~~~~~~~~~~~~~ Pre-run File Check ~~~~~~~~~~~~~
rdriv.sys PRESENT!
ItunesMusic.exe NOT PRESENT!
wkssvc.exe NOT PRESENT!
~~~~~~~~~~~~~ Post run File Check ~~~~~~~~~~~~~
rdriv.sys NOT PRESENT!
ItunesMusic.exe NOT PRESENT!
wkssvc.exe NOT PRESENT!
___________________________________________________________________
Logfile of HijackThis v1.99.1
Scan saved at 13:21:33, on 07/08/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [MSConfig] F:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [WinampAgent] F:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [MessengerPlus3] "F:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Jet Detection] "F:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [AVG7_EMC] F:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [AVG7_CC] F:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [MsnMsgr] "F:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\avgfwafu.dll
O10 - Unknown file in Winsock LSP: f:\windows\system32\avgfwafu.dll
O20 - AppInit_DLLs: MsgPlusLoader.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - F:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: ewido security suite control - ewido networks - F:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - F:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\System32\nvsvc32.exe
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - F:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
___________________________________________________________________
---------------------------------------------------------
ewido security suite - Rapport de scan
---------------------------------------------------------
+ Créé le: 13:06:06, 07/08/2005
+ Somme de contrôle: A9EFBE8B
+ Résultats du scan:
C:\Program Files\Kazaa\TopSearch.dll -> Spyware.Altnet : Nettoyer et sauvegarder
:mozilla.9:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Doubleclick : Nettoyer et sauvegarder
:mozilla.23:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Mediaplex : Nettoyer et sauvegarder
:mozilla.24:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Bluestreak : Nettoyer et sauvegarder
:mozilla.25:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Adtech : Nettoyer et sauvegarder
:mozilla.26:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Adtech : Nettoyer et sauvegarder
:mozilla.29:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.30:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.31:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.32:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.33:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Smartadserver : Nettoyer et sauvegarder
:mozilla.41:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Googleadservices : Nettoyer et sauvegarder
:mozilla.44:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Weborama : Nettoyer et sauvegarder
:mozilla.45:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Weborama : Nettoyer et sauvegarder
:mozilla.46:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Weborama : Nettoyer et sauvegarder
:mozilla.47:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Weborama : Nettoyer et sauvegarder
:mozilla.50:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Nettoyer et sauvegarder
:mozilla.51:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Sexcounter : Nettoyer et sauvegarder
:mozilla.52:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Sexcounter : Nettoyer et sauvegarder
:mozilla.53:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Serving-sys : Nettoyer et sauvegarder
:mozilla.54:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Serving-sys : Nettoyer et sauvegarder
:mozilla.55:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Serving-sys : Nettoyer et sauvegarder
:mozilla.56:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Serving-sys : Nettoyer et sauvegarder
:mozilla.57:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Serving-sys : Nettoyer et sauvegarder
:mozilla.75:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Nettoyer et sauvegarder
:mozilla.76:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Nettoyer et sauvegarder
:mozilla.77:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Nettoyer et sauvegarder
:mozilla.78:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Nettoyer et sauvegarder
:mozilla.79:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Nettoyer et sauvegarder
:mozilla.101:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Nettoyer et sauvegarder
:mozilla.102:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Nettoyer et sauvegarder
:mozilla.103:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Nettoyer et sauvegarder
:mozilla.104:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Nettoyer et sauvegarder
:mozilla.105:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Nettoyer et sauvegarder
:mozilla.106:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Casalemedia : Nettoyer et sauvegarder
:mozilla.107:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Casalemedia : Nettoyer et sauvegarder
:mozilla.108:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Casalemedia : Nettoyer et sauvegarder
:mozilla.116:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Valueclick : Nettoyer et sauvegarder
:mozilla.122:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Advertising : Nettoyer et sauvegarder
:mozilla.123:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Pointroll : Nettoyer et sauvegarder
:mozilla.124:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Pointroll : Nettoyer et sauvegarder
:mozilla.125:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Pointroll : Nettoyer et sauvegarder
:mozilla.126:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Pointroll : Nettoyer et sauvegarder
:mozilla.133:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Atdmt : Nettoyer et sauvegarder
:mozilla.134:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Advertising : Nettoyer et sauvegarder
:mozilla.135:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Advertising : Nettoyer et sauvegarder
:mozilla.136:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.Advertising : Nettoyer et sauvegarder
:mozilla.141:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.2o7 : Nettoyer et sauvegarder
:mozilla.142:F:\Documents and Settings\Adrien\Application Data\Mozilla\Firefox\Profiles\17dcxt7o.default\cookies.txt -> Spyware.Cookie.2o7 : Nettoyer et sauvegarder
F:\Documents and Settings\Adrien\Cookies\
[email protected][2].txt -> Spyware.Cookie.2o7 : Nettoyer et sauvegarder
F:\Documents and Settings\Adrien\Cookies\adrien@advertising[1].txt -> Spyware.Cookie.Advertising : Nettoyer et sauvegarder
F:\Documents and Settings\Adrien\Cookies\adrien@atdmt[2].txt -> Spyware.Cookie.Atdmt : Nettoyer et sauvegarder
F:\Documents and Settings\Adrien\Cookies\
[email protected][1].txt -> Spyware.Cookie.Advertising : Nettoyer et sauvegarder
F:\Documents and Settings\Adrien\Cookies\adrien@weborama[2].txt -> Spyware.Cookie.Weborama : Nettoyer et sauvegarder
F:\Documents and Settings\Adrien\Cookies\
[email protected][2].txt -> Spyware.Cookie.Smartadserver : Nettoyer et sauvegarder
F:\Documents and Settings\Gérald\Cookies\gérald@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Nettoyer et sauvegarder
F:\Documents and Settings\Gérald\Cookies\gé
[email protected][1].txt -> Spyware.Cookie.Smartadserver : Nettoyer et sauvegarder
::Fin du rapport
_________________________________________________________
Incident Status Location
Hacktool:HackTool/Flood No disinfected C:\Adrien\EmpScripT3\script\nHTMLn.dll
Hacktool:HackTool/Flood No disinfected C:\Adrien\EmpScripT3.11.exe[nHTMLn.dll]
Hacktool:HackTool/Flood No disinfected C:\Adrien\mIRC\EmpScripT3\script\nHTMLn.dll
Hacktool:HackTool/Flood No disinfected C:\Program Files\Empereur Script 3\EmpScripT3\script\nHTMLn.dll
Hacktool:HackTool/Flood No disinfected C:\Program Files\Save\EmpScripT3.12.exe[nHTMLn.dll]
Hacktool:HackTool/Flood No disinfected F:\Adrien\Empereur Script 3\EmpScripT3\script\nHTMLn.dll
Adware:adware/yyqu No disinfected F:\WINDOWS\smss.exe
Virus:W32/Sdbot.ftp Disinfected F:\WINDOWS\system32\i

rdriv has been deleted i think!