[Troyan+Barniere pub]

Résolu
Salutation,

En surfant, je me suis ramassé quelques troyans. J'ai utilisé donc : Clean Up ; ensuite, en Mode sans echec, j'ai appliqué Ad-Adware et a-squared. Mais il me reste quelques bricoles, comme la barniere de pub et d'autres chose que mes soft non pas détecté.

Voici les log ci-joints :

Logfile of HijackThis v1.99.1
Scan saved at 16:56:09, on 23/12/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [dmvcu.exe] C:\WINDOWS\System32\dmvcu.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [desktop] C:\WINDOWS\System32\idemlog.exe
O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"
O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7DA181BB-EF8D-4A7E-8C53-7BFC718EF71D} (Upload Class) - http://photos.wanadoo.fr/al/presentation/pc/resources/activex/Ephoto.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photoways.com/clients/ImageUploader3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{47E7FC26-403B-4079-9626-FEA7EDB05B20}: NameServer = 85.255.114.75,85.255.112.148
O17 - HKLM\System\CS1\Services\Tcpip\..\{47E7FC26-403B-4079-9626-FEA7EDB05B20}: NameServer = 85.255.114.75,85.255.112.148
O20 - Winlogon Notify: style2 - C:\WINDOWS\q174546093_disk.dll (file missing)
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

Par avance, Merci.

27 réponses

Résumé de la discussion

Question : suite à une navigation, une infection par troyans subsiste malgré l'usage de Clean Up, Ad-Adware et a-squared, avec des éléments résiduels tels qu'une barre de pub non détectée. Plusieurs interventions évoquées incluent la suppression manuelle d'une clé de registre ZPMODEMSYSNTDRVNT et l'usage de RegEdit, ainsi que des outils comme SmitFraudFix pour cibler les débris restants. D'autres messages présentent des rapports HijackThis et des résultats détaillés des scans, montrant des listes longues d'entrées de démarrage et d'extensions variables à nettoyer. En parallèle, les échanges soulignent que certains éléments malveillants peuvent persister dans le registre et que les solutions proposées nécessitent vérification et précision pour éviter des réinfections.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut AlexMex !!! :oD

    Tout d'abord, désinstalle UnspyPC via le Panneau de Configuration (Ajout/Suppression de programmes)

    Ensuite, analyse ces 2 fichiers ici :
    http://www.virustotal.com/xhtml/virustotal_en.html

    C:\WINDOWS\System32\dmvcu.exe
    C:\WINDOWS\System32\idemlog.exe

    Enfin, copie-colle les rapports des scans de ces 2 fichiers ici.

    Tiens-moi au courant !!! :-)
    A+++++
    1. Salut,

      J'ai toujours Norton qui s'exite : ALerte trojan .... Malgre les scan.
      Là, je suis perdu de chez perdu.
      UnSpy (Fichier inconnu même sous rechercher)
      Je rêgle un autre problème aussi.

      C'est koi Regis59 ton programme exactement ?

      Voic le log actuellement

      Logfile of HijackThis v1.99.1
      Scan saved at 05:01:44, on 24/12/2005
      Platform: Windows XP SP1 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Intel\ASF Agent\ASFAgent.exe
      C:\WINDOWS\System32\CTsvcCDA.exe
      C:\Program Files\Norton AntiVirus\navapsvc.exe
      C:\WINDOWS\System32\nvsvc32.exe
      C:\WINDOWS\System32\MsPMSPSv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\System32\DSentry.exe
      C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
      C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
      C:\PROGRA~1\Wanadoo\CnxMon.exe
      C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
      C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
      C:\PROGRA~1\NORTON~1\navapw32.exe
      C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
      C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Winamp\winampa.exe
      C:\WINDOWS\System32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\eMule\emule.exe
      C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe
      C:\Program Files\Digital Line Detect\DLG.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\PROGRA~1\Livecom\Toaster\Toaster.exe
      C:\PROGRA~1\Livecom\APPLIC~1\eConfv4\ftplayer.exe
      C:\WINDOWS\System32\wuauclt.exe
      C:\WINDOWS\System32\wuauclt.exe
      C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
      O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
      O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
      O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
      O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
      O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
      O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
      O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
      O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
      O4 - HKLM\..\Run: [dmvcu.exe] C:\WINDOWS\System32\dmvcu.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [desktop] C:\WINDOWS\System32\idemlog.exe
      O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"
      O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
      O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
      O4 - Global Startup: Digital Line Detect.lnk = ?
      O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
      O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
      O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
      O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
      O16 - DPF: {7DA181BB-EF8D-4A7E-8C53-7BFC718EF71D} (Upload Class) - http://photos.wanadoo.fr/al/presentation/pc/resources/activex/Ephoto.cab
      O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photoways.com/clients/ImageUploader3.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{47E7FC26-403B-4079-9626-FEA7EDB05B20}: NameServer = 85.255.114.75,85.255.112.148
      O17 - HKLM\System\CS1\Services\Tcpip\..\{47E7FC26-403B-4079-9626-FEA7EDB05B20}: NameServer = 85.255.114.75,85.255.112.148
      O20 - Winlogon Notify: style2 - C:\WINDOWS\q174546093_disk.dll (file missing)
      O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
      O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
      O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
      1. Salut,

        J'ai toujours Norton qui s'exite : ALerte trojan .... Malgre les scan.
        Là, je suis perdu de chez perdu.
        UnSpy (Fichier inconnu même sous rechercher)
        Je rêgle un autre problème aussi.

        C'est koi Regis59 ton programme exactement ?

        Voic le log actuellement

        Logfile of HijackThis v1.99.1
        Scan saved at 05:01:44, on 24/12/2005
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Intel\ASF Agent\ASFAgent.exe
        C:\WINDOWS\System32\CTsvcCDA.exe
        C:\Program Files\Norton AntiVirus\navapsvc.exe
        C:\WINDOWS\System32\nvsvc32.exe
        C:\WINDOWS\System32\MsPMSPSv.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\System32\DSentry.exe
        C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
        C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
        C:\PROGRA~1\Wanadoo\CnxMon.exe
        C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
        C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
        C:\PROGRA~1\NORTON~1\navapw32.exe
        C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
        C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\Winamp\winampa.exe
        C:\WINDOWS\System32\ctfmon.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\eMule\emule.exe
        C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe
        C:\Program Files\Digital Line Detect\DLG.exe
        C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
        C:\PROGRA~1\Livecom\Toaster\Toaster.exe
        C:\PROGRA~1\Livecom\APPLIC~1\eConfv4\ftplayer.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
        O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
        O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
        O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
        O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
        O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
        O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
        O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
        O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
        O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
        O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
        O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKLM\..\Run: [dmvcu.exe] C:\WINDOWS\System32\dmvcu.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [desktop] C:\WINDOWS\System32\idemlog.exe
        O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"
        O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
        O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
        O4 - Global Startup: Digital Line Detect.lnk = ?
        O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
        O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
        O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
        O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
        O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
        O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
        O16 - DPF: {7DA181BB-EF8D-4A7E-8C53-7BFC718EF71D} (Upload Class) - http://photos.wanadoo.fr/al/presentation/pc/resources/activex/Ephoto.cab
        O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photoways.com/clients/ImageUploader3.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{47E7FC26-403B-4079-9626-FEA7EDB05B20}: NameServer = 85.255.114.75,85.255.112.148
        O17 - HKLM\System\CS1\Services\Tcpip\..\{47E7FC26-403B-4079-9626-FEA7EDB05B20}: NameServer = 85.255.114.75,85.255.112.148
        O20 - Winlogon Notify: style2 - C:\WINDOWS\q174546093_disk.dll (file missing)
        O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
        O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
        O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
        O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
        O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
        1. Salut,

          Merci,

          Regis59, voici le rapport du programme :

          Rapport fait à 5:41:54,40 le 24/12/2005
          Executé à partir de C:\Documents and Settings\Alexandre
          OS: Microsoft Windows XP [version 5.1.2600]

          *********************************************

          Vérification HKLM\...\...\...\...\ruins

          Windows Registry Editor Version 5.00

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins]
          "xedocne"=hex:5d,43,00,00,57,56,65,61,74,7f,10,46,17,08,27,13,00,00,00
          "repiwoh"=hex:bd,49,00,00,b0,b1,91,8b,98,9f,ea,26,f7,e8,c7,13,00,00,00
          "23plhps"=hex:87,4d,00,00,6f,6a,4a,5e,42,07,7c,78,39,22,09,13,00,00,00
          "mgcppp"=hex:55,4e,00,00,50,58,60,15,09,7f,46,77,18,67,12,00,00,00
          "tesvaf"=hex:b9,4f,00,00,8a,87,8a,81,ab,90,22,d3,e4,c3,12,00,00,00
          "golmedi"=hex:83,50,00,00,79,7a,4d,5d,5a,4f,2f,7c,3d,26,0d,13,00,00,00
          "32refaselif"=hex:51,51,00,00,22,27,18,1b,71,0f,72,7b,16,5e,61,92,43,34,b3,17,\
          00,00,00
          "ucvmd"=hex:8d,15,00,00,64,67,a6,5d,b7,06,37,c8,27,11,00,00,00

          *********************************************

          Fichiers détectés :

          C:\WINDOWS\system32\favset.exe Présent !
          C:\WINDOWS\System32\idesk.conf Présent !

          *********************************************

          Recherche des processus aleatoires
          d'après les modèles : cs***.exe, dm***.exe, ya***.exe

          C:\WINDOWS\System32
          CSRSS.EXE

          *********************************************

          Recherche presence C:\WINDOWS\System32\idemlog.exe...

          non trouvé...
          1. salut

            dis moi juste, dans ajout/suppression de programme, tu as UnSpyPC?

            Jte donnerais la manip apres ta reponse

            a+
            1. Salut regis59,

              Dans Ajout/Supprimer, je ne l'ai pas ....
              (Et idem, dans les archives de ProgramFiles)

              Merci.
              1. Salut,
                J'ai quelques News. En surfant sur quelques forums, j'ai effectué quelques autres manip :

                1) Un Scan sous Panda antivirus

                Incident Statut Analyse

                Adware:adware/securityerror Non désinfecté C:\WINDOWS\SYSTEM32\ot.ico
                Spyware:spyware/smitfraud Non désinfecté Registre Windows
                A la suite de cela, j'ai supprimé le fichier ot.ico (un icone infecté qui ne servait à rien pour moi - Icone de pseudo antispyware ...)

                2)Sous un même forum, une personne préconisait d'utiliser (pour la même infection) Ewido anti-malware. Tout en suivant les consignes, voici le rapport :

                ---------------------------------------------------------
                ewido anti-malware - Rapport de scan
                ---------------------------------------------------------

                + Créé le: 17:37:11, 24/12/2005
                + Somme de contrôle: 5BCA6917

                + Résultats du scan:

                C:\Documents and Settings\Alexandre\Cookies\alexandre@247realmedia[1].txt -> Spyware.Cookie.247realmedia : Nettoyer et sauvegarder
                C:\Documents and Settings\Alexandre\Cookies\alexandre@adtech[2].txt -> Spyware.Cookie.Adtech : Nettoyer et sauvegarder
                C:\Documents and Settings\Alexandre\Cookies\alexandre@estat[1].txt -> Spyware.Cookie.Estat : Nettoyer et sauvegarder
                C:\WINDOWS\sites.ini -> Spyware.PSGuard : Nettoyer et sauvegarder
                C:\WINDOWS\SYSTEM32\favset.exe -> Trojan.Favadd.an : Nettoyer et sauvegarder

                ::Fin du rapport

                3) Rapport HKML :

                Rapport fait à 17:50:21,62 le 24/12/2005
                Executé à partir de C:\Documents and Settings\Alexandre
                OS: Microsoft Windows XP [version 5.1.2600]

                *********************************************

                Vérification HKLM\...\...\...\...\ruins

                Windows Registry Editor Version 5.00

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins]
                "xedocne"=hex:5d,43,00,00,57,56,65,61,74,7f,10,46,17,08,27,13,00,00,00
                "repiwoh"=hex:bd,49,00,00,b0,b1,91,8b,98,9f,ea,26,f7,e8,c7,13,00,00,00
                "23plhps"=hex:87,4d,00,00,6f,6a,4a,5e,42,07,7c,78,39,22,09,13,00,00,00
                "mgcppp"=hex:55,4e,00,00,50,58,60,15,09,7f,46,77,18,67,12,00,00,00
                "tesvaf"=hex:b9,4f,00,00,8a,87,8a,81,ab,90,22,d3,e4,c3,12,00,00,00
                "golmedi"=hex:83,50,00,00,79,7a,4d,5d,5a,4f,2f,7c,3d,26,0d,13,00,00,00
                "32refaselif"=hex:51,51,00,00,22,27,18,1b,71,0f,72,7b,16,5e,61,92,43,34,b3,17,\
                00,00,00
                "ucvmd"=hex:8d,15,00,00,64,67,a6,5d,b7,06,37,c8,27,11,00,00,00

                *********************************************

                Fichiers détectés :

                C:\WINDOWS\System32\idesk.conf Présent !

                *********************************************

                Recherche des processus aleatoires
                d'après les modèles : cs***.exe, dm***.exe, ya***.exe

                C:\WINDOWS\System32
                CSRSS.EXE

                *********************************************

                Recherche presence C:\WINDOWS\System32\idemlog.exe...

                non trouvé...

                4) Revoici, le log de Hijack :
                Logfile of HijackThis v1.99.1
                Scan saved at 17:39:56, on 24/12/2005
                Platform: Windows XP SP1 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\System32\DSentry.exe
                C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                C:\PROGRA~1\Wanadoo\CnxMon.exe
                C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                C:\PROGRA~1\NORTON~1\navapw32.exe
                C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
                C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
                C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
                C:\Program Files\QuickTime\qttask.exe
                C:\Program Files\Winamp\winampa.exe
                C:\WINDOWS\System32\ctfmon.exe
                C:\Program Files\Messenger\msmsgs.exe
                C:\Program Files\Digital Line Detect\DLG.exe
                C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe
                C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                C:\PROGRA~1\Livecom\Toaster\Toaster.exe
                C:\PROGRA~1\Livecom\APPLIC~1\eConfv4\ftplayer.exe
                C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                C:\WINDOWS\System32\CTsvcCDA.exe
                C:\Program Files\ewido anti-malware\ewidoctrl.exe
                C:\Program Files\Norton AntiVirus\navapsvc.exe
                C:\WINDOWS\System32\nvsvc32.exe
                C:\WINDOWS\System32\MsPMSPSv.exe
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
                O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
                O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
                O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
                O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
                O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
                O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
                O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                O4 - HKCU\..\Run: [desktop] C:\WINDOWS\System32\idemlog.exe
                O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
                O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                O4 - Global Startup: Digital Line Detect.lnk = ?
                O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
                O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
                O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

                Merci (par avance).
                1. Slt,

                  Voici le Post de Smitfraut :

                  SmitFraudFix v2.08

                  Rapport fait à 21:44:43,14 le 24/12/2005
                  Executé à partir de C:\Documents and Settings\Alexandre\Mes documents\alex.dave\Info\SmitfraudFix\SmitfraudFix
                  OS: Microsoft Windows XP [version 5.1.2600]

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32\LogFiles

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Alexandre\Application Data

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                  "Source"="C:\\WINDOWS\\warnhp.html"
                  "SubscribedURL"=""
                  "FriendlyName"="Warning homepage"

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                  "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pr‚-chargeur Browseui"
                  "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="D‚mon de cache des cat‚gories de composant"
                  "{6AC3806F-8B39-4746-9C38-6B01CB7331FF}"="Memory monitor"

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

                  Merci à vous et Bonnes fêtes de fin d'année.
                  1. ok

                    tu peux me remettre un hijack this + le programme stp

                    merci

                    a+
                    1. Slt,

                      Voici le log :

                      Logfile of HijackThis v1.99.1
                      Scan saved at 20:49:34, on 25/12/2005
                      Platform: Windows XP SP1 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\System32\DSentry.exe
                      C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                      C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
                      C:\PROGRA~1\Wanadoo\CnxMon.exe
                      C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                      C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                      C:\PROGRA~1\NORTON~1\navapw32.exe
                      C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\Program Files\Winamp\winampa.exe
                      C:\WINDOWS\System32\ctfmon.exe
                      C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe
                      C:\Program Files\Digital Line Detect\DLG.exe
                      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                      C:\PROGRA~1\Livecom\Toaster\Toaster.exe
                      C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                      C:\WINDOWS\System32\CTsvcCDA.exe
                      C:\Program Files\ewido anti-malware\ewidoctrl.exe
                      C:\PROGRA~1\Livecom\APPLIC~1\eConfv4\ftplayer.exe
                      C:\Program Files\Norton AntiVirus\navapsvc.exe
                      C:\WINDOWS\System32\nvsvc32.exe
                      C:\WINDOWS\System32\MsPMSPSv.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\WINDOWS\System32\wuauclt.exe
                      C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
                      C:\Program Files\Internet Explorer\IEXPLORE.EXE
                      C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
                      O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                      O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
                      O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
                      O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                      O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                      O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
                      O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
                      O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
                      O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
                      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                      O4 - HKCU\..\Run: [desktop] C:\WINDOWS\System32\idemlog.exe
                      O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
                      O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                      O4 - Global Startup: Digital Line Detect.lnk = ?
                      O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                      O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                      O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                      O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
                      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                      O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
                      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                      O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                      O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

                      Merci et Bonnes fêtes de noel
                      1. Houps .....,

                        J'avais pas lu la fin de ta phrase, désolé.

                        Rapport fait à 20:54:12,68 le 25/12/2005
                        Executé à partir de C:\Documents and Settings\Alexandre
                        OS: Microsoft Windows XP [version 5.1.2600]

                        *********************************************

                        Vérification HKLM\...\...\...\...\ruins

                        Windows Registry Editor Version 5.00

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins]
                        "xedocne"=hex:5d,43,00,00,57,56,65,61,74,7f,10,46,17,08,27,13,00,00,00
                        "repiwoh"=hex:bd,49,00,00,b0,b1,91,8b,98,9f,ea,26,f7,e8,c7,13,00,00,00
                        "23plhps"=hex:87,4d,00,00,6f,6a,4a,5e,42,07,7c,78,39,22,09,13,00,00,00
                        "mgcppp"=hex:55,4e,00,00,50,58,60,15,09,7f,46,77,18,67,12,00,00,00
                        "tesvaf"=hex:b9,4f,00,00,8a,87,8a,81,ab,90,22,d3,e4,c3,12,00,00,00
                        "golmedi"=hex:83,50,00,00,79,7a,4d,5d,5a,4f,2f,7c,3d,26,0d,13,00,00,00
                        "32refaselif"=hex:51,51,00,00,22,27,18,1b,71,0f,72,7b,16,5e,61,92,43,34,b3,17,\
                        00,00,00
                        "ucvmd"=hex:8d,15,00,00,64,67,a6,5d,b7,06,37,c8,27,11,00,00,00

                        *********************************************

                        Fichiers détectés :

                        C:\WINDOWS\System32\idesk.conf Présent !

                        *********************************************

                        Recherche des processus aleatoires
                        d'après les modèles : cs***.exe, dm***.exe, ya***.exe

                        C:\WINDOWS\System32
                        CSRSS.EXE

                        *********************************************

                        Recherche presence C:\WINDOWS\System32\idemlog.exe...

                        non trouvé...
                        1. Tu veux peut être le log de smithfraud ..... Je suis perdu entre les fêtes de fin d'année et le décalage avec la France. Je te redonne le tout.

                          SmitFraudFix v2.08

                          Rapport fait à 20:56:51,59 le 25/12/2005
                          Executé à partir de C:\Documents and Settings\Alexandre\Mes documents\alex.dave\Info\SmitfraudFix\SmitfraudFix
                          OS: Microsoft Windows XP [version 5.1.2600]

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32\LogFiles

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Alexandre\Application Data

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                          "Source"="C:\\WINDOWS\\warnhp.html"
                          "SubscribedURL"=""
                          "FriendlyName"="Warning homepage"

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                          "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pr‚-chargeur Browseui"
                          "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="D‚mon de cache des cat‚gories de composant"
                          "{6AC3806F-8B39-4746-9C38-6B01CB7331FF}"="Memory monitor"

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

                          Logfile of HijackThis v1.99.1
                          Scan saved at 20:49:34, on 25/12/2005
                          Platform: Windows XP SP1 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\System32\DSentry.exe
                          C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                          C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
                          C:\PROGRA~1\Wanadoo\CnxMon.exe
                          C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                          C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                          C:\PROGRA~1\NORTON~1\navapw32.exe
                          C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
                          C:\Program Files\QuickTime\qttask.exe
                          C:\Program Files\Winamp\winampa.exe
                          C:\WINDOWS\System32\ctfmon.exe
                          C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe
                          C:\Program Files\Digital Line Detect\DLG.exe
                          C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                          C:\PROGRA~1\Livecom\Toaster\Toaster.exe
                          C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                          C:\WINDOWS\System32\CTsvcCDA.exe
                          C:\Program Files\ewido anti-malware\ewidoctrl.exe
                          C:\PROGRA~1\Livecom\APPLIC~1\eConfv4\ftplayer.exe
                          C:\Program Files\Norton AntiVirus\navapsvc.exe
                          C:\WINDOWS\System32\nvsvc32.exe
                          C:\WINDOWS\System32\MsPMSPSv.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\WINDOWS\System32\wuauclt.exe
                          C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
                          C:\Program Files\Internet Explorer\IEXPLORE.EXE
                          C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                          O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
                          O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                          O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
                          O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
                          O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                          O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
                          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                          O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
                          O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
                          O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
                          O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
                          O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                          O4 - HKCU\..\Run: [desktop] C:\WINDOWS\System32\idemlog.exe
                          O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
                          O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                          O4 - Global Startup: Digital Line Detect.lnk = ?
                          O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                          O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                          O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                          O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                          O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                          O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
                          O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                          O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                          O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                          O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
                          O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                          O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                          O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                          O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                          O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                          O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                          O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

                          Merci encore
                          1. salut

                            1/Télécharge: Pocket Killbox ici
                            http://www.downloads.subratam.org/KillBox.exe

                            :: Démo d utilisation (merci a Balltrap34 pour cette réalisation) ::
                            http://pageperso.aol.fr/balltrap34/killbox.htm

                            2/Télécharge Registry Search Tool, ici
                            http://www.billsway.com/vbspage/vbsfiles/RegSrch.zip

                            -----------------------------------------------------------------
                            ¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

                            O4 - HKCU\..\Run: [desktop] C:\WINDOWS\System32\idemlog.exe

                            -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

                            Déconnecte toi d'internet c'est important

                            puis vérifie ceci:
                            demarrer > connection > clic droit sur ta connection > propriétés
                            gestion de reseau
                            assure toi que protocole internet tcp/ip est en surbrillance (attention, ne décoche pas la case)> clic sur propriétés > selectionne "obtenir les adresses des serveurs automatiquement"
                            valide avec ok

                            -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

                            ouvre le bloc note et copie et colle ceci à l'interieur:
                            Regedit4 doit etre sur la 1er ligne de ton bloc note
                            *****************************
                            REGEDIT4

                            [-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\HCLEAN32.EXE]

                            [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Windows\CurrentVersion\ruins]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion]
                            "Disabled"=-

                            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins]

                            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WareOut]

                            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                            "System"=-
                            "System"=""

                            [-HKEY_LOCAL_MACHINE\SOFTWARE\WareOut]

                            ***********************
                            Puis enregistrer sous et dans:
                            Nom du fichier, met fix.reg
                            Type de fichier: selectionne "tous les fichiers"
                            clic sur enregistrer

                            ensuite double clic sur fix.reg et accepte de fusionner

                            -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

                            1- Double-clic sur KillBox.exe (Pocket Killbox)

                            Avec la methode du bloc note (voir video)
                            voici la liste:

                            C:\WINDOWS\System32\idesk.conf
                            C:\WINDOWS\System32\idemlog.exe

                            Si le pc ne redemarre pas automatiquement ou si killbox t'envois ce message:
                            "Pending file Rename Operations Registry Data has been Removed by External Process"
                            ignore le et redemarre le pc normallement

                            _-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

                            décompresse Registry Search Tool et tape ou colle
                            ZPMODEMSYSNTDRVNT

                            et copie colle le résultat dans le bloc note et donne le nous

                            a+

                            Note:Une fois toute cette manip effectué, met nous 3 rapports:
                            Hcscrch
                            Hijack this
                            Registry searsh tools

                            1. Slt à vous,

                              Voici les log,

                              1) Hcscrch

                              Rapport fait à 22:09:54,01 le 25/12/2005
                              Executé à partir de C:\Documents and Settings\Alexandre
                              OS: Microsoft Windows XP [version 5.1.2600]

                              *********************************************

                              Vérification HKLM\...\...\...\...\ruins

                              *********************************************

                              Fichiers détectés :

                              *********************************************

                              Recherche des processus aleatoires
                              d'après les modèles : cs***.exe, dm***.exe, ya***.exe

                              C:\WINDOWS\System32
                              CSRSS.EXE

                              *********************************************

                              Recherche presence C:\WINDOWS\System32\idemlog.exe...

                              non trouvé...
                              2) Hijack

                              Logfile of HijackThis v1.99.1
                              Scan saved at 22:11:12, on 25/12/2005
                              Platform: Windows XP SP1 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                              C:\WINDOWS\System32\CTsvcCDA.exe
                              C:\Program Files\ewido anti-malware\ewidoctrl.exe
                              C:\Program Files\Norton AntiVirus\navapsvc.exe
                              C:\WINDOWS\System32\nvsvc32.exe
                              C:\WINDOWS\System32\MsPMSPSv.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\System32\DSentry.exe
                              C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                              C:\PROGRA~1\Wanadoo\CnxMon.exe
                              C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                              C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                              C:\PROGRA~1\NORTON~1\navapw32.exe
                              C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
                              C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
                              C:\Program Files\QuickTime\qttask.exe
                              C:\Program Files\Winamp\winampa.exe
                              C:\WINDOWS\System32\ctfmon.exe
                              C:\Program Files\Messenger\msmsgs.exe
                              C:\Program Files\eMule\emule.exe
                              C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe
                              C:\Program Files\Digital Line Detect\DLG.exe
                              C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                              C:\PROGRA~1\Livecom\Toaster\Toaster.exe
                              C:\PROGRA~1\Livecom\APPLIC~1\eConfv4\ftplayer.exe
                              C:\WINDOWS\System32\wuauclt.exe
                              C:\WINDOWS\system32\NOTEPAD.EXE
                              C:\Program Files\Internet Explorer\IEXPLORE.EXE
                              C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                              O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                              O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
                              O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                              O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
                              O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
                              O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                              O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                              O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                              O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                              O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
                              O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
                              O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
                              O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
                              O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                              O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
                              O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                              O4 - Global Startup: Digital Line Detect.lnk = ?
                              O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                              O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                              O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                              O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                              O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                              O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
                              O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                              O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                              O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                              O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
                              O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                              O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                              O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                              O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                              O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                              O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                              O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

                              3) Registry searsh tools

                              REGEDIT4
                              ; RegSrch.vbs © Bill James

                              ; Registry search results for string "ZPMODEMSYSNTDRVNT" 25/12/2005 22:05:39

                              ; NOTE: This file will be deleted when you close WordPad.
                              ; You must manually save this file to a new location if you want to refer to it again later.
                              ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                              "Service"="ZPMODEMSYSNTDRVNT"

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                              "DeviceDesc"="ZPMODEMSYSNTDRVNT"

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000\Control]

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT]

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT]
                              "DisplayName"="ZPMODEMSYSNTDRVNT"

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Security]

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Enum]

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Enum]
                              "0"="Root\\LEGACY_ZPMODEMSYSNTDRVNT\\0000"

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                              "Service"="ZPMODEMSYSNTDRVNT"

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                              "DeviceDesc"="ZPMODEMSYSNTDRVNT"

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT]

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT]
                              "DisplayName"="ZPMODEMSYSNTDRVNT"

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT\Security]

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                              "Service"="ZPMODEMSYSNTDRVNT"

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                              "DeviceDesc"="ZPMODEMSYSNTDRVNT"

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000\Control]

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT]

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT]
                              "DisplayName"="ZPMODEMSYSNTDRVNT"

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Security]

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Enum]

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Enum]
                              "0"="Root\\LEGACY_ZPMODEMSYSNTDRVNT\\0000"

                              Merci à vous.
                              1. re,

                                tutoie moi, je suis certainement plus jeune que toi lol

                                ouvre le bloc note et copie colle ceci entre les etoiles
                                **********
                                REGEDIT4

                                [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                                [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                                "Service"=-

                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                                "DeviceDesc"=-

                                [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000\Control]

                                [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT]

                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT]
                                "DisplayName"=-

                                [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Security]

                                [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Enum]

                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Enum]
                                "0"=-

                                [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                                [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                                "Service"=-

                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                                "DeviceDesc"=-

                                [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT]

                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT]
                                "DisplayName"=-

                                [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT\Security]

                                [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                                [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                                "Service"=-

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                                "DeviceDesc"=-

                                [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000\Control]

                                [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT]

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT]
                                "DisplayName"=-

                                [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Security]

                                [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Enum]

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Enum]
                                "0"=-

                                ************
                                enregistre le sur ton bureau et nomme le xxx.reg
                                et dans la case en dessous type met sur tous fichiers

                                la vas sur ton bureau et double clik sur se fichier que tu vient de faire et accepte la fusion avec le registre

                                puis relance le prog, retape le meme et remet un rapport

                                a+
                                1. Slt,

                                  Questions :

                                  PS : je passe sur le log de Hcscrch car je pense qu'il a rien trouvé (?!?).
                                  Je te donne le log de Hijack (cierto), Mais le log de l'autre prog (Registry searsh tools), tu en as besoin ?

                                  Les p'tits reg que tu me donnes sert (+/-) à quoi (c'est de la simple curiosité) ? Génèrer des registres (un truc comme ça) ?
                                  1. salut,

                                    je passe sur le log de Hcscrch car je pense qu'il a rien trouvé (?!?).
                                    Si c est le cas, tant mieux

                                    Je te donne le log de Hijack (cierto), Mais le log de l'autre prog (Registry searsh tools), tu en as besoin ?
                                    Si quand tu tapes dans ta recherches, il te dis no instance found, tu poses pas sinon oui tu le dones a regis

                                    Les p'tits reg que tu me donnes sert (+/-) à quoi (c'est de la simple curiosité) ?

                                    Il servent a generer des rapports
                                    registry searsh tool permet de chercher dans ton registre les infection et par une manip avec le bloc note permet de le supprimer
                                    Hcsearsh sert a detecter des infections speciales, ce prog a ete creer par moe31 et avec regis afin de detecter les infections lié a cette barre

                                    tu as toujours cette barre?
                                    Remet juste registry searsh tools stp

                                    a+
                                    1. Slt,

                                      Merci pour tes réponses et merci à moe31 et regis (donc)

                                      Voici le log :
                                      REGEDIT4
                                      ; RegSrch.vbs © Bill James

                                      ; Registry search results for string "ZPMODEMSYSNTDRVNT" 26/12/2005 16:36:31

                                      ; NOTE: This file will be deleted when you close WordPad.
                                      ; You must manually save this file to a new location if you want to refer to it again later.
                                      ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)

                                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                                      "Service"="ZPMODEMSYSNTDRVNT"

                                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                                      "DeviceDesc"="ZPMODEMSYSNTDRVNT"

                                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000\Control]

                                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT]

                                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Enum]

                                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                                      "Service"="ZPMODEMSYSNTDRVNT"

                                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                                      "DeviceDesc"="ZPMODEMSYSNTDRVNT"

                                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT]

                                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                                      "Service"="ZPMODEMSYSNTDRVNT"

                                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                                      "DeviceDesc"="ZPMODEMSYSNTDRVNT"

                                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000\Control]

                                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT]

                                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Enum]

                                      et le hijack :
                                      Logfile of HijackThis v1.99.1
                                      Scan saved at 16:39:30, on 26/12/2005
                                      Platform: Windows XP SP1 (WinNT 5.01.2600)
                                      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                                      Running processes:
                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                                      C:\WINDOWS\System32\CTsvcCDA.exe
                                      C:\Program Files\ewido anti-malware\ewidoctrl.exe
                                      C:\Program Files\Norton AntiVirus\navapsvc.exe
                                      C:\WINDOWS\System32\nvsvc32.exe
                                      C:\WINDOWS\System32\MsPMSPSv.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\WINDOWS\System32\DSentry.exe
                                      C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                                      C:\PROGRA~1\Wanadoo\CnxMon.exe
                                      C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                                      C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                                      C:\PROGRA~1\NORTON~1\navapw32.exe
                                      C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
                                      C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
                                      C:\Program Files\QuickTime\qttask.exe
                                      C:\Program Files\Winamp\winampa.exe
                                      C:\WINDOWS\System32\ctfmon.exe
                                      C:\Program Files\eMule\emule.exe
                                      C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe
                                      C:\Program Files\Digital Line Detect\DLG.exe
                                      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                                      C:\PROGRA~1\Livecom\Toaster\Toaster.exe
                                      C:\PROGRA~1\Livecom\APPLIC~1\eConfv4\ftplayer.exe
                                      C:\WINDOWS\System32\wuauclt.exe
                                      C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                      C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                      C:\WINDOWS\system32\NOTEPAD.EXE
                                      C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                                      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                                      O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
                                      O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                                      O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
                                      O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
                                      O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                                      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                                      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                                      O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
                                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                      O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
                                      O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
                                      O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
                                      O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
                                      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                      O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                      O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
                                      O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                                      O4 - Global Startup: Digital Line Detect.lnk = ?
                                      O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                      O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                                      O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                                      O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                                      O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
                                      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                                      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                                      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                                      O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                                      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
                                      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                                      O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                                      O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                                      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                                      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                                      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                                      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                                      • 1
                                      • 2