Erreur 317 icones dans le burreau

Résolu
Bonjour à tous alors voila mon problème.

apres avoir été sur astalavista.com, je me suis choppé une petite saloperie du genre une petite icone en forme de rond rouge avec une croix blanche à l'intérieur dans ma barre d'outil m'averti que je suis inffecté de spy ..... et 15 racourcis s'ouvrent sur mon burreau, j'ai beau essayer de les enlever, elles reviennent toujours et un click droit sur le rond rouge m'ouvre la page pour sois disant telecharger cet anti-spy donc impossible à fermer ..

Je ne peux donc pas trouver sa provenance et même en faisant ctrl-alt-delete je n'arrive pas a mettre la main dessus.

tout les xxx minutes il m'envoie un message d'erreur de type 317 en me donnant 2 poirts ouvert sur mon pc.

j'ai donc télécharger zone alarm, kaspersky et regfreeze , j'ai tout mis a jours et j'ai tout scanné, j'ai enlevé beaucoup de saloperies mais pas celle-ci.

j'ai déja essayer le mode sans échec avec toutes les info du haut mais même en mode sans échec cette icone est déjà ouverte au démarrage sans échec.

please un ptit poil d'aide serait bienvenu merci.

47 réponses

Résumé de la discussion

Problème de sécurité informatique: une infection par spyware survient après avoir visité un site douteux, avec une icône rouge et une croix blanche bloquant des actions et des raccourcis qui s'ouvrent sans fin. Plusieurs solutions proposées incluent HijackThis, L2MFix, VX2Finder ou Pocket Kill Box pour identifier et supprimer les éléments malveillants, tandis que Zone Alarm et Kaspersky complètent les scans. D'autres proposent des manipulations manuelles de Windows, comme nettoyer des clés de registre Winlogon/Notify et Startup, ou supprimer des DLL dans System32 et redémarrer en mode sans échec. En cas de détails supplémentaires, certains suggèrent d'examiner les entrées Trusted Zone et les redirections IE liées à des extensions et d'ajouter des rapports pour suivi.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    salut
    fait ceci
    HijackThis (ici) http://www.florensac-chasse-trap.com/
    section virus

    telecharge le et met le dans son propre dossier ex/c :hj

    clik sur do a systeme scan et save a logfile
    et copier coller le rapport
    0
    1. Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\System32\GSICON.EXE
      C:\WINDOWS\System32\dslagent.exe
      C:\Program Files\Winamp\winampa.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\WINDOWS\System32\nvsvc32.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\Program Files\RegFreeze\regfreeze.exe
      C:\WINDOWS\System32\wuauclt.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\hkj\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
      O1 - Hosts: 82.179.166.164 lender-search.com
      O1 - Hosts: 82.179.166.165 hot-searches.com
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
      O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
      O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
      O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - Startup: RegFreeze.lnk = C:\Program Files\RegFreeze\regfreeze.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
      O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
      O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
      O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
      O9 - Extra button: Microsoft AntiSpyware helper - {3CC86DCD-B8B6-4071-AA1B-A91B731BE21C} - (no file) (HKCU)
      O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {3CC86DCD-B8B6-4071-AA1B-A91B731BE21C} - (no file) (HKCU)
      O15 - Trusted Zone: www.master69.biz
      O15 - Trusted Zone: www.sgrunt.biz
      O15 - Trusted Zone: www.yeak.net
      O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:\foo.mht!http://82.179.170.82/e9xr2.chm::/file.exe
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{13034399-CA2F-44F4-B198-908A9D5F9505}: NameServer = 195.238.2.21 195.238.2.22
      O17 - HKLM\System\CS1\Services\Tcpip\..\{13034399-CA2F-44F4-B198-908A9D5F9505}: NameServer = 195.238.2.21 195.238.2.22
      O18 - Filter: text/html - {4F7681E5-6CAF-478D-9CB8-4CA593BEE7FB} - C:\WINDOWS\System32\xplugin.dll
      O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      0
      1. Contributeur sécurité
        salut
        commence par ceci
        vas sur se site
        http://virusscan.jotti.org/
        clik sur parcourir recherche ceci
        C:\center.exe et clik sur submit
        la il vas mettre un rapport met nous le

        imprime ceci pour ne rien oublier et tous faire
        tous faire dans l ordre imperativement
        -------------------------
        tous da bord telecharge ces programmes si tu ne les a pas et met les a jour mais ne les utilise pas encore
        adaware (1)
        spyboot (2)
        (ici) http://www.florensac-chasse-trap.com/ section virus
        et aussi ceci
        CleanUp312.exe (3)

        ----------------

        demarre en mode sans echec
        mode sans echec pour cela tu tapote la touche f8
        des le debut de l allumage du pc sans t arreter
        une fenetre vas souvrir tute deplace avec les fleches du clavier sur demarreren mode sans echec
        une fois sur le bureau il ni auras pas toutes les couleurs et autres c est normal.si f8 ne marche pas utilise la touche f5
        -------------------------
        desactive ta restauration systeme
        pour ça tu fais clic droit sur poste de travail
        propriété tu clique sur onglet restauration système
        tu coche la case désactiver la restauration et applique
        ------------

        assure toi de ceci
        Affiche tous les fichiers et dossiers :
        cliquer sur démarrer/panneau de configuration/option des dossiers/affichage
        Cocher afficher les dossiers cacher

        Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

        Décocher masquer les extensions dont le type est connu
        Puis fais «Ok» pour valider les changements.

        Et appliquer
        ----------------------
        vide tes fichiers temps et tempory internet file sur tous les utilisateur
        utilise ceci pour le faire
        http://pageperso.aol.fr/Balltrap34/CleanUp312.exe

        --------------------
        relance hijack coche ces lignes et ensuite clik sur fix
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
        O1 - Hosts file is located at: C:\WINDOWS\nsdb\hosts
        O1 - Hosts: 82.179.166.164 lender-search.com
        O1 - Hosts: 82.179.166.165 hot-searches.com
        O15 - Trusted Zone: www.master69.biz
        O15 - Trusted Zone: www.sgrunt.biz
        O15 - Trusted Zone: www.yeak.net
        O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:\foo.mht!http://82.179.170.82/e9xr2.chm::/file.exe
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
        O18 - Filter: text/html - {4F7681E5-6CAF-478D-9CB8-4CA593BEE7FB} - C:\WINDOWS\System32\xplugin.dll
        ------------------------------
        passe adaware et vire tous se qu il trouve
        ----------
        passe spy boot et vire tous se qu il trouvent
        -------------

        tu vide ta poubelle et tu redemarre en mode normal et refait un hijack
        et precise ou en sont tes soucis

        --
        0
        1. Alors voila j'ai fait tout ce qui était écrit plus haut j'ai même scanné avec kespersky en mode sans échec une fois toutes les étapes du haut accomplie mais mon problème persiste.

          Le problème est que même en mode sans échec ce programme est déja actif, il est le seul présent dans ma barre d'outil.
          il m'ouvre une page toute les xxx minutes, il m'envoie un message d'erreur 317 et crée une 20èene de raccourci publicitaire sur mon burreau et son impossible a enlever de plus a cause de lui plus moyen d'utiliser d'image de fond a mon écran ça fonctionne plus lol..

          j'ai tout fait sauf sur virusscan.joti.org car je n'ai pas trouvé de center.exe dans parcourir enfin bon sinon j'a
          0
          1. sinon j'ai fait tout le reste .

            Voila l'analyse apres reboot:

            Logfile of HijackThis v1.99.1
            Scan saved at 10:32:09, on 23/04/2005
            Platform: Windows XP SP1 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\System32\GSICON.EXE
            C:\WINDOWS\System32\dslagent.exe
            C:\Program Files\D-Tools\daemon.exe
            C:\Program Files\Winamp\winampa.exe
            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            C:\WINDOWS\System32\nvsvc32.exe
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\Program Files\MSN Messenger\MsnMsgr.Exe
            C:\WINDOWS\System32\wuauclt.exe
            C:\Program Files\RegFreeze\regfreeze.exe
            C:\WINDOWS\System32\wuauclt.exe
            C:\hkj\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
            O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
            O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
            O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - Startup: RegFreeze.lnk = C:\Program Files\RegFreeze\regfreeze.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
            O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
            O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
            O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
            O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
            O9 - Extra button: Microsoft AntiSpyware helper - {3CC86DCD-B8B6-4071-AA1B-A91B731BE21C} - (no file) (HKCU)
            O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {3CC86DCD-B8B6-4071-AA1B-A91B731BE21C} - (no file) (HKCU)
            O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            0
            1. Contributeur sécurité
              salut
              desinstal ceci
              C:\Program Files\RegFreeze\regfreeze.exe
              et refait un hijack et dit moi quelle sont ces icones
              0
              1. Voila voilou:

                Logfile of HijackThis v1.99.1
                Scan saved at 11:32:15, on 23/04/2005
                Platform: Windows XP SP1 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\System32\GSICON.EXE
                C:\WINDOWS\System32\dslagent.exe
                C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                C:\WINDOWS\System32\nvsvc32.exe
                C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                C:\WINDOWS\System32\wuauclt.exe
                C:\hkj\HijackThis.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.newgenlook.info/ad/ad0179/
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
                O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
                O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
                O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
                O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
                O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                O9 - Extra button: Microsoft AntiSpyware helper - {3CC86DCD-B8B6-4071-AA1B-A91B731BE21C} - (no file) (HKCU)
                O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {3CC86DCD-B8B6-4071-AA1B-A91B731BE21C} - (no file) (HKCU)
                O17 - HKLM\System\CCS\Services\Tcpip\..\{13034399-CA2F-44F4-B198-908A9D5F9505}: NameServer = 195.238.2.21 195.238.2.22
                O17 - HKLM\System\CS1\Services\Tcpip\..\{13034399-CA2F-44F4-B198-908A9D5F9505}: NameServer = 195.238.2.21 195.238.2.22
                O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

                les icones sur le burreau sont :

                pornstars, remove spyware, viagra, mp3, online betting, online casino, oral sex, party pocker, pharmacy, phentermine, britney spears, car insurance, cigarettes, credit card, cruises, forex trading, lesbian sex, air tickets, big tits, blackjack
                0
                1. Contributeur sécurité
                  relance hijack coche et fix ceci
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.newgenlook.info/ad/ad0179/
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

                  suppr les icones par clik droit et verifie qu il ne revienne pas
                  redemarre et refait un hijack
                  0
                  1. Bah rien faire ils sont toujours la et reviennent toujours.

                    et R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.newgenlook.info/ad/ad0179/
                    cette ligne reviens tout le temps et ne veux pas se barer meme pares le fix.

                    Ce qui m'ennerve , c'est ce programme d
                    0
                    1. bon je reprends grrr, ce qui m'ennerve, c'est le prog ouvert dans ma barre d'outil cet espece de rond rouge barré d'une croix blanche que je ne peux pas fermer, meme pas voir sa provenance ni rien, si je click droit il ouvre une page internet pas moyen de le fermer, ni en faisant ctrl+alt+del je ne le vois pas grrrrr

                      Meme en mode sans échec il est la, y'a pas un moyen pour le forcer a se fermer pour ainsi passer un viruscan ou autre ensuite ?

                      En tout K ca a un rapport avec newgenerationlook ça c déjà sur :-(
                      0
                      1. Contributeur sécurité
                        oki
                        fait ceci
                        telecharge ceci
                        http://www.downloads.subratam.org/l2mfix.exe
                        decompresse le double clik dessus appuie sur n importe quelle touche et ensuite choisi l option 1
                        attend il vas faire un rapport fait un copier coller de celui ci
                        ne fait surtout rien d autres
                        0
                        1. voila :

                          L2MFIX find log 1.03
                          These are the registry keys present
                          **********************************************************************************
                          Winlogon/notify:
                          Windows Registry Editor Version 5.00

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
                          "Asynchronous"=dword:00000000
                          "Impersonate"=dword:00000000
                          "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
                          6c,00,00,00
                          "Logoff"="ChainWlxLogoffEvent"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
                          "Asynchronous"=dword:00000000
                          "Impersonate"=dword:00000000
                          "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
                          6c,00,6c,00,00,00
                          "Logoff"="CryptnetWlxLogoffEvent"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
                          "DLLName"="cscdll.dll"
                          "Logon"="WinlogonLogonEvent"
                          "Logoff"="WinlogonLogoffEvent"
                          "ScreenSaver"="WinlogonScreenSaverEvent"
                          "Startup"="WinlogonStartupEvent"
                          "Shutdown"="WinlogonShutdownEvent"
                          "StartShell"="WinlogonStartShellEvent"
                          "Impersonate"=dword:00000000
                          "Asynchronous"=dword:00000001

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
                          "DLLName"="wlnotify.dll"
                          "Logon"="SCardStartCertProp"
                          "Logoff"="SCardStopCertProp"
                          "Lock"="SCardSuspendCertProp"
                          "Unlock"="SCardResumeCertProp"
                          "Enabled"=dword:00000001
                          "Impersonate"=dword:00000001
                          "Asynchronous"=dword:00000001

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
                          "Asynchronous"=dword:00000000
                          "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                          6c,00,6c,00,00,00
                          "Impersonate"=dword:00000000
                          "StartShell"="SchedStartShell"
                          "Logoff"="SchedEventLogOff"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
                          "Logoff"="WLEventLogoff"
                          "Impersonate"=dword:00000000
                          "Asynchronous"=dword:00000001
                          "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
                          6c,00,6c,00,00,00

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
                          "DLLName"="WlNotify.dll"
                          "Lock"="SensLockEvent"
                          "Logon"="SensLogonEvent"
                          "Logoff"="SensLogoffEvent"
                          "Safe"=dword:00000001
                          "MaxWait"=dword:00000258
                          "StartScreenSaver"="SensStartScreenSaverEvent"
                          "StopScreenSaver"="SensStopScreenSaverEvent"
                          "Startup"="SensStartupEvent"
                          "Shutdown"="SensShutdownEvent"
                          "StartShell"="SensStartShellEvent"
                          "PostShell"="SensPostShellEvent"
                          "Disconnect"="SensDisconnectEvent"
                          "Reconnect"="SensReconnectEvent"
                          "Unlock"="SensUnlockEvent"
                          "Impersonate"=dword:00000001
                          "Asynchronous"=dword:00000001

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
                          "Asynchronous"=dword:00000000
                          "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                          6c,00,6c,00,00,00
                          "Impersonate"=dword:00000000
                          "Logoff"="TSEventLogoff"
                          "Logon"="TSEventLogon"
                          "PostShell"="TSEventPostShell"
                          "Shutdown"="TSEventShutdown"
                          "StartShell"="TSEventStartShell"
                          "Startup"="TSEventStartup"
                          "MaxWait"=dword:00000258
                          "Reconnect"="TSEventReconnect"
                          "Disconnect"="TSEventDisconnect"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
                          "DLLName"="wlnotify.dll"
                          "Logon"="RegisterTicketExpiredNotificationEvent"
                          "Logoff"="UnregisterTicketExpiredNotificationEvent"
                          "Impersonate"=dword:00000001
                          "Asynchronous"=dword:00000001

                          **********************************************************************************
                          useragent:
                          Windows Registry Editor Version 5.00

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

                          **********************************************************************************
                          Shell Extension key:
                          Windows Registry Editor Version 5.00

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
                          "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
                          "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
                          "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
                          "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
                          "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                          "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
                          "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
                          "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
                          "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
                          "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
                          "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Page de compatibilit‚"
                          "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'environnement"
                          "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
                          "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'environnement pour les objets r‚seau de Microsoft Windows"
                          "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
                          "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
                          "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensions de l'environnement de compression de fichiers"
                          "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension de l'environnement d'imprimante Web"
                          "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
                          "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu contextuel de cryptage"
                          "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
                          "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extension ic“ne HyperTerminal"
                          "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
                          "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
                          "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
                          "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                          "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
                          "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
                          "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
                          "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau"
                          "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Connexions r‚seau"
                          "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Scanneurs et appareils photo"
                          "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Scanneurs et appareils photo"
                          "{905667aa-acd6-11d2-8080-00805f6596d2}"="&Scanneurs et appareils photo"
                          "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Scanneurs et appareils photo"
                          "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Scanneurs et appareils photo"
                          "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
                          "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
                          "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensions de l'interpr‚teur de commandes pour l'environnement d'ex‚cution de scripts Windows"
                          "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Liaison de donn‚es Microsoft"
                          "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
                          "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
                          "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
                          "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barre des tƒches et menu D‚marrer"
                          "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Rechercher"
                          "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                          "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                          "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ex‚cuter..."
                          "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
                          "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Courrier ‚lectronique"
                          "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Polices"
                          "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Outils d'administration"
                          "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
                          "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
                          "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
                          "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
                          "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
                          "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
                          "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
                          "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
                          "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
                          "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
                          "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
                          "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
                          "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Bande de recherche"
                          "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
                          "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
                          "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
                          "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
                          "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
                          "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
                          "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
                          "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
                          "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
                          "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
                          "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
                          "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
                          "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Analyseur de la barre d'adresses"
                          "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
                          "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
                          "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
                          "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
                          "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
                          "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
                          "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
                          "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
                          "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
                          "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
                          "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
                          "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
                          "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
                          "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
                          "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
                          "{FF393560-C2A7-11CF-BFF4-444553540000}"="Historique"
                          "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                          "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                          "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
                          "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
                          "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
                          "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
                          "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
                          "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
                          "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
                          "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
                          "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                          "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                          "{88C6C381-2E85-11D0-94DE-444553540000}"="Dossier ActiveX Cache"
                          "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
                          "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
                          "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Dossier Inscription"
                          "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
                          "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
                          "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
                          "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
                          "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
                          "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
                          "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
                          "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'applications d'environnement"
                          "{0B124F8F-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
                          "{CFCCC7A0-A282-11D1-9082-006008059382}"="Publication d'application Darwin"
                          "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
                          "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
                          "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extracteur de miniatures de fichier + GDI"
                          "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Gestionnaire de miniatures - Informations de r‚sum‚ (DOCFILES)"
                          "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
                          "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
                          "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Assistant Publication de sites Web"
                          "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Commande d'impressions via le Web"
                          "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objet Assistant de publication Shell"
                          "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Assistant Obtenir une identit‚ Passport"
                          "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Comptes d'utilisateurs"
                          "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
                          "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
                          "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Fichier de chaŒne"
                          "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Raccourci de chaŒne"
                          "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
                          "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
                          "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
                          "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
                          "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
                          "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
                          "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
                          "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
                          "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
                          "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
                          "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
                          "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
                          "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
                          "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
                          "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
                          "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
                          "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
                          "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
                          "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
                          "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
                          "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
                          "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
                          "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
                          "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
                          "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
                          "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
                          "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
                          "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
                          "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
                          "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
                          "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
                          "{A70C977A-BF00-412C-90B7-034C51DA2439}"="NvCpl DesktopContext Class"
                          "{FFB699E0-306A-11d3-8BD1-00104B6F7516}"="Play on my TV helper"
                          "{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
                          "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
                          "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
                          "{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
                          "{2AA59FC0-31E8-42DA-9D3C-E9A52953853B}"="CopyToCD shell extension"
                          "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
                          "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
                          "{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b5 (beta test) Context Menu Shell Extension"
                          "{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b5 (beta test) DragDrop Shell Extension"
                          "{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b5 (beta test) Context Menu Shell Extension"
                          "{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.6b5 (beta test) Property Sheet Shell Extension"

                          **********************************************************************************
                          HKEY ROOT CLASSIDS:
                          **********************************************************************************
                          Files Found are not all bad files:

                          C:\WINDOWS\SYSTEM32\
                          elbycdio.dll Tue 12 Apr 2005 13:53:00 A.... 50.176 49,00 K
                          gwfspi~1.dll Fri 28 Jan 2005 16:37:58 A.... 23.304 22,76 K
                          param32.dll Fri 22 Apr 2005 16:56:44 A.... 15.872 15,50 K
                          vsdata.dll Wed 26 Jan 2005 3:47:08 A.... 75.544 73,77 K
                          vsinit.dll Wed 26 Jan 2005 3:47:20 A.... 116.504 113,77 K
                          vsmonapi.dll Wed 26 Jan 2005 3:47:28 A.... 112.408 109,77 K
                          vspubapi.dll Wed 26 Jan 2005 3:47:32 A.... 169.752 165,77 K
                          vsregexp.dll Wed 26 Jan 2005 3:47:36 A.... 71.448 69,77 K
                          vsutil.dll Wed 26 Jan 2005 3:47:48 A.... 333.592 325,77 K
                          vsutil~1.dll Wed 26 Jan 2005 3:41:36 A.... 50.864 49,67 K
                          vsxml.dll Wed 26 Jan 2005 3:47:56 A.... 100.120 97,77 K
                          wnaspint.dll Wed 23 Feb 2005 1:00:00 A.... 57.344 56,00 K
                          zlcomm.dll Wed 26 Jan 2005 3:48:16 A.... 71.448 69,77 K
                          zlcommdb.dll Wed 26 Jan 2005 3:48:20 A.... 63.256 61,77 K

                          14 items found: 14 files, 0 directories.
                          Total of file sizes: 1.311.632 bytes 1,25 M
                          Locate .tmp files:

                          No matches found.
                          **********************************************************************************
                          Directory Listing of system files:
                          Le volume dans le lecteur C n'a pas de nom.
                          Le num‚ro de s‚rie du volume est C03D-AFB5

                          R‚pertoire de C:\WINDOWS\System32

                          23/04/2005 00:32 <REP> dllcache
                          24/03/2005 00:16 <REP> Microsoft
                          16/03/2005 14:07 56 9EFAF32989.sys
                          1 fichier(s) 56 octets
                          2 R‚p(s) 22.930.173.952 octets libres
                          0
                          1. Contributeur sécurité
                            oki
                            relance l2mfix et clik sur l2mfix.bat et cette foix clik sur l option2 et laisse le faire et met moi le rapport et un
                            nouveau rapport hijack
                            et dit moi ou en sont tes soucis stp
                            0
                            1. L2Mfix 1.03

                              Running From:
                              C:\hkj\l2mfix

                              RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
                              Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
                              This program is Freeware, use it on your own risk!

                              Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
                              (ID-NI) ALLOW Read BUILTIN\Utilisateurs
                              (ID-IO) ALLOW Read BUILTIN\Utilisateurs
                              (ID-NI) ALLOW Full access BUILTIN\Administrateurs
                              (ID-IO) ALLOW Full access BUILTIN\Administrateurs
                              (ID-NI) ALLOW Full access AUTORITE NT\SYSTEM
                              (ID-IO) ALLOW Full access AUTORITE NT\SYSTEM
                              (ID-IO) ALLOW Full access CREATEUR PROPRIETAIRE

                              Setting registry permissions:

                              RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
                              Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
                              This program is Freeware, use it on your own risk!

                              Denying C(CI) access for predefined group "Administrators"
                              - adding new ACCESS DENY entry

                              Registry Permissions set too:

                              RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
                              Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
                              This program is Freeware, use it on your own risk!

                              Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
                              (CI) DENY --C------- BUILTIN\Administrateurs
                              (ID-NI) ALLOW Read BUILTIN\Utilisateurs
                              (ID-IO) ALLOW Read BUILTIN\Utilisateurs
                              (ID-NI) ALLOW Full access BUILTIN\Administrateurs
                              (ID-IO) ALLOW Full access BUILTIN\Administrateurs
                              (ID-NI) ALLOW Full access AUTORITE NT\SYSTEM
                              (ID-IO) ALLOW Full access AUTORITE NT\SYSTEM
                              (ID-IO) ALLOW Full access CREATEUR PROPRIETAIRE

                              Setting up for Reboot

                              Starting Reboot!

                              C:\hkj\l2mfix
                              System Rebooted!

                              Running From:
                              C:\hkj\l2mfix

                              killing explorer and rundll32.exe

                              Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
                              Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
                              Killing PID 1516 'explorer.exe'
                              Killing PID 1516 'explorer.exe'

                              Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
                              Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
                              Error, Cannot find a process with an image name of rundll32.exe

                              Scanning First Pass. Please Wait!

                              First Pass Completed

                              Second Pass Scanning

                              Second pass Completed!

                              Zipping up files for submission:
                              adding: clear.reg (188 bytes security) (deflated 2%)
                              adding: echo.reg (188 bytes security) (deflated 6%)
                              adding: direct.txt (188 bytes security) (stored 0%)
                              adding: lo2.txt (188 bytes security) (deflated 70%)
                              adding: readme.txt (188 bytes security) (deflated 49%)
                              adding: report.txt (188 bytes security) (deflated 63%)
                              adding: test.txt (188 bytes security) (stored 0%)
                              adding: test2.txt (188 bytes security) (stored 0%)
                              adding: test3.txt (188 bytes security) (stored 0%)
                              adding: test5.txt (188 bytes security) (stored 0%)
                              adding: backregs/shell.reg (188 bytes security) (deflated 74%)

                              Restoring Registry Permissions:

                              RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
                              Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
                              This program is Freeware, use it on your own risk!

                              Revoking access for predefined group "Administrators"
                              Inherited ACE can not be revoked here!
                              Inherited ACE can not be revoked here!

                              Registry permissions set too:

                              RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
                              Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
                              This program is Freeware, use it on your own risk!

                              Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
                              (ID-NI) ALLOW Read BUILTIN\Utilisateurs
                              (ID-IO) ALLOW Read BUILTIN\Utilisateurs
                              (ID-NI) ALLOW Full access BUILTIN\Administrateurs
                              (ID-IO) ALLOW Full access BUILTIN\Administrateurs
                              (ID-NI) ALLOW Full access AUTORITE NT\SYSTEM
                              (ID-IO) ALLOW Full access AUTORITE NT\SYSTEM
                              (ID-IO) ALLOW Full access CREATEUR PROPRIETAIRE

                              Restoring Sedebugprivilege:

                              Granting SeDebugPrivilege to Administrators ... failed (GetAccountSid(Administrators)=1332

                              The following Is the Current Export of the Winlogon notify key:
                              ****************************************************************************
                              Windows Registry Editor Version 5.00

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
                              "Asynchronous"=dword:00000000
                              "Impersonate"=dword:00000000
                              "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
                              6c,00,00,00
                              "Logoff"="ChainWlxLogoffEvent"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
                              "Asynchronous"=dword:00000000
                              "Impersonate"=dword:00000000
                              "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
                              6c,00,6c,00,00,00
                              "Logoff"="CryptnetWlxLogoffEvent"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
                              "DLLName"="cscdll.dll"
                              "Logon"="WinlogonLogonEvent"
                              "Logoff"="WinlogonLogoffEvent"
                              "ScreenSaver"="WinlogonScreenSaverEvent"
                              "Startup"="WinlogonStartupEvent"
                              "Shutdown"="WinlogonShutdownEvent"
                              "StartShell"="WinlogonStartShellEvent"
                              "Impersonate"=dword:00000000
                              "Asynchronous"=dword:00000001

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
                              "DLLName"="wlnotify.dll"
                              "Logon"="SCardStartCertProp"
                              "Logoff"="SCardStopCertProp"
                              "Lock"="SCardSuspendCertProp"
                              "Unlock"="SCardResumeCertProp"
                              "Enabled"=dword:00000001
                              "Impersonate"=dword:00000001
                              "Asynchronous"=dword:00000001

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
                              "Asynchronous"=dword:00000000
                              "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                              6c,00,6c,00,00,00
                              "Impersonate"=dword:00000000
                              "StartShell"="SchedStartShell"
                              "Logoff"="SchedEventLogOff"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
                              "Logoff"="WLEventLogoff"
                              "Impersonate"=dword:00000000
                              "Asynchronous"=dword:00000001
                              "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
                              6c,00,6c,00,00,00

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
                              "DLLName"="WlNotify.dll"
                              "Lock"="SensLockEvent"
                              "Logon"="SensLogonEvent"
                              "Logoff"="SensLogoffEvent"
                              "Safe"=dword:00000001
                              "MaxWait"=dword:00000258
                              "StartScreenSaver"="SensStartScreenSaverEvent"
                              "StopScreenSaver"="SensStopScreenSaverEvent"
                              "Startup"="SensStartupEvent"
                              "Shutdown"="SensShutdownEvent"
                              "StartShell"="SensStartShellEvent"
                              "PostShell"="SensPostShellEvent"
                              "Disconnect"="SensDisconnectEvent"
                              "Reconnect"="SensReconnectEvent"
                              "Unlock"="SensUnlockEvent"
                              "Impersonate"=dword:00000001
                              "Asynchronous"=dword:00000001

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
                              "Asynchronous"=dword:00000000
                              "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                              6c,00,6c,00,00,00
                              "Impersonate"=dword:00000000
                              "Logoff"="TSEventLogoff"
                              "Logon"="TSEventLogon"
                              "PostShell"="TSEventPostShell"
                              "Shutdown"="TSEventShutdown"
                              "StartShell"="TSEventStartShell"
                              "Startup"="TSEventStartup"
                              "MaxWait"=dword:00000258
                              "Reconnect"="TSEventReconnect"
                              "Disconnect"="TSEventDisconnect"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
                              "DLLName"="wlnotify.dll"
                              "Logon"="RegisterTicketExpiredNotificationEvent"
                              "Logoff"="UnregisterTicketExpiredNotificationEvent"
                              "Impersonate"=dword:00000001
                              "Asynchronous"=dword:00000001

                              The following are the files found:
                              ****************************************************************************

                              Registry Entries that were Deleted:
                              Please verify that the listing looks ok.
                              If there was something deleted wrongly there are backups in the backreg folder.
                              ****************************************************************************
                              REGEDIT4

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
                              REGEDIT4

                              [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                              ****************************************************************************
                              Desktop.ini Contents:
                              ****************************************************************************
                              ****************************************************************************

                              --------------------------------------------------------------------------------------------------------------------------------------------------------

                              VOILA pour hijack

                              Logfile of HijackThis v1.99.1
                              Scan saved at 13:15:15, on 23/04/2005
                              Platform: Windows XP SP1 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\System32\GSICON.EXE
                              C:\WINDOWS\System32\dslagent.exe
                              C:\Program Files\D-Tools\daemon.exe
                              C:\Program Files\Winamp\winampa.exe
                              C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                              C:\Program Files\MSN Messenger\MsnMsgr.Exe
                              C:\WINDOWS\System32\nvsvc32.exe
                              C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                              C:\WINDOWS\explorer.exe
                              C:\WINDOWS\system32\NOTEPAD.EXE
                              C:\WINDOWS\System32\wuauclt.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\hkj\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.newgenlook.info/ad/ad0179/
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                              O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                              O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
                              O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
                              O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                              O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                              O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                              O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
                              O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
                              O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
                              O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                              O9 - Extra button: Microsoft AntiSpyware helper - {3CC86DCD-B8B6-4071-AA1B-A91B731BE21C} - (no file) (HKCU)
                              O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {3CC86DCD-B8B6-4071-AA1B-A91B731BE21C} - (no file) (HKCU)
                              O17 - HKLM\System\CCS\Services\Tcpip\..\{13034399-CA2F-44F4-B198-908A9D5F9505}: NameServer = 195.238.2.21 195.238.2.22
                              O17 - HKLM\System\CS1\Services\Tcpip\..\{13034399-CA2F-44F4-B198-908A9D5F9505}: NameServer = 195.238.2.21 195.238.2.22
                              O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
                              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                              O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                              0
                              1. Et pour ce qui est du problème bah il est toujours la et les raccourci reviennent toujours snif
                                0
                                1. voila ce que ça donne:

                                  Startup items buried in registry:
                                  ---------------------------------

                                  HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                                  "MsnMsgr" = ""C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background" [MS]

                                  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                                  "GSICONEXE" = "GSICON.EXE" ["Eicon Networks"]
                                  "DSLAGENTEXE" = "dslagent.exe USB" [null data]
                                  "DAEMON Tools-1033" = ""C:\Program Files\D-Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]
                                  "NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
                                  "WinampAgent" = "C:\Program Files\Winamp\winampa.exe" [null data]
                                  "Zone Labs Client" = ""C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"" ["Zone Labs Inc."]
                                  "NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup" [MS]
                                  "KAVPersonal50" = ""C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize" ["Kaspersky Lab"]

                                  HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
                                  {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
                                  -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx" [empty string]
                                  {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
                                  -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" ["Safer Networking Limited"]
                                  {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = "Google Toolbar Helper" [from CLSID]
                                  -> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

                                  HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
                                  "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
                                  -> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
                                  "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
                                  "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
                                  "{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
                                  "{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
                                  "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
                                  "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
                                  "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
                                  "{2AA59FC0-31E8-42DA-9D3C-E9A52953853B}" = "CopyToCD shell extension"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\VSO\COPYTO~1\CTCDSH~1.DLL" ["VSO Software"]
                                  "{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
                                  "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
                                  "{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.6b5 (beta test) Context Menu Shell Extension"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
                                  "{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.6b5 (beta test) DragDrop Shell Extension"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
                                  "{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.6b5 (beta test) Context Menu Shell Extension"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
                                  "{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.6b5 (beta test) Property Sheet Shell Extension"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]

                                  HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\
                                  INFECTION WARNING! "{D56A1203-1452-EBA1-7294-EE3377770000}" = "Interlinking Memory Support"
                                  -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\param32.dll" [null data]

                                  Enabled Screen Saver:
                                  ---------------------

                                  HKCU\Control Panel\Desktop\
                                  "SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]

                                  Enabled Wallpaper and Active Desktop:
                                  -------------------------------------

                                  Active Desktop is disabled.

                                  HKCU\Control Panel\Desktop\
                                  "Wallpaper" = "C:\wp.bmp"

                                  Startup items in "pegase" & "All Users" startup folders:
                                  --------------------------------------------------------

                                  C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
                                  "Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l" [MS]

                                  Winsock2 Service Provider DLLs:
                                  -------------------------------

                                  Namespace Service Providers

                                  HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
                                  000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
                                  000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
                                  000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

                                  Transport Service Providers

                                  HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
                                  0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
                                  %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
                                  %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

                                  Toolbars, Explorer Bars, Extensions:
                                  ------------------------------------

                                  Toolbars

                                  HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
                                  "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
                                  -> {CLSID}\(Default) = "&Google"
                                  -> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

                                  HKLM\Software\Microsoft\Internet Explorer\Toolbar\
                                  "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
                                  -> {CLSID}\(Default) = "&Google"
                                  -> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

                                  Extensions (Tools menu items, main toolbar menu buttons)

                                  HKCU\Software\Microsoft\Internet Explorer\Extensions\
                                  {3CC86DCD-B8B6-4071-AA1B-A91B731BE21C}\
                                  "ButtonText" = "Microsoft AntiSpyware helper"
                                  "MenuText" = "Microsoft AntiSpyware helper"

                                  HKLM\Software\Microsoft\Internet Explorer\Extensions\
                                  {FB5F1910-F110-11D2-BB9E-00C04F795683}\
                                  "ButtonText" = "Messenger"
                                  "MenuText" = "Windows Messenger"
                                  "Exec" = "C:\Program Files\Messenger\MSMSGS.EXE" [MS]

                                  Running Services (Display Name, Service Name, Path {Service DLL}):
                                  ------------------------------------------------------------------

                                  kavsvc, kavsvc, ""C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe"" ["Kaspersky Lab"]
                                  NVIDIA Display Driver Service, NVSvc, "C:\WINDOWS\System32\nvsvc32.exe" ["NVIDIA Corporation"]
                                  TrueVector Internet Monitor, vsmon, "C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service" ["Zone Labs Inc."]
                                  Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\System32\wdfmgr.exe" [MS]

                                  ----------
                                  This report excludes default entries except where indicated.
                                  To see *everywhere* the script checks and *everything* it finds,
                                  launch it from a command prompt or a shortcut with the -all parameter.
                                  ----------
                                  0
                                  1. Contributeur sécurité
                                    oki
                                    recherche et suppr ceci
                                    C:\WINDOWS\System32\param32.dll
                                    suppr tes icones avec le clik droit redemarre et dit moiou cela en est
                                    0
                                    1. trouvé mais impossible à effacer "utilisation en cours", dans propriété il a bien été créé hier.

                                      Mais comment fermer le programme qui l'utilise pour l'effacer ça j'ai toujours pas trouvé.
                                      0
                                      1. Contributeur sécurité
                                        demarre en mode sans echec et la tu devrait pouvoir le suppr
                                        0
                                        • 1
                                        • 2
                                        • 3