[virus] infecté!!!! aidez moi s.v.p.

valentin93 Messages postés 29 Statut Membre -  
 Regis59 -
voila jai un virus, voici un scan:

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Apps\ActivBoard\nhksrv.exe
C:\Program Files\Alwil

Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil

Software\Avast4\ashServ.exe
C:\Program Files\Fichiers

communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virtual CD v4

SDK\system\vcssecs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil

Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil

Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers

communs\Logitech\QCDriver3\LVCOMS.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers

communs\Real\Update_OB\realsched.exe
C:\Program

Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MessengerPlus!

3\MsgPlus.exe
C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\LogitechDesktopM

essenger.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adobe\Acrobat

7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\shell386.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft

Money\System\urlmap.exe
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://www.liporn.com
R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Window Title = Microsoft

Internet Explorer
R1 -

HKCU\Software\Microsoft\Windows\CurrentVer

sion\Internet Settings,ProxyOverride =

localhost
R0 - HKCU\Software\Microsoft\Internet

Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

C:\Program Files\Adobe\Acrobat

7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: winapi32.MyBHO -

{1CBC7F79-C21A-4468-8116-38E8AD875816} -

C:\WINDOWS\system32\winapi32.dll
O2 - BHO: Google Toolbar Helper -

{AA58ED58-01DD-4d91-8333-CF10577473F7} -

c:\program files\google\googletoolbar1.dll
O2 - BHO: ZToolbar Activator Class -

{da7ff3f8-08be-4cac-bc00-94d91c6ae7f4} -

C:\WINDOWS\system32\azesearch4.ocx (file

missing)
O2 - BHO: AddressBar Class -

{f65b197f-8260-4d52-909a-f70118e646eb} -

C:\WINDOWS\system32\iasada.dll
O2 - BHO: (no name) -

{FDD3B846-8D59-4ffb-8758-209B6AD74ACC} -

C:\Program Files\Microsoft

Money\System\mnyviewer.dll
O3 - Toolbar: Search -

{a19ef336-01d4-48e6-926a-fe7e1c747aed} -

C:\WINDOWS\system32\azesearch4.ocx (file

missing)
O3 - Toolbar: &Google -

{2318C2B1-4965-11d4-9B18-009027A5CD4F} -

c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program

Files\Fichiers

communs\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [avast!]

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program

Files\Fichiers

communs\Real\Update_OB\realsched.exe"

-osboot
O4 - HKLM\..\Run: [LogitechGalleryRepair]

C:\Program

Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run:

[LogitechImageStudioTray] C:\Program

Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task]

"C:\Program Files\QuickTime\qttask.exe"

-atboottime
O4 - HKLM\..\Run: [MessengerPlus3]

"C:\Program Files\MessengerPlus!

3\MsgPlus.exe"
O4 - HKLM\..\Run: [NeroFilterCheck]

C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [winsysupd]

C:\windows\winsysupd8.exe
O4 - HKCU\..\Run: [LDM] C:\Program

Files\Logitech\Desktop

Messenger\8876480\Program\LogitechDesktopM

essenger.exe
O4 - HKCU\..\Run: [Update Service]

"C:\Program Files\Fichiers communs\Teknum

Systems\update.exe" /startup
O4 - HKCU\..\Run: [MessengerPlus3]

"C:\Program Files\MessengerPlus!

3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program

Files\MSN Messenger\msnmsgr.exe"

/background
O4 - Global Startup: Adobe Gamma

Loader.exe.lnk = C:\Program Files\Fichiers

communs\Adobe\Calibration\Adobe Gamma

Loader.exe
O4 - Global Startup: Lancement rapide

d'Adobe Reader.lnk = C:\Program

Files\Adobe\Acrobat

7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop

Messenger.lnk = C:\Program

Files\Logitech\Desktop

Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Ralink Wireless

Utility.lnk = C:\Program

Files\RALINK\Common\RaUI.exe
O8 - Extra context menu item: &Traduire à

partir de l'anglais - res://C:\Program

Files\Google\GoogleToolbar1.dll/cmwordtran

s.html
O8 - Extra context menu item: Pages liées

- res://C:\Program

Files\Google\GoogleToolbar1.dll/cmbacklink

s.html
O8 - Extra context menu item: Pages

similaires - res://C:\Program

Files\Google\GoogleToolbar1.dll/cmsimilar.

html
O8 - Extra context menu item: Recherche

&Google - res://C:\Program

Files\Google\GoogleToolbar1.dll/cmsearch.h

tml
O8 - Extra context menu item: Version de

la page actuelle disponible dans le cache

Google - res://C:\Program

Files\Google\GoogleToolbar1.dll/cmcache.ht

ml
O9 - Extra button: Packard Bell -

{1D49B7D4-524D-4ac9-BC34-B4822CAE4BB1} -

C:\Apps\IECustom\script.htm
O9 - Extra button: Real.com -

{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -

C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide -

{E023F504-0C5A-4750-A1E7-A9046DEA8A21} -

C:\Program Files\Microsoft

Money\System\mnyviewer.dll
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows

Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted IP range: 67.19.185.246
O16 - DPF:

{00B71CFB-6864-4346-A978-C0A14556272C}

(Checkers Class) -

http://messenger.zone.msn.com/binary/msgrc

hkr.cab31267.cab
O16 - DPF:

{14B87622-7E19-4EA8-93B3-97215F77A6BC} -

http://messenger.zone.msn.com/binary/Messe

ngerStatsPAClient.cab31267.cab
O16 - DPF:

{2917297F-F02B-4B9D-81DF-494B6333150B}

(Minesweeper Flags Class) -

http://messenger.zone.msn.com/binary/MineS

weeper.cab31267.cab
O16 - DPF:

{8E0D4DE5-3180-4024-A327-4DFAD1796A8D}

(MessengerStatsClient Class) -

http://messenger.zone.msn.com/binary/Messe

ngerStatsClient.cab31267.cab
O16 - DPF:

{D7BF3304-138B-4DD5-86EE-491BB6A2286C} -

http://www.azebar.com/install/azesearch.ca

b
O16 - DPF:

{F6BF0D00-0B2A-4A75-BF7B-F385591623AF}

(Solitaire Showdown Class) -

http://messenger.zone.msn.com/binary/Solit

aireShowdown.cab31267.cab
O18 - Protocol: bw+0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw+0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw-0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw-0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw00 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw00s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw10 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw10s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw20 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw20s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw30 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw30s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw40 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw40s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw50 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw50s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw60 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw60s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw70 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw70s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw80 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw80s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw90 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw90s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwa0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwa0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwb0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwb0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwc0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwc0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwd0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwd0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwe0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwe0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwf0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwf0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwfile-8876480 -

{9462A756-7B47-47BC-8C80-C34B9B80B32B} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\GAPlugProtocol-8

876480.dll
O18 - Protocol: bwg0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwg0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwh0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwh0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwi0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwi0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwj0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwj0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwk0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwk0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwl0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwl0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwm0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwm0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwn0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwn0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwo0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwo0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwp0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwp0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwq0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwq0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwr0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwr0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bws0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bws0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwt0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwt0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwu0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwu0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwv0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwv0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bww0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bww0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwx0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwx0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwy0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwy0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwz0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwz0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: msnim -

{828030A1-22C1-4009-854F-8E305202313F} -

"C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file

missing)
O18 - Protocol: offline-8876480 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O23 - Service: Adobe LM Service - Adobe

Systems - C:\Program Files\Fichiers

communs\Adobe Systems

Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control

Service (aswUpdSv) - Unknown owner -

C:\Program Files\Alwil

Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown

owner - C:\Program Files\Alwil

Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner -

Unknown owner - C:\Program Files\Alwil

Software\Avast4\ashMaiSv.exe" /service

(file missing)
O23 - Service: avast! Web Scanner -

Unknown owner - C:\Program Files\Alwil

Software\Avast4\ashWebSv.exe" /service

(file missing)
O23 - Service: Netropa NHK Server (nhksrv)

- Unknown owner -

C:\Apps\ActivBoard\nhksrv.exe
O23 - Service: NVIDIA Driver Helper

Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService

(SLService) - -

C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sony SPTI Service (SPTISRV)

- Sony Corporation -

C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisr

v.exe
O23 - Service: Virtual CD v4 Security

service (SDK - Version) (VCSSecS) - H+H

Software GmbH - C:\Program Files\Virtual

CD v4 SDK\system\vcssecs.exe
A voir également:

31 réponses

valentin93 Messages postés 29 Statut Membre
 
AIDEZ MOI LA

Logfile of HijackThis v1.99.1
Scan saved at 19:41:27, on 15/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2

(6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Apps\ActivBoard\nhksrv.exe
C:\Program Files\Alwil

Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil

Software\Avast4\ashServ.exe
C:\Program Files\Fichiers

communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virtual CD v4

SDK\system\vcssecs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil

Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil

Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers

communs\Logitech\QCDriver3\LVCOMS.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers

communs\Real\Update_OB\realsched.exe
C:\Program

Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MessengerPlus!

3\MsgPlus.exe
C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\LogitechDesktopM

essenger.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adobe\Acrobat

7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\shell386.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft

Money\System\urlmap.exe
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://www.liporn.com
R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Window Title = Microsoft

Internet Explorer
R1 -

HKCU\Software\Microsoft\Windows\CurrentVer

sion\Internet Settings,ProxyOverride =

localhost
R0 - HKCU\Software\Microsoft\Internet

Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

C:\Program Files\Adobe\Acrobat

7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: winapi32.MyBHO -

{1CBC7F79-C21A-4468-8116-38E8AD875816} -

C:\WINDOWS\system32\winapi32.dll
O2 - BHO: Google Toolbar Helper -

{AA58ED58-01DD-4d91-8333-CF10577473F7} -

c:\program files\google\googletoolbar1.dll
O2 - BHO: ZToolbar Activator Class -

{da7ff3f8-08be-4cac-bc00-94d91c6ae7f4} -

C:\WINDOWS\system32\azesearch4.ocx (file

missing)
O2 - BHO: AddressBar Class -

{f65b197f-8260-4d52-909a-f70118e646eb} -

C:\WINDOWS\system32\iasada.dll
O2 - BHO: (no name) -

{FDD3B846-8D59-4ffb-8758-209B6AD74ACC} -

C:\Program Files\Microsoft

Money\System\mnyviewer.dll
O3 - Toolbar: Search -

{a19ef336-01d4-48e6-926a-fe7e1c747aed} -

C:\WINDOWS\system32\azesearch4.ocx (file

missing)
O3 - Toolbar: &Google -

{2318C2B1-4965-11d4-9B18-009027A5CD4F} -

c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program

Files\Fichiers

communs\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [avast!]

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program

Files\Fichiers

communs\Real\Update_OB\realsched.exe"

-osboot
O4 - HKLM\..\Run: [LogitechGalleryRepair]

C:\Program

Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run:

[LogitechImageStudioTray] C:\Program

Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task]

"C:\Program Files\QuickTime\qttask.exe"

-atboottime
O4 - HKLM\..\Run: [MessengerPlus3]

"C:\Program Files\MessengerPlus!

3\MsgPlus.exe"
O4 - HKLM\..\Run: [NeroFilterCheck]

C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [winsysupd]

C:\windows\winsysupd8.exe
O4 - HKCU\..\Run: [LDM] C:\Program

Files\Logitech\Desktop

Messenger\8876480\Program\LogitechDesktopM

essenger.exe
O4 - HKCU\..\Run: [Update Service]

"C:\Program Files\Fichiers communs\Teknum

Systems\update.exe" /startup
O4 - HKCU\..\Run: [MessengerPlus3]

"C:\Program Files\MessengerPlus!

3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ctfmon.exe]

C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program

Files\MSN Messenger\msnmsgr.exe"

/background
O4 - Global Startup: Adobe Gamma

Loader.exe.lnk = C:\Program Files\Fichiers

communs\Adobe\Calibration\Adobe Gamma

Loader.exe
O4 - Global Startup: Lancement rapide

d'Adobe Reader.lnk = C:\Program

Files\Adobe\Acrobat

7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop

Messenger.lnk = C:\Program

Files\Logitech\Desktop

Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Ralink Wireless

Utility.lnk = C:\Program

Files\RALINK\Common\RaUI.exe
O8 - Extra context menu item: &Traduire à

partir de l'anglais - res://C:\Program

Files\Google\GoogleToolbar1.dll/cmwordtran

s.html
O8 - Extra context menu item: Pages liées

- res://C:\Program

Files\Google\GoogleToolbar1.dll/cmbacklink

s.html
O8 - Extra context menu item: Pages

similaires - res://C:\Program

Files\Google\GoogleToolbar1.dll/cmsimilar.

html
O8 - Extra context menu item: Recherche

&Google - res://C:\Program

Files\Google\GoogleToolbar1.dll/cmsearch.h

tml
O8 - Extra context menu item: Version de

la page actuelle disponible dans le cache

Google - res://C:\Program

Files\Google\GoogleToolbar1.dll/cmcache.ht

ml
O9 - Extra button: Packard Bell -

{1D49B7D4-524D-4ac9-BC34-B4822CAE4BB1} -

C:\Apps\IECustom\script.htm
O9 - Extra button: Real.com -

{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -

C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide -

{E023F504-0C5A-4750-A1E7-A9046DEA8A21} -

C:\Program Files\Microsoft

Money\System\mnyviewer.dll
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows

Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted IP range: 67.19.185.246
O16 - DPF:

{00B71CFB-6864-4346-A978-C0A14556272C}

(Checkers Class) -

http://messenger.zone.msn.com/binary/msgrc

hkr.cab31267.cab
O16 - DPF:

{14B87622-7E19-4EA8-93B3-97215F77A6BC} -

http://messenger.zone.msn.com/binary/Messe

ngerStatsPAClient.cab31267.cab
O16 - DPF:

{2917297F-F02B-4B9D-81DF-494B6333150B}

(Minesweeper Flags Class) -

http://messenger.zone.msn.com/binary/MineS

weeper.cab31267.cab
O16 - DPF:

{8E0D4DE5-3180-4024-A327-4DFAD1796A8D}

(MessengerStatsClient Class) -

http://messenger.zone.msn.com/binary/Messe

ngerStatsClient.cab31267.cab
O16 - DPF:

{D7BF3304-138B-4DD5-86EE-491BB6A2286C} -

http://www.azebar.com/install/azesearch.ca

b
O16 - DPF:

{F6BF0D00-0B2A-4A75-BF7B-F385591623AF}

(Solitaire Showdown Class) -

http://messenger.zone.msn.com/binary/Solit

aireShowdown.cab31267.cab
O18 - Protocol: bw+0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw+0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw-0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw-0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw00 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw00s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw10 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw10s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw20 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw20s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw30 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw30s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw40 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw40s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw50 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw50s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw60 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw60s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw70 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw70s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw80 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw80s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw90 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bw90s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwa0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwa0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwb0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwb0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwc0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwc0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwd0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwd0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwe0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwe0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwf0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwf0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwfile-8876480 -

{9462A756-7B47-47BC-8C80-C34B9B80B32B} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\GAPlugProtocol-8

876480.dll
O18 - Protocol: bwg0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwg0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwh0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwh0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwi0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwi0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwj0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwj0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwk0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwk0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwl0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwl0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwm0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwm0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwn0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwn0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwo0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwo0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwp0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwp0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwq0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwq0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwr0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwr0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bws0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bws0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwt0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwt0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwu0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwu0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwv0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwv0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bww0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bww0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwx0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwx0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwy0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwy0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwz0 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: bwz0s -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O18 - Protocol: msnim -

{828030A1-22C1-4009-854F-8E305202313F} -

"C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file

missing)
O18 - Protocol: offline-8876480 -

{6EDC6297-4383-4CE8-9C15-BE39998F9B51} -

C:\Program Files\Logitech\Desktop

Messenger\8876480\Program\BWPlugProtocol-8

876480.dll
O23 - Service: Adobe LM Service - Adobe

Systems - C:\Program Files\Fichiers

communs\Adobe Systems

Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control

Service (aswUpdSv) - Unknown owner -

C:\Program Files\Alwil

Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown

owner - C:\Program Files\Alwil

Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner -

Unknown owner - C:\Program Files\Alwil

Software\Avast4\ashMaiSv.exe" /service

(file missing)
O23 - Service: avast! Web Scanner -

Unknown owner - C:\Program Files\Alwil

Software\Avast4\ashWebSv.exe" /service

(file missing)
O23 - Service: Netropa NHK Server (nhksrv)

- Unknown owner -

C:\Apps\ActivBoard\nhksrv.exe
O23 - Service: NVIDIA Driver Helper

Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService

(SLService) - -

C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sony SPTI Service (SPTISRV)

- Sony Corporation -

C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisr

v.exe
O23 - Service: Virtual CD v4 Security

service (SDK - Version) (VCSSecS) - H+H

Software GmbH - C:\Program Files\Virtual

CD v4 SDK\system\vcssecs.exe
0
Utilisateur anonyme
 
salut

Télécharge ceci: (merci a S!RI pour ce programme).
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 3.

Et remet un hijack this

a+
0
neness
 
slt régis
tu m'a déjà dépannée plusieurs fois notemment fin novembre, juste avant d'accoucher... je t'avais promis une photo de mon petit sur le forum. je ne sais pas comment l'envoyer et je m'excuse de m'imisser dans cette discussion mais je ne sais comment te conatcter en direct.
j'attends tes instructions
@+
vanessa
0
valentin93 Messages postés 29 Statut Membre
 
Logfile of HijackThis v1.99.1
Scan saved at 00:45:07, on 16/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Apps\ActivBoard\nhksrv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\WINDOWS\system32\osk.exe
C:\WINDOWS\system32\MSSWCHX.EXE
C:\WINDOWS\system32\shell386.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Program Files\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: winapi32.MyBHO - {1CBC7F79-C21A-4468-8116-38E8AD875816} - C:\WINDOWS\system32\winapi32.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe]
0
Utilisateur anonyme
 
Salut

Reéxecute Smitfraudfix.cmd mais cette fois,choisit l’option 1, il va générer un rapport
Copie/colle le sur le poste stp.

a+
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
valentin93 Messages postés 29 Statut Membre
 
SmitFraudFix v2.21

Rapport fait à 0:57:21,90 le 16/02/2006
Executé à partir de C:\Documents and Settings\VALENTIN\Local Settings\Temporary Internet Files\Content.IE5\JTI42LA5\SmitfraudFix[1]\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600]

»»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

»»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

C:\WINDOWS\adw.htm PRESENT !
C:\WINDOWS\back.gif PRESENT !
C:\WINDOWS\bg.gif PRESENT !
C:\WINDOWS\download-btn.gif PRESENT !

»»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

»»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

»»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

C:\WINDOWS\system32\adsmart.exe PRESENT !
C:\WINDOWS\system32\bu.exe PRESENT !
C:\WINDOWS\system32\exa32.exe PRESENT !
C:\WINDOWS\system32\intxt.exe PRESENT !
C:\WINDOWS\system32\mswinb32.dll PRESENT !
C:\WINDOWS\system32\mswinb32.exe PRESENT !
C:\WINDOWS\system32\mswinf32.dll PRESENT !
C:\WINDOWS\system32\mswinf32.exe PRESENT !
C:\WINDOWS\system32\mswinup32.dll PRESENT !
C:\WINDOWS\system32\mswinxml.dll PRESENT !
C:\WINDOWS\system32\shell386.exe PRESENT !
C:\WINDOWS\system32\winapi32.dll PRESENT !
C:\WINDOWS\system32\winlfl32.dll PRESENT !

»»»»»»»»»»»»»»»»»»»»»»»» Recherche ...\Application Data

»»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

»»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

»»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

»»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

»»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"

»»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"

[HKEY_CLASSES_ROOT\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"

[HKEY_CLASSES_ROOT\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"

»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

»»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
0
Utilisateur anonyme
 
Re,

Démarre en mode sans échec :
Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
(Si F8 ne marche pas utilise la touche F5).
----------------------------------------------------------------------------
Relance le programme Smitfraud,
Cette fois choisit l’option 2, répond oui a tous ;
Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

Puis remet un Hijack This

a demain.
0
valentin93 Messages postés 29 Statut Membre
 
voici le raport:

SmitFraudFix v2.21

Rapport fait à 1:12:43,31 le 16/02/2006
Executé à partir de C:\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600]

»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage Fichiers Temporaires

»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

Nettoyage terminé.

»»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

voici le hijackthis:

Logfile of HijackThis v1.99.1
Scan saved at 01:27:17, on 16/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Apps\ActivBoard\nhksrv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\WINDOWS\system32\osk.exe
C:\WINDOWS\system32\MSSWCHX.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: Packard Bell - {1D49B7D4-524D-4ac9-BC34-B4822CAE4BB1} - C:\Apps\IECustom\script.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} - http://www.azebar.com/install/azesearch.cab
O18 - Protocol: bw+0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: offline-8876480 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
0
Utilisateur anonyme
 
Salut

¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com

O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} - http://www.azebar.com/install/azesearch.cab

Puis redemarre ton PC, remet un hijack this et dis moi ou en sont tes soucis

a+
0
valentin93 Messages postés 29 Statut Membre
 
le raportdeja:


Logfile of HijackThis v1.99.1
Scan saved at 11:44:27, on 16/02/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Apps\ActivBoard\nhksrv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\WINDOWS\system32\OSK.exe
C:\WINDOWS\system32\MSSWCHX.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Program Files\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: Packard Bell - {1D49B7D4-524D-4ac9-BC34-B4822CAE4BB1} - C:\Apps\IECustom\script.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {D7BF3304-138B-4DD5-86EE-491BB6A2286C} - http://www.azebar.com/install/azesearch.cab
O18 - Protocol: bw+0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: offline-8876480 - {6EDC6297-4383-4CE8-9C15-BE39998F9B51} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Apps\ActivBoard\nhksrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe

ensuite mon clavier ne refonctionne toujours pas, alors que je peu utiliser la touche F8 au debut du demarage, dans windows je ne peu plus taper au clavier,( alors que je peu utiliser les boutons pour changer de chansons ect...).
mon pare-feu windows ne peu pas se remettre en route, il me dise celon " une erreur inconnu". et les liens ds mes favori ne sont pas parti,des liens de site de cul ect....
je ne peu nonplus aller faire l'antivirus en ligne de www.secuser.com, jai une photo de e qu'il mette.
http://rapidshare.de/files/13388108/Sans_titre.JPG.html


et aufaitejai atraper ce virus sur astalavista.com(komparhasar) en soisdisant telechargant un plugin de activeX inpeu le meme style que sur limage sidessu

(excusez les fautes dortographe)
0
Utilisateur anonyme
 
Salut

Le rapport d ewido?

ensuite fais ceci:

Télécharge lopxp ici:

http://pageperso.aol.fr/balltrap34/lopxp.zip (Merci Moe31 et Balltrap34)

2) dezippe le (clic droit dessus > extraire tout)
et lance lopxp.bat
le bloc note va s'ouvrir, copie et colle le contenu ici

A+

0
valentin93 Messages postés 29 Statut Membre
 
Rapport fait à 12:07:54,73 le 16/02/2006

Le volume dans le lecteur C s'appelle HDD
Le num‚ro de s‚rie du volume est 98C0-C07B

R‚pertoire de C:\Documents and Settings\Administrateur\Application Data

09/04/2005 15:52 <REP> Dossier de t‚l‚chargement Share-to-Web
09/04/2005 15:41 62 desktop.ini
09/04/2005 15:41 <REP> Adobe
09/04/2005 15:41 <REP> Identities
09/04/2005 15:41 <REP> InterTrust
09/04/2005 15:41 <REP> ..
09/04/2005 15:41 <REP> Microsoft
09/04/2005 15:41 <REP> .
1 fichier(s) 62 octets
7 R‚p(s) 15027748864 octets libres
Le volume dans le lecteur C s'appelle HDD
Le num‚ro de s‚rie du volume est 98C0-C07B

R‚pertoire de C:\Documents and Settings\All Users\Application Data

19/10/2005 19:46 <REP> Adobe Systems
03/10/2005 18:08 <REP> MSN6
13/09/2005 17:09 <REP> Adobe
30/07/2005 19:39 <REP> Pinnacle
08/07/2005 12:47 <REP> Sony Corporation
22/06/2005 13:51 <REP> Messenger Plus!
21/04/2005 18:14 <REP> Spybot - Search & Destroy
30/03/2005 12:48 <REP> acid program anti atom
25/01/2005 18:40 <REP> QuickTime
17/01/2005 19:37 <REP> CyberLink
17/01/2005 19:21 <REP> SBSI
17/01/2005 19:08 62 desktop.ini
17/01/2005 19:08 <REP> Microsoft
17/01/2005 19:08 <REP> .
17/01/2005 19:08 <REP> ..
1 fichier(s) 62 octets
14 R‚p(s) 15027744768 octets libres
Le volume dans le lecteur C s'appelle HDD
Le num‚ro de s‚rie du volume est 98C0-C07B

R‚pertoire de C:\Documents and Settings\Default User\Application Data

17/01/2005 20:03 <REP> InterTrust
17/01/2005 20:03 <REP> Adobe
17/01/2005 20:03 <REP> Identities
17/01/2005 19:08 62 desktop.ini
17/01/2005 19:08 <REP> Microsoft
17/01/2005 19:08 <REP> ..
17/01/2005 19:08 <REP> .
1 fichier(s) 62 octets
6 R‚p(s) 15027744768 octets libres
Le volume dans le lecteur C s'appelle HDD
Le num‚ro de s‚rie du volume est 98C0-C07B

R‚pertoire de C:\Documents and Settings\Isabelle\Application Data

28/01/2006 19:14 <REP> VERITAS
13/09/2005 17:11 <REP> AdobeUM
06/08/2005 13:17 <REP> Sony Corporation
12/06/2005 08:32 <REP> Lavasoft
21/05/2005 14:46 <REP> Macromedia
21/05/2005 14:36 <REP> Dossier de t‚l‚chargement Share-to-Web
21/05/2005 14:31 <REP> Real
21/05/2005 14:30 62 desktop.ini
21/05/2005 14:30 <REP> Adobe
21/05/2005 14:30 <REP> InterTrust
21/05/2005 14:30 <REP> Identities
21/05/2005 14:30 <REP> ..
21/05/2005 14:30 <REP> .
21/05/2005 14:30 <REP> Microsoft
1 fichier(s) 62 octets
13 R‚p(s) 15027744768 octets libres
Le volume dans le lecteur C s'appelle HDD
Le num‚ro de s‚rie du volume est 98C0-C07B

R‚pertoire de C:\Documents and Settings\Isabelle2\Application Data

22/04/2005 17:58 <REP> spweng
22/04/2005 17:50 <REP> Lavasoft
21/04/2005 21:07 <REP> Mozilla
03/04/2005 16:58 <REP> Microsoft Web Folders
05/03/2005 11:31 <REP> Template
15/02/2005 19:11 <REP> Help
26/01/2005 18:46 <REP> Real
19/01/2005 19:02 <REP> Dossier de t‚l‚chargement Share-to-Web
19/01/2005 19:02 <REP> Dossier de t‚l‚chargement Share-to-Web
19/01/2005 09:23 <REP> Macromedia
18/01/2005 19:43 62 desktop.ini
18/01/2005 19:43 <REP> Adobe
18/01/2005 19:43 <REP> Identities
18/01/2005 19:43 <REP> InterTrust
18/01/2005 19:43 <REP> Microsoft
18/01/2005 19:43 <REP> .
18/01/2005 19:43 <REP> ..
1 fichier(s) 62 octets
16 R‚p(s) 15027740672 octets libres
Le volume dans le lecteur C s'appelle HDD
Le num‚ro de s‚rie du volume est 98C0-C07B

R‚pertoire de C:\Documents and Settings\Propri‚taire\Application Data

17/01/2005 19:27 <REP> Adobe
17/01/2005 19:27 <REP> InterTrust
17/01/2005 19:19 <REP> Identities
17/01/2005 19:18 62 desktop.ini
17/01/2005 19:18 <REP> ..
17/01/2005 19:18 <REP> Microsoft
17/01/2005 19:18 <REP> .
1 fichier(s) 62 octets
6 R‚p(s) 15027740672 octets libres
Le volume dans le lecteur C s'appelle HDD
Le num‚ro de s‚rie du volume est 98C0-C07B

R‚pertoire de C:\Documents and Settings\sarah\Application Data

13/02/2006 18:09 <REP> Ahead
12/01/2006 14:40 <REP> vlc
17/11/2005 21:38 <REP> AdobeUM
23/07/2005 18:42 <REP> Media Player Classic
29/06/2005 10:33 <REP> MobileAction
21/06/2005 11:38 <REP> VERITAS
14/06/2005 15:01 <REP> Help
21/04/2005 22:00 <REP> Mozilla
25/01/2005 21:34 <REP> Real
19/01/2005 20:03 <REP> Dossier de t‚l‚chargement Share-to-Web
19/01/2005 19:59 <REP> Dossier de t‚l‚chargement Share-to-Web
17/01/2005 22:12 <REP> Macromedia
17/01/2005 22:11 62 desktop.ini
17/01/2005 22:11 <REP> Adobe
17/01/2005 22:11 <REP> Identities
17/01/2005 22:11 <REP> InterTrust
17/01/2005 22:10 <REP> ..
17/01/2005 22:10 <REP> .
17/01/2005 22:10 <REP> Microsoft
1 fichier(s) 62 octets
18 R‚p(s) 15027740672 octets libres
Le volume dans le lecteur C s'appelle HDD
Le num‚ro de s‚rie du volume est 98C0-C07B

R‚pertoire de C:\Documents and Settings\VALENTIN\Application Data

13/02/2006 16:55 <REP> Ahead
10/01/2006 19:07 <REP> vlc
22/10/2005 19:21 <REP> Samsung
18/10/2005 21:12 <REP> Media Player Classic
15/10/2005 14:45 <REP> AdobeUM
09/10/2005 18:56 <REP> Smartelectronix
03/10/2005 18:08 <REP> MSN6
23/09/2005 20:19 <REP> Atari
07/09/2005 16:27 <REP> Sony
31/07/2005 07:41 <REP> Steinberg
08/07/2005 12:53 <REP> Sony Corporation
12/06/2005 16:07 <REP> TuneUp Software
12/06/2005 12:37 <REP> Google
09/05/2005 16:34 <REP> VERITAS
09/05/2005 15:20 <REP> FotoWire
25/04/2005 17:56 <REP> Real
23/04/2005 19:48 <REP> Help
22/04/2005 12:24 <REP> NetMedia Providers
22/04/2005 12:24 <REP> Publish Providers
22/04/2005 12:24 <REP> Sonic Foundry
22/04/2005 11:24 <REP> Lavasoft
22/04/2005 11:17 <REP> Dossier de t‚l‚chargement Share-to-Web
21/04/2005 21:43 <REP> Macromedia
21/04/2005 21:16 <REP> Mozilla
21/04/2005 21:16 62 desktop.ini
21/04/2005 21:16 <REP> Adobe
21/04/2005 21:16 <REP> InterTrust
21/04/2005 21:16 <REP> Identities
21/04/2005 21:16 <REP> Microsoft
21/04/2005 21:16 <REP> .
21/04/2005 21:16 <REP> ..
1 fichier(s) 62 octets
30 R‚p(s) 15027740672 octets libres
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks

Le volume dans le lecteur C s'appelle HDD
Le num‚ro de s‚rie du volume est 98C0-C07B

R‚pertoire de C:\WINDOWS\Tasks

12/06/2005 16:08 418 Maintenance en 1 clic.job
17/01/2005 19:15 6 SA.DAT
17/01/2005 19:13 <REP> ..
17/01/2005 19:13 <REP> .
01/01/1980 00:00 65 desktop.ini
3 fichier(s) 489 octets
2 R‚p(s) 15ÿ027ÿ736ÿ576 octets libres

******************************************
Recherche dans Program files

Le dossier C:\Program Files\C2Media n'existe pas

*************** Fin du rapport ****************
pour le ewido hier soir je les sa a mis 190min, jen refais un, ou te montre celui d'hier?
0
Utilisateur anonyme
 
re;

si t as le rapport d hier, donne le moi et c est bon.

Lance ce scan en ligne:
http://www.bitdefender.fr/scan8/ie.html
Copie/colle le rapport

a+
0
valentin93 Messages postés 29 Statut Membre
 
tien celui d'hier,

http://rapidshare.de/files/13389411/xscan.txt.html

etton scan en ligne me fait ceci (c'est un truc comme sa quand j'ai telecharger sa a mis le virus dc la j'esite inpeu):

http://rapidshare.de/files/13389516/pro.bmp.html
0
Utilisateur anonyme
 
salut

je n ai rien sur les liens

a+
0
valentin93 Messages postés 29 Statut Membre
 
ta pas msn? je tenvoi sur sa, ou par @mail
0
Utilisateur anonyme
 
Salut,

colle le ici ça sera mieux :-/
0
valentin93 Messages postés 29 Statut Membre
 
je ne sais comment faire.....
0
Utilisateur anonyme
 
Tu peux pas tout selectionner, faire copier, venir dans un message et coller?
0
valentin93 Messages postés 29 Statut Membre
 
non je peu pa le copier sa rentre pas meme en plusieres messages il en faudrai 40 minimum.dc comment faire?
0
Utilisateur anonyme
 
Pourquoi tu l as fait chez trendmicro alors que je te le conseillais chez Bitdefender? lol
0
valentin93 Messages postés 29 Statut Membre
 
tu na pas vu l'image, je dois t'envoyer, sa ne marche pas ton scan en ligne sa me met un truc qui fait parti du virus, tu na pas ujn email ou quelque chose dans le genre?stp
0
Utilisateur anonyme
 
re

SpySweeper (de Webroot)
(c'est une version d'essai de 14 jours)
http://www.download.com/Webroot-Spy-Sweepe...4-10405877.html
ou
http://www.webroot.com/consumer/products/spysweeper?acode=af1&rc=3597

• clique sur le lien Free Trial sous la rubrique "SpySweeper"
• installe le programme. Une fois installé, il va se lancer.
• L'option de le mettre à jour va s'afficher, clique sur Yes
• Une fois les mises à jour faites, clique Options sur la gauche
• Clique sur l'onglet Sweep Options
• Sous What to Sweep tu coches les options suivantes :

Sweep Memory
Sweep Registry
Sweep Cookies
Sweep All User Accounts
Enable Direct Disk Sweeping
Sweep Contents of Compressed Files
Sweep for Rootkits
Décoche Do not Sweep System Restore Folder

• clique sur Sweep Now sur la gauche
• clique sur Start
• quand le scan est terminé, clique sur Next• assure toi que tous les items sont cochés, puis clique sur Next
• Tous les items cochés seront éliminés
• Si SpySweeper veut redémarrer pour terminer le nettoyage : ACCEPTE
• Clique Session Log en haut à droite, et copie tout ce qu'il y a dans la fenêtre
• Clique sur l'onglet Summary, puis clique sur Finish
• Colle enfin

a+
0
valentin93 Messages postés 29 Statut Membre
 
bon comme personne na réusi a me débloqer hier jai mis la disquette rouge mais je ne peu pas valider le formatage puisk mon clavier ne marche pas, jai essee plusieres clavier different mais aucun ne fonctionne, je pense que c'est a cause du viruse, comment faire svp??
0
Utilisateur anonyme
 
salut

remet un hijack this mais je penses pas que ca vienne d un virus

a+
0