documents and Settings\Daniel.f\Cookies\daniel.f@pacificpoker[1].txt
C:\Documents and Settings\Daniel.f\Cookies\daniel.f@rotator.its.adjuggler[2].txt
C:\Documents and Settings\Daniel.f\Cookies\daniel.f@rotator.its.adjuggler[3].txt
C:\Documents and Settings\TEMP\Cookies\daniel@rotator.its.adjuggler[1].txt
(!) -- Fichiers temporaires supprimés.
.
============== Scan additionnel ==============
.
.
* Mozilla FireFox Version 3.5.2 *
.
Nom du profil: tdogpxei.default (HP_Propri‚taire)
.
(Prefs.js) user_pref("browser.search.defaultenginename", "Ask");
(Prefs.js) user_pref("browser.search.selectedEngine", "Google");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.google.fr/");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.1.2");
.
.
.
* Internet Explorer Version 8.0.6001.18702 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Search Page: hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
Search Bar: hxxp://search.msn.com/spbasic.htm
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
===================================
.
8717 Octet(s) - C:\Ad-Report-CLEAN.log
5259 Octet(s) - C:\Ad-Report-SCAN.log
.
3 Fichier(s) - C:\DOCUME~1\HP_PRO~1.NOM\LOCALS~1\Temp
122 Fichier(s) - C:\WINDOWS\Temp
.
34 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
34 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
.
Fin à: 23:59:22 | 04/09/2009
.
============== E.O.F ==============
.
-----------\\ ToolBar S&D 1.2.9 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) XP 3200+ )
BIOS : Rev. 3.11
USER : HP_Propriétaire ( Administrator )
BOOT : Fail-safe boot
Antivirus : Symantec Endpoint Protection 11.0.777.1008 (Not Activated)
Firewall : Symantec Endpoint Protection 10.0 (Activated)
C:\ (Local Disk) - NTFS - Total:29 Go (Free:4 Go)
D:\ (Local Disk) - NTFS - Total:157 Go (Free:8 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB)
"C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
Option : [2] ( 05/09/2009| 0:02 )
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ Extensions
(AlExAnDrE) - {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} => flashgot
(HP_Propri‚taire.NOM-641695C7437) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user
(HP_Propri‚taire.NOM-641695C7437) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Search Page"="
http://ie.redirect.hp.com/..."
"Default_Page_URL"="
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search bar"="
http://go.microsoft.com/fwlink/?linkid=54896"
"Window Title"="
http://go.microsoft.com/fwlink/?linkid=54896"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Page"="
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="
http://www.msn.com/"
"Search Bar"="
http://search.msn.com/spbasic.htm"
--------------------\\ Recherche d'autres infections
--------------------\\ ROGUES ..
C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Privacy Eraser Pro
C:\PROGRA~1\PrivacyEraser Computing
1 - "C:\ToolBar SD\TB_1.txt" - 31/08/2009|15:16 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 05/09/2009| 0:12 - Option : [2]
-----------\\ Fin du rapport a 0:12:21,00
SmitFraudFix v2.423
Rapport fait à 0:14:05,03, 05/09/2009
Executé à partir de C:\Documents and Settings\HP_Propri‚taire.NOM-641695C7437\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode sans echec
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\svchost.exe
D:\Programmes\Symantec\Endpoint11\Rtvscan.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\HP_Propriétaire.NOM-641695C7437\Bureau\SmitfraudFix\Policies.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Propri‚taire.NOM-641695C7437
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HP_PRO~1.NOM\LOCALS~1\Temp
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Propri‚taire.NOM-641695C7437\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HP_PRO~1.NOM\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
»»»»»»»»»»»»»»»»»»»»»»»» o4Patch
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\WINDOWS\\System32\\dsound32.dll"
"LoadAppInit_DLLs"=dword:00000001
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
»»»»»»»»»»»»»»»»»»»»»»»» RK
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{1F612DB2-0896-4316-80B8-F711DD9025A5}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{1F612DB2-0896-4316-80B8-F711DD9025A5}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{1F612DB2-0896-4316-80B8-F711DD9025A5}: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
Voila =D