Downloader.wintrim.da

Résolu
bonjour

aidez moi svp
des fenetres publicitaires s'ouvrent quand je navigue sur internet me demandant d'installer pleins de logiciels

voici mon hijackThis:

Logfile of HijackThis v1.99.1
Scan saved at 21:09:07, on 20/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Armor2net\Armor2net Personal Firewall\Armor2net.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\NCLAUNCH.EXe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sagem - Utilitaire pour Clé Wi-Fi USB 802.11b\WlanUtility.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\PROGRA~1\DAP\DAPIEBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Armor2net] C:\Program Files\Armor2net\Armor2net Personal Firewall\Armor2net.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - Startup: Sagem - Utilitaire pour Clé Wi-Fi USB.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
O16 - DPF: JT's Blocks - http://download.games.yahoo.com/games/clients/y/blt1_x.cab
O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by20fd.bay20.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_sit...
O16 - DPF: {71DA2A4E-ACB3-4065-9E41-8BC42EABE427} - http://scripts.dlv4.com/binaries/IA/svcia32_FR_XP.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game18.zylomgames.com/activex/zylomgamesplayer.cab
O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f001.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - https://www.ea.com/ea-studios/popcap
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4779/mcfscan.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe

20 réponses

  1. Contributeur sécurité
    Salut,

    Télécharge Blacklight (de F-Secure) a l’une des 2 adresses :
    https://www.f-secure.com/en
    https://www.f-secure.com/en

    et sauvegarde le sur ton Bureau.

    Double-clique blbeta.exe et accepte la licence ; laisse [X]scan through Windows Explorer activé ; clique Scan puis Next

    Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).

    Copie et colle le contenu de ce rapport dans ta prochaine réponse

    A+
    0
    1. bonsoir
      je n'arrive pas à l'executer, et pourtant je suis l'administrateur de mon PC !!!!
      j'ai le message suivant :

      F-secure Blacklight could not acquire necessary privileges (SeDebugPrivilege);
      - Your computer settings may prevent acquiring these privileges.
      - A malicious program might have disabled these privilegese.

      je ne sais pas s'il ya une relation mais je n'arrive plus à afficher le dossier system32 et pourtant sous Ms-Dos j'arrive à le voir.
      0
  2. Contributeur sécurité
    Re,

    remet un hijack this

    +

    Telecharge ceci
    https://www.silentrunners.org/Silent%20Runners.vbs
    Execute le,atends quelques minutes, il va creer ensuite un dossier juste a coté de silent runner sous format texte, copie/colle ce qu il te donnera

    Merci de faire cela demain matin.
    A+
    0
    1. bonjour
      voici le log hijackthis:

      Logfile of HijackThis v1.99.1
      Scan saved at 23:01:01, on 21/07/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\System32\igfxtray.exe
      C:\WINDOWS\System32\hkcmd.exe
      C:\Program Files\Armor2net\Armor2net Personal Firewall\Armor2net.exe
      C:\Program Files\McAfee.com\VSO\mcvsshld.exe
      C:\Program Files\McAfee.com\VSO\oasclnt.exe
      C:\PROGRA~1\mcafee.com\agent\mcagent.exe
      C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\NCLAUNCH.EXe
      c:\progra~1\mcafee.com\vso\mcvsescn.exe
      C:\WINDOWS\System32\drivers\CDAC11BA.EXE
      C:\Program Files\Sagem - Utilitaire pour Clé Wi-Fi USB 802.11b\WlanUtility.exe
      C:\Program Files\ewido anti-spyware 4.0\guard.exe
      c:\program files\mcafee.com\agent\mcdetect.exe
      c:\PROGRA~1\mcafee.com\vso\mcshield.exe
      C:\WINDOWS\system32\slserv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
      c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
      C:\WINDOWS\system32\svchost.exe
      c:\progra~1\mcafee.com\vso\mcvsftsn.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\a-squared\a2upd.exe
      C:\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
      O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\PROGRA~1\DAP\DAPIEBar.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
      O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
      O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
      O4 - HKLM\..\Run: [Armor2net] C:\Program Files\Armor2net\Armor2net Personal Firewall\Armor2net.exe
      O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
      O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
      O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
      O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
      O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
      O4 - Startup: Sagem - Utilitaire pour Clé Wi-Fi USB.lnk = ?
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
      O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
      O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
      O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
      O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
      O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
      O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
      O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
      O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
      O16 - DPF: JT's Blocks - http://download.games.yahoo.com/games/clients/y/blt1_x.cab
      O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab
      O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
      O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by20fd.bay20.hotmail.msn.com/resources/MsnPUpld.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_sit...
      O16 - DPF: {71DA2A4E-ACB3-4065-9E41-8BC42EABE427} - http://scripts.dlv4.com/binaries/IA/svcia32_FR_XP.cab
      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
      O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
      O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game18.zylomgames.com/activex/zylomgamesplayer.cab
      O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f001.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
      O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
      O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - https://www.ea.com/ea-studios/popcap
      O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4779/mcfscan.cab
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
      O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
      O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
      O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
      O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
      O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
      O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe

      et voici pour Silent Runners.vbs:

      "Silent Runners.vbs", revision 46, https://www.silentrunners.org/
      Operating System: Windows XP SP2
      Output limited to non-default values, except where indicated by "{++}"

      Startup items buried in registry:
      ---------------------------------

      HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
      "CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
      "NCLaunch" = "C:\WINDOWS\NCLAUNCH.EXe" ["Northcode Inc."]

      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
      "IgfxTray" = "C:\WINDOWS\System32\igfxtray.exe" ["Intel Corporation"]
      "HotKeysCmds" = "C:\WINDOWS\System32\hkcmd.exe" ["Intel Corporation"]
      "NeroCheck" = "C:\WINDOWS\System32\\NeroCheck.exe" ["Ahead Software Gmbh"]
      "SpeedTouch USB Diagnostics" = ""C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon" ["THOMSON"]
      "Armor2net" = "C:\Program Files\Armor2net\Armor2net Personal Firewall\Armor2net.exe" ["Armor2net Software Ltd."]
      "VSOCheckTask" = ""C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask" ["McAfee, Inc."]
      "VirusScan Online" = "C:\Program Files\McAfee.com\VSO\mcvsshld.exe" ["McAfee, Inc."]
      "OASClnt" = "C:\Program Files\McAfee.com\VSO\oasclnt.exe" ["McAfee, Inc."]
      "MCAgentExe" = "c:\PROGRA~1\mcafee.com\agent\mcagent.exe" ["McAfee, Inc"]
      "MCUpdateExe" = "C:\PROGRA~1\mcafee.com\agent\McUpdate.exe" ["McAfee, Inc"]
      "SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe" ["Sun Microsystems, Inc."]
      "mqevibl" = "c:\windows\system32\mqevibl.exe mqevibl" [null data]
      "!ewido" = ""C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized" ["Anti-Malware Development a.s."]

      HKLM\Software\Microsoft\Active Setup\Installed Components\
      >{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\(Default) = "Outlook Express"
      \StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE" [MS]
      {5945c046-1e7d-11d1-bc44-00c04fd912be}\(Default) = "Windows Messenger 4.7"
      \StubPath = "rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.Remove.PerUser" [MS]
      {8b15971b-5355-4c82-8c07-7e181ea07608}\(Default) = "Fax"
      \StubPath = "rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.UnInstall.PerUser" [MS]
      {94de52c8-2d59-4f1b-883e-79663d2d9a8c}\(Default) = "Fax Provider"
      \StubPath = "rundll32.exe C:\WINDOWS\System32\Setup\FxsOcm.dll,XP_UninstallProvider" [MS]

      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
      {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
      -> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"
      \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
      {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
      -> {HKLM...CLSID} = (no title provided)
      \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
      {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
      -> {HKLM...CLSID} = "SSVHelper Class"
      \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll" ["Sun Microsystems, Inc."]
      {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
      -> {HKLM...CLSID} = "Google Toolbar Helper"
      \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

      HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
      "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
      -> {HKLM...CLSID} = "Extension Affichage Panorama du Panneau de configuration"
      \InProcServer32\(Default) = "deskpan.dll" [file not found]
      "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
      -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
      \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]

      et merci d'avance pour votre aide regis
      0
      1. Contributeur sécurité
        Re,

        Le rapport de silent runner n est pas entier

        Peux tu attendre quelques minutes avant de le relever?

        Merci
        A+
        0
        1. bonjour

          désolée mais je crois que maintenant, j'ai le bon log :

          "Silent Runners.vbs", revision 46, https://www.silentrunners.org/
          Operating System: Windows XP SP2
          Output limited to non-default values, except where indicated by "{++}"

          Startup items buried in registry:
          ---------------------------------

          HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
          "CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
          "NCLaunch" = "C:\WINDOWS\NCLAUNCH.EXe" ["Northcode Inc."]

          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
          "IgfxTray" = "C:\WINDOWS\System32\igfxtray.exe" ["Intel Corporation"]
          "HotKeysCmds" = "C:\WINDOWS\System32\hkcmd.exe" ["Intel Corporation"]
          "NeroCheck" = "C:\WINDOWS\System32\\NeroCheck.exe" ["Ahead Software Gmbh"]
          "SpeedTouch USB Diagnostics" = ""C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon" ["THOMSON"]
          "Armor2net" = "C:\Program Files\Armor2net\Armor2net Personal Firewall\Armor2net.exe" ["Armor2net Software Ltd."]
          "VSOCheckTask" = ""C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask" ["McAfee, Inc."]
          "VirusScan Online" = "C:\Program Files\McAfee.com\VSO\mcvsshld.exe" ["McAfee, Inc."]
          "OASClnt" = "C:\Program Files\McAfee.com\VSO\oasclnt.exe" ["McAfee, Inc."]
          "MCAgentExe" = "c:\PROGRA~1\mcafee.com\agent\mcagent.exe" ["McAfee, Inc"]
          "MCUpdateExe" = "c:\PROGRA~1\mcafee.com\agent\mcupdate.exe" ["McAfee, Inc"]
          "SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe" ["Sun Microsystems, Inc."]
          "mqevibl" = "c:\windows\system32\mqevibl.exe mqevibl" [null data]
          "!ewido" = ""C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized" ["Anti-Malware Development a.s."]

          HKLM\Software\Microsoft\Active Setup\Installed Components\
          >{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\(Default) = "Outlook Express"
          \StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE" [MS]
          {5945c046-1e7d-11d1-bc44-00c04fd912be}\(Default) = "Windows Messenger 4.7"
          \StubPath = "rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.Remove.PerUser" [MS]
          {8b15971b-5355-4c82-8c07-7e181ea07608}\(Default) = "Fax"
          \StubPath = "rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.UnInstall.PerUser" [MS]
          {94de52c8-2d59-4f1b-883e-79663d2d9a8c}\(Default) = "Fax Provider"
          \StubPath = "rundll32.exe C:\WINDOWS\System32\Setup\FxsOcm.dll,XP_UninstallProvider" [MS]

          HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
          -> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"
          \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
          {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
          -> {HKLM...CLSID} = (no title provided)
          \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
          {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
          -> {HKLM...CLSID} = "SSVHelper Class"
          \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll" ["Sun Microsystems, Inc."]
          {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
          -> {HKLM...CLSID} = "Google Toolbar Helper"
          \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

          HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
          "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
          -> {HKLM...CLSID} = "Extension Affichage Panorama du Panneau de configuration"
          \InProcServer32\(Default) = "deskpan.dll" [file not found]
          "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
          -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
          \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
          "{E0D79300-84BE-11CE-9641-444553540000}" = "WinZip"
          -> {HKLM...CLSID} = "WinZip"
          \InProcServer32\(Default) = "C:\PROGRA~1\WinZip\wzshlext.dll" [null data]
          "{E0D79301-84BE-11CE-9641-444553540000}" = "WinZip"
          -> {HKLM...CLSID} = "WinZip"
          \InProcServer32\(Default) = "C:\PROGRA~1\WinZip\wzshlext.dll" [null data]
          "{E0D79302-84BE-11CE-9641-444553540000}" = "WinZip"
          -> {HKLM...CLSID} = "WinZip"
          \InProcServer32\(Default) = "C:\PROGRA~1\WinZip\wzshlext.dll" [null data]
          "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
          -> {HKLM...CLSID} = "WinRAR"
          \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
          "{B446400D-0030-457b-8F64-422A19605186}" = "Logitech Gallery"
          -> {HKLM...CLSID} = "Logitech Gallery"
          \InProcServer32\(Default) = "C:\Program Files\Logitech\ImageStudio\NameSpc.dll" ["Logitech Inc."]
          "{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
          -> {HKLM...CLSID} = "Portable Media Devices"
          \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
          "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
          -> {HKLM...CLSID} = "Portable Media Devices Menu"
          \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
          "{01060040-070D-11D3-B35B-00805F010AA5}" = "SBoxLight.ShPropSheet"
          -> {HKLM...CLSID} = "Security BOX LIGHT (C) ShPropSheet CoClass"
          \InProcServer32\(Default) = "C:\PROGRA~1\SBOXFR~1\SHPROP~1.DLL" ["Methode et Solution Informatique S.A. -- http://msi-sa.fr/ -- contact@msi-sa.fr"]
          "{01061038-070D-11D3-B35B-00805F010AA5}" = "SBoxLight.ShDropIco"
          -> {HKLM...CLSID} = "Security BOX® FreeWare"
          \InProcServer32\(Default) = "C:\PROGRA~1\SBOXFR~1\SHDROP~1.DLL" ["Methode et Solution Informatique S.A. -- http://msi-sa.fr/ -- contact@msi-sa.fr"]
          "{01060010-070D-11D3-B35B-00805F010AA5}" = "SBoxLight.ShCtxMnu"
          -> {HKLM...CLSID} = "Security BOX LIGHT (C) ShCtxMnu CoClass"
          \InProcServer32\(Default) = "C:\PROGRA~1\SBOXFR~1\SHCTXM~1.DLL" ["Methode et Solution Informatique S.A. -- http://msi-sa.fr/ -- contact@msi-sa.fr"]
          "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
          -> {HKLM...CLSID} = "Outlook File Icon Extension"
          \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL" [MS]
          "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
          -> {HKLM...CLSID} = (no title provided)
          \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
          "{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band"
          -> {HKLM...CLSID} = "Shell Search Band"
          \InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
          "{86637DEE-91AE-4EE1-906C-3C743B53507F}" = "Exif Tag Viewer"
          -> {HKLM...CLSID} = "ExifPage Class"
          \InProcServer32\(Default) = "C:\WINDOWS\system32\ExifView.dll" ["Foxbat"]
          "{AB77609F-2178-4E6F-9C4B-44AC179D937A}" = "a² Context Menu Shell Extension"
          -> {HKLM...CLSID} = "a² Context Menu Shell Extension"
          \InProcServer32\(Default) = "C:\PROGRA~1\A-SQUA~1\A2CONT~1.DLL" [null data]

          HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
          INFECTION WARNING! "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "ewido anti-spyware 4.0"
          -> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
          \InProcServer32\(Default) = "C:\Program Files\ewido anti-spyware 4.0\shellexecutehook.dll" ["Anti-Malware Development a.s."]

          HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
          INFECTION WARNING! WgaLogon\DLLName = "WgaLogon.dll" [MS]

          HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
          {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
          -> {HKLM...CLSID} = "PDF Shell Extension"
          \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]

          HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
          DAP_Menu\(Default) = "{BED4C38B-F765-45AC-8C56-613F76BBF43E}"
          -> {HKLM...CLSID} = "DAPMenuShellExt Class"
          \InProcServer32\(Default) = "C:\PROGRA~1\DAP\PRIVAC~1\DAPCTX~1.DLL" ["Speedbit Ltd."]
          ewido anti-spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
          -> {HKLM...CLSID} = "CContextScan Object"
          \InProcServer32\(Default) = "C:\Program Files\ewido anti-spyware 4.0\context.dll" ["Anti-Malware Development a.s."]
          IMMenuShellExt\(Default) = "{F8984111-38B6-11D5-8725-0050DA2761C4}"
          -> {HKLM...CLSID} = "IMMenuShellExt Class"
          \InProcServer32\(Default) = "C:\PROGRA~1\INCRED~1\bin\ImShExt.dll" ["IncrediMail, Ltd."]
          SBoxShellMenu\(Default) = "{01060010-070D-11D3-B35B-00805F010AA5}"
          -> {HKLM...CLSID} = "Security BOX LIGHT (C) ShCtxMnu CoClass"
          \InProcServer32\(Default) = "C:\PROGRA~1\SBOXFR~1\SHCTXM~1.DLL" ["Methode et Solution Informatique S.A. -- http://msi-sa.fr/ -- contact@msi-sa.fr"]
          WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
          -> {HKLM...CLSID} = "WinRAR"
          \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
          WinZip\(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
          -> {HKLM...CLSID} = "WinZip"
          \InProcServer32\(Default) = "C:\PROGRA~1\WinZip\wzshlext.dll" [null data]

          HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
          ewido anti-spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
          -> {HKLM...CLSID} = "CContextScan Object"
          \InProcServer32\(Default) = "C:\Program Files\ewido anti-spyware 4.0\context.dll" ["Anti-Malware Development a.s."]
          WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
          -> {HKLM...CLSID} = "WinRAR"
          \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
          WinZip\(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
          -> {HKLM...CLSID} = "WinZip"
          \InProcServer32\(Default) = "C:\PROGRA~1\WinZip\wzshlext.dll" [null data]

          HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
          a2ContMenu\(Default) = "{AB77609F-2178-4E6F-9C4B-44AC179D937A}"
          -> {HKLM...CLSID} = "a² Context Menu Shell Extension"
          \InProcServer32\(Default) = "C:\PROGRA~1\A-SQUA~1\A2CONT~1.DLL" [null data]
          SBoxShellMenu\(Default) = "{01060010-070D-11D3-B35B-00805F010AA5}"
          -> {HKLM...CLSID} = "Security BOX LIGHT (C) ShCtxMnu CoClass"
          \InProcServer32\(Default) = "C:\PROGRA~1\SBOXFR~1\SHCTXM~1.DLL" ["Methode et Solution Informatique S.A. -- http://msi-sa.fr/ -- contact@msi-sa.fr"]
          WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
          -> {HKLM...CLSID} = "WinRAR"
          \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
          WinZip\(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
          -> {HKLM...CLSID} = "WinZip"
          \InProcServer32\(Default) = "C:\PROGRA~1\WinZip\wzshlext.dll" [null data]

          Active Desktop and Wallpaper:
          -----------------------------

          Active Desktop is disabled at this entry:
          HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

          Enabled Screen Saver:
          ---------------------

          HKCU\Control Panel\Desktop\
          "SCRNSAVE.EXE" = "C:\WINDOWS\Fish.scr" [null data]

          Startup items in "Utilisateur" & "All Users" startup folders:
          -------------------------------------------------------------

          C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\Démarrage
          "Sagem - Utilitaire pour Clé Wi-Fi USB" -> shortcut to: "C:\Program Files\Sagem - Utilitaire pour Clé Wi-Fi USB 802.11b\WlanUtility.exe" [empty string]

          C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
          "Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office10\OSA.EXE -b -l" [MS]

          Enabled Scheduled Tasks:
          ------------------------

          "McAfee.com Scan for Viruses - My Computer (USER-Utilisateur)" -> launches: "c:\program files\mcafee.com\vso\mcmnhdlr.exe /runtask:0" ["McAfee, Inc."]

          Winsock2 Service Provider DLLs:
          -------------------------------

          Namespace Service Providers

          HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
          000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
          000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
          000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

          Transport Service Providers

          HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
          0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
          C:\Program Files\Armor2net\Armor2net Personal Firewall\NETDOG.DLL [null data], 01 - 05
          %SystemRoot%\system32\mswsock.dll [MS], 06 - 27

          Toolbars, Explorer Bars, Extensions:
          ------------------------------------

          Toolbars

          HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
          "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
          -> {HKLM...CLSID} = "&Google"
          \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

          HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
          "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
          -> {HKLM...CLSID} = "&Google"
          \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

          HKLM\Software\Microsoft\Internet Explorer\Toolbar\
          "{BA52B914-B692-46C4-B683-905236F6F655}" = "McAfee VirusScan"
          -> {HKLM...CLSID} = "McAfee VirusScan"
          \InProcServer32\(Default) = "c:\progra~1\mcafee.com\vso\mcvsshl.dll" ["McAfee, Inc."]
          "{62999427-33FC-4BAF-9C9C-BCE6BD127F08}" = "DAP Bar"
          -> {HKLM...CLSID} = "DAP Bar"
          \InProcServer32\(Default) = "C:\PROGRA~1\DAP\DAPIEBar.dll" [empty string]
          "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
          -> {HKLM...CLSID} = "&Google"
          \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

          Extensions (Tools menu items, main toolbar menu buttons)

          HKLM\Software\Microsoft\Internet Explorer\Extensions\
          {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
          "MenuText" = "Console Java (Sun)"
          "CLSIDExtension" = "{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}"
          -> {HKCU...CLSID} = "Java Plug-in"
          \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll" ["Sun Microsystems, Inc."]
          -> {HKLM...CLSID} = "Java Plug-in 1.5.0_07"
          \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll" ["Sun Microsystems, Inc."]

          Miscellaneous IE Hijack Points
          ------------------------------

          C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

          Added lines (compared with English-language version):
          [Strings]: SAFESITE_VALUE="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2ffr%2f%3f"

          Missing lines (compared with English-language version):
          [Strings]: 1 line

          Running Services (Display Name, Service Name, Path {Service DLL}):
          ------------------------------------------------------------------

          C-DillaCdaC11BA, C-DillaCdaC11BA, "C:\WINDOWS\System32\drivers\CDAC11BA.EXE" ["Macrovision"]
          ewido anti-spyware 4.0 guard, ewido anti-spyware 4.0 guard, "C:\Program Files\ewido anti-spyware 4.0\guard.exe" ["Anti-Malware Development a.s."]
          McAfee Task Scheduler, McTskshd.exe, "c:\PROGRA~1\mcafee.com\agent\mctskshd.exe" ["McAfee, Inc"]
          McAfee WSC Integration, McDetect.exe, "c:\program files\mcafee.com\agent\mcdetect.exe" ["McAfee, Inc"]
          McAfee.com McShield, McShield, "c:\PROGRA~1\mcafee.com\vso\mcshield.exe" ["McAfee Inc."]
          SmartLinkService, SLService, "slserv.exe" [" "]
          Symantec Core LC, Symantec Core LC, "C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe" ["Symantec Corporation"]
          Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]

          Print Monitors:
          ---------------

          HKLM\System\CurrentControlSet\Control\Print\Monitors\
          hpzlnt04\Driver = "hpzlnt04.dll" ["HP"]

          ----------
          + This report excludes default entries except where indicated.
          + To see *everywhere* the script checks and *everything* it finds,
          launch it from a command prompt or a shortcut with the -all parameter.
          + The search for DESKTOP.INI DLL launch points on all local fixed drives
          took 394 seconds.
          + The search for all Registry CLSIDs containing dormant Explorer Bars
          took 897 seconds.
          ---------- (total run time: 3089 seconds)

          merci
          0
          1. Contributeur sécurité
            Re,

            Lance ce scan en ligne:
            http://www.bitdefender.fr/scan8/ie.html
            Copie/colle le rapport

            A+
            0
            1. bonsoir
              voici le rapport d'analyse:

              BitDefender Online Scanner
              Rapport d'analyse généré à: Sat, Jul 22, 2006 - 21:44:53
              Voie d'analyse: C:\;D:\;F:\;
              Statistiques
              Temps
              01:14:04

              Fichiers
              361601

              Directoires
              4259

              Secteurs de boot
              3

              Archives
              8792

              Paquets programmes
              26180

              Résultats

              Virus identifiés
              2

              Fichiers infectés
              2

              Fichiers suspects
              0

              Avertissements
              0

              Désinfectés
              0

              Fichiers effacés
              2

              Info sur les moteurs

              Définition virus
              416915

              Version des moteurs
              AVCORE v1.0 (build 2310) (i386) (Apr 17 2006 16:24:38)

              Analyse des plugins
              13

              Archive des plugins
              39

              Unpack des plugins
              5

              E-mail plugins
              6

              Système plugins
              1

              Paramètres d'analyse

              Première action
              Désinfecté

              Seconde Action
              Supprimé

              Heuristique
              Oui

              Acceptez les avertissements
              Oui

              Extensions analysées
              *;

              Excludez les extensions

              Analyse d'emails
              Oui

              Analyse des Archives
              Oui

              Analyser paquets programmes
              Oui

              Analyse des fichiers
              Oui

              Analyse de boot
              Oui

              Fichier analysé
              Statut

              C:\RECYCLER\S-1-5-21-2490121115-3007047209-1020043247-1005\Dc3.exe=>(RAR Sfx o)=>1.exe
              Infecté par: BehavesLike:Trojan.FirewallBypass

              C:\RECYCLER\S-1-5-21-2490121115-3007047209-1020043247-1005\Dc3.exe=>(RAR Sfx o)=>1.exe
              Echec de la désinfection

              C:\RECYCLER\S-1-5-21-2490121115-3007047209-1020043247-1005\Dc3.exe=>(RAR Sfx o)=>1.exe
              Supprimé

              C:\RECYCLER\S-1-5-21-2490121115-3007047209-1020043247-1005\Dc3.exe=>(RAR Sfx o)
              Echec de la mise à jour

              C:\WINDOWS\backup\S\50924000.DAT=>(Embedded EXE g)=>(Embedded EXE o)
              Infecté par: Trojan.Qurl.3

              C:\WINDOWS\backup\S\50924000.DAT=>(Embedded EXE g)=>(Embedded EXE o)
              Echec de la désinfection

              C:\WINDOWS\backup\S\50924000.DAT=>(Embedded EXE g)=>(Embedded EXE o)
              Supprimé

              C:\WINDOWS\backup\S\50924000.DAT=>(Embedded EXE g)
              Echec de la mise à jour

              BitDefender Online Scanner - Rapport virus en temps réel

              Généré à: Sat, Jul 22, 2006 - 21:46:33

              --------------------------------------------------------------------------

              Info d'analyse

              Fichiers scannés
              361748

              Infectés Fichiers
              2

              Virus Détectés

              BehavesLike:Trojan.FirewallBypass
              1

              Trojan.Qurl.3
              1

              et merci
              0
              1. Contributeur sécurité
                Salut

                Essai de retelecharger black light maintenant.

                A+
                0
                1. bonjour
                  je viens de le faire et il me redonne exactement le meme message !!!!

                  que faire ?
                  0
                  1. Contributeur sécurité
                    Re,

                    ¤Affiche tous les fichiers et dossiers :
                    Clique sur démarrer/panneau de configuration/outil/option des dossiers/affichage

                    Coche « afficher les fichiers et dossiers cachés »

                    Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                    Décoche « masquer les extensions dont le type est connu »
                    Puis fais «Ok» pour valider les changements.

                    Et appliquer !
                    ----------------------------------------------------------------------------
                    Est ce que tu as ceci ?

                    c:\windows\system32\mqevibl.exe

                    A+
                    0
                    1. bonsoir
                      oui j'ai ce fichier
                      que dois je faire ?
                      0
                      1. Contributeur sécurité
                        Salut

                        Ok, et est ce que tu as ceci:

                        c:\WINDOWS\system32\mqevibl_nav.dat
                        c:\WINDOWS\system32\mqevibl.dat
                        c:\WINDOWS\system32\mqevibl_navps.dat

                        A+
                        0
                        1. Contributeur sécurité
                          OK

                          Dans ajout/suppression de programmes, desinstalles mailskinner s il s y trouve

                          Puis supprime ceci:
                          c:\windows\system32\mqevibl.exe
                          c:\WINDOWS\system32\mqevibl_nav.dat
                          c:\WINDOWS\system32\mqevibl.dat
                          c:\WINDOWS\system32\mqevibl_navps.dat

                          A+
                          0
                          1. re

                            je viens de supprimer les fichiers mqevibl.

                            je fais quoi maintenant ?

                            merci
                            0
                            1. Contributeur sécurité
                              Salut

                              Normalement tu devrais avoir moins de messages publicitaires voir nul.

                              Remet un hijack this + un silent runner

                              a+
                              0
                              1. re

                                voici le log hijackthis:

                                Logfile of HijackThis v1.99.1
                                Scan saved at 21:03:42, on 24/07/2006
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                                c:\program files\mcafee.com\agent\mcdetect.exe
                                c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                                C:\WINDOWS\System32\igfxtray.exe
                                C:\WINDOWS\System32\hkcmd.exe
                                C:\Program Files\Armor2net\Armor2net Personal Firewall\Armor2net.exe
                                C:\Program Files\McAfee.com\VSO\mcvsshld.exe
                                c:\progra~1\mcafee.com\vso\mcvsescn.exe
                                c:\program files\mcafee.com\agent\mcagent.exe
                                C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
                                C:\WINDOWS\system32\slserv.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\NCLAUNCH.EXe
                                c:\progra~1\mcafee.com\vso\mcvsftsn.exe
                                C:\WINDOWS\explorer.exe
                                C:\Program Files\Shareaza\Shareaza.exe
                                C:\Program Files\MSN Messenger\msnmsgr.exe
                                C:\WINDOWS\system32\NOTEPAD.EXE
                                C:\HijackThis\HijackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
                                O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                                O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
                                O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
                                O4 - HKLM\..\Run: [Armor2net] C:\Program Files\Armor2net\Armor2net Personal Firewall\Armor2net.exe
                                O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
                                O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
                                O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
                                O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
                                O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
                                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
                                O4 - Startup: Sagem - Utilitaire pour Clé Wi-Fi USB.lnk = ?
                                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                                O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
                                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
                                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
                                O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
                                O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
                                O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
                                O10 - Unknown file in Winsock LSP: c:\program files\armor2net\armor2net personal firewall\netdog.dll
                                O16 - DPF: JT's Blocks - http://download.games.yahoo.com/games/clients/y/blt1_x.cab
                                O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab
                                O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                                O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
                                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
                                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by20fd.bay20.hotmail.msn.com/resources/MsnPUpld.cab
                                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_sit...
                                O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                                O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                                O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                                O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
                                O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game18.zylomgames.com/activex/zylomgamesplayer.cab
                                O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f001.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
                                O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
                                O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - https://www.ea.com/ea-studios/popcap
                                O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4779/mcfscan.cab
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{ACB68CF1-52CF-4B86-8046-3268BDA18CB7}: NameServer = 212.217.0.14 212.217.1.14
                                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                                O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                                O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                                O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
                                O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
                                O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                                O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
                                O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                                O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe

                                et le Silent Runners.vbs:

                                "Silent Runners.vbs", revision 46, https://www.silentrunners.org/
                                Operating System: Windows XP SP2
                                Output limited to non-default values, except where indicated by "{++}"

                                Startup items buried in registry:
                                ---------------------------------

                                HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                                "CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
                                "NCLaunch" = "C:\WINDOWS\NCLAUNCH.EXe" ["Northcode Inc."]

                                HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                                "IgfxTray" = "C:\WINDOWS\System32\igfxtray.exe" ["Intel Corporation"]
                                "HotKeysCmds" = "C:\WINDOWS\System32\hkcmd.exe" ["Intel Corporation"]
                                "NeroCheck" = "C:\WINDOWS\System32\\NeroCheck.exe" ["Ahead Software Gmbh"]
                                "SpeedTouch USB Diagnostics" = ""C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon" ["THOMSON"]
                                "Armor2net" = "C:\Program Files\Armor2net\Armor2net Personal Firewall\Armor2net.exe" ["Armor2net Software Ltd."]
                                "VSOCheckTask" = ""C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask" ["McAfee, Inc."]
                                "VirusScan Online" = "C:\Program Files\McAfee.com\VSO\mcvsshld.exe" ["McAfee, Inc."]
                                "OASClnt" = "C:\Program Files\McAfee.com\VSO\oasclnt.exe" ["McAfee, Inc."]
                                "MCAgentExe" = "c:\PROGRA~1\mcafee.com\agent\mcagent.exe" ["McAfee, Inc"]
                                "MCUpdateExe" = "c:\PROGRA~1\mcafee.com\agent\mcupdate.exe" ["McAfee, Inc"]
                                "SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe" ["Sun Microsystems, Inc."]

                                HKLM\Software\Microsoft\Active Setup\Installed Components\
                                >{881dd1c5-3dcf-431b-b061-f3f88e8be88a}\(Default) = "Outlook Express"
                                \StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigOE" [MS]
                                {5945c046-1e7d-11d1-bc44-00c04fd912be}\(Default) = "Windows Messenger 4.7"
                                \StubPath = "rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.Remove.PerUser" [MS]
                                {8b15971b-5355-4c82-8c07-7e181ea07608}\(Default) = "Fax"
                                \StubPath = "rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.UnInstall.PerUser" [MS]
                                {94de52c8-2d59-4f1b-883e-79663d2d9a8c}\(Default) = "Fax Provider"
                                \StubPath = "rundll32.exe C:\WINDOWS\System32\Setup\FxsOcm.dll,XP_UninstallProvider" [MS]

                                HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
                                {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
                                -> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"
                                \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
                                {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
                                -> {HKLM...CLSID} = (no title provided)
                                \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
                                {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
                                -> {HKLM...CLSID} = "SSVHelper Class"
                                \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll" ["Sun Microsystems, Inc."]
                                {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
                                -> {HKLM...CLSID} = "Google Toolbar Helper"
                                \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

                                HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
                                "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
                                -> {HKLM...CLSID} = "Extension Affichage Panorama du Panneau de configuration"
                                \InProcServer32\(Default) = "deskpan.dll" [file not found]
                                "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
                                -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
                                \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
                                "{E0D79300-84BE-11CE-9641-444553540000}" = "WinZip"
                                -> {HKLM...CLSID} = "WinZip"
                                \InProcServer32\(Default) = "C:\PROGRA~1\WinZip\wzshlext.dll" [null data]
                                "{E0D79301-84BE-11CE-9641-444553540000}" = "WinZip"
                                -> {HKLM...CLSID} = "WinZip"
                                \InProcServer32\(Default) = "C:\PROGRA~1\WinZip\wzshlext.dll" [null data]
                                "{E0D79302-84BE-11CE-9641-444553540000}" = "WinZip"
                                -> {HKLM...CLSID} = "WinZip"
                                \InProcServer32\(Default) = "C:\PROGRA~1\WinZip\wzshlext.dll" [null data]
                                "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
                                -> {HKLM...CLSID} = "WinRAR"
                                \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
                                "{B446400D-0030-457b-8F64-422A19605186}" = "Logitech Gallery"
                                -> {HKLM...CLSID} = "Logitech Gallery"
                                \InProcServer32\(Default) = "C:\Program Files\Logitech\ImageStudio\NameSpc.dll" ["Logitech Inc."]
                                "{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
                                -> {HKLM...CLSID} = "Portable Media Devices"
                                \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
                                "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
                                -> {HKLM...CLSID} = "Portable Media Devices Menu"
                                \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
                                "{01060040-070D-11D3-B35B-00805F010AA5}" = "SBoxLight.ShPropSheet"
                                -> {HKLM...CLSID} = "Security BOX LIGHT (C) ShPropSheet CoClass"
                                \InProcServer32\(Default) = "C:\PROGRA~1\SBOXFR~1\SHPROP~1.DLL" ["Methode et Solution Informatique S.A. -- http://msi-sa.fr/ -- contact@msi-sa.fr"]
                                "{01061038-070D-11D3-B35B-00805F010AA5}" = "SBoxLight.ShDropIco"
                                -> {HKLM...CLSID} = "Security BOX® FreeWare"
                                \InProcServer32\(Default) = "C:\PROGRA~1\SBOXFR~1\SHDROP~1.DLL" ["Methode et Solution Informatique S.A. -- http://msi-sa.fr/ -- contact@msi-sa.fr"]
                                "{01060010-070D-11D3-B35B-00805F010AA5}" = "SBoxLight.ShCtxMnu"
                                -> {HKLM...CLSID} = "Security BOX LIGHT (C) ShCtxMnu CoClass"
                                \InProcServer32\(Default) = "C:\PROGRA~1\SBOXFR~1\SHCTXM~1.DLL" ["Methode et Solution Informatique S.A. -- http://msi-sa.fr/ -- contact@msi-sa.fr"]
                                "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
                                -> {HKLM...CLSID} = "Outlook File Icon Extension"
                                \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL" [MS]
                                "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
                                -> {HKLM...CLSID} = (no title provided)
                                \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
                                "{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band"
                                -> {HKLM...CLSID} = "Shell Search Band"
                                \InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
                                "{86637DEE-91AE-4EE1-906C-3C743B53507F}" = "Exif Tag Viewer"
                                -> {HKLM...CLSID} = "ExifPage Class"
                                \InProcServer32\(Default) = "C:\WINDOWS\system32\ExifView.dll" ["Foxbat"]

                                HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
                                INFECTION WARNING! WgaLogon\DLLName = "WgaLogon.dll" [MS]

                                HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
                                {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
                                -> {HKLM...CLSID} = "PDF Shell Extension"
                                \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]

                                HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
                                IMMenuShellExt\(Default) = "{F8984111-38B6-11D5-8725-0050DA2761C4}"
                                -> {HKLM...CLSID} = "IMMenuShellExt Class"
                                \InProcServer32\(Default) = "C:\PROGRA~1\INCRED~1\bin\ImShExt.dll" ["IncrediMail, Ltd."]
                                SBoxShellMenu\(Default) = "{01060010-070D-11D3-B35B-00805F010AA5}"
                                -> {HKLM...CLSID} = "Security BOX LIGHT (C) ShCtxMnu CoClass"
                                \InProcServer32\(Default) = "C:\PROGRA~1\SBOXFR~1\SHCTXM~1.DLL" ["Methode et Solution Informatique S.A. -- http://msi-sa.fr/ -- contact@msi-sa.fr"]
                                WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                                -> {HKLM...CLSID} = "WinRAR"
                                \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
                                WinZip\(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
                                -> {HKLM...CLSID} = "WinZip"
                                \InProcServer32\(Default) = "C:\PROGRA~1\WinZip\wzshlext.dll" [null data]

                                HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
                                WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                                -> {HKLM...CLSID} = "WinRAR"
                                \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
                                WinZip\(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
                                -> {HKLM...CLSID} = "WinZip"
                                \InProcServer32\(Default) = "C:\PROGRA~1\WinZip\wzshlext.dll" [null data]

                                HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
                                SBoxShellMenu\(Default) = "{01060010-070D-11D3-B35B-00805F010AA5}"
                                -> {HKLM...CLSID} = "Security BOX LIGHT (C) ShCtxMnu CoClass"
                                \InProcServer32\(Default) = "C:\PROGRA~1\SBOXFR~1\SHCTXM~1.DLL" ["Methode et Solution Informatique S.A. -- http://msi-sa.fr/ -- contact@msi-sa.fr"]
                                WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                                -> {HKLM...CLSID} = "WinRAR"
                                \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
                                WinZip\(Default) = "{E0D79300-84BE-11CE-9641-444553540000}"
                                -> {HKLM...CLSID} = "WinZip"
                                \InProcServer32\(Default) = "C:\PROGRA~1\WinZip\wzshlext.dll" [null data]

                                Active Desktop and Wallpaper:
                                -----------------------------

                                Active Desktop is disabled at this entry:
                                HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

                                Enabled Screen Saver:
                                ---------------------

                                HKCU\Control Panel\Desktop\
                                "SCRNSAVE.EXE" = "C:\WINDOWS\Fish.scr" [null data]

                                Startup items in "Utilisateur" & "All Users" startup folders:
                                -------------------------------------------------------------

                                C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\Démarrage
                                "Sagem - Utilitaire pour Clé Wi-Fi USB" -> shortcut to: "C:\Program Files\Sagem - Utilitaire pour Clé Wi-Fi USB 802.11b\WlanUtility.exe" [empty string]

                                C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
                                "Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office10\OSA.EXE -b -l" [MS]

                                Enabled Scheduled Tasks:
                                ------------------------

                                "McAfee.com Scan for Viruses - My Computer (USER-Utilisateur)" -> launches: "c:\program files\mcafee.com\vso\mcmnhdlr.exe /runtask:0" ["McAfee, Inc."]

                                Winsock2 Service Provider DLLs:
                                -------------------------------

                                Namespace Service Providers

                                HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
                                000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
                                000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
                                000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

                                Transport Service Providers

                                HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
                                0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
                                C:\Program Files\Armor2net\Armor2net Personal Firewall\NETDOG.DLL [null data], 01 - 05
                                %SystemRoot%\system32\mswsock.dll [MS], 06 - 27

                                Toolbars, Explorer Bars, Extensions:
                                ------------------------------------

                                Toolbars

                                HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
                                "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
                                -> {HKLM...CLSID} = "&Google"
                                \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

                                HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
                                "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
                                -> {HKLM...CLSID} = "&Google"
                                \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

                                HKLM\Software\Microsoft\Internet Explorer\Toolbar\
                                "{BA52B914-B692-46C4-B683-905236F6F655}" = "McAfee VirusScan"
                                -> {HKLM...CLSID} = "McAfee VirusScan"
                                \InProcServer32\(Default) = "c:\progra~1\mcafee.com\vso\mcvsshl.dll" ["McAfee, Inc."]
                                "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
                                -> {HKLM...CLSID} = "&Google"
                                \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]

                                Extensions (Tools menu items, main toolbar menu buttons)

                                HKLM\Software\Microsoft\Internet Explorer\Extensions\
                                {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
                                "MenuText" = "Console Java (Sun)"
                                "CLSIDExtension" = "{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}"
                                -> {HKCU...CLSID} = "Java Plug-in"
                                \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll" ["Sun Microsystems, Inc."]
                                -> {HKLM...CLSID} = "Java Plug-in 1.5.0_07"
                                \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll" ["Sun Microsystems, Inc."]

                                {85D1F590-48F4-11D9-9669-0800200C9A66}\
                                "MenuText" = "Uninstall BitDefender Online Scanner v8"
                                "Exec" = "%windir%\bdoscandel.exe" [null data]

                                Miscellaneous IE Hijack Points
                                ------------------------------

                                C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

                                Added lines (compared with English-language version):
                                [Strings]: SAFESITE_VALUE="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2ffr%2f%3f"

                                Missing lines (compared with English-language version):
                                [Strings]: 1 line

                                Running Services (Display Name, Service Name, Path {Service DLL}):
                                ------------------------------------------------------------------

                                C-DillaCdaC11BA, C-DillaCdaC11BA, "C:\WINDOWS\System32\drivers\CDAC11BA.EXE" ["Macrovision"]
                                McAfee Task Scheduler, McTskshd.exe, "c:\PROGRA~1\mcafee.com\agent\mctskshd.exe" ["McAfee, Inc"]
                                McAfee WSC Integration, McDetect.exe, "c:\program files\mcafee.com\agent\mcdetect.exe" ["McAfee, Inc"]
                                SmartLinkService, SLService, "slserv.exe" [" "]
                                Symantec Core LC, Symantec Core LC, "C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe" ["Symantec Corporation"]
                                Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]

                                Print Monitors:
                                ---------------

                                HKLM\System\CurrentControlSet\Control\Print\Monitors\
                                hpzlnt04\Driver = "hpzlnt04.dll" ["HP"]

                                ----------
                                + This report excludes default entries except where indicated.
                                + To see *everywhere* the script checks and *everything* it finds,
                                launch it from a command prompt or a shortcut with the -all parameter.
                                + The search for DESKTOP.INI DLL launch points on all local fixed drives
                                took 114 seconds.
                                + The search for all Registry CLSIDs containing dormant Explorer Bars
                                took 52 seconds.
                                ---------- (total run time: 258 seconds)

                                et merci pour ton aide :)
                                0
                                1. Contributeur sécurité
                                  Salut

                                  Ou en sont tes soucis?

                                  a+
                                  0
                                  1. bonsoir

                                    oufff c'est bon maintenant, je n'ai plus de problème
                                    merci bcp régis pour ton aide :)
                                    0
                                    1. Contributeur sécurité
                                      Bonsoir

                                      Content pour toi :-)

                                      Bonne continuation
                                      0