Chalut
bon alors j'ai fait tous les scans possibles, et voici les rapports qui ont donné uelque chose :
a-squared Report
Scan Started: 09/03/2006 14:55:23
Scan Finished: 09/03/2006 15:17:48
Scanning Time: 0h 22min 25sec
Scanned Files: 71130
Infected Files: 8
Nom du fichier Diagnostic
C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@247realmedia[1].txt Trace.TrackingCookie
C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@bluestreak[2].txt Trace.TrackingCookie
C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@com[1].txt Trace.TrackingCookie
C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@doubleclick[1].txt Trace.TrackingCookie
C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@tradedoubler[2].txt Trace.TrackingCookie
C:\Documents and Settings\Jean-Christophe\Cookies\jean-christophe@weborama[1].txt Trace.TrackingCookie
C:\Documents and Settings\Jean-Christophe\Mes documents\Installs\SmitfraudFix\Process.exe Riskware.RiskTool.Win32.Processor.20
C:\WINDOWS\system32\Process.exe Riskware.RiskTool.Win32.Processor.20
TOUS ces fichiers ont été effacés.
voici ad aware
Ad-Aware SE Build 1.06r1
Logfile Created on:jeudi 9 mars 2006 16:28:34
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R95 06.03.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):16 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
09-03-2006 16:28:34 - Scan started. (Full System Scan)
MRU List Object Recognized!
Location: : C:\Documents and Settings\Jean-Christophe\recent
Description :
MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description :
MRU List Object Recognized!
Location: : S-1-5-21-1229272821-1177238915-839522115-1007\software\microsoft\internet explorer
Description :
MRU List Object Recognized!
Location: : S-1-5-21-1229272821-1177238915-839522115-1007\software\microsoft\internet explorer\main
Description :
MRU List Object Recognized!
Location: : S-1-5-21-1229272821-1177238915-839522115-1007\software\microsoft\internet explorer\typedurls
Description :
MRU List Object Recognized!
Location: : S-1-5-21-1229272821-1177238915-839522115-1007\software\microsoft\mediaplayer\player\settings
Description :
MRU List Object Recognized!
Location: : S-1-5-21-1229272821-1177238915-839522115-1007\software\microsoft\office\11.0\common\general
Description :
MRU List Object Recognized!
Location: : S-1-5-21-1229272821-1177238915-839522115-1007\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description :
MRU List Object Recognized!
Location: : S-1-5-21-1229272821-1177238915-839522115-1007\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description :
MRU List Object Recognized!
Location: : S-1-5-21-1229272821-1177238915-839522115-1007\software\microsoft\windows\currentversion\explorer\recentdocs
Description :
MRU List Object Recognized!
Location: : S-1-5-21-1229272821-1177238915-839522115-1007\software\realnetworks\realplayer\6.0\preferences
Description :
MRU List Object Recognized!
Location: : S-1-5-21-1229272821-1177238915-839522115-1007\software\realnetworks\realplayer\6.0\preferences
Description :
MRU List Object Recognized!
Location: : S-1-5-21-1229272821-1177238915-839522115-1007\software\realnetworks\realplayer\6.0\preferences
Description :
MRU List Object Recognized!
Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general
Description :
MRU List Object Recognized!
Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general
Description :
MRU List Object Recognized!
Location: : S-1-5-21-1229272821-1177238915-839522115-1007\software\microsoft\windows media\wmsdk\general
Description :
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 144
ThreadCreationTime : 09-03-2006 13:49:34
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 196
ThreadCreationTime : 09-03-2006 13:49:44
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 220
ThreadCreationTime : 09-03-2006 13:49:45
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 264
ThreadCreationTime : 09-03-2006 13:49:49
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Applications Services et Contrôleur
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 276
ThreadCreationTime : 09-03-2006 13:49:49
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 428
ThreadCreationTime : 09-03-2006 13:49:52
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 488
ThreadCreationTime : 09-03-2006 13:49:54
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [msmpeng.exe]
FilePath : C:\Program Files\Windows Defender\
ProcessID : 524
ThreadCreationTime : 09-03-2006 13:49:55
BasePriority : Normal
FileVersion : 1.1.1051.0
ProductVersion : 1.1.1051.0
ProductName : Windows Defender
CompanyName : Microsoft Corporation
FileDescription : Service Executable
InternalName : MsMpEng.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : MsMpEng.exe
#:9 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 588
ThreadCreationTime : 09-03-2006 13:49:56
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [sdmcp.exe]
FilePath : C:\PROGRA~1\FICHIE~1\Stardock\
ProcessID : 776
ThreadCreationTime : 09-03-2006 13:50:33
BasePriority : Normal
FileVersion : 0, 0, 5, 11
ProductVersion : 0, 0, 5, 11
ProductName : Stardock MCP Core Services (System Extensions and Hooks)
CompanyName : Stardock
FileDescription : MCPServer
InternalName : MCP
LegalCopyright : Copyright © 2005
OriginalFilename : SDMCP.exe
#:11 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 868
ThreadCreationTime : 09-03-2006 13:50:33
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Explorateur Windows
InternalName : explorer
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : EXPLORER.EXE
#:12 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ProcessID : 1316
ThreadCreationTime : 09-03-2006 14:18:16
BasePriority : Normal
FileVersion : 7.00.5296.0 (winmain(wmbla).060125-1505)
ProductVersion : 7.00.5296.0
ProductName : Microsoft® Internet Explorer
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : IEXPLORE.EXE
#:13 [helpsvc.exe]
FilePath : C:\WINDOWS\PCHealth\HelpCtr\Binaries\
ProcessID : 1680
ThreadCreationTime : 09-03-2006 15:14:43
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Microsoft Help Center Service
InternalName : HELPSVC.EXE
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : HELPSVC.EXE
#:14 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 2012
ThreadCreationTime : 09-03-2006 15:28:06
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 16
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 16
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 16
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 16
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 16
Deep scanning and examining files (D:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for D:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 16
Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 16
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 16
16:36:12 Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:07:38.31
Objects scanned:116519
Objects identified:0
Objects ignored:0
New critical objects:0
et avscan
Report file date: jeudi 9 mars 2006 15:29
Jobname: 'Local Drives'
Scanning for 327730 virus strains and unwanted programs.
Licensed to: AntiVir PersonalEdition Classic
Serialnumber: 0000149996-WURGE-0001
Platform: Windows XP
Windowsversion: (Service Pack 2) [5.1.2600]
Username: Jean-Christophe
Computername: TOF
Versioninformations:
AVSCAN.EXE : 7.0.0.21 528424 23/02/2006 09:22:32
AVSCAN.DLL : 7.0.0.21 42536 23/02/2006 09:22:32
LUKE.DLL : 7.0.0.21 114728 23/02/2006 09:22:32
LUKERES.DLL : 7.0.0.21 27688 23/02/2006 09:22:32
ANTIVIR0.VDF : 6.32.0.60 4323840 01/03/2006 14:15:46
ANTIVIR1.VDF : 6.34.0.11 1424384 09/03/2006 13:45:07
ANTIVIR2.VDF : 6.34.0.12 1536 09/03/2006 13:45:07
ANTIVIR3.VDF : 6.34.0.22 24064 09/03/2006 13:45:07
AVEWIN32.DLL : 6.33.0.38 1163776 01/03/2006 09:24:36
AVPREF.DLL : 6.34.0.0 38440 23/02/2006 09:22:30
AVREP.DLL : 6.34.0.20 2428968 09/03/2006 13:45:08
AVPACK32.DLL : 6.33.0.6 331816 23/02/2006 09:22:30
AVREG.DLL : 6.31.0.90 27688 23/02/2006 09:22:30
NETNT.DLL : 6.32.0.0 6696 23/02/2006 09:22:32
NETNW.DLL : 6.32.0.0 9768 23/02/2006 09:22:32
Start of the scan: jeudi 9 mars 2006 15:29
Start scanning boot sectors:
Boot sector 'C:'
[NOTE] No virus was found!
Boot sector 'D:'
[NOTE] No virus was found!
Starting to scan the registry.
The registry was scanned ( 22 files ).
Starting the file scan:
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\Jean-Christophe\ntuser.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\Jean-Christophe\NtUser.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\Jean-Christophe\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\Jean-Christophe\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService\NTUSER.DAT
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService\ntuser.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\default
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\default.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SAM
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SAM.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SECURITY
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SECURITY.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\software
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\software.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\system
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\system.LOG
[WARNING] The file could not be opened!
The path E:\ could ot be found!
Le périphérique n'est pas prêt.
End of the scan: jeudi 9 mars 2006 16:18
Used time: 49:30 min
The scan has been done completely.
4202 Scanning directories
290323 Files were scanned
0 viruses and/or unwanted programs was found
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
2005 Archives were scanned
38 Warnings
0 Notes
J'ai pas compris ces 38 warning, qui ne sont affichés nulle part. Bon, l'adresse bizarre est toujours dans la barre iexplorer d'adresse, j'y comprends plus rien, ça me casse les 8==D ce truc.
Si tu as n'importe quelle idée, je suis preneur. De mon côté je vais continuer à regarder ce que je peux trouver
Merci!