Cheval de troie clicker.fr

Bonjour à vous les pros de l'informatique.
j'essaie d'aider mon papa à se débarasser d'un virus.
Il y a 2 jours, il avait un Trojan horse que j'ai détruit manuellement en suivant l'adresse de sa position (windows system 32). pour nous, il n'y avait plus rien sauf qu'il a du infecter certains fichiers étant donné que nous n'avions plus l'écran de fond.
je pensais aujourd'hui faire une remise à jour de la version xp mais entre temps, un cheval de troie clicker .fr est trouvé quand on lance le adaware. par ontre, avg antivirus ne trouve rien.
au niveau de l'accès, c'est bizarre car l'adresse est en systeme volume information (je n'ai plus l'exact intitulé sorry, tout mis en quanrantaine pour destruction).
pourriez vous me dire si c'est toujours infecté si possible ce soir pour aider mon papa qui adore bidouiller mais déteste ces virus pas beaux
merci d'avance à tous ;)
Configuration: windows xp

30 réponses

Résumé de la discussion

Un utilisateur rencontre une infection sous Windows XP liée à un cheval de Troie détecté par Ad-Aware et d'autres outils, avec des symptômes comme l'absence de fond d'écran et des éléments suspects dans System32. Des réponses de la communauté évoquent des rapports et outils comme SmitFraudFix et HijackThis, et recommandent d'exécuter Silent Runners pour cibler les démarrages et clés à nettoyer. En parallèle, les éléments des rapports révèlent de nombreuses entrées Run et des composants de sécurité variables; une démarche progressive associant outils dédiés et nettoyage manuel est préconisée pour éviter les rechutes.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Salut pat,

    1-Télécharge ceci: (merci a S!RI pour ce programme).
    http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1, il va générer un rapport
    Copie/colle le sur le poste stp.

    2-systeme volume information (je n'ai plus l'exact intitulé sorry, tout mis en quanrantaine pour destruction).

    Ceci est un point de restauration infecté. Si tu as des alertes provenant de la, signale le nous.

    3-télécharge HijackThis ici:
    https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/29061.html

    Dézippe le dans un dossier prévu à cet effet.
    Par exemple C:\hijackthis < Enregistre le bien dans c : !
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/Hijenr.gif

    Lance le puis:
    clique sur "do a system scan and save logfile" (cf démo)
    faire un copier coller du log entier sur le forum

    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/demohijack.htm

    Bon courage

    A+
    0
    1. Encore un régis pour m'aider! j'adoore les régis...(j'en ai un au bureau qui m'aide souvent)
      alors voilà le rapport n°1 demandé:

      SmitFraudFix v2.70

      Rapport fait à 20:46:19,37, 15/07/2006
      Executé à partir de C:\Program Files\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Utilisateur\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\UTILIS~1\Favoris

      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="C:\\WINDOWS\\desktop.html"
      "SubscribedURL"="C:\\WINDOWS\\desktop.html"
      "FriendlyName"="Security"

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin

      Et voici le log :
      Logfile of HijackThis v1.99.1
      Scan saved at 21:01:26, on 15/07/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
      C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
      C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wdfmgr.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\Program Files\Canon\MultiPASS4\MPTBox.exe
      C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\a-squared Anti-Malware\a2guard.exe
      C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\3M\PSNLite\PsnLite.exe
      C:\PROGRA~1\3M\PSNLite\PSNGive.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\a-squared Anti-Malware\a2scan.exe
      C:\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://toolbar.google.com/intl/fr/done.html
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: (no name) - {7BC19787-4D2C-38E9-4247-5F663BA6DA30} - trycrt.dll (file missing)
      O1 - Hosts: localhost 127.0.0.1
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
      O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
      O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
      O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [monitr32] C:\Program Files\Canon\MultiPASS4\monitr32.exe
      O4 - HKLM\..\Run: [MPTBox] C:\Program Files\Canon\MultiPASS4\MPTBox.exe
      O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
      O4 - HKLM\..\Run: [hgqhp.exe] C:\WINDOWS\system32\hgqhp.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [Kargo] StartCpl.exe
      O4 - HKLM\..\Run: [ActionScr] Brong32.exe
      O4 - HKLM\..\Run: [utbmi.exe] C:\WINDOWS\system32\utbmi.exe
      O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
      O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
      O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
      O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"
      O4 - HKCU\..\Run: [control64] InpriseMon.exe
      O4 - HKCU\..\Run: [utsgmon] AliceSD.exe
      O4 - HKCU\..\Run: [runload32] MNTP.exe
      O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
      O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
      O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
      O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
      O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
      O17 - HKLM\System\CCS\Services\Tcpip\..\{11725286-D2F5-4F41-888F-20AE507DA2DA}: NameServer = 85.255.115.26,85.255.112.110
      O17 - HKLM\System\CCS\Services\Tcpip\..\{417B99C6-7CBA-47A0-98BE-373C8FAE261B}: NameServer = 85.255.115.26,85.255.112.110
      O17 - HKLM\System\CCS\Services\Tcpip\..\{817AE6AC-733A-4B21-903B-143302F737F8}: NameServer = 85.255.115.26,85.255.112.110
      O17 - HKLM\System\CCS\Services\Tcpip\..\{D911B995-ED24-4671-8E78-BB0338F9C5E7}: NameServer = 85.255.115.26 85.255.112.110
      O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.26 85.255.112.110
      O17 - HKLM\System\CS1\Services\Tcpip\..\{11725286-D2F5-4F41-888F-20AE507DA2DA}: NameServer = 85.255.115.26,85.255.112.110
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.26 85.255.112.110
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
      O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
      O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
      O23 - Service: MpService - Canon Inc - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

      Merci règ pour ton aide
      dans l'attente...
      0
      1. Contributeur sécurité
        Salut lol

        Oui mais ce n est pas mon prénom, appelle moi Quentin ! ;-)

        Tu es tres infecté, tu as chopé l infection du moment !!

        1-Télécharge Blacklight (de F-Secure) a l’une des 2 adresses :
        https://www.f-secure.com/en
        https://www.f-secure.com/en

        et sauvegarde le sur ton Bureau.

        Double-clique blbeta.exe et accepte la licence ; laisse [X]scan through Windows Explorer activé ; clique Scan puis Next

        Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).

        Copie et colle le contenu de ce rapport dans ta prochaine réponse

        2- Tu peux supprimer smitfraudfix de ton ordinateur.

        A+
        0
        1. Salut quentin, je vois que tu travailles tard pour sauver les pôvres âmes perdues en informatique!...

          Voilà le contenu du rapport:
          07/16/06 15:01:43 [Info]: BlackLight Engine 1.0.42 initialized
          07/16/06 15:01:43 [Info]: OS: 5.1 build 2600 (Service Pack 2)
          07/16/06 15:01:43 [Note]: 7019 4
          07/16/06 15:01:43 [Note]: 7005 0
          07/16/06 15:01:54 [Note]: 7006 0
          07/16/06 15:01:54 [Note]: 7011 860
          07/16/06 15:01:54 [Note]: 7026 0
          07/16/06 15:01:54 [Note]: 7026 0
          07/16/06 15:01:58 [Note]: FSRAW library version 1.7.1019
          07/16/06 15:03:15 [Note]: 7007 0

          Désolée pour ma réponse tardive en espérant que tu travailles en ce chaud jour dominical entre 2 plongeons dans la piscine ...
          sinon, mon papa continuera tout seul, il ne parle pas anglais mais il est vrai que tes explications sont très claires ...
          merci et à + ;)
          0
          1. Contributeur sécurité
            Salut Pat,

            Surtout, si vous avez la moindre question ou autre, demander moi, y a aucuns soucis !!
            Ce n'est pas tellement un travail lol mais une passion d aider dans ce domaine.
            Arf, dans le nord pour trouver une piscine, faut bien chercher lol
            J'aurais besoin d'un dernier rapport avant que je te donne une marche a suivre:

            Telecharge ceci
            https://www.silentrunners.org/Silent%20Runners.vbs
            Execute le,atends quelques minutes, il va creer ensuite un dossier juste a coté de silent runner sous format texte, copie/colle ce qu il te donnera

            Pas de soucis, je vais continuer avec ton papa, du moment qu il sait taper au clavier, ecrire un message sur le forum, apres on s en sortiera sans problemes ;-)

            A bientot
            A+
            0
            1. Salut,
              suis encore là mais mon papa se débrouille bien et pourra continuer si tu ne trouves pas la solution today

              voilà le rapport:
              "Silent Runners.vbs", revision 46, https://www.silentrunners.org/
              Operating System: Windows XP SP2
              Output limited to non-default values, except where indicated by "{++}"

              Startup items buried in registry:
              ---------------------------------

              HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
              "ccleaner" = ""C:\Program Files\CCleaner\ccleaner.exe" /AUTO" ["CCleaner.com"]
              "WOOKIT" = "C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe" [file not found]
              "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
              "KillAndClean" = ""C:\Program Files\KillAndClean\KillAndClean.exe"" [file not found]
              "control64" = "InpriseMon.exe" [file not found]
              "utsgmon" = "AliceSD.exe" [file not found]
              "runload32" = "MNTP.exe" [file not found]

              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
              "SoundMAXPnP" = "C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" ["Analog Devices, Inc."]
              "SoundMAX" = ""C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray" ["Analog Devices, Inc."]
              "Ptipbmf" = "rundll32.exe ptipbmf.dll,SetWriteCacheMode" [MS]
              "PE2CKFNT SE" = "C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [null data]
              "RemoteControl" = ""C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"" ["Cyberlink Corp."]
              "NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
              "monitr32" = "C:\Program Files\Canon\MultiPASS4\monitr32.exe" ["Canon Inc"]
              "MPTBox" = "C:\Program Files\Canon\MultiPASS4\MPTBox.exe" ["Canon Inc"]
              "CnxDslTaskBar" = ""C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"" ["Conexant Systems, Inc."]
              "hgqhp.exe" = "C:\WINDOWS\system32\hgqhp.exe" [file not found]
              "HP Software Update" = "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Co."]
              "Kargo" = "StartCpl.exe" [file not found]
              "ActionScr" = "Brong32.exe" [file not found]
              "utbmi.exe" = "C:\WINDOWS\system32\utbmi.exe" [file not found]
              "a-squared" = ""C:\Program Files\a-squared Anti-Malware\a2guard.exe"" ["Emsi Software GmbH"]
              "TrojanScanner" = "C:\Program Files\Trojan Remover\Trjscan.exe" ["Simply Super Software"]
              "AVG7_CC" = "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]

              HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
              {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
              -> {HKLM...CLSID} = "AcroIEHlprObj Class"
              \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
              {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
              -> {HKLM...CLSID} = (no title provided)
              \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
              {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
              -> {HKLM...CLSID} = "Google Toolbar Helper"
              \InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]

              HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
              "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
              -> {HKLM...CLSID} = "Extension Affichage Panorama du Panneau de configuration"
              \InProcServer32\(Default) = "deskpan.dll" [file not found]
              "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
              -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
              \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
              "{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
              -> {HKLM...CLSID} = "Microsoft Office Outlook"
              \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL" [MS]
              "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
              -> {HKLM...CLSID} = "Outlook File Icon Extension"
              \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL" [MS]
              "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
              -> {HKLM...CLSID} = (no title provided)
              \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS]
              "{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
              -> {HKLM...CLSID} = "Portable Media Devices"
              \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
              "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
              -> {HKLM...CLSID} = "Portable Media Devices Menu"
              \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
              "{4B4604E0-8961-11D4-A0EC-009099164712}" = "Mon MultiPASS"
              -> {HKLM...CLSID} = "Mon MultiPASS"
              \InProcServer32\(Default) = "C:\Program Files\Canon\MultiPASS4\DTM4.DLL" ["Canon Inc"]
              "{AB77609F-2178-4E6F-9C4B-44AC179D937A}" = "a-squared Context Menu Shell Extension"
              -> {HKLM...CLSID} = "a-squared context menu"
              \InProcServer32\(Default) = "C:\PROGRA~1\A-SQUA~1\A2CONT~1.DLL" ["Emsi Software GmbH"]
              "{52B87208-9CCF-42C9-B88E-069281105805}" = "Trojan Remover Shell Extension"
              -> {HKLM...CLSID} = "Trojan Remover Shell Extension"
              \InProcServer32\(Default) = "C:\PROGRA~1\TROJAN~1\Trshlex.dll" ["Simply Super Software"]
              "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
              -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
              \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."]
              "{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
              -> {HKLM...CLSID} = "AVG7 Find Extension Class"
              \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."]

              HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
              INFECTION WARNING! "System" = "csrkz.exe" [file not found]

              HKLM\Software\Classes\PROTOCOLS\Filter\
              INFECTION WARNING! text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
              -> {HKLM...CLSID} = (no title provided)
              \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]

              Merci encore pour ton aide
              a tout'
              patricia
              0
              1. Contributeur sécurité
                Bonjour,

                Méthode à suivre dans l'ordre...

                Dans ajout/suppression de programme desinstalles ceci:

                kill and clean
                ----------------------------------------------------------------------------
                ¤Télécharge ces logiciels mais que tu n‘utilises pas tout de suite:

                1/

                Spybot S&D 1.4
                https://www.safer-networking.org/

                Démo d’utilisation (merci à Balltrap34 pour cette réalisation).
                http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

                2/

                Ad-Aware SE 1.06
                https://www.adaware.com/
                -Une aide:
                http://usa.lucretius-ada.com/zcvisitor/8782d344-4821-11ea-83ce-0a2cdf2c6be7?campaignid=0d1dff40-82d7-11e9-9533-0a157bfa6bfc
                - installe le patch français, tu pourras le trouver ici:
                http://download.lavasoft.de.edgesuite.net/public/pllangs.exe
                et une petite vidéo d'utilisation ici:(merci à Moe31 pour cette réalisation).
                http://pageperso.aol.fr/balltrap34/adawrevid.asf

                3/ Ewido:

                http://perso.orange.fr/entraide-hijackthis/Ewido/

                Installation puis mises à jour.

                4/ Ccleaner :

                https://www.pcastuces.com/logitheque/ccleaner.htm

                5/Télécharge le FixWareout d'un de ces deux sites sur le bureau:
                http://downloads.subratam.org/Fixwareout.exe
                http://swandog46.geekstogo.com/Fixwareout.exe

                ----------------------------------------------------------------------------
                ¤Affiche tous les fichiers et dossiers :
                Clique sur démarrer/panneau de configuration/outil/option des dossiers/affichage

                Coche « afficher les fichiers et dossiers cachés »

                Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                Décoche « masquer les extensions dont le type est connu »
                Puis fais «Ok» pour valider les changements.

                Et appliquer !
                ----------------------------------------------------------------------------
                Lance le fix warout:

                clique sur Next, puis Install, puis assure toi que "Run fixit" est activé puis clique sur Finish.
                Le fix va commencer, suis les messages à l'écran. Il te sera demandé de redémarrer ton ordinateur, fais le. Ton système mettra un peu plus de temps au démarrage, c'est normal.

                Quand ton système aura redémarré, suis les invites des messages.

                Ensuite lance HijackThis. Clique sur Scan et coche les lignes suivantes:

                R3 - URLSearchHook: (no name) - {7BC19787-4D2C-38E9-4247-5F663BA6DA30} - trycrt.dll (file missing)

                O1 - Hosts: localhost 127.0.0.1

                O4 - HKLM\..\Run: [hgqhp.exe] C:\WINDOWS\system32\hgqhp.exe

                O4 - HKLM\..\Run: [Kargo] StartCpl.exe

                O4 - HKLM\..\Run: [Kargo] StartCpl.exe

                O4 - HKLM\..\Run: [ActionScr] Brong32.exe

                O4 - HKLM\..\Run: [utbmi.exe] C:\WINDOWS\system32\utbmi.exe

                O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"

                O4 - HKCU\..\Run: [control64] InpriseMon.exe

                O4 - HKCU\..\Run: [utsgmon] AliceSD.exe

                O4 - HKCU\..\Run: [runload32] MNTP.exe

                O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

                O17 - HKLM\System\CCS\Services\Tcpip\..\{11725286-D2F5-4F41-888F-20AE507DA2DA}: NameServer = 85.255.115.26,85.255.112.110

                O17 - HKLM\System\CCS\Services\Tcpip\..\{417B99C6-7CBA-47A0-98BE-373C8FAE261B}: NameServer = 85.255.115.26,85.255.112.110

                O17 - HKLM\System\CCS\Services\Tcpip\..\{817AE6AC-733A-4B21-903B-143302F737F8}: NameServer = 85.255.115.26,85.255.112.110

                O17 - HKLM\System\CCS\Services\Tcpip\..\{D911B995-ED24-4671-8E78-BB0338F9C5E7}: NameServer = 85.255.115.26 85.255.112.110

                O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.26 85.255.112.110

                O17 - HKLM\System\CS1\Services\Tcpip\..\{11725286-D2F5-4F41-888F-20AE507DA2DA}: NameServer = 85.255.115.26,85.255.112.110

                O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.26 85.255.112.110

                Clique sur Fix Checked. Ferme HijackThis et clique sur OK pour continuer la procédure.

                A la fin du fix, tu auras peut-être encore besoin de redémarrer le PC.

                ----------------------------------------------------------------------------
                ¤Démarre en mode sans échec :
                Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                (Si F8 ne marche pas utilise la touche F5).
                ----------------------------------------------------------------------------
                ¤Recherche et supprime ceci:
                attention seulement les fichiers (si présents).

                C:\WINDOWS\system32\hgqhp.exe
                C:\WINDOWS\system32\utbmi.exe
                C:\Program Files\KillAndClean
                csrkz.exe (surrement dans systeme32)

                ----------------------------------------------------------------------------
                ¤ Lancer et exécuter Ewido pour un scan complet et copier/coller le rapport en forum.
                ----------------------------------------------------------------------------
                ¤ Passe Ad-Aware et supprime tout ce qu’il trouve + supprime les quarantaines…
                ----------------------------------------------------------------------------
                ¤ Passe Spybot et corrige tout ce qu’il trouve + vaccine + supprime les quarantaines…
                -------------------------------------------------------------------------------------------
                ¤ Lance CCleaner.

                Suppression des fichiers temporaires

                Va dans la section "Options" situé dans la marge gauche. Va dans "Avancé" et décoche "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Retourne ensuite dans la section "Nettoyeur"
                Fais bien attention de cocher toutes les cases dans la marge gauche (Internet Explorer/Windows Explorer/Système/Avancé)
                • Clique sur Analyse
                • Patiente le temps du scan, qui peut prendre un peu de temps si c'est la première fois.
                • Une fois le scan terminé, clique sur Lancer le Nettoyage

                Suppression des incohérence du registre

                • Clique sur l'icône Erreurs situés dans la marge à gauche.
                • Puis clique sur Analyser les erreurs
                • Patiente pendant que CCleaner scan ton registre.
                • Une fois le scan terminé, coche toutes les entrèes qu'il t'aura trouvée.
                • Tu peux cliquer ensuite sur Corriger les erreurs.
                Si tu n'est pas sur de ce que tu fais, tu peux choisir de sauvegarder les entrées cochées pour les restaurer ultérieurement
                ----------------------------------------------------------------------------
                ¤ Vide ta Corbeille.
                ----------------------------------------------------------------------------
                ¤ Redémarre en mode normal, relance Hijackthis et copie/colle un nouveau rapport sur le forum.

                Précise tes soucis s’il en reste....

                Tiens-moi au courant

                A+
                0
                1. A y est! enfin tout fini, ça a été un peu laborieux...
                  pour commencer, j'ai recoché les options que tu m'avais demandé de décocher
                  ensuite, voici le rapport ewido:
                  ---------------------------------------------------------
                  ewido anti-spyware - Scan Report
                  ---------------------------------------------------------

                  + Created at: 20:02:34 16/07/2006

                  + Scan result:

                  C:\WINDOWS\system32\csrgs.exe -> Downloader.Agent.uj : No action taken.
                  C:\Documents and Settings\Utilisateur\Cookies\utilisateur@247realmedia[2].txt -> TrackingCookie.247realmedia : No action taken.
                  C:\Documents and Settings\Utilisateur\Cookies\utilisateur@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
                  C:\Documents and Settings\Utilisateur\Cookies\utilisateur@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
                  C:\Documents and Settings\Utilisateur\Cookies\utilisateur@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
                  C:\Documents and Settings\Utilisateur\Cookies\utilisateur@com[1].txt -> TrackingCookie.Com : No action taken.
                  C:\Documents and Settings\Utilisateur\Cookies\utilisateur@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
                  C:\Documents and Settings\Utilisateur\Cookies\utilisateur@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
                  C:\Documents and Settings\Utilisateur\Cookies\utilisateur@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.
                  C:\WINDOWS\system32\ebzib.exe -> Trojan.DNSChanger.ef : No action taken.
                  C:\WINDOWS\system32\gwrml.ex$ -> Trojan.DNSChanger.ef : No action taken.
                  C:\WINDOWS\system32\dmaqe.exe -> Trojan.Pakes : No action taken.
                  C:\WINDOWS\system32\dmoqu.exe -> Trojan.Pakes : No action taken.
                  C:\WINDOWS\system32\dmzra.ex$ -> Trojan.Pakes : No action taken.

                  ::Report end

                  A signaler, je ne sais pas si c'est important mais lors du 1er Hijackthis, il manquait certaines lignes que tu m'as demandé de cocher:

                  O1 - Hosts: localhost 127.0.0.1
                  O4 - HKLM\..\Run: [hgqhp.exe] C:\WINDOWS\system32\hgqhp.exe
                  celle ci n'apparaissait pas en double (comme inidqué à moins que ce ne soit une erreur...ce qui m'étonnerait): O4 - HKLM\..\Run: [Kargo] StartCpl.exe
                  manquaient aussi:
                  O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{D911B995-ED24-4671-8E78-BB0338F9C5E7}: NameServer = 85.255.115.26 85.255.112.110

                  Puis lors du redémarrage en mode sans échec, je n'ai trouvé aucun des fichiers cités (peut être normal vu que je n'avais pas les lignes plus haut)

                  petit souci avec ccleaner qui ne se lançait pas, j'ai du redémarrer en normal, le télécharger à nouveau puis revenir en mode sans échec et là il s'est lancé

                  voici maintenant le rapport final hijackthis
                  Logfile of HijackThis v1.99.1
                  Scan saved at 20:56:41, on 16/07/2006
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\csrss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                  C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                  C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
                  C:\Program Files\ewido anti-spyware 4.0\guard.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                  C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
                  C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\wdfmgr.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\System32\alg.exe
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                  C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                  C:\Program Files\Canon\MultiPASS4\MPTBox.exe
                  C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
                  C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  C:\Program Files\a-squared Anti-Malware\a2guard.exe
                  C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                  C:\Program Files\ewido anti-spyware 4.0\ewido.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\3M\PSNLite\PsnLite.exe
                  C:\PROGRA~1\3M\PSNLite\PSNGive.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://toolbar.google.com/intl/fr/done.html
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                  O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                  O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
                  O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
                  O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [monitr32] C:\Program Files\Canon\MultiPASS4\monitr32.exe
                  O4 - HKLM\..\Run: [MPTBox] C:\Program Files\Canon\MultiPASS4\MPTBox.exe
                  O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
                  O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                  O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
                  O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
                  O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                  O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                  O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                  O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                  O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
                  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                  O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                  O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                  O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
                  O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
                  O23 - Service: MpService - Canon Inc - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
                  O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

                  Pour finir, je ne sais pas si tous les virus sont partis. L'écran de fond n'est par contre toujours pas affiché et il me semble que certains paramétrages ont sauté (notamment, la barre d'accès internet + bureau + autres icônes en bas à gauche du bureau, à côté de démarrer). La page de démarrage sur internet a suaté aussi, je vais la restaurer ...

                  A suivre pour le reste, merci encore pour ton aide précieuse et ton retour (au moins de base genre si situation catastrophique ou non) si possible ce soir, je suis encore là un peu de temps pour aider mon pôpa
                  merci et à bientôt
                  patricia
                  0
                  1. j'ai oublié de te préciser: j'ai restauré page de démarrage + affichage des icônes, par contre internet est à présent très long + barre de tâche s'est rajoutée et reviens à chaque reconnexion malgré l'intervention dans l'option affichage (ça ne tient pas)
                    bouh! ouh! ouh!
                    à bientôt peut être si tu dois voler à mon secours une autre fois où je rejoindrais ce forum, c'est très sympa comme échange.
                    Je passe la main à mon papa
                    merci et bonne nuit si je n'ai pas de tes nouvelles ce soir
                    0
                    1. Contributeur sécurité
                      Salut

                      Il faut absolument que tu lances ewido, et pendant le scan il faut que tu choissises l option supprimer.
                      La y a des infections, et tu as choisis de ne rien faire, elles sont toujours presente, alors lance un scan et supprime tout ce qu il trouve.

                      a+
                      0
                      1. ça y est ewido lancé
                        te faudra t il à nouveau le rapport + log hijackthis?
                        0
                        1. Contributeur sécurité
                          Si possible ca serait bien oui ;-)

                          Bon courage Patricia :-)
                          0
                          1. voilà le rapport:
                            ---------------------------------------------------------
                            ewido anti-spyware - Scan Report
                            ---------------------------------------------------------

                            + Created at: 22:21:12 16/07/2006

                            + Scan result:

                            C:\WINDOWS\system32\csrgs.exe -> Downloader.Agent.uj : Cleaned.
                            C:\Documents and Settings\Utilisateur\Cookies\utilisateur@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
                            C:\Documents and Settings\Utilisateur\Cookies\utilisateur@carlson.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
                            C:\Documents and Settings\Utilisateur\Cookies\utilisateur@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
                            C:\Documents and Settings\Utilisateur\Cookies\utilisateur@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
                            C:\Documents and Settings\Utilisateur\Cookies\utilisateur@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Cleaned.
                            C:\Documents and Settings\Utilisateur\Cookies\utilisateur@weborama[1].txt -> TrackingCookie.Weborama : Cleaned.
                            C:\WINDOWS\system32\ebzib.exe -> Trojan.DNSChanger.ef : Cleaned.
                            C:\WINDOWS\system32\gwrml.ex$ -> Trojan.DNSChanger.ef : Cleaned.
                            C:\WINDOWS\system32\dmaqe.exe -> Trojan.Pakes : Cleaned.
                            C:\WINDOWS\system32\dmoqu.exe -> Trojan.Pakes : Cleaned.
                            C:\WINDOWS\system32\dmzra.ex$ -> Trojan.Pakes : Cleaned.

                            ::Report end

                            et le log hijackthis:
                            Logfile of HijackThis v1.99.1
                            Scan saved at 22:24:26, on 16/07/2006
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\csrss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                            C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                            C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
                            C:\Program Files\ewido anti-spyware 4.0\guard.exe
                            C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                            C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
                            C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\wdfmgr.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\System32\alg.exe
                            C:\WINDOWS\system32\wscntfy.exe
                            C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                            C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                            C:\Program Files\Canon\MultiPASS4\MPTBox.exe
                            C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
                            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                            C:\Program Files\a-squared Anti-Malware\a2guard.exe
                            C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                            C:\Program Files\3M\PSNLite\PsnLite.exe
                            C:\PROGRA~1\3M\PSNLite\PSNGive.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
                            C:\Program Files\a-squared Anti-Malware\a2scan.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\ewido anti-spyware 4.0\ewido.exe
                            C:\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://toolbar.google.com/intl/fr/done.html
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                            O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                            O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                            O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
                            O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
                            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                            O4 - HKLM\..\Run: [monitr32] C:\Program Files\Canon\MultiPASS4\monitr32.exe
                            O4 - HKLM\..\Run: [MPTBox] C:\Program Files\Canon\MultiPASS4\MPTBox.exe
                            O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
                            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                            O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
                            O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                            O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
                            O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                            O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
                            O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                            O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                            O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                            O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                            O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
                            O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
                            O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
                            O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
                            O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
                            O17 - HKLM\System\CCS\Services\Tcpip\..\{D911B995-ED24-4671-8E78-BB0338F9C5E7}: NameServer = 85.255.115.26 85.255.112.110
                            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                            O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                            O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                            O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe
                            O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
                            O23 - Service: MpService - Canon Inc - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
                            O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

                            merci encore, pour ma part, je vais au dodo (me suis couchée un peu tard hier soir)
                            bonne nuit et à +
                            patdebod ;)
                            0
                            1. Contributeur sécurité
                              Salut Pat,

                              Bonne nuit !
                              Ca semble pas mal tout ca, tu peux me dire quels soucis tu as encore?
                              Si non, tu as des questions? :-)

                              A+
                              (bonne nuit a toi Patricia et a ton papa)
                              0
                              1. j'chuis encore là!!!!
                                et ben si tout va bien d'après toi c'est merveilleux
                                par contre, quand on est sur le bureau on dirait que ça clignote (comme si ça travaillait derrière), mais peut être faut il recharger...
                                et de plus, on n'arrive pas à fixer l'image de fond pour le bureau (et là j'vois pas car tout est ok côté affichage)
                                petite aide encore tout de suite?
                                Merci sinon et à + ;)
                                0
                                1. Contributeur sécurité
                                  Salut

                                  Redemarre ton pc et remet moi un rapport de silent runner (tu te souviens?)

                                  Si tu le fais pas ce soir, c est pas grave :-)

                                  A bientot
                                  0
                                  1. et voilà le rapport silent runner:

                                    "Silent Runners.vbs", revision 46, https://www.silentrunners.org/
                                    Operating System: Windows XP SP2
                                    Output limited to non-default values, except where indicated by "{++}"

                                    Startup items buried in registry:
                                    ---------------------------------

                                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                                    "ccleaner" = ""C:\Program Files\CCleaner\ccleaner.exe" /AUTO" ["Piriform Ltd"]
                                    "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]

                                    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                                    "SoundMAXPnP" = "C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" ["Analog Devices, Inc."]
                                    "SoundMAX" = ""C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray" ["Analog Devices, Inc."]
                                    "Ptipbmf" = "rundll32.exe ptipbmf.dll,SetWriteCacheMode" [MS]
                                    "PE2CKFNT SE" = "C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [null data]
                                    "RemoteControl" = ""C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"" ["Cyberlink Corp."]
                                    "NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
                                    "monitr32" = "C:\Program Files\Canon\MultiPASS4\monitr32.exe" ["Canon Inc"]
                                    "MPTBox" = "C:\Program Files\Canon\MultiPASS4\MPTBox.exe" ["Canon Inc"]
                                    "CnxDslTaskBar" = ""C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"" ["Conexant Systems, Inc."]
                                    "HP Software Update" = "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Co."]
                                    "a-squared" = ""C:\Program Files\a-squared Anti-Malware\a2guard.exe"" ["Emsi Software GmbH"]
                                    "AVG7_CC" = "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]
                                    "!ewido" = ""C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized" ["Anti-Malware Development a.s."]

                                    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
                                    {02478D38-C3F9-4EFB-9B51-7695ECA05670}\(Default) = (no title provided)
                                    -> {HKLM...CLSID} = "Yahoo! Toolbar Helper"
                                    \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]
                                    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
                                    -> {HKLM...CLSID} = "AcroIEHlprObj Class"
                                    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
                                    {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
                                    -> {HKLM...CLSID} = (no title provided)
                                    \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
                                    {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
                                    -> {HKLM...CLSID} = "Google Toolbar Helper"
                                    \InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]

                                    HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
                                    "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
                                    -> {HKLM...CLSID} = "Extension Affichage Panorama du Panneau de configuration"
                                    \InProcServer32\(Default) = "deskpan.dll" [file not found]

                                    merci :)
                                    0
                                    1. Contributeur sécurité
                                      Il n est pas entier, peux tu attendre qqs minutes avant de prendre le rapport,

                                      merci

                                      Et douce nuit, j y regarderais certainement demain !

                                      Biz et poignée de main a papa lol
                                      0
                                      1. Désolé pour le retard, c'est papa qui reprend la main, ça t'évitera de draguer ma fille...je plaisante
                                        Voici le rapport qui j'espère sera complet

                                        A+ :)
                                        "Silent Runners.vbs", revision 46, https://www.silentrunners.org/
                                        Operating System: Windows XP SP2
                                        Output limited to non-default values, except where indicated by "{++}"

                                        Startup items buried in registry:
                                        ---------------------------------

                                        HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                                        "ccleaner" = ""C:\Program Files\CCleaner\ccleaner.exe" /AUTO" ["Piriform Ltd"]
                                        "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]

                                        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                                        "SoundMAXPnP" = "C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" ["Analog Devices, Inc."]
                                        "SoundMAX" = ""C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray" ["Analog Devices, Inc."]
                                        "Ptipbmf" = "rundll32.exe ptipbmf.dll,SetWriteCacheMode" [MS]
                                        "PE2CKFNT SE" = "C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [null data]
                                        "RemoteControl" = ""C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"" ["Cyberlink Corp."]
                                        "NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
                                        "monitr32" = "C:\Program Files\Canon\MultiPASS4\monitr32.exe" ["Canon Inc"]
                                        "MPTBox" = "C:\Program Files\Canon\MultiPASS4\MPTBox.exe" ["Canon Inc"]
                                        "CnxDslTaskBar" = ""C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"" ["Conexant Systems, Inc."]
                                        "HP Software Update" = "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" ["Hewlett-Packard Co."]
                                        "a-squared" = ""C:\Program Files\a-squared Anti-Malware\a2guard.exe"" ["Emsi Software GmbH"]
                                        "AVG7_CC" = "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]
                                        "!ewido" = ""C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized" ["Anti-Malware Development a.s."]

                                        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
                                        {02478D38-C3F9-4EFB-9B51-7695ECA05670}\(Default) = (no title provided)
                                        -> {HKLM...CLSID} = "Yahoo! Toolbar Helper"
                                        \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]
                                        {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
                                        -> {HKLM...CLSID} = "AcroIEHlprObj Class"
                                        \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
                                        {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
                                        -> {HKLM...CLSID} = (no title provided)
                                        \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
                                        {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
                                        -> {HKLM...CLSID} = "Google Toolbar Helper"
                                        \InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]

                                        HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
                                        "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
                                        -> {HKLM...CLSID} = "Extension Affichage Panorama du Panneau de configuration"
                                        \InProcServer32\(Default) = "deskpan.dll" [file not found]
                                        "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
                                        -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
                                        \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
                                        "{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
                                        -> {HKLM...CLSID} = "Microsoft Office Outlook"
                                        \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL" [MS]
                                        "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
                                        -> {HKLM...CLSID} = "Outlook File Icon Extension"
                                        \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL" [MS]
                                        "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
                                        -> {HKLM...CLSID} = (no title provided)
                                        \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS]
                                        "{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
                                        -> {HKLM...CLSID} = "Portable Media Devices"
                                        \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
                                        "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
                                        -> {HKLM...CLSID} = "Portable Media Devices Menu"
                                        \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
                                        "{4B4604E0-8961-11D4-A0EC-009099164712}" = "Mon MultiPASS"
                                        -> {HKLM...CLSID} = "Mon MultiPASS"
                                        \InProcServer32\(Default) = "C:\Program Files\Canon\MultiPASS4\DTM4.DLL" ["Canon Inc"]
                                        "{AB77609F-2178-4E6F-9C4B-44AC179D937A}" = "a-squared Context Menu Shell Extension"
                                        -> {HKLM...CLSID} = "a-squared context menu"
                                        \InProcServer32\(Default) = "C:\PROGRA~1\A-SQUA~1\A2CONT~1.DLL" ["Emsi Software GmbH"]
                                        "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
                                        -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
                                        \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."]
                                        "{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
                                        -> {HKLM...CLSID} = "AVG7 Find Extension Class"
                                        \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."]

                                        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
                                        INFECTION WARNING! "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "ewido anti-spyware 4.0"
                                        -> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
                                        \InProcServer32\(Default) = "C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll" ["Anti-Malware Development a.s."]

                                        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
                                        "System" = (value not set)

                                        HKLM\Software\Classes\PROTOCOLS\Filter\
                                        INFECTION WARNING! text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
                                        -> {HKLM...CLSID} = (no title provided)
                                        \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]

                                        HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
                                        {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
                                        -> {HKLM...CLSID} = "PDF Shell Extension"
                                        \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]

                                        HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
                                        AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
                                        -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
                                        \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."]
                                        ewido anti-spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
                                        -> {HKLM...CLSID} = "CContextScan Object"
                                        \InProcServer32\(Default) = "C:\Program Files\ewido anti-spyware 4.0\context.dll" ["Anti-Malware Development a.s."]
                                        PowerArchiver\(Default) = "{d03d3e68-0c44-3d45-b15f-bcfd8a8b4c7e}"
                                        -> {HKLM...CLSID} = "PowerArchiver Shell Extensions"
                                        \InProcServer32\(Default) = "C:\Program Files\PowerArchiver\PASHLEXT.DLL" ["eFront Media, Inc."]

                                        HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
                                        ewido anti-spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
                                        -> {HKLM...CLSID} = "CContextScan Object"
                                        \InProcServer32\(Default) = "C:\Program Files\ewido anti-spyware 4.0\context.dll" ["Anti-Malware Development a.s."]

                                        HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
                                        a2ContMenu\(Default) = "{AB77609F-2178-4E6F-9C4B-44AC179D937A}"
                                        -> {HKLM...CLSID} = "a-squared context menu"
                                        \InProcServer32\(Default) = "C:\PROGRA~1\A-SQUA~1\A2CONT~1.DLL" ["Emsi Software GmbH"]
                                        AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
                                        -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
                                        \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."]
                                        PowerArchiver\(Default) = "{d03d3e68-0c44-3d45-b15f-bcfd8a8b4c7e}"
                                        -> {HKLM...CLSID} = "PowerArchiver Shell Extensions"
                                        \InProcServer32\(Default) = "C:\Program Files\PowerArchiver\PASHLEXT.DLL" ["eFront Media, Inc."]

                                        Active Desktop and Wallpaper:
                                        -----------------------------

                                        Active Desktop is enabled at this entry:
                                        HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

                                        HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
                                        "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

                                        Active Desktop web content:

                                        HKCU\Software\Microsoft\Internet Explorer\Desktop\Components\0\
                                        "FriendlyName" = "Security"
                                        "Source" = "C:\WINDOWS\desktop.html"
                                        "SubscribedURL" = "C:\WINDOWS\desktop.html"

                                        Enabled Screen Saver:
                                        ---------------------

                                        HKCU\Control Panel\Desktop\
                                        "SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]

                                        Startup items in "Utilisateur" & "All Users" startup folders:
                                        -------------------------------------------------------------

                                        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
                                        "Démarrage rapide du logiciel HP Image Zone" -> shortcut to: "C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe -s" [null data]
                                        "HP Digital Imaging Monitor" -> shortcut to: "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" ["Hewlett-Packard Co."]
                                        "Post-it® Software Notes Lite" -> shortcut to: "C:\Program Files\3M\PSNLite\PsnLite.exe -RegRun" ["3M"]

                                        Winsock2 Service Provider DLLs:
                                        -------------------------------

                                        Namespace Service Providers

                                        HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
                                        000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
                                        000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
                                        000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

                                        Transport Service Providers

                                        HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
                                        0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
                                        C:\WINDOWS\system32\avgfwafu.dll ["GRISOFT, s.r.o."], 01 - 05
                                        %SystemRoot%\system32\mswsock.dll [MS], 06 - 08, 11 - 24
                                        %SystemRoot%\system32\rsvpsp.dll [MS], 09 - 10

                                        Toolbars, Explorer Bars, Extensions:
                                        ------------------------------------

                                        Toolbars

                                        HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
                                        "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
                                        -> {HKLM...CLSID} = "&Google"
                                        \InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]

                                        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
                                        "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
                                        -> {HKLM...CLSID} = "&Google"
                                        \InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]
                                        "{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
                                        -> {HKLM...CLSID} = "Yahoo! Toolbar"
                                        \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]

                                        HKLM\Software\Microsoft\Internet Explorer\Toolbar\
                                        "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
                                        -> {HKLM...CLSID} = "&Google"
                                        \InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]
                                        "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
                                        -> {HKLM...CLSID} = "Yahoo! Toolbar"
                                        \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]

                                        Extensions (Tools menu items, main toolbar menu buttons)

                                        HKLM\Software\Microsoft\Internet Explorer\Extensions\
                                        {92780B25-18CC-41C8-B9BE-3C9C571A8263}\
                                        "ButtonText" = "Recherche"

                                        {FB5F1910-F110-11D2-BB9E-00C04F795683}\
                                        "ButtonText" = "Messenger"
                                        "MenuText" = "Windows Messenger"
                                        "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]

                                        Miscellaneous IE Hijack Points
                                        ------------------------------

                                        C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

                                        Added lines (compared with English-language version):
                                        [Strings]: SAFESITE_VALUE="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2ffr%2f%3f"

                                        Missing lines (compared with English-language version):
                                        [Strings]: 1 line

                                        Running Services (Display Name, Service Name, Path {Service DLL}):
                                        ------------------------------------------------------------------

                                        AVG Firewall, AVGFwSrv, "C:\PROGRA~1\Grisoft\AVG7\avgfwsrv.exe /srvfsys" ["GRISOFT, s.r.o."]
                                        AVG7 Alert Manager Server, Avg7Alrt, "C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe" ["GRISOFT, s.r.o."]
                                        AVG7 Update Service, Avg7UpdSvc, "C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe" ["GRISOFT, s.r.o."]
                                        ewido anti-spyware 4.0 guard, ewido anti-spyware 4.0 guard, "C:\Program Files\ewido anti-spyware 4.0\guard.exe" ["Anti-Malware Development a.s."]
                                        Machine Debug Manager, MDM, ""C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE"" [MS]
                                        MpService, MpService, "C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE" ["Canon Inc"]
                                        SoundMAX Agent Service, SoundMAX Agent Service (default), "C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe" ["Analog Devices, Inc."]
                                        Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]

                                        Print Monitors:
                                        ---------------

                                        HKLM\System\CurrentControlSet\Control\Print\Monitors\
                                        Contrôleur de langue Canon MP\Driver = "MPASSMON.DLL" ["Canon Inc"]
                                        CutePDF Writer Monitor\Driver = "cpwmon2k.dll" [null data]
                                        Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]
                                        Port USB Canon MultiPASS\Driver = "mpupmon.dll" [null data]

                                        ----------
                                        + This report excludes default entries except where indicated.
                                        + To see *everywhere* the script checks and *everything* it finds,
                                        launch it from a command prompt or a shortcut with the -all parameter.
                                        + To search all directories of local fixed drives for DESKTOP.INI
                                        DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
                                        use the -supp parameter or answer "No" at the first message box.
                                        ---------- (total run time: 30 seconds, including 5 seconds for message boxes)
                                        0
                                        1. Contributeur sécurité
                                          Salut

                                          Elle est tres sympathique votre fille lol
                                          (J espere que la papa aussi lol)

                                          Ou en sont vos soucis SVP? :-)

                                          A+
                                          0
                                          • 1
                                          • 2