Erreur es survenue sur le script d cette page

kevin re moi 'voila mari ses fai' -  
ogfile of HijackThis v1.99.1
Scan saved at 09:11:55, on 21/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\Newhmu\Cgzbhct.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\eChanblard\emule.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\kevin\LOCALS~1\Temp\Rar$EX03.312\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.noos.fr/
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Fichiers communs\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Yksaqlgo] C:\Program Files\Newhmu\Cgzbhct.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a-squared\a2guard.exe"
O4 - Global Startup: Norton Internet Security.lnk = C:\Program Files\Norton Internet Security\nisfirst.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPxySvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

18 réponses

Résumé de la discussion

Analyse d'un log HijackThis v1.99.1 sur Windows XP SP2 met en évidence de nombreuses entrées de démarrage et services potentiellement indésirables, avec des composants de sécurité et des applications tierces. La liste contient des éléments O4 et O23 liés à Spybot, Symantec, RealPlayer et MSN Messenger, ainsi que des modules de navigation et des services système potentiellement problématiques. Le thread inclut des échanges sur le nettoyage via un outil de cleanup, montrant la suppression de nombreux fichiers temporaires et éléments contenus dans les dossiers Content.IE5 et Cookies, certains restant en cours d'utilisation. Des éléments restant en cours d'utilisation nécessitent un redémarrage pour être définitivement supprimés, illustrant une nuance utile sur l'efficacité du nettoyage et la nécessité d'un reboot.

Bobot (l’IA à votre service)
  1. et voisi le resultat de clean up merci a toi mari et les autre de maider a retirer mon truck

    CleanUp! started on 01/21/06 09:18:58.
    ...
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\23QZ61AN\hit[5].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\23QZ61AN\icoimp2[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\23QZ61AN\index[1].htm - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\23QZ61AN\i[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\23QZ61AN\onglet_dbt[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\23QZ61AN\onglet_mid[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\23QZ61AN\pixel_8EA6D6[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\23QZ61AN\tomshardware[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\1812177485@Top,Middle,Right[1] - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\1823594764@Top,Right[1] - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\ajout[1].htm - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\dossier-dev[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\dossier-graphisme[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\dossier-materiel[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\dossier-virus[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\dossier-windows[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\erreur[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\forum[1].htm - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\hit[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\hit[2].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\hit[3].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\hit[4].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\hit[5].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\icohome2[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\icowri2[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\index[2].htm - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\inscription[1].htm - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\onglet_fin[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\G1KH67KH\s[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\P290B60Z\echanblard[1].htm currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\2100496549M[1].jpg - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\affich-2049035-VIRUS-INFECTE[1].htm - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\affich-2049761[1].htm - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\ampoule[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\carre1[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\carrevalid[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\carre[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\charte-ciblage[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\charte-justice[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\code[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\dossier-jeuxvideos[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\dossier-reseau[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\dossier-video[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\dossier-webmastering[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\dossier[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\editer[1].htm - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\hit[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\hit[2].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\hit[3].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\icofav2[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\index[1].htm currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\menu[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\menu[2].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\UPOFEPE5\webbulle-rss[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\1437211226@Top,Middle,Right[1] - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\1942399593@Top,Middle,Right[1] - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\2100496530M[1].jpg - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\ajout-selection[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\ajout[1].htm - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\ajout[2].htm - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\ajout[3].htm - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\arrondibg[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\arrondisup[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\autosearch[1].js - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\background[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\carre0[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\carregold[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\ccm-encyclopedie-informatique[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\ccm[1].css - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\charte-peace[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\charte-sms[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\dossier-cafe[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\dossier-gravure[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\dossier-internet[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\dossier-logiciel[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\dossier-tux[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\empty[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\F&color_bg=F0F0F0&color_text=000000&color_link=0000FF&color_url=008000&color_border=000000&ad_type=text&u_h=600&u_w=800&u_ah=600&u_aw=800&u_cd=32&u_tz=60&u_java=true currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\g[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\hit[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\hit[2].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\hit[3].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\hit[4].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\hit[5].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\hit[6].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\horloge[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\icofav[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\icohome[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\icoimp[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\icomail2[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\icomail[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\icozip[1].gif - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\index[1].htm - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\logotop[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\rayures[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\rechercher[1].png - deleted
    C:\Documents and Settings\kevin\locals~1\tempor~1\Content.IE5\WD87WRCF\yahoo[1].png - deleted
    C:\Documents and Settings\kevin\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Temp\~DF5C7D.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Temp\~DFD33F.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Temp\Rar$EX03.312\HijackThis.exe currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Temporary Internet Files\Content.IE5\P290B60Z\echanblard[1].htm currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Temporary Internet Files\Content.IE5\UPOFEPE5\index[1].htm currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Temporary Internet Files\Content.IE5\WD87WRCF\F&color_bg=F0F0F0&color_text=000000&color_link=0000FF&color_url=008000&color_border=000000&ad_type=text&u_h=600&u_w=800&u_ah=600&u_aw=800&u_cd=32&u_tz=60&u_java=true currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\Default User\Cookies\index.dat - deleted
    C:\Documents and Settings\Default User\locals~1\tempor~1\Content.IE5\index.dat - deleted
    C:\Documents and Settings\Default User\locals~1\tempor~1\Content.IE5\ - deleted
    C:\BOOT.BAK - deleted
    C:\APPS\Packard Bell Companion\config.xml.bak - deleted
    C:\Documents and Settings\All Users\DRM\DRMv1.bak - deleted
    C:\Documents and Settings\Default User\Local Settings\Historique\History.IE5\index.dat - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\Modèles\~$Normal.dot - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR58.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR59.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR5A.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR5B.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR5C.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR90.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR91.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR92.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR93.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR94.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFRA2.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFRA4.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR4.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR4C.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR4D.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR4E.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR4F.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR5.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR50.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR51.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR52.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR53.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR54.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR55.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR56.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR84.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR85.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR87.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR8A.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR8C.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR95.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR98.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR9A.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR9D.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR9E.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR9F.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFRA1.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFRA5.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFRA7.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFRAC.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFRAD.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFRD.tmp - deleted
    C:\Documents and Settings\kevin\Application Data\Microsoft\Office\Fichiers récents\index.dat - deleted
    C:\Documents and Settings\kevin\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Application Data\Sony Corporation\Image Converter\LasE80.tmp - deleted
    C:\Documents and Settings\kevin\Local Settings\Application Data\Sony Corporation\Image Converter\LesB3C.tmp - deleted
    C:\Documents and Settings\kevin\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Historique\History.IE5\MSHist012006012020060121\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Historique\History.IE5\MSHist012006012120060122\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Temp\~DF5C7D.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Temp\~DFD33F.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Temp\~DF5C7D.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Temp\~DFD33F.tmp currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\kevin\UserData\index.dat - deleted
    C:\Documents and Settings\LocalService\Cookies\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat currently in use. Will be deleted when Windows is restarted.
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\Address Book\marchal nadine.wab~ - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR84.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR85.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR86.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR87.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\Backgrounds\TFR88.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR78.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR79.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR7A.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR7B.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR7C.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR7D.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR7E.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR7F.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR80.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR81.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR82.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\MSN Messenger\129226551\UserTile\TFR8A.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\Office\fbc7.tmp - deleted
    C:\Documents and Settings\marchal nadine\Application Data\Microsoft\Office\Fichiers récents\index.dat - deleted
    C:\Documents and Settings\marchal nadine\Local Settings\Historique\History.IE5\index.dat - deleted
    C:\Documents and Settings\marchal nadine\Local Settings\Historique\History.IE5\MSHist012005022820050307\index.dat - deleted
    C:\Documents and Settings\marchal nadine\Local Settings\Historique\History.IE5\MSHist012005030720050314\index.dat - deleted
    C:\Documents and Settings\marchal nadine\Local Settings\Historique\History.IE5\MSHist012005031420050321\index.dat - deleted
    C:\Documents and Settings\marchal nadine\Local Settings\Historique\History.IE5\MSHist012005032120050322\index.dat - deleted
    C:\Documents and Settings\marchal nadine\Local Settings\Historique\History.IE5\MSHist012005103120051101\index.dat - deleted
    C:\Documents and Settings\marchal nadine\Local Settings\Historique\History.IE5\MSHist012006011820060119\index.dat - deleted
    C:\Documents and Settings\marchal nadine\Mes documents\Pocket_PC My Documents\UAContents\MMS UA\Inbox.inf.bak - deleted
    C:\Documents and Settings\marchal nadine\Mes documents\Pocket_PC My Documents\UAContents\MMS UA\Outbox.inf.bak - deleted
    C:\Documents and Settings\marchal nadine\Mes documents\Pocket_PC My Documents\UAContents\MMS UA\Sent.inf.bak - deleted
    C:\Documents and Settings\marchal nadine\UserData\index.dat - deleted
    C:\Documents and Settings\NetworkService\Local Settings\Historique\History.IE5\index.dat - deleted
    C:\Documents and Settings\NetworkService\Local Settings\Historique\History.IE5\MSHist012005092320050924\index.dat - deleted
    C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak - deleted
    C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak - deleted
    C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak - deleted
    C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\Sauvegarde de la licence\drmv2lic.bak - deleted
    C:\Program Files\eChanblard\downloads.bak - deleted
    C:\Program Files\eChanblard\eMule_Chicane.tmpl - deleted
    C:\Program Files\eChanblard\eMule.tmpl - deleted
    C:\Program Files\eChanblard\config\clients.met.bak - deleted
    C:\Program Files\eChanblard\config\eMule Light.tmpl - deleted
    C:\Program Files\eChanblard\config\eMule.tmpl - deleted
    C:\Program Files\eChanblard\Temp\001.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\002.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\003.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\004.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\006.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\007.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\009.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\010.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\011.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\012.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\013.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\015.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\016.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\017.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\018.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\019.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\020.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\021.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\023.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\024.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\025.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\026.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\029.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\030.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\037.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\045.part.met.bak - deleted
    C:\Program Files\eChanblard\Temp\GTO.E-rec.tmp - deleted
    C:\Program Files\eChanblard\Temp\Vandr-rec.tmp - deleted
    C:\Program Files\Fichiers communs\Sony Shared\OpenMG\omglog.bak - deleted
    C:\Program Files\Fichiers communs\Symantec Shared\Persist.BAK - deleted
    C:\Program Files\Fichiers communs\Symantec Shared\IDS\IDSSettg.BAK - deleted
    C:\Program Files\Hewlett-Packard\Digital Imaging\Migrate\hpqgends.tmp - deleted
    C:\Program Files\Hewlett-Packard\Digital Imaging\{7C8BB31C-E09E-4c7d-BBF1-45E33B467FE1}\Drivers\Scanner\hpqgends.tmp - deleted
    C:\Program Files\InterActual\InterActual Player\iti67D9.tmp - deleted
    C:\Program Files\Kazaa\Db\np.tmp - deleted
    C:\Program Files\Norton AntiVirus\NAVOPTS.BAK - deleted
    C:\Program Files\Real\RealPlayer\DataCache.dcp.bak - deleted
    C:\Program Files\Valve\Steam\SteamApps\kevinledemon\counter-strike source\cstrike\demoheader.tmp - deleted
    C:\Program Files\Valve\Steam\SteamApps\kevinledemon\half-life 2\hl2\demoheader.tmp - deleted
    C:\Program Files\Valve\Steam\SteamApps\kevinledemon\half-life 2 deathmatch\hl2mp\demoheader.tmp - deleted
    C:\Program Files\Wanadoo\~ - deleted
    C:\Program Files\Wanadoo\backup\~ - deleted
    C:\Program Files\Warcraft III\Maps\Download\~AOS GT 1664BeeR BetA 1.0.w3x - deleted
    C:\Program Files\World of Warcraft\WTF\Account\SAURONDU94\SavedVariables.lua.bak - deleted
    C:\Program Files\World of Warcraft\WTF\Account\SAURONDU94\Minidevil\SavedVariables\Blizzard_BattlefieldMinimap.lua.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc150.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc151.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc152.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc153.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc154.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc155.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc157.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc158.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc26.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc27.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc28.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc33.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc34.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc35.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc36.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc78.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc79.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc80.bak - deleted
    C:\RECYCLER\S-1-5-21-138565909-2557846544-1462708042-1008\Dc81.bak - deleted
    C:\WINDOWS\Active Setup Log.BAK - deleted
    C:\WINDOWS\imsins.BAK - deleted
    C:\WINDOWS\dxlog.chk - deleted
    C:\WINDOWS\Help\wmplayer.bak - deleted
    C:\WINDOWS\inf\mplayer2.bak - deleted
    C:\WINDOWS\Installer\MSI1F9.tmp - deleted
    C:\WINDOWS\PCHealth\HelpCtr\Config\Cache\Personal_32_1036.dat.bak - deleted
    C:\WINDOWS\PCHealth\HelpCtr\OfflineCache\index.dat - deleted
    C:\WINDOWS\repair\system.bak - deleted
    C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.chk - deleted
    C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\7e808a3c27f845e09ebb11aa4251afd5\BIT8.tmp - deleted
    C:\WINDOWS\system32\shdocvw.bak - deleted
    C:\WINDOWS\system32\CONFIG.TMP - deleted
    C:\WINDOWS\system32\PerfStringBackup.TMP - deleted
    C:\WINDOWS\system32\setb4.tmp - deleted
    C:\WINDOWS\system32\CatRoot2\edb.chk - deleted
    C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat - deleted
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat - deleted
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012004103120041101\index.dat - deleted
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat - deleted
    'Run MRU' list - removed from the registry.
    Paint Recent File List - removed from the registry.
    WordPad Recent File List - removed from the registry.
    Telnet's MRU list - removed from the registry.
    CleanUp! 4.0 recovered 843055104 bytes of disk space from -1042827607 files.
    CleanUp! finished on 01/21/06 09:28:57.
    0
    1. Re,

      Pour les pôtes...

      http://www.commentcamarche.net/forum/affich-2045214-erreur-script-internet-explorer#2006-01-21%2009%3A28%3A30

      Kevin tu aurais pu ré-expliquer ton blème !!!
      C'est un autre forum, ils ne sont pas censés le connaître.
      Et dire BONJOUR et le .....aussi!!!
      A+
      0
      1. oui ok lol escuser moi bonjour a tous
        jai sa qui saffiche et me blok mon norton et plin de truc comme le restauration de system

        une erreur est survenue sur le script de cette page

        ligne:34
        car:4
        erreur: cette objet ne gère pas cette propriété ou cette méthode
        code:0
        URL:res://nisfirst.exe/subscription.htm
        voilou aller @+
        0
    2. OK.
      Tu as passé le CleanUp comme je te l'ai demandé????

      chépofaire;;mésavaviendre..
      La critique est aisée et l'art est difficile Les Glorieux, II,5
      0
      1. oui mari ses le 2 eme article que jai fai @+
        0
    3. Modérateur
      Salut Kevin, coucou Marie. :-)

      Pour commencer, relance HijackThis. Clique sur Do a system scan only.

      Coche cette ligne et clique sur Fix Checked :
      O4 - HKLM\..\Run: [Yksaqlgo] C:\Program Files\Newhmu\Cgzbhct.exe

      Ensuite, supprime ce dossier :
      C:\Program Files\Newhmu

      Quand tu dis jai sa qui saffiche et me blok mon norton et plin de truc comme le restauration de system, ces erreurs s'affichent lorsque tu lances des applications ou une page Web ???

      A++++++
      0
      1. lu nilou oui ses fai se que tu ma di coche
        O4 - HKLM\..\Run: [Yksaqlgo] C:\Program Files\Newhmu\Cgzbhct.exe
        appres tu ma di de suprimmer sa den C:\Program Files\Newhmu
        et la ses le prob sa fai impossible de le supprimer
        oui sa me fai quan jouvre norton merci @+
        0
      2. @kevinnre nilou ses bon sers supprimer appres je fai koi
        0
      3. Modérateur
        @kevinnCoucou. :-D

        C'est bon, tu as supprimé le dossier ???
        Remets un nouveau log HijackThis pour voir où nous en sommes.

        Tu peux supprimer Norton Antivirus et le remplacer par un autre.
        C'est une "passoire à virus", si je puis dire. ;-)))

        Voici une liste d'antivirus que tu peux choisir (installe-en un seul)
        http://www.commentcamarche.net/faq/sujet-35-Antivirus-gratuit-lequel-choisir

        A++++++
        0
    4. re nilou et mari met il va pa partir
      O4 - HKLM\..\Run: [Yksaqlgo] C:\Program Files\Newhmu\Cgzbhct.exe met ses supprimer du disque dur
      0
      1. re lol met je pe pa le changer tu ses pk mon pere a pa fini l abonemenet ilfin en mars sers sa le pb

        tien lol ou nou en somme
        C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
        C:\WINDOWS\wanmpsvc.exe
        C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\eChanblard\emule.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\PROGRA~1\CleanUp!\cleanup.exe
        C:\Program Files\WinRAR\WinRAR.exe
        C:\DOCUME~1\kevin\LOCALS~1\Temp\Rar$EX00.344\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.noos.fr/
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
        O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Fichiers communs\Symantec Shared\ccRegVfy.exe"
        O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [Yksaqlgo] C:\Program Files\Newhmu\Cgzbhct.exe
        O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a-squared\a2guard.exe"
        O4 - Global Startup: Norton Internet Security.lnk = C:\Program Files\Norton Internet Security\nisfirst.exe
        O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
        O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
        O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
        O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
        O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
        O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
        O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPxySvc.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
        O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
        O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
        O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
        O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
        0
        1. Modérateur
          Coucou. :-D

          Relance HijackThis et coche ces lignes :

          O4 - HKLM\..\Run: [Yksaqlgo] C:\Program Files\Newhmu\Cgzbhct.exe
          O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
          O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
          O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
          O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
          O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone

          Redémarre en Mode sans Echec.
          Pour cela, appuie sur la touche F8 dès le début de l’allumage du PC sans t’arrêter.
          Une fenêtre va s’ouvrir. Déplace-toi avec les flèches du clavier sur Démarrer en mode sans échec puis tape sur Entrée.
          Une fois sur le bureau, s’il n’y a pas toutes les couleurs et autres, c’est normal !
          (Si F8 ne marche pas utilise la touche F5).
          Tu pourras alors supprimer le dossier récalcitrant !!!

          Tiens-moi au courant !!!
          A+++++
          0
          1. re il y a pa sa sur HijackThis

            O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
            O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
            O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
            O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
            O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone

            a++++ appres tu me di fo que je face comm mm en mode sans echec
            lol met le quel dossier récalcitrant !!!
            0
            1. re lol tien regarde
              Logfile of HijackThis v1.99.1
              Scan saved at 10:38:49, on 21/01/2006
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
              C:\Program Files\Norton Internet Security\NISUM.EXE
              C:\Program Files\Norton Internet Security\ccPxySvc.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
              C:\Program Files\Norton AntiVirus\navapsvc.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
              C:\WINDOWS\wanmpsvc.exe
              C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\MSN Messenger\msnmsgr.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\eChanblard\emule.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\DOCUME~1\kevin\LOCALS~1\Temp\Rar$EX00.125\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.noos.fr/
              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
              O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
              O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Fichiers communs\Symantec Shared\ccRegVfy.exe"
              O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [Yksaqlgo] C:\Program Files\Newhmu\Cgzbhct.exe
              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a-squared\a2guard.exe"
              O4 - Global Startup: Norton Internet Security.lnk = C:\Program Files\Norton Internet Security\nisfirst.exe
              O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
              O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
              O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
              O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPxySvc.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
              O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
              O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
              O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
              O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
              O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
              O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

              aller @+ nilou
              0
              1. Modérateur
                Re Kévin.

                Les lignes 015 ont disparu. Cool.
                Le dossier récalcitrant, c'est le dossier que tu n'arrives pas à supprimer en mode normal.

                Celui-là : C:\Program Files\Newhmu
                En Mode sans échec, tu pourras le supprimer.

                Fais la manip' et reposte un nouveau log HijackThis après.
                A+++++++
                0
                1. re cool
                  ss bon ses effacer le dossier regarde
                  Logfile of HijackThis v1.99.1
                  Scan saved at 10:49:09, on 21/01/2006
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                  C:\Program Files\Norton Internet Security\NISUM.EXE
                  C:\Program Files\Norton Internet Security\ccPxySvc.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                  C:\Program Files\Norton AntiVirus\navapsvc.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                  C:\WINDOWS\wanmpsvc.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\Program Files\MSN Messenger\msnmsgr.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Program Files\eChanblard\emule.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\WINDOWS\system32\NOTEPAD.EXE
                  C:\DOCUME~1\kevin\LOCALS~1\Temp\Rar$EX00.141\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.noos.fr/
                  O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                  O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                  O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                  O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Fichiers communs\Symantec Shared\ccRegVfy.exe"
                  O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a-squared\a2guard.exe"
                  O4 - Global Startup: Norton Internet Security.lnk = C:\Program Files\Norton Internet Security\nisfirst.exe
                  O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                  O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                  O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPxySvc.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                  O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
                  O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                  O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                  O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                  O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                  O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

                  merci je sui pres a continuer lol ^^ en faite je ve juste que le erreur soi supprimer et que norton refonctionne appres lol je men fou car aappres je machete un pc merci davance nilou
                  0
                  1. Modérateur
                    Coucou ! :-)

                    Bon. Ton problème n'est pas dû aux bestioles.
                    Je ne vois plus rien dans ton log HijackThis ...

                    Au fait, c'est quoi cette histoire de Restauration système ??? :-)
                    Tu n'arrives plus à restaurer ton système ?? c'est ça ?
                    Arrives-tu à scanner avec Norton ??

                    A+++++
                    0
                    1. re lol mm pa tu voi lol pour le restauration du system sses que je clic dessu et paf une page blanche
                      @+
                      0
                  2. Modérateur
                    Re

                    Essaie de faire ce scan en ligne :
                    http://webscanner.kaspersky.fr/

                    Copie-colle le rapport à la fin du scan.
                    A+++++
                    0
                    1. @Nilou17re
                      et la sa me fai sa
                      Failed to load interface -- You must have administrative rights on this computer; you also must have the Internet Explorer security settings to the Medium level
                      @+
                      0
                  3. salut!!!
                    PLZ jai besoin de quelquin qui peux maider plz tres urgent

                    une erreur est survenue sur le script de cette page

                    ligne:34
                    car:4
                    erreur: cette objet ne gère pas cette propriété ou cette méthode
                    code:0
                    URL:res://nisfirst.exe/subscription.htm
                    plz merci de maider et surtou de maider a virer sette merde car sa me blok plin de truc
                    @+
                    0