Malwarebytes fait en sans echec puis traitement:
voici le log
Malwarebytes' Anti-Malware 1.37
Version de la base de données: 2182
Windows 5.1.2600 Service Pack 3
11/06/2009 21:43:00
mbam-log-2009-06-11 (21-43-00).txt
Type de recherche: Examen complet (C:|)
Eléments examinés: 162059
Temps écoulé: 1 hour(s), 15 minute(s), 8 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 3
Clé(s) du Registre infectée(s): 10
Valeur(s) du Registre infectée(s): 5
Elément(s) de données du Registre infecté(s): 5
Dossier(s) infecté(s): 26
Fichier(s) infecté(s): 179
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
C:WINDOWSsystem32zoyageze.dll (Trojan.Vundo.H) -> Delete on reboot.
c:WINDOWSsystem32 oyoyavi.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32dsprop32.dll (Worm.P2P) -> Delete on reboot.
Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{d586a753-f65f-4c62-a40b-24ed0b18c9a6} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOTCLSID{d586a753-f65f-4c62-a40b-24ed0b18c9a6} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOTCLSID{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogonNotifyf4d0703e598 (Worm.P2P) -> Delete on reboot.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallExcellentAdDisplay (Adware.ExcellentAdDisplay) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOTAppIDExcellentAdDisplay.DLL (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionUninstallPlayMP3 (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftcontim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftdslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoft
dfa (Trojan.Vundo) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunf4d07091 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRuncpmf7e3430d (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunzegenumulo (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionExplorerSharedTaskScheduler{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionShellServiceObjectDelayLoadssodl (Trojan.Vundo.H) -> Delete on reboot.
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo.H) -> Data: c:windowssystem32zoyageze.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlLSANotification Packages (Trojan.Vundo.H) -> Data: c:windowssystem32zoyageze.dll -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Trojan.Vundo.H) -> Data: c:windowssystem32 oyoyavi.dll -> Delete on reboot.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindowsAppInit_DLLs (Worm.P2P) -> Data: c:windowssystem32dsprop32.dll -> Delete on reboot.
HKEY_LOCAL_MACHINESOFTWAREMicrosoftSecurity CenterUpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
C:Program FilesMyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharAvatar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharCache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharGame (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharHistory (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharicons (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessage (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMON (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharNotifier (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharSettings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesFunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsScreenSaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsscreensaverCache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsscreensaverImages (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsShared (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsSharedCache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:Program FilesWebMediaPlayer (Adware.EGDAccess) -> Quarantined and deleted successfully.
c:program fileswebmediaplayer
esources (Adware.EGDAccess) -> Quarantined and deleted successfully.
c:program fileswebmediaplayerskins (Adware.EGDAccess) -> Quarantined and deleted successfully.
c:program fileswebmediaplayerupdates (Adware.EGDAccess) -> Quarantined and deleted successfully.
C:Program FilesPlayMP3z (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
C:Program FilesMoreRelevantAdvertisingProgram (Adware.MoreRelevantAdvertising) -> Quarantined and deleted successfully.
C:WINDOWSsystem32SystemService32 (Worm.Archive) -> Quarantined and deleted successfully.
C:Program FilesExcellentAdDisplay (Adware.ExcellentAdDisplay) -> Quarantined and deleted successfully.
Fichier(s) infecté(s):
c:WINDOWSsystem32gukehere.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
c:WINDOWSsystem32erehekug.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
c:WINDOWSsystem32 oyoyavi.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32dukovolo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32hejapive.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
c:documents and settingsestellelocal settingsapplication dataqckwqmy_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
c:documents and settingsestellelocal settingsapplication dataqckwqmy_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
c:documents and settingsestellelocal settingsapplication dataqckwqmy.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
c:documents and settingsestellelocal settingsapplication dataqckwqmy.exe (Adware.Navipromo.H) -> Quarantined and deleted successfully.
C:WINDOWSsystem32zoyageze.dll (Trojan.Vundo.H) -> Delete on reboot.
C:WINDOWSsystem32dsprop32.dll (Worm.P2P) -> Delete on reboot.
c:documents and settingsestelle.estelle-afd6537Bureauackupsackup-20090611-181614-878.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
c:program filesinternet explorermsimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3IMSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3RESTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3HIGHIN.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3HTML.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3IDLE.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3IMPIPE.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3MEDINT.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3MSG.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3OUTLCN.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3PLUGIN.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3SKIN.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3SKPLAY.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3SLSRCH.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3SRCHMN.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binMWSBAR.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binMWSOEMON.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binMWSOEPLG.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binMWSOESTB.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binMWSSRCAS.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binMWSSVC.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binNPMYWEBS.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
c:program filesPlayMP3zPlayMP3.exe (Adware.PlayMP3z) -> Quarantined and deleted successfully.
c:program fileswindows livemessenger
iched20.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:system volume information\_restore{5ed304ca-1589-4f7a-8ec7-5c6a04e58534}RP148A0061948.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:system volume information\_restore{5ed304ca-1589-4f7a-8ec7-5c6a04e58534}RP97A0031456.DLL (Adware.FunWeb) -> Quarantined and deleted successfully.
c:system volume information\_restore{5ed304ca-1589-4f7a-8ec7-5c6a04e58534}RP97snapshotMFEX-1.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP10A0002001.exe (Adware.PlayMP3z) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP23A0007577.exe (Adware.PlayMP3z) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP38A0015067.exe (Adware.PlayMP3z) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031054.exe (Worm.P2P) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031058.exe (Worm.P2P) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031059.exe (Worm.P2P) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031060.exe (Worm.P2P) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031061.exe (Worm.P2P) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031063.dll (Adware.BHO) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031064.dll (Adware.BHO) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031065.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031066.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031067.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031069.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031071.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031074.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031075.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031076.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031077.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031078.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031081.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031083.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031084.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031085.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031086.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031087.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031088.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031089.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031090.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031094.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031095.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031096.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP65A0031097.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP66A0032158.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
c:system volume information\_restore{688a9983-81e5-4206-9fc1-e15177c9da06}RP9A0001997.exe (Adware.PlayMP3z) -> Quarantined and deleted successfully.
c:WINDOWSsystem32DD.tmp (Worm.P2P) -> Quarantined and deleted successfully.
c:WINDOWSsystem32fihasine.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
c:WINDOWSsystem32wasodoku.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3HTMLMU.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3SCHMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binF3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binFWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3FFXTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3NTSTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchar1.binM3NTSTBR.MANIFEST (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharAvatarCOMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharCache 0518727 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharCache 0C2F3E5.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharCache 1A48ED7.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharCache 1A4963A.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharCache 1A4B480.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharCache 1A4DAD4.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharCache 1AFAB43.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharCache 1AFB1CB.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharCache 1AFB565.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharCache 1AFB749.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharCache 1AFB8D0 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharCachefiles.ini (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharGameCHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharGameCHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharGameREVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharHistorysearch3 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchariconsCM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchariconsMFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchariconsPSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchariconsSMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchariconsWB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearchariconsWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMONask_logo.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMONautoup.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMONautoup.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMONcenter.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMONindex.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMONmid_dots.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMONmws_logo.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMONprotect.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMONshocked.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMONstop.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMONsystray.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMONsystrayp.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMON p_grad.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharMessageCOMMONwarn.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharNotifierCOMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharNotifierDOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharNotifierFISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharNotifierKUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharNotifierLIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharNotifierMAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharNotifierMAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharNotifierOPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharNotifierROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharNotifierSEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharNotifierSURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharSettingsprevcfg2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharSettingssetting2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharSettingssettings.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesmywebsearcharSettingss_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsscreensaverCache 1AEB366.swf (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsscreensaverCachefiles.ini (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsscreensaverImages 1A46110.urr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsscreensaverImages 1AEA481.urr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsscreensaverImages 1AECB82.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsscreensaverImageswrkparam.lst (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsSharedCacheCursorManiaBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsSharedCacheMyFunCardsIMBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsSharedCacheSmileyCentralBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program filesfunwebproductsSharedCacheWebfettiBtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:program fileswebmediaplayersqlite3.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
c:program fileswebmediaplayeruninst.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
c:program fileswebmediaplayerWebMediaPlayer.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
c:program fileswebmediaplayer
esourceswmp_translation_file.xml (Adware.EGDAccess) -> Quarantined and deleted successfully.
c:program fileswebmediaplayerskinsclassic.skn (Adware.EGDAccess) -> Quarantined and deleted successfully.
c:program filesPlayMP3zuninstall.exe (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
c:program filesmorerelevantadvertisingprogramuninstall.exe (Adware.MoreRelevantAdvertising) -> Quarantined and deleted successfully.
c:WINDOWSsystem32systemservice32165.crack.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:WINDOWSsystem32systemservice32166.keygen.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:WINDOWSsystem32systemservice32167.serial.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:WINDOWSsystem32systemservice32168.setup.zip.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:WINDOWSsystem32systemservice32169.music.au.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:WINDOWSsystem32systemservice32170.music.mp3.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:WINDOWSsystem32systemservice32171.music2.au.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:WINDOWSsystem32systemservice32172.music.snd.kwd (Worm.Archive) -> Quarantined and deleted successfully.
c:program filesexcellentaddisplayuninstall.exe (Adware.ExcellentAdDisplay) -> Quarantined and deleted successfully.
c:WINDOWSsystem32D.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:WINDOWSsystem32E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:documents and settingsestelle.estelle-afd6537Bureaukillspy.exe (Rogue.KillSpy) -> Quarantined and deleted successfully.
C:WINDOWSsystem32wogutopa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
puis rédémarrage normal et log hijackthis ;
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:56:26, on 11/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSExplorer.EXE
C:Program FilesAviraAntiVir Desktopsched.exe
C:Program FilesJavajre6injqs.exe
C:Program FilesMicrosoft LifeCamMSCamS32.exe
C:Program FilesMicrosoftSearch Enhancement PackSeaPortSeaPort.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesVIAVIAudioiSBADeckADeck.exe
C:Program FilesJavajre6injusched.exe
C:WINDOWSvVX1000.exe
C:Program FilesAviraAntiVir Desktopavgnt.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesWindows LiveMessengermsnmsgr.exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
C:Documents and Settingsestelle.ESTELLE-AFD6537Bureaukillspy.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
http://www.01net.com
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://www.01net.com
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Windows Internet Explorer fourni par IE 8 FOURNI PAR 01NET.COM
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:Program FilesOrangeHSSSearchURLHookSearchPageURL.dll (file missing)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesFichiers communsMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier5.1.1309.3572swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:Program FilesJavajre6injp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:Program FilesWindows LiveToolbarwltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:Program FilesJavajre6libdeployjqsiejqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:Program FilesWindows LiveToolbarwltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:Program FilesGoogleGoogle ToolbarGoogleToolbar.dll
O4 - HKLM..Run: [AudioDeck] C:Program FilesVIAVIAudioiSBADeckADeck.exe 1
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre6injusched.exe"
O4 - HKLM..Run: [LifeCam] "C:Program FilesMicrosoft LifeCamLifeExp.exe"
O4 - HKLM..Run: [VX1000] C:WINDOWSvVX1000.exe
O4 - HKLM..Run: [avgnt] "C:Program FilesAviraAntiVir Desktopavgnt.exe" /min
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [msnmsgr] "C:Program FilesWindows LiveMessengermsnmsgr.exe" /background
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SERVICE RESEAU')
O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SYSTEM')
O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'Default user')
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program FilesWindows LiveWriterWriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:Program FilesWindows LiveWriterWriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:Program FilesMessengermsmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} (Microsoft Genuine Advantage Self Support Tool) -
http://go.microsoft.com/fwlink/?LinkId=82580
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) -
http://messenger.zone.msn.com/FR-FR/a-U ... E_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/Mi ... b56986.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:Program FilesGoogleGoogle ToolbarComponentfastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: ,
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:Program FilesAviraAntiVir Desktopsched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:Program FilesAviraAntiVir Desktopavguard.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:Program FilesJavajre6injqs.exe
--
End of file - 6914 bytes
Est ce ok, ou faut il faire autre chose (ps, j'ai fait ccleaner et lancé jv16tools puis viré les registres verts) ?