Remove toolbar

J'ai désintaller REmove toolbar a l'aide de HjackThis et Cleanup40,la barre est partie mais j'aimerais savoir si mon pc est clean.Voissi mon Hjckthis:
Logfile of HijackThis v1.99.1
Scan saved at 12:13:40, on 10/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sitecom\Logiciel Bluetooth\BTTray.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\God\Mes documents\Nouveau dossier\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O1 - Hosts: 222.111.150.111 gwgt1.joymax.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie_ctx.htm
O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Télécharger le site web avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: Télécharger sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Télécharger tout avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5DDCC37F-7C6B-48B8-9664-97C537920CA0} (aecviz Class) - http://www.maisonfamiliale.com/AECVIZ/npaecviz.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/fr/check/qdiagh.cab?326
O17 - HKLM\System\CCS\Services\Tcpip\..\{5ACE17C7-9295-4026-BFC9-E0AC225A6FC2}: NameServer = 85.255.116.170,85.255.112.213
O17 - HKLM\System\CCS\Services\Tcpip\..\{A59316D6-7634-4CE6-B660-C122F100F753}: NameServer = 85.255.116.170,85.255.112.213
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDC1CBF7-B191-448C-934B-AC41C611BF49}: NameServer = 85.255.116.170,85.255.112.213
O17 - HKLM\System\CS1\Services\Tcpip\..\{5ACE17C7-9295-4026-BFC9-E0AC225A6FC2}: NameServer = 85.255.116.170,85.255.112.213
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\System32\btxppanel.dll
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

J'aimerais savoir si il reste des lignes a fixer.
Merci d'avance.

11 réponses

  1. J'aimerais savoir aussi comment retrouver mon affichage xp car une fois cleanup éffectué c un affichage classique et pas moyen de retrouver l'xp.
    0
    1. Contributeur
      bjr
      9/ - *Perte du thème XP
      Suite à une infection, vous perdez votre thème Xp et il est impossible de le remettre dans les options puisqu'il n'apparait plus? Pas de panique...
      Télécharger ceci et le décompresser
      http://pageperso.aol.fr/Balltrap34/luna.zip
      Ensuite le mettre le dans C:\WINDOWS\Resources\Themes\Luna
      et double cliquer dessus
      Ensuite réessayer de remettre le style xp
      0
      1. Merci de ton aide,j'ai bien retrouver le theme xp,par contre lorsque fais des recherches sur google losque je clique sur lien il ne m'envois pas sur le site demandé mais vers un site bidon.J'aimerais savoir si c'est parce qu'il me reste des fichiers de remove toolbar.
        0
        1. Contributeur
          hum
          possible
          dance cas, suivre ceci pour en savoir plus et éventuellement corriger
          ============
          CCM
          Merci de procéder dans l’ordre,
          Télécharge TOUS ces programmes (si tu n’as pas), installe-les.
          Fais les mises à jour des progr 1/, 2/, 3/
          Scan avec TOUS, COLLE les rapports de 3/ & 6/

          1/ -Ad-Aware (gratuit) :
          https://forums.cnetfrance.fr

          2/ - Spybot (gratuit) :
          http://telecharger.01net.com/windows/Internet/internet_utlitaire/fiches/26157.html

          3/ - Ewido (dowload)- gratuit même après 14 jours d’essai
          http://perso.wanadoo.fr/entraide-hijackthis/Ewido/
          Copie/COLLE le rapport généré sur ce forum

          4/ - regcleaner ( nettoyeur de registre)
          http://www.01net.com/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/4894.html
          Son tuto
          http://www.softastuces.com/tuto/maint/regcleaner/index.php

          5/ - cleanup40 (nettoyeur de cookies+temps+tempos+prefetch+historique+etc..)
          http://pageperso.aol.fr/Balltrap34/CleanUp40.exe
          Démo
          http://pageperso.aol.fr/balltrap34/democleanup.htm

          6/ - Scan online avec BitDefender – fonctionne uniquement sous Internet Explorer en acceptant l’activX (à défaut de réussite, essaie avec Kasper et Panda )
          https://assiste.com/404_La_page_demandee_n_existe_pas.php
          Copie/COLLE le rapport entier

          7/ - Hijackthis – outil de diagnostic et réparation
          lire démo
          http://pageperso.aol.fr/balltrap34/Hijenr.gif
          http://pageperso.aol.fr/balltrap34/demohijack.htm
          Téléchargement version française
          http://telechargement.zebulon.fr/160-patch-francais-pour-hijackthis-1991.html

          Au boulot – Bon courage
          0
          1. J'ai fais tous ce que tu as demandé et j'ai tjs le meme probleme,voici les rapports que tu as demandé:

            Ewido
            ewido anti-malware - Rapport de scan
            ---------------------------------------------------------

            + Créé le: 11:33:29, 11/04/2006
            + Somme de contrôle: 3BFA3C3

            + Résultats du scan:

            [500] VM_00D70000 -> Downloader.Agent.uj : Erreur durant le nettoyage
            [528] VM_00DE0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
            [1620] VM_009D0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
            [1804] VM_009A0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
            [1860] VM_008A0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
            [1908] VM_00390000 -> Downloader.Agent.uj : Erreur durant le nettoyage
            [1924] VM_008C0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
            [2020] VM_003E0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
            [3204] VM_003F0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
            C:\Documents and Settings\God\Cookies\god@247realmedia[1].txt -> TrackingCookie.247realmedia : Nettoyer et sauvegarder
            C:\Documents and Settings\God\Cookies\god@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder

            ::Fin du rapport

            BitDefender
            Time
            01:43:50

            Files
            355888

            Folders
            3423

            Boot Sectors
            2

            Archives
            1943

            Packed Files
            43452

            Results

            Identified Viruses
            1

            Infected Files
            7

            Suspect Files
            0

            Warnings
            0

            Disinfected
            0

            Deleted Files
            7

            Engines Info

            Virus Definitions
            369495

            Engine build
            AVCORE v1.0 (build 2292) (i386) (Mar 3 2005 11:57:29)

            Scan plugins
            13

            Archive plugins
            39

            Unpack plugins
            4

            E-mail plugins
            6

            System plugins
            1

            Scan Settings

            First Action
            Disinfect

            Second Action
            Delete

            Heuristics
            Yes

            Enable Warnings
            Yes

            Scanned Extensions
            *;

            Exclude Extensions

            Scan Emails
            Yes

            Scan Archives
            Yes

            Scan Packed
            Yes

            Scan Files
            Yes

            Scan Boot
            Yes

            Scanned File
            Status

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0179985.exe
            Infected with: Trojan.Downloader.FFZ

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0179985.exe
            Disinfection failed

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0179985.exe
            Deleted

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0180144.exe
            Infected with: Trojan.Downloader.FFZ

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0180144.exe
            Disinfection failed

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0180144.exe
            Deleted

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0180781.exe
            Infected with: Trojan.Downloader.FFZ

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0180781.exe
            Disinfection failed

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0180781.exe
            Deleted

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0181325.exe
            Infected with: Trojan.Downloader.FFZ

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0181325.exe
            Disinfection failed

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0181325.exe
            Deleted

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0181950.exe
            Infected with: Trojan.Downloader.FFZ

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0181950.exe
            Disinfection failed

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0181950.exe
            Deleted

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0182400.exe
            Infected with: Trojan.Downloader.FFZ

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0182400.exe
            Disinfection failed

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0182400.exe
            Deleted

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP105\A0183731.exe
            Infected with: Trojan.Downloader.FFZ

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP105\A0183731.exe
            Disinfection failed

            C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP105\A0183731.exe
            Deleted

            Voici mon Hijackthis:
            Logfile of HijackThis v1.99.1
            Scan saved at 13:51:22, on 11/04/2006
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\drivers\CDAC11BA.EXE
            C:\WINDOWS\System32\nvsvc32.exe
            C:\WINDOWS\system32\wdfmgr.exe
            C:\WINDOWS\System32\alg.exe
            C:\Program Files\ewido anti-malware\ewidoguard.exe
            C:\Program Files\ewido anti-malware\ewidoctrl.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\RunDll32.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
            C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\WINDOWS\system32\NOTEPAD.EXE
            C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O1 - Hosts: 222.111.150.111 gwgt1.joymax.com
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
            O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
            O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
            O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
            O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
            O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
            O8 - Extra context menu item: Télécharger le site web avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
            O8 - Extra context menu item: Télécharger sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
            O8 - Extra context menu item: Télécharger tout avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
            O16 - DPF: {5DDCC37F-7C6B-48B8-9664-97C537920CA0} (aecviz Class) - http://www.maisonfamiliale.com/AECVIZ/npaecviz.cab
            O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
            O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/fr/check/qdiagh.cab?326
            O17 - HKLM\System\CCS\Services\Tcpip\..\{5ACE17C7-9295-4026-BFC9-E0AC225A6FC2}: NameServer = 85.255.116.170,85.255.112.213
            O17 - HKLM\System\CCS\Services\Tcpip\..\{CDC1CBF7-B191-448C-934B-AC41C611BF49}: NameServer = 85.255.116.170,85.255.112.213
            O17 - HKLM\System\CS1\Services\Tcpip\..\{5ACE17C7-9295-4026-BFC9-E0AC225A6FC2}: NameServer = 85.255.116.170,85.255.112.213
            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
            O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
            O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
            O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
            O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

            Bon courage a toi aussi pour trouver ce qui vas pas.
            0
            1. Contributeur
              hello
              =====

              p:r rapport à Ewido, tu fais ceci pour solutionner l' erreur

              7/ - * Erreur de nettoyage dans ewido

              Si vous rencontrez ce genre de probleme avec ewido:

              [2660] VM_00890000 -> Downloader.Agent.uj : Erreur durant le nettoyage
              [2728] VM_00BA0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
              [2984] VM_009A0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
              [3048] VM_00950000 -> Downloader.Agent.uj : Erreur durant le nettoyage

              Télécharger ceci :
              http://downloads.subratam.org/Fixwareout.exe
              Installer le et suivre la procédure,
              puis refaire un scan avec ewido en mode sans échec ; et de nouveau en mode normal.

              ===============

              p/r au rapport de bitdefender

              8/ - * System volume information

              Si à la suite d'analyse, l'infection se situe dans :

              C:\system volume information\_Restore....

              Cela signifie que c'est un point de restauration qui est infecté (à savoir que l'infection est inactive). Pour résoudre le souci :

              ¤Désactive la restauration système (uniquement si tu es sous XP):
              Cliquer droit sur poste de travail puis,
              propriété, tu cliques sur onglet restauration système
              Cocher la case « désactiver la restauration » et applique.

              Puis,

              ¤Réactiver la restauration système (uniquement si tu es sous XP):
              Cliquer droit sur poste de travail puis,
              propriété, tu cliques sur onglet restauration système
              Décocher la case « désactiver la restauration » et applique.

              ================

              p:r au rapport Hijack
              je présume que ton FAI n est en Biélorussie ?
              http://www.dnsstuff.com/tools/whois.ch?ip=85.255.116.170
              non ?
              alors tu fixes les lignes suivantes :

              O17 - HKLM\System\CCS\Services\Tcpip\..\{5ACE17C7-9295-4026-BFC9-E0AC225A6FC2}: NameServer = 85.255.116.170,85.255.112.213
              O17 - HKLM\System\CCS\Services\Tcpip\..\{CDC1CBF7-B191-448C-934B-AC41C611BF49}: NameServer = 85.255.116.170,85.255.112.213
              O17 - HKLM\System\CS1\Services\Tcpip\..\{5ACE17C7-9295-4026-BFC9-E0AC225A6FC2}: NameServer = 85.255.116.170,85.255.112.213

              tu coches aussi ceci

              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
              O16 - DPF: {5DDCC37F-7C6B-48B8-9664-97C537920CA0} (aecviz Class) - http://www.maisonfamiliale.com/AECVIZ/npaecviz.cab
              O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
              O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/fr/check/qdiagh.cab?326

              ==========

              je vais déplacer ton log par commodité de lecture

              0
              1. Contributeur
                re

                Voici mon Hijackthis:
                Logfile of HijackThis v1.99.1
                Scan saved at 13:51:22, on 11/04/2006
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                C:\WINDOWS\System32\nvsvc32.exe
                C:\WINDOWS\system32\wdfmgr.exe
                C:\WINDOWS\System32\alg.exe
                C:\Program Files\ewido anti-malware\ewidoguard.exe
                C:\Program Files\ewido anti-malware\ewidoctrl.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\RunDll32.exe
                C:\Program Files\QuickTime\qttask.exe
                C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\WINDOWS\system32\NOTEPAD.EXE
                C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

                O1 - Hosts: 222.111.150.111 gwgt1.joymax.com

                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

                O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
                O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
                O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
                O8 - Extra context menu item: Télécharger le site web avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
                O8 - Extra context menu item: Télécharger sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
                O8 - Extra context menu item: Télécharger tout avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm

                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

                O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
                O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                0
                1. Contributeur
                  re

                  fixe cette méchante ligne :

                  O1 - Hosts: 222.111.150.111 gwgt1.joymax.com

                  + ceci pour le plaisir

                  O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

                  O4 - HKLM\..\Run: [O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

                  O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

                  O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe

                  O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

                  O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"

                  O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

                  ==============
                  précise tes blems à présent
                  0
                  1. J'ai fais tous ce que tu m'as dit et pour le moment on dirais bien que mon probleme est résolu,je ne suis plus envoyé vers des sites bidons quand j'utilise google.
                    Je mets mon nouveau HijackThis pour que tu puisse voir si tous est en regle.

                    Logfile of HijackThis v1.99.1
                    Scan saved at 14:32:08, on 13/04/2006
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                    C:\Program Files\ewido anti-malware\ewidoctrl.exe
                    C:\Program Files\ewido anti-malware\ewidoguard.exe
                    C:\WINDOWS\System32\nvsvc32.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                    O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                    O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
                    O8 - Extra context menu item: Télécharger le site web avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
                    O8 - Extra context menu item: Télécharger sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
                    O8 - Extra context menu item: Télécharger tout avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
                    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                    O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                    0
                    1. Contributeur
                      hello

                      RAS ds ce log

                      tu peux fixer cette ligne inutile au run :

                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      ======
                      tu as kasper comme antivirus
                      mais quoi comme pare-feu ??
                      0
                      1. Mon pare-feu c'est celui intégré dans windows xp.
                        0
                        1. Salut,

                          le pare-feu de Windows ne vaut pas grand chose remplace le par celui-ci il est grauit et bien plus performant ;-)

                          Kerio:
                          Pare-feu Kerio
                          -tutoriel: pour configurer et comprendre Kerio
                          https://kerio.probb.fr/
                          0