Fenetre intenpestive pub ect.. a court d'idée

Salut a vous!! je tourne depuis pa mal de temps sur les forum qui parle de prévention et d'anéentisement de log indesirable jen sui victime actuellement et pa moyen de les retirer grrrr!!
donc jai avg-spywar et ad-adware également ccleaner le tout mi a jour regulierement et p moyen de supr ses pub qui m'arrive genre vermins et otre doctor qui veul me filé des antivirus plus que louche bref jé avast mi a jour sur un xp celeron m360. je met ossi le rapport hijackthis je sai pa tro se que cé mai bon si sa peu vou aider et m'aider par la suite ^^

Logfile of HijackThis v1.99.1
Scan saved at 22:59:38, on 06.01.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Video ActiveX Object\pmsngr.exe
C:\WINDOWS\system32\keyhook.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Arcade\PCMService.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\WINDOWS\system32\ElkCtrl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Acer\Empowering Technology\eRecovery\Monitor.exe
C:\WINDOWS\system32\sistray.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Program Files\FlashGet\flashget.exe
C:\Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.acer.com/worldwide/selection.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FLASHGET\jccatch.dll
O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FLASHGET\getflash.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\system32\ElkCtrl.exe /automation
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: Télécharger tout avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FLASHGET\flashget.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: carbinyl - {8d8c2387-7f80-4022-9be6-43630a969558} - C:\WINDOWS\system32\gwquvw.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe

merci du coup de main je suis connecte si dial directe !!!

Domo !!^^
Configuration: Windows XP
Internet Explorer 7.0

30 réponses

Résumé de la discussion

Problème majeur : des publicités intrusives et des programmes potentiellement malveillants apparaissent sur Windows XP, avec un rapport HijackThis et des tentatives de prévention insuffisantes pour éliminer l'infection. Plusieurs conseils visent au nettoyage en mode sans échec et à la désinstallation d'éléments douteux comme FlashGet, puis à l'emploi d'outils dédiés tels que ComboFix et BlackLight. En parallèle, la sécurité passe par l'examen des autoruns et des services, l'élimination des barres d'outils et le recours à des antivirus fiables à jour. D'autres précautions incluent l'activation d'un pare-feu robuste et une surveillance des connexions sortantes pour prévenir les réinfections et les vols de données, tout en restant attentif aux mises à jour.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonsoir Marylou,

    télécharge Blacklight (de F-Secure), sauvegarde le sur ton Bureau:

    https://europe.f-secure.com/exclude/blacklight/index.shtml

    Double-clique blbeta.exe et accepte la licence ;clique Scan puis Next

    Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).

    Copie et colle le contenu de ce rapport dans ta prochaine réponse

    a+
    0
    1. voila c fait mai bon je parle po anglai moi !!
      ^^ sa pa été facile mai bon voici le rapport:

      01/06/07 23:40:03 [Info]: BlackLight Engine 1.0.55 initialized
      01/06/07 23:40:03 [Info]: OS: 5.1 build 2600 (Service Pack 2)
      01/06/07 23:40:03 [Note]: 7019 4
      01/06/07 23:40:03 [Note]: 7005 0
      01/06/07 23:40:04 [Note]: 7006 0
      01/06/07 23:40:04 [Note]: 7011 320
      01/06/07 23:40:04 [Note]: 7026 0
      01/06/07 23:40:04 [Note]: 7026 0
      01/06/07 23:40:11 [Note]: FSRAW library version 1.7.1021
      01/06/07 23:40:27 [Note]: 7007 0
      0
      1. Contributeur sécurité
        re,

        rien dans ce rapport!

        1) Télécharge SmitfraudFix de S!Ri:
        http://siri.urz.free.fr/Fix/SmitfraudFix.zip
        Tu le dézippes sur le Bureau.

        * Tu ouvres SmitfraudFix, tu double cliques sur SmitfraudFix.cmd et tu choisis l’option 1
        Postes le rapport.

        2) Télécharge AVG Anti-Spyware:

        https://www.avg.com/en-ww/free-antivirus-download

        Tu l'installes.
        Lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente

        Lance AVG Anti-Spyware
        Clique sur le bouton Analyse (de la barre d'outils)
        Puis sur l'onglets Comment réagir, clique sur Actions recommandées. Sélectionne Quarantaine.
        Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
        A la fin du scan, choisis l'option " Appliquer toutes les actions " en bas.
        Clique sur "Enregistrer le rapport". Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

        poste le rapport AVG!

        a+
        0
        1. re re did ^_^

          avg né pas encor fini mai je te met le rapport de simfraud deja :

          SmitFraudFix v2.132

          Rapport fait à 0:07:26.70, 07.01.2007
          Executé à partir de C:\Documents and Settings\TonyS\Bureau\SmitfraudFix
          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
          Le type du système de fichiers est FAT32
          Fix executé en mode normal

          »»»»»»»»»»»»»»»»»»»»»»»» C:\

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\TonyS

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\TonyS\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\TONYS\FAVORIS

          »»»»»»»»»»»»»»»»»»»»»»»» Bureau

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

          »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
          "Source"="About:Home"
          "SubscribedURL"="About:Home"
          "FriendlyName"="Ma page d'accueil"

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
          "{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"

          [HKEY_CLASSES_ROOT\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]
          @="C:\WINDOWS\system32\gwquvw.dll"

          [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]
          @="C:\WINDOWS\system32\gwquvw.dll"

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"=""

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "System"=""

          »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

          »»»»»»»»»»»»»»»»»»»»»»»» Fin

          Bisou !! a toute ^_^
          0
          1. Suite rapport avg (rien de bien concret)
            snifff

            + Créé à: 00:14:11 07.01.2007

            + Résultat de l'analyse:

            HKU\S-1-5-21-1757688669-3711597655-2696784309-1005\Software\Internet Security -> Adware.IntCodec : Aucune action entreprise.
            C:\Documents and Settings\TonyS\Cookies\tonys@247realmedia[1].txt -> TrackingCookie.247realmedia : Aucune action entreprise.

            Fin du rapport
            0
            1. Contributeur
              slt did et marylou,

              tu peux refaire le scan avec AVG et le regler sur "supprimer" car tu n'as rien supprimé du tout.

              Juste pour controle,tu peux passer l'option 2 de smitfraudfix STP

              * Redémarres le PC en mode sans échec : Au démarrage tu tapotes sur la touche F8 de ton clavier (ou F5 ) et tu choisis le [mode sans échec]

              * Ouvre le dossier [SmitfraudFix] et double clic sur Smitfraudfix.cmd, choisit l’option 2 et tu réponds oui à tout.

              Copie/colle le rapport sur le forum stp.

              a+
              0
              1. Contributeur sécurité
                re,

                bizarre, bizarre!

                intcodec me fais penser à smitfraud!

                je vais poser la question au créateur de l'outil, peut être une nouvelle variante!

                du temps, Télécharge DiagHelp.zip sur ton bureau:

                http://www.malekal.com/download/DiagHelp.zip

                Ne double-clic pas dessus !! Fais un clic droit sur le fichier et extraire tout
                Un nouveau dossier chercher va être créé DiagHelp
                Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)
                Une fenêtre va s'ouvrir, choisis l'option 1
                L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande

                Copie et colle le rapport ici!

                a+
                0
                1. Contributeur
                  slt did,

                  bizarre, bizarre!

                  comme tu dis, le fix aurait du le voir...

                  je voulais voir si le fix nettoyait cette dll présente dans le rapport :

                  C:\WINDOWS\system32\gwquvw.dll (zlob)

                  A+
                  0
              2. Salut tous

                Did ta réponse est sûrement là : gwquvw.dll
                Ce qui colle avec AntiVermins dont il parle, enfin je pense je comprends casi rien à ce qu'il a écrit !

                Bonne chasse
                0
                1. voila jé fait le nettoyage en mode sans echec donc voici le rapprt au faite merci pour l'attention que vous me porter !!

                  SmitFraudFix v2.132

                  Rapport fait à 0:39:28.40, 07.01.2007
                  Executé à partir de C:\Documents and Settings\TonyS\Bureau\SmitfraudFix
                  OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                  Le type du système de fichiers est FAT32
                  Fix executé en mode sans echec

                  »»»»»»»»»»»»»»»»»»»»»»»» Avant SmitFraudFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                  "{8d8c2387-7f80-4022-9be6-43630a969558}"="carbinyl"

                  [HKEY_CLASSES_ROOT\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]
                  @="C:\WINDOWS\system32\gwquvw.dll"

                  [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8d8c2387-7f80-4022-9be6-43630a969558}\InProcServer32]
                  @="C:\WINDOWS\system32\gwquvw.dll"

                  »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                  »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                  GenericRenosFix by S!Ri

                  C:\WINDOWS\system32\gwquvw.dll -> Hoax.Win32.Renos.gen.i
                  C:\WINDOWS\system32\gwquvw.dll -> Deleted

                  »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                  »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  "System"=""

                  »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                  Nettoyage terminé.

                  »»»»»»»»»»»»»»»»»»»»»»»» Après SmitFraudFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Fin
                  0
                  1. Contributeur sécurité
                    re,

                    bien vu seb!

                    Cependant, je vais tout de même contacter S!RI

                    pour vérif, repasse l'option1

                    a+
                    0
                    1. Contributeur sécurité
                      re,

                      rend toi ici:

                      http://siri.urz.free.fr/upload/

                      clique sur Parcourir>parcours les differents dossiers jusqu'a arriver ici:

                      C:\WINDOWS\system32\gwquvw.dll

                      fais un clique gauche sur gwquvw.dll il va prendre une couleur bleue. clique ensuite sur

                      ouvrir

                      a coté de "Lien vers le message du forum où le fichier a été demandé" copie/colle ceci:

                      fenetre intenpestive pub ect a court d idee#2007 01 07%2000%3A50%3A29

                      a+
                      0
                      1. "C:\WINDOWS\system32\gwquvw.dll -> Deleted"
                        0
                        1. Alors voila jai pa u le temp de tou suivre, mai depui avoir effacer en mode sans echec avec simtfraud tout est a 1 ere vue regler.
                          Donc MERCIIIIII et gros gros bisouss jai pa capter la moitié des truc que vou m'avez fai faire mai vou tous assurez sur ce coup là !!!

                          ^_^ je vous direz bien a charge de revenge mais bon ...

                          Merci encor d'avoir consacrer du temps ma situation je pense que les raport que vou vouliez ne sont plus nécéssaire sof si vou voulez faire du zèle!!!
                          hihihi

                          merci ++
                          0
                          1. Contributeur sécurité
                            re boulepate62,

                            j'ai bien vu!lol!

                            mais je voudrais l'upload du fichier tout de même!

                            ce fichier est tout récent!

                            a+
                            0
                            1. Contributeur sécurité
                              re,

                              moi je veux l'upload Marylou!

                              a+
                              0
                              1. lol trop tard elle veut déjà partir !

                                Tu n'aura pas ce que tu veux, à moins d'un miracle ;-)
                                0
                                1. Contributeur sécurité
                                  re boulepate62,

                                  sont pénibles ces femmes!

                                  a+
                                  0
                                  1. ^^ je ve bien moi mai il y a pa ou plus le dll dans sys 32. dsl si il y a une otre facon de t'aider je suis toute oui ....
                                    0
                                    1. bah tu l'a supprimer donc trop tard ;-)

                                      FlashGet contient un spyware tu devrais le désinstaller et le remplacer par un autre.

                                      Tu as quoi comme pare-feu ?

                                      Fait ça pour vérifier stp

                                      Télécharge ComboFix
                                      http://download.bleepingcomputer.com/sUBs/combofix.exe

                                      Ferme ton navigateur web avant d'exécuter ce programme
                                      Double-clique dessus et appuye sur "Y" pour continuer

                                      Attends quelques minutes..un rapport va s'ouvrir enregistre son contenu, puis copie et colle le ici stp
                                      0
                                      1. bin jai le par feu de base de xp sé tout !

                                        Bon voici ton rapport:
                                        pas de betise in!!

                                        TonyS - 07-01-07 1:33:15.18 Service Pack 2
                                        ComboFix 06.11.27 - Running from: "C:\Downloads"

                                        ((((((((((((((((((((((((((((((( Files Created from 2006-12-07 to 2007-01-07 ))))))))))))))))))))))))))))))))))

                                        2007-01-07 00:07 2,736 --a------ C:\WINDOWS\system32\tmp.reg
                                        2007-01-07 00:06 79,360 --a------ C:\WINDOWS\system32\swxcacls.exe
                                        2007-01-07 00:06 53,248 --a------ C:\WINDOWS\system32\Process.exe
                                        2007-01-07 00:06 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
                                        2007-01-07 00:06 40,960 --a------ C:\WINDOWS\system32\swsc.exe
                                        2007-01-07 00:06 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
                                        2007-01-07 00:06 135,168 --a------ C:\WINDOWS\system32\swreg.exe
                                        2007-01-06 22:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
                                        2007-01-06 22:28 <REP> dr-h----- C:\Documents and Settings\TonyS\Recent
                                        2007-01-06 22:25 <REP> d-------- C:\Program Files\Yahoo!
                                        2007-01-06 22:25 <REP> d-------- C:\Program Files\CCleaner
                                        2007-01-06 22:13 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
                                        2007-01-06 22:13 <REP> d-------- C:\Program Files\Grisoft
                                        2007-01-06 21:12 <REP> d-------- C:\Documents and Settings\TonyS\Application Data\Lavasoft
                                        2007-01-06 20:59 <REP> d-------- C:\Program Files\Lavasoft
                                        2007-01-05 01:21 <REP> d-------- C:\Program Files\Google
                                        2007-01-05 01:21 <REP> d-------- C:\Documents and Settings\TonyS\Application Data\Google
                                        2007-01-05 01:21 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Google
                                        2006-12-22 01:36 <REP> d-------- C:\Program Files\UxTheme Multipatcher Fr
                                        2006-12-21 23:58 99,840 --a------ C:\WINDOWS\ZIPDLL.DLL
                                        2006-12-21 23:58 299,520 --a------ C:\WINDOWS\uninst.exe
                                        2006-12-21 23:58 288,768 --a------ C:\WINDOWS\chdcu1.exe
                                        2006-12-21 23:58 <REP> d-------- C:\Program Files\Theme Maker
                                        2006-12-14 04:23 <REP> d-------- C:\Program Files\Windows Media Connect 2
                                        2006-12-14 04:21 <REP> d-------- C:\WINDOWS\system32\LogFiles
                                        2006-12-14 04:21 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
                                        2006-12-10 17:21 <REP> d-------- C:\WINDOWS\WBEM
                                        2006-12-10 17:21 <REP> d-------- C:\WINDOWS\system32\fr-fr
                                        2006-12-10 17:19 <REP> d--h----- C:\WINDOWS\ie7
                                        2006-12-10 17:18 121,856 --------- C:\WINDOWS\system32\xmllite.dll
                                        2006-12-10 17:18 <REP> d-------- C:\WINDOWS\network diagnostic
                                        2006-12-10 16:59 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
                                        2006-12-10 16:56 <REP> d-------- C:\Program Files\MSXML 4.0
                                        2006-12-07 13:19 <REP> d--hs---- C:\Documents and Settings\TonyS\UserData

                                        (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

                                        2006-12-03 02:48 2419133 --a------ C:\WINDOWS\Resident Evil Antidote Screensaver.scr
                                        2006-12-03 00:03 2481067 --a------ C:\WINDOWS\Resident Evil 4.scr
                                        2006-11-08 06:07 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
                                        2006-11-07 21:03 6049280 --------- C:\WINDOWS\system32\ieframe.dll
                                        2006-11-07 21:03 50688 --------- C:\WINDOWS\system32\msfeedsbs.dll
                                        2006-11-07 21:03 458752 --------- C:\WINDOWS\system32\msfeeds.dll
                                        2006-11-07 21:03 413696 --a------ C:\WINDOWS\system32\vbscript.dll
                                        2006-11-07 21:03 231424 --a------ C:\WINDOWS\system32\webcheck.dll
                                        2006-11-07 21:03 180736 --------- C:\WINDOWS\system32\ieui.dll
                                        2006-11-07 21:03 156160 --a------ C:\WINDOWS\system32\msls31.dll
                                        2006-11-07 03:27 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
                                        2006-11-07 03:27 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
                                        2006-11-07 03:26 71680 --a------ C:\WINDOWS\system32\admparse.dll
                                        2006-11-07 03:26 55296 --a------ C:\WINDOWS\system32\iesetup.dll
                                        2006-11-07 03:26 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
                                        2006-11-07 03:26 43008 --a------ C:\WINDOWS\system32\iernonce.dll
                                        2006-11-07 03:26 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
                                        2006-11-07 03:26 13312 --a------ C:\WINDOWS\system32\ieudinit.exe
                                        2006-11-07 03:26 123904 --a------ C:\WINDOWS\system32\advpack.dll
                                        2006-11-07 03:25 161792 --a------ C:\WINDOWS\system32\ieakui.dll
                                        2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
                                        2006-11-03 10:03 8292352 --a------ C:\WINDOWS\system32\wmploc.dll
                                        2006-11-03 09:59 99840 --a------ C:\WINDOWS\system32\wmpshell.dll
                                        2006-11-03 09:58 272384 --a------ C:\WINDOWS\system32\wmerror.dll
                                        2006-11-03 09:56 7680 --a------ C:\WINDOWS\system32\asferror.dll
                                        2006-11-02 11:52 44032 --------- C:\WINDOWS\system32\wpdshextres.dll
                                        2006-10-25 02:36 868 --a------ C:\WINDOWS\HotFix.bat
                                        2006-10-25 02:36 657 --a------ C:\WINDOWS\CLEANUP.CMD
                                        2006-10-20 02:38 716800 --a------ C:\WINDOWS\system32\sxs.dll
                                        2006-10-18 21:58 8704 --a------ C:\WINDOWS\system32\wdfmgr.exe
                                        2006-10-18 21:58 8704 --a------ C:\WINDOWS\system32\uwdf.exe
                                        2006-10-18 21:47 991744 --a------ C:\WINDOWS\system32\drmv2clt.dll
                                        2006-10-18 21:47 937984 --a------ C:\WINDOWS\system32\WMNetMgr.dll
                                        2006-10-18 21:47 767488 --------- C:\WINDOWS\system32\WMVSENCD.dll
                                        2006-10-18 21:47 757248 --a------ C:\WINDOWS\system32\WMADMOD.dll
                                        2006-10-18 21:47 656896 --------- C:\WINDOWS\system32\WMVXENCD.dll
                                        2006-10-18 21:47 63488 --a------ C:\WINDOWS\system32\wpdmtpus.dll
                                        2006-10-18 21:47 629760 --a------ C:\WINDOWS\system32\wpd_ci.dll
                                        2006-10-18 21:47 613376 --------- C:\WINDOWS\system32\wmpmde.dll
                                        2006-10-18 21:47 603648 --a------ C:\WINDOWS\system32\WMSPDMOD.dll
                                        2006-10-18 21:47 542720 --a------ C:\WINDOWS\system32\blackbox.dll
                                        2006-10-18 21:47 535040 --------- C:\WINDOWS\system32\wmdrmsdk.dll
                                        2006-10-18 21:47 429056 --a------ C:\WINDOWS\system32\WMDRMdev.dll
                                        2006-10-18 21:47 414208 --a------ C:\WINDOWS\system32\msscp.dll
                                        2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmoe2.dll
                                        2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmvdmod.dll
                                        2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\WMVADVE.DLL
                                        2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\WMVADVD.dll
                                        2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmoe2.dll
                                        2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wmsdmod.dll
                                        2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\wdfapi.dll
                                        2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\MPG4DMOD.dll
                                        2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\MP4SDMOD.dll
                                        2006-10-18 21:47 4096 --a------ C:\WINDOWS\system32\MP43DMOD.dll
                                        2006-10-18 21:47 37376 --a------ C:\WINDOWS\system32\wmdmps.dll
                                        2006-10-18 21:47 35840 --a------ C:\WINDOWS\system32\wpdconns.dll
                                        2006-10-18 21:47 356352 --a------ C:\WINDOWS\system32\wpdsp.dll
                                        2006-10-18 21:47 348672 --a------ C:\WINDOWS\system32\WMDRMNet.dll
                                        2006-10-18 21:47 33792 --a------ C:\WINDOWS\system32\wmdmlog.dll
                                        2006-10-18 21:47 321536 --a------ C:\WINDOWS\system32\mswmdm.dll
                                        2006-10-18 21:47 317440 --------- C:\WINDOWS\system32\MP4SDECD.dll
                                        2006-10-18 21:47 314880 --a------ C:\WINDOWS\system32\wmpdxm.dll
                                        2006-10-18 21:47 295936 --------- C:\WINDOWS\system32\wmpeffects.dll
                                        2006-10-18 21:47 284160 --------- C:\WINDOWS\system32\PortableDeviceApi.dll
                                        2006-10-18 21:47 276992 --a------ C:\WINDOWS\system32\Audiodev.dll
                                        2006-10-18 21:47 27136 --a------ C:\WINDOWS\system32\MsPMSNSv.dll
                                        2006-10-18 21:47 2603008 --------- C:\WINDOWS\system32\WpdShext.dll
                                        2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\MPG4DECD.dll
                                        2006-10-18 21:47 259072 --------- C:\WINDOWS\system32\MP43DECD.dll
                                        2006-10-18 21:47 2450944 --a------ C:\WINDOWS\system32\wmvcore.dll
                                        2006-10-18 21:47 242688 --a------ C:\WINDOWS\system32\wmpasf.dll
                                        2006-10-18 21:47 229376 --a------ C:\WINDOWS\system32\cewmdm.dll
                                        2006-10-18 21:47 222208 --a------ C:\WINDOWS\system32\wmasf.dll
                                        2006-10-18 21:47 212992 --------- C:\WINDOWS\system32\MFPLAT.dll
                                        2006-10-18 21:47 211456 --a------ C:\WINDOWS\system32\qasf.dll
                                        2006-10-18 21:47 204288 --a------ C:\WINDOWS\system32\wmpsrcwp.dll
                                        2006-10-18 21:47 199168 --------- C:\WINDOWS\system32\PortableDeviceWMDRM.dll
                                        2006-10-18 21:47 179712 --a------ C:\WINDOWS\system32\msnetobj.dll
                                        2006-10-18 21:47 175616 --a------ C:\WINDOWS\system32\MsPMSP.dll
                                        2006-10-18 21:47 166912 --------- C:\WINDOWS\system32\PortableDeviceTypes.dll
                                        2006-10-18 21:47 1661440 --a------ C:\WINDOWS\system32\wmpencen.dll
                                        2006-10-18 21:47 1574912 --------- C:\WINDOWS\system32\WMVENCOD.dll
                                        2006-10-18 21:47 157184 --a------ C:\WINDOWS\system32\wmidx.dll
                                        2006-10-18 21:47 154624 --a------ C:\WINDOWS\system32\wpdmtp.dll
                                        2006-10-18 21:47 1543680 --------- C:\WINDOWS\system32\WMVDECOD.dll
                                        2006-10-18 21:47 1382912 --------- C:\WINDOWS\system32\WMVSDECD.dll
                                        2006-10-18 21:47 133632 --------- C:\WINDOWS\system32\WPDShServiceObj.dll
                                        2006-10-18 21:47 1329152 --a------ C:\WINDOWS\system32\WMSPDMOE.dll
                                        2006-10-18 21:47 132096 --------- C:\WINDOWS\system32\PortableDeviceWiaCompat.dll
                                        2006-10-18 21:47 130048 --------- C:\WINDOWS\system32\wmpps.dll
                                        2006-10-18 21:47 11264 --a------ C:\WINDOWS\system32\LAPRXY.dll
                                        2006-10-18 21:47 1117696 --a------ C:\WINDOWS\system32\WMADMOE.dll
                                        2006-10-18 21:47 101888 --------- C:\WINDOWS\system32\PortableDeviceClassExtension.dll
                                        2006-10-18 20:03 100864 --a------ C:\WINDOWS\system32\logagent.exe
                                        2006-10-18 20:00 249856 --------- C:\WINDOWS\system32\drmupgds.exe
                                        2006-10-18 20:00 17408 --------- C:\WINDOWS\system32\wpdshextautoplay.exe
                                        2006-10-17 12:06 78336 --a------ C:\WINDOWS\system32\ieencode.dll
                                        2006-10-17 12:05 40960 --a------ C:\WINDOWS\system32\licmgr10.dll
                                        2006-10-17 12:05 206336 --------- C:\WINDOWS\system32\WinFXDocObj.exe
                                        2006-10-17 12:05 105984 --a------ C:\WINDOWS\system32\url.dll
                                        2006-10-17 12:04 101376 --a------ C:\WINDOWS\system32\occache.dll
                                        2006-10-17 11:58 61952 --------- C:\WINDOWS\system32\icardie.dll
                                        2006-10-17 11:58 12288 --------- C:\WINDOWS\system32\msfeedssync.exe
                                        2006-10-17 11:57 36352 --a------ C:\WINDOWS\system32\imgutil.dll
                                        2006-10-17 11:57 266752 --------- C:\WINDOWS\system32\iertutil.dll
                                        2006-10-17 11:56 45568 --a------ C:\WINDOWS\system32\mshta.exe
                                        2006-10-17 11:28 48128 --a------ C:\WINDOWS\system32\mshtmler.dll
                                        2006-10-17 11:27 380928 --------- C:\WINDOWS\system32\ieapfltr.dll
                                        2006-10-13 13:36 145920 --a------ C:\WINDOWS\system32\nwprovau.dll

                                        (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

                                        *Note* empty entries are not shown

                                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
                                        "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
                                        "MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
                                        "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"

                                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
                                        "LaunchApp"="Alaunch"
                                        "SiSPower"="Rundll32.exe SiSPower.dll,ModeAgent"
                                        "SiS Windows KeyHook"="C:\\WINDOWS\\system32\\keyhook.exe"
                                        "SoundMan"="SOUNDMAN.EXE"
                                        "SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
                                        "SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
                                        "PCMService"="\"C:\\Program Files\\Arcade\\PCMService.exe\""
                                        "IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
                                        "MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
                                        "PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
                                        "PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
                                        "LManager"="C:\\Program Files\\Launch Manager\\QtZgAcer.EXE"
                                        "eRecoveryService"="C:\\Acer\\Empowering Technology\\eRecovery\\Monitor.exe"
                                        "avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
                                        "LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
                                        "LogitechCameraAssistant"="C:\\Program Files\\Logitech\\Video\\CameraAssistant.exe"
                                        "LogitechVideo[inspector]"="C:\\Program Files\\Logitech\\Video\\InstallHelper.exe /inspect"
                                        "LogitechCameraService(E)"="C:\\WINDOWS\\system32\\ElkCtrl.exe /automation"
                                        "!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

                                        [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
                                        "DeskHtmlVersion"=dword:00000110
                                        "DeskHtmlMinorVersion"=dword:00000005
                                        "Settings"=dword:00000001
                                        "GeneralFlags"=dword:00000000

                                        [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
                                        "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"

                                        [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
                                        "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"

                                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
                                        "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
                                        "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"

                                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
                                        "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
                                        "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

                                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
                                        "NoDriveTypeAutoRun"=dword:00000091

                                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

                                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                                        "dontdisplaylastusername"=dword:00000000
                                        "legalnoticecaption"=""
                                        "legalnoticetext"=""
                                        "shutdownwithoutlogon"=dword:00000001
                                        "undockwithoutlogon"=dword:00000001

                                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]

                                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
                                        "none"="C:\\Program Files\\Video ActiveX Object\\pmsngr.exe"

                                        [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
                                        "NoDriveTypeAutoRun"=dword:00000091

                                        [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
                                        "NoDriveTypeAutoRun"=dword:00000091

                                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
                                        "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
                                        "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
                                        "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
                                        "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
                                        "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

                                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
                                        "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

                                        Completion time: 07-01-07 1:33:55.45
                                        C:\ComboFix.txt ... 07-01-07 01:33
                                        0
                                        • 1
                                        • 2