Re,
Voici donc le rapport du système donné par spyware terminator
Spyware Terminator Version: 1.8.7.991
Start time: 27/04/2007 22:22:02
System: Windows XP
User: Limited
Processes Scan
C:\WINDOWS\SYSTEM32\SVCHOST.EXE [Microsoft Corporation] C:\WINDOWS\SYSTEM32\ESENT.DLL [Microsoft Corporation
],
C:\WINDOWS\SYSTEM32\DLA\TFSWCTRL.EXE [Sonic Solutions] TFSWAPI.DLL [Sonic Solutions], TFSWCRES.DLL [Sonic Solutions],
C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\AVGNT.EXE [Avira GmbH] AVGCMXP.DLL [Avira GmbH], AVWINLL.DLL [Avira GmbH],
C:\MULTIMEDIA\QUICKTIME 5\QTTASK.EXE [Apple Computer, Inc.] QUICKTIME.QTS [Apple Computer, Inc.], QUICKTIMEAUTHORING.QTX [Apple Computer, Inc.], QUICKTIMECAPTURE.QTX [Apple Computer, Inc.], QUICKTIMEEFFECTS.QTX [Apple Computer, Inc.], QUICKTIMEESSENTIALS.QTX [Apple Computer, Inc.], QUICKTIMEIMAGE.QTX [Apple Computer, Inc.], QUICKTIMEINTERNETEXTRAS.QTX [Apple Computer, Inc.], QUICKTIMEMUSIC.QTX [Apple Computer, Inc.], QUICKTIMESTREAMING.QTX [Apple Computer, Inc.], QUICKTIMESTREAMINGAUTHORING.QTX [Apple Computer, Inc.], QUICKTIMESTREAMINGEXTRAS.QTX [Apple Computer, Inc.], C:\WINDOWS\SYSTEM32\QUICKTIMEVR.QTX [Apple Computer, Inc],
C:\WINDOWS\SYSTEM32\DEVLDR32.EXE [Creative Technology Ltd.] DEVCON32.DLL [Creative Technology Ltd.], SFMAN32.DLL [Creative Technology Ltd.],
C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE [Crawler.com]
C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\SCHED.EXE [Avira GmbH] SCHEDR.DLL [Avira GmbH], AVEVTLOG.DLL [Avira GmbH], C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\SQLITE3.DLL [Empty],
C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\AVGUARD.EXE [Avira GmbH] AVEVTLOG.DLL, GUARDMSG.DLL [Avira GmbH], SQLITE3.DLL, AVPREF.DLL [Avira GmbH], SMTPLIB.DLL [Avira GmbH], AVEWIN32.DLL [Avira GmbH],
C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\KPF4SS.EXE [Sunbelt Software] C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\POCOFOUNDATION.DLL [Empty], C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\POCOXML.DLL [Empty], C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\POCOEXT.DLL [Empty], KFE.DLL [Sunbelt Software], C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\LIBEAY32.DLL [Empty], C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\SSLEAY32.DLL [Empty], C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\CURLLIB.DLL [The cURL library, http://curl.haxx.se/], KWSAPI.DLL [Sunbelt Software],
C:\PROGRAM FILES\SPYWARE TERMINATOR\SP_RSSER.EXE [Crawler.com]
C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\KPF4GUI.EXE [Sunbelt Software] LIBEAY32.DLL, SSLEAY32.DLL, POCOFOUNDATION.DLL, POCOXML.DLL, POCOEXT.DLL, LIBEAY32.DLL, SSLEAY32.DLL, POCOFOUNDATION.DLL, POCOXML.DLL, POCOEXT.DLL,
C:\WINDOWS\SYSTEM32\WUAUCLT.EXE [Microsoft Corporation] ESENT.DLL,
C:\PROGRAM FILES\MOZILLA FIREFOX\FIREFOX.EXE [Mozilla Corporation] C:\PROGRAM FILES\MOZILLA FIREFOX\JS3250.DLL [Netscape Communications Corporation], C:\PROGRAM FILES\MOZILLA FIREFOX\NSPR4.DLL [Netscape Communications Corporation], C:\PROGRAM FILES\MOZILLA FIREFOX\XPCOM_CORE.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\PLC4.DLL [Netscape Communications Corporation], C:\PROGRAM FILES\MOZILLA FIREFOX\PLDS4.DLL [Netscape Communications Corporation], C:\PROGRAM FILES\MOZILLA FIREFOX\SMIME3.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\NSS3.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\SOFTOKN3.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\SSL3.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\XPCOM_COMPAT.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS\MYSPELL.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS\JAR50.DLL [Mozilla Foundation], C:\DOCUMENTS AND SETTINGS\EMILIE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\3LQ1RKM7.DEFAULT\EXTENSIONS\{3112CA9C-DE6D-4884-A869-9855DE68056C}\COMPONENTS\METRICS.DLL [Empty], C:\PROGRAM FILES\MOZILLA FIREFOX\XPCOM.DLL [Mozilla Foundation], C:\DOCUMENTS AND SETTINGS\EMILIE\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\3LQ1RKM7.DEFAULT\EXTENSIONS\{3112CA9C-DE6D-4884-A869-9855DE68056C}\COMPONENTS\GOOGLETOOLBAR.DLL [Empty], C:\PROGRAM FILES\MOZILLA FIREFOX\FREEBL3.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\NSSCKBI.DLL [Mozilla Foundation], C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS\SPELLCHK.DLL [Mozilla Foundation],
C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATOR.EXE [Crawler.com]
Startup Scan
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"Microsoft DLL Verifier" = "mscon32.exe" [ file not found ]
"KernelFaultCheck" = "C:\WINDOWS\SYSTEM32\DUMPREP.EXE" [ Microsoft Corporation ]
"dla" = "C:\WINDOWS\SYSTEM32\DLA\TFSWCTRL.EXE" [ Sonic Solutions ]
"avgnt" = "C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\AVGNT.EXE" [ Avira GmbH ]
"jkddah" = "C:\WINDOWS\SYSTEM32\JKDDAH.EXE" [ Empty ]
"SpywareTerminator" = "C:\PROGRAM FILES\SPYWARE TERMINATOR\SPYWARETERMINATORSHIELD.EXE" [ Crawler.com ]
"MSConfig" = "C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\MSCONFIG.EXE" [ Microsoft Corporation ]
"MSConfig" = "C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\MSCONFIG.EXE" [ Microsoft Corporation ]
Toolbars Scan
&Google {2318C2B1-4965-11d4-9B18-009027A5CD4F} C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR3.DLL [Google Inc.]
Windows Live Toolbar {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\MSNTB.DLL [Microsoft Corporation]
&Crawler Toolbar {4B3803EA-5230-4DC3-A7FC-33638F3D3542} C:\Program Files\Crawler\Toolbar\ctbr.dll [Crawler.com]
BHO Scan
AcroIEHlprObj Class {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX [Empty]
{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} C:\Program Files\Crawler\Toolbar\ctbr.dll [Crawler.com]
{53707962-6F74-2D53-2644-206D7942484F} C:\Sécurité\Spybot - Search & Destroy\SDHelper.dll [Safer Networking Limited]
DriveLetterAccess {5CA3D70E-1895-11CF-8E15-001234567890} C:\WINDOWS\SYSTEM32\DLA\TFSWSHX.DLL [Sonic Solutions]
{7E853D72-626A-48EC-A868-BA8D5E23E045} [file not found]
Windows Live Sign-in Helper {9030D464-4C02-4ABF-8ECC-5164760863C6} C:\PROGRAM FILES\FICHIERS COMMUNS\MICROSOFT SHARED\WINDOWS LIVE\WINDOWSLIVELOGIN.DLL [Microsoft Corporation]
Google Toolbar Helper {AA58ED58-01DD-4d91-8333-CF10577473F7} C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR3.DLL [Google Inc.]
Windows Live Toolbar Helper {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\MSNTB.DLL [Microsoft Corporation]
{40B2063F-DB01-4962-BE63-59435C01283C} [file not found]
{92780B25-18CC-41C8-B9BE-3C9C571A8263} [file not found]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{42071714-76d4-11d1-8b24-00a0c9068ff3} = Extension Affichage Panorama du Panneau de configuration (deskpan.dll) [file not found]
{764BF0E1-F219-11ce-972D-00AA00A14F56} = Extensions de l'environnement de compression de fichiers () [file not found]
{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA} = Menu contextuel de cryptage () [file not found]
{88895560-9AA2-1069-930E-00AA0030EBC8} = Extension icône HyperTerminal (C:\WINDOWS\SYSTEM32\HTICONS.DLL) [Hilgraeve, Inc.]
{0DF44EAA-FF21-4412-828E-260A8728E7F1} = Barre des tâches et menu Démarrer () [file not found]
{7A9D77BD-5403-11d2-8785-2E0420524153} = Comptes d'utilisateurs () [file not found]
{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} = Messenger Sharing Folders (C:\PROGRAM FILES\MSN MESSENGER\FSSHEXT.8.1.0178.00.DLL) [Microsoft Corporation]
{45AC2688-0253-4ED8-97DE-B5370FA7D48A} = Shell Extension for Malware scanning (C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\SHLEXT.DLL) [Avira GmbH]
{00020D75-0000-0000-C000-000000000046} = Microsoft Office Outlook Desktop Icon Handler (C:\Utilitaires\MSOffice\OFFICE11\MLSHEXT.DLL) [Microsoft Corporation]
{0006F045-0000-0000-C000-000000000046} = Microsoft Office Outlook Custom Icon Handler (C:\Utilitaires\MSOffice\OFFICE11\OLKFSTUB.DLL) [Microsoft Corporation]
{42042206-2D85-11D3-8CFF-005004838597} = Microsoft Office HTML Icon Handler (C:\UTILITAIRES\MSOFFICE\OFFICE11\MSOHEV.DLL) [Microsoft Corporation]
{CA5FEE26-14C1-4B5A-86E9-233FC0EE2682} = IZArc DragDrop Menu (C:\UTILITAIRES\IZARC\IZARCCM.DLL) [Empty]
{8D9D4D0D-FDDD-44CB-AAB2-6161FA0757C5} = IZArc Shell Context Menu (C:\UTILITAIRES\IZARC\IZARCCM.DLL) [Empty]
{5CA3D70E-1895-11CF-8E15-001234567890} = DriveLetterAccess (C:\WINDOWS\SYSTEM32\DLA\TFSWSHX.DLL) [Sonic Solutions]
{AC1DB655-4F9A-4c39-8AD2-A65324A4C446} = Autodesk Drawing Preview (C:\PROGRAM FILES\FICHIERS COMMUNS\AUTODESK SHARED\THUMBNAIL\ACTHUMBNAIL16.DLL) [Autodesk]
{36A21736-36C2-4C11-8ACB-D4136F2B57BD} = Identificateur de superposition : icône Signatures numériques de AutoCAD (C:\WINDOWS\SYSTEM32\ACSIGNICON.DLL) [Autodesk]
{6DEA92E9-8682-4b6a-97DE-354772FE5727} = Autodesk DWF Preview (C:\PROGRAM FILES\FICHIERS COMMUNS\AUTODESK SHARED\THUMBNAIL\ACDWFTHMBPRXY16.DLL) [Autodesk]
{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} = Shell Extensions for RealOne Player (C:\MULTIMEDIA\REAL MEDIA PLAYER\RPSHELL.DLL) [RealNetworks, Inc.]
{BD88A479-9623-4897-8546-BC62B9628F44} = SPTHandler (C:\PROGRAM FILES\SPYWARE TERMINATOR\SPTCONTMENU.DLL) [Crawler.com]
Winlogon Notify Scan
WgaLogon = WgaLogon.dll (WgaLogon.dll) [file not found]
Services Scan
"Adobe LM Service" = C:\PROGRAM FILES\FICHIERS COMMUNS\ADOBE SYSTEMS SHARED\SERVICE\ADOBELMSVC.EXE [Empty]
"AN983" = C:\WINDOWS\SYSTEM32\DRIVERS\AN983.SYS [ADMtek Incorporated.]
"AntiVirScheduler" = C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\SCHED.EXE [Avira GmbH]
"AntiVirService" = C:\PROGRAM FILES\ANTIVIR PERSONALEDITION CLASSIC\AVGUARD.EXE [Avira GmbH]
"Autodesk Licensing Service" = C:\PROGRAM FILES\FICHIERS COMMUNS\AUTODESK SHARED\SERVICE\ADSKSCSRV.EXE [Autodesk, Inc.]
"AVG Anti-Spyware Driver" = C:\SéCURITé\AVG ANTI-SPYWARE 7.5\GUARD.SYS [Empty]
"AVG Anti-Spyware Guard" = C:\SéCURITé\AVG ANTI-SPYWARE 7.5\GUARD.EXE [Anti-Malware Development a.s.]
"AvgAsCln" = C:\WINDOWS\SYSTEM32\DRIVERS\AVGASCLN.SYS [GRISOFT, s.r.o.]
"avgntdd" = C:\WINDOWS\SYSTEM32\DRIVERS\AVGNTDD.SYS [AVIRA GmbH]
"avgntmgr" = C:\WINDOWS\SYSTEM32\DRIVERS\AVGNTMGR.SYS [AVIRA GmbH]
"basic2" = C:\WINDOWS\SYSTEM32\DRIVERS\HSF_BSC2.SYS [Conexant]
"ctljystk" = C:\WINDOWS\SYSTEM32\DRIVERS\CTLJYSTK.SYS [Creative Technology Ltd.]
"dmboot" = C:\WINDOWS\SYSTEM32\DRIVERS\DMBOOT.SYS [Microsoft Corp., Veritas Software]
"dmio" = C:\WINDOWS\SYSTEM32\DRIVERS\DMIO.SYS [Microsoft Corp., Veritas Software]
"dmload" = C:\WINDOWS\SYSTEM32\DRIVERS\DMLOAD.SYS [Microsoft Corp., Veritas Software.]
"drvmcdb" = C:\WINDOWS\SYSTEM32\DRIVERS\DRVMCDB.SYS [Sonic Solutions]
"drvnddm" = C:\WINDOWS\SYSTEM32\DRIVERS\DRVNDDM.SYS [Sonic Solutions]
"emu10k" = C:\WINDOWS\SYSTEM32\DRIVERS\EMU10K1M.SYS [Creative Technology Ltd.]
"emu10k1" = C:\WINDOWS\SYSTEM32\DRIVERS\CTLFACEM.SYS [Creative Technology Ltd.]
"Fallback" = C:\WINDOWS\SYSTEM32\DRIVERS\HSF_FALL.SYS [Conexant]
"FETNDIS" = C:\WINDOWS\SYSTEM32\DRIVERS\FETND5.SYS [VIA Technologies, Inc. ]
"Fsks" = C:\WINDOWS\SYSTEM32\DRIVERS\HSF_FSKS.SYS [Conexant]
"fwdrv" = C:\WINDOWS\SYSTEM32\DRIVERS\FWDRV.SYS [Sunbelt Software]
"gusvc" = C:\PROGRAM FILES\GOOGLE\COMMON\GOOGLE UPDATER\GOOGLEUPDATERSERVICE.EXE [Google]
"hsf_msft" = C:\WINDOWS\SYSTEM32\DRIVERS\HSF_MSFT.SYS [Conexant]
"IDriverT" = C:\PROGRAM FILES\FICHIERS COMMUNS\INSTALLSHIELD\DRIVER\11\INTEL 32\IDRIVERT.EXE [Macrovision Corporation]
"iPodService" = C:\MULTIMEDIA\IPOD\BIN\IPODSERVICE.EXE [Apple Computer, Inc.]
"K56" = C:\WINDOWS\SYSTEM32\DRIVERS\HSF_K56K.SYS [Conexant]
"khips" = C:\WINDOWS\SYSTEM32\DRIVERS\KHIPS.SYS [Sunbelt Software]
"KPF4" = C:\PROGRAM FILES\SUNBELT SOFTWARE\PERSONAL FIREWALL\KPF4SS.EXE [Sunbelt Software]
"LightScribeService" = C:\PROGRAM FILES\FICHIERS COMMUNS\LIGHTSCRIBE\LSSRVC.EXE [Hewlett-Packard Company]
"MSDisk" = C:\WINDOWS\SYSTEM32\IRDVXC.EXE [file not found]
"nv4" = C:\WINDOWS\SYSTEM32\DRIVERS\NV4.SYS [NVIDIA Corporation]
"P1131VID" = C:\WINDOWS\SYSTEM32\DRIVERS\P1131VID.SYS [Creative Technology Ltd.]
"Ptilink" = C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS [Parallel Technologies, Inc.]
"PxHelp20" = C:\WINDOWS\SYSTEM32\DRIVERS\PXHELP20.SYS [Sonic Solutions]
"Rksample" = C:\WINDOWS\SYSTEM32\DRIVERS\HSF_SAMP.SYS [Conexant]
"Secdrv" = C:\WINDOWS\SYSTEM32\DRIVERS\SECDRV.SYS [Empty]
"sfman" = C:\WINDOWS\SYSTEM32\DRIVERS\SFMANM.SYS [Creative Technology Ltd.]
"SoftFax" = C:\WINDOWS\SYSTEM32\DRIVERS\HSF_FAXX.SYS [Conexant]
"SONYPVU1" = C:\WINDOWS\SYSTEM32\DRIVERS\SONYPVU1.SYS [Sony Corporation]
"sp_rsdrv2" = C:\WINDOWS\SYSTEM32\DRIVERS\SP_RSDRV2.SYS [Empty]
"sp_rssrv" = C:\PROGRAM FILES\SPYWARE TERMINATOR\SP_RSSER.EXE [Crawler.com]
"sscdbhk5" = C:\WINDOWS\SYSTEM32\DRIVERS\SSCDBHK5.SYS [Sonic Solutions]
"ssrtln" = C:\WINDOWS\SYSTEM32\DRIVERS\SSRTLN.SYS [Sonic Solutions]
"tfsnboio" = C:\WINDOWS\SYSTEM32\DLA\TFSNBOIO.SYS [Sonic Solutions]
"tfsncofs" = C:\WINDOWS\SYSTEM32\DLA\TFSNCOFS.SYS [Sonic Solutions]
"tfsndrct" = C:\WINDOWS\SYSTEM32\DLA\TFSNDRCT.SYS [Sonic Solutions]
"tfsndres" = C:\WINDOWS\SYSTEM32\DLA\TFSNDRES.SYS [Sonic Solutions]
"tfsnifs" = C:\WINDOWS\SYSTEM32\DLA\TFSNIFS.SYS [Sonic Solutions]
"tfsnopio" = C:\WINDOWS\SYSTEM32\DLA\TFSNOPIO.SYS [Sonic Solutions]
"tfsnpool" = C:\WINDOWS\SYSTEM32\DLA\TFSNPOOL.SYS [Sonic Solutions]
"tfsnudf" = C:\WINDOWS\SYSTEM32\DLA\TFSNUDF.SYS [Sonic Solutions]
"tfsnudfa" = C:\WINDOWS\SYSTEM32\DLA\TFSNUDFA.SYS [Sonic Solutions]
"Tones" = C:\WINDOWS\SYSTEM32\DRIVERS\HSF_TONE.SYS [Conexant]
"UMWdf" = C:\WINDOWS\System32\wdfmgr.exe [file not found]
"V124" = C:\WINDOWS\SYSTEM32\DRIVERS\HSF_V124.SYS [Conexant]
Protocol Filters Scan
Class Install Handler = {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} (C:\WINDOWS\SYSTEM32\URLMON.DLL) [Microsoft Corporation]
text/xml = {807553E5-5146-11D5-A672-00B0D022E945} (C:\PROGRAM FILES\FICHIERS COMMUNS\MICROSOFT SHARED\OFFICE11\MSOXMLMF.DLL) [Microsoft Corporation]
Hosts Scan
LOCALHOST mapping = 1
IE Scan
IERESET.INF missing START_PAGE_URL="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome" or START_PAGE_URL="http://www.msn.com"
IERESET.INF missing SAFESITE_VALUE="http://home.microsoft.com/" or SAFESITE_VALUE="ie.search.msn.com"
Voilà!
J'espère que j'ai tout fait comme il faut,
A+, merci
Emilie