Drivecleaner,spyware secure

Résolu
bonjour, je suis inscrite depuis deux jours à ccm et j'espère que vous m'excuserez si je fais quelques erreurs dans mes explications. je me suis rendue compte que je n'étais pas la seule loin de là, à avoir des problèmes avec ces pages intempestives qui s'ouvrent et vous disent que vos fichiers sont infectés et vous proposent d'installer drivecleaner, spyware secure errorsafe ou autre chose. je ne sais pas trop quoi faire. je suis sous windows xp, j'utilise de préférence firefox, j'ai bitdefender 9 comme antivirus. je vous remercie de bien vouloir m'aider à régler ce problème.
Configuration: Windows XP
Firefox 2.0.0.2

15 réponses

Résumé de la discussion

Des pages intempestives affichent des messages d'infection et proposent d'installer DriveCleaner, Spyware Secure ou d'autres outils, sur Windows XP avec Firefox et BitDefender 9. Plusieurs contribuent recommandent de mettre à jour l'antivirus et le pare-feu, d'utiliser Spybot pour éliminer les spywares, puis d'employer CCleaner pour optimiser le système. D'autres suggèrent des outils spécialisés comme HijackThis pour générer un log et guider le nettoyage, et évoquent des remèdes tels que SmitFraudFix ou des rapports d'analyse. Un guide pratique détaille l'utilisation d'HijackThis pour effectuer un scan système et générer un fichier log exploitable.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour jibi
    Assure-toi d'abord que ton antivirus est bien à jour et que ton parefeu fonctionne correctement.
    Tu peux utiliser Spybot pour éliminer les spywares. Il est gratuit et régulièrement mis à jour. Sinon, parmi les programmes de "nettoyage", CCLeaner est efficace et ne cherche pas à en "faire trop".
    1. Contributeur
      Bonjour,

      Télécharge Hijackthis : http://www.merijn.org/files/hijackthis.zip

      Installe-le dans un dossier dédié

      Renomme le en "scanner.exe"

      Double-clique sur "Scanner.exe"

      Et tu clique sur "do a system scan and save a logfile"

      Un fichier .txt va apparaître tu le copie-colle dans ta prochaine réponse.

      Démo : (merci à balltrap34 pour cette réalisation)
      http://pageperso.aol.fr/balltrap34/demohijack.htm
      1. à l'aide darkiller... que dois-je faire après avoir scanné et envoyé le fichier log ?
    2. merci toptibal, j'ai vérifié parefeu et antivirus, et téléchargé spybot et ccleaner comme tu me le conseillais.. il ne me reste qu'une page récalcitrante "spyware-sécure", quand j'ouvre internet.. ce qui est un "grand mieux", mais je me suis également aperçue que certains fichiers dont je n'arrivais pas à me débarrasser ont été définitivement éliminés et là mon ordi est très content... alors merci beaucoup
      1. j'ai testé une solution qui me paraissait plus facile au départ...maintenant je vais tenter la tienne,j'espère m'en sortir en suivant comme il faut tes indications, merci d'avance

        Logfile of HijackThis v1.99.1
        Scan saved at 19:01:07, on 17/03/2007
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16414)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
        C:\Program Files\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\HPZipm12.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
        C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
        C:\Program Files\Java\jre1.5.0\bin\jusched.exe
        C:\WINDOWS\RTHDCPL.EXE
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\WINDOWS\system32\rundll32.exe
        C:\windows\system\hpsysdrv.exe
        C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
        C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe
        C:\progra~1\bitdef~1\bdswitch.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\BitDefender9\bdoesrv.exe
        C:\progra~1\bitdef~1\bdnagent.exe
        C:\Program Files\Logitech\Video\LogiTray.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\WINDOWS\system32\LVComS.exe
        C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
        C:\PROGRA~1\INCRED~1\bin\IMApp.exe
        C:\Program Files\MSN Messenger\usnsvc.exe
        C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
        C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
        C:\Program Files\BitDefender9\vsserv.exe
        c:\progra~1\bitdef~1\bdmcon.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Documents and Settings\HP_Propriétaire\Mes documents\docs divers\hija\scanner.exe.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://home.neuf.fr/
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
        O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
        O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe"
        O4 - HKLM\..\Run: [BDSwitchAgent] "c:\progra~1\bitdef~1\bdswitch.exe"
        O4 - HKLM\..\Run: [BDOESRV] "C:\Program Files\BitDefender9\bdoesrv.exe"
        O4 - HKLM\..\Run: [BDNewsAgent] "c:\progra~1\bitdef~1\bdnagent.exe"
        O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\BITDEF~1\bdmcon.exe
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
        O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
        O4 - HKLM\..\Run: [UVS10 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
        O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
        O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O11 - Options group: [INTERNATIONAL] International*
        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
        O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
        O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
        O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender9\vsserv.exe" /service (file missing)
        O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
        1. Contributeur
          Re,

          Donc télécharge clean : http://www.malekal.com/download/clean.zip

          Installe-le sur le bureau et dezippe-le.
          Un dossier clean va être créér

          ----------------------------------------------------------------------------
          Redémarre en mode sans échec tuto : http://forum.telecharger.01net.com/forum/high-tech/SECURITE/Securite/redemarrer-mode-echec-sujet_1526_1.htm
          (Attention pendant le mode sans échec tu n'as pas accès a internet !! )
          ----------------------------------------------------------------------------
          Ouvre Hijackthis et clique sur "do a system scan only" puis coche cette ligne :

          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

          Puis clique sur "Fix Checked"

          Ensuite supprime manuellement ce fichier :

          ALCMTR.EXE
          ----------------------------------------------------------------------------
          Un dossier clean va être créer double-clique dessus
          Puis double clique sur clean.cmd et choisit l'option 1.Patiente un peu.
          Poste ce rapport dans ton prochain post+un rapport Hijackthis
          1. encore moi, désolée de te déranger à nouveau. je suis un peu perdue. à partir du moment où j'ai cliqué sur "fix checked", un dossier backup a été fait. j'ai cliqué à nouveau sur "do a system scan only". la ligne avec alcmtr.exe avait disparu.. j'en suis là, je ne vois pas de dossier clean et je ne trouve pas clean.cmd. pourrais-tu m'aider à nouveau ?
        2. Contributeur
          Re,

          C'est normal que alcmtr.exe aie disparu. C'est voulu.

          Donc je récapitule pour clean.

          Si tu n'as pas encore télécharger clean fait le ici : http://www.malekal.com/download/clean.zip

          Puis suis ces instructions :

          Installe-le sur le bureau et dezippe-le.
          Un dossier clean va être créer double-clique dessus
          Puis double clique sur clean.cmd et choisit l'option 1.Patiente un peu.
          Poste ce rapport dans ton prochain post
          1. Rapport clean par Malekal_morte - http://www.malekal.com
            Option 1, executee le 18/03/2007 a 0:06:30,68

            *** Recherche de fichiers sur C:

            *** Recherche des fichiers dans C:\WINDOWS\

            *** Recherche des fichiers dans C:\WINDOWS\system32
            C:\WINDOWS\system32\bdod.bin FOUND

            *** Fin du rapport !
            avec un peu de mal mais voilà le rapport, je ne suis pas très douée... merci d'avoir répondu.
        3. Contributeur
          Re,

          Redémarre en mode sans échec tuto : http://forum.telecharger.01net.com/forum/high-tech/SECURITE/Securite/redemarrer-mode-echec-sujet_1526_1.htm
          (Attention pendant le mode sans échec tu n'as pas accès a internet !! )

          Puis ouvre le dossier clean puis clique sur clean.cmd et choisi l'option 2.

          Redémarre normalement.

          Poste le rapport clean ainsi qu'un rapport Hijackthis
          1. Logfile of HijackThis v1.99.1
            Scan saved at 00:52:11, on 18/03/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16414)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
            C:\Program Files\Java\jre1.5.0\bin\jusched.exe
            C:\WINDOWS\RTHDCPL.EXE
            C:\Program Files\QuickTime\qttask.exe
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\windows\system\hpsysdrv.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
            C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe
            C:\PROGRA~1\BITDEF~1\bdswitch.exe
            C:\Program Files\BitDefender9\bdoesrv.exe
            C:\PROGRA~1\BITDEF~1\bdnagent.exe
            C:\PROGRA~1\BITDEF~1\bdmcon.exe
            C:\Program Files\Logitech\Video\LogiTray.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\MSN Messenger\MsnMsgr.Exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
            C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
            C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
            C:\Program Files\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
            C:\WINDOWS\system32\LVComS.exe
            C:\PROGRA~1\INCRED~1\bin\IMApp.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\HPZipm12.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
            C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
            C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
            C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
            C:\Program Files\BitDefender9\vsserv.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\MSN Messenger\usnsvc.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Documents and Settings\HP_Propriétaire\Mes documents\docs divers\hija\scanner.exe.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://home.neuf.fr/
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
            O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
            O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe"
            O4 - HKLM\..\Run: [BDSwitchAgent] "C:\PROGRA~1\BITDEF~1\bdswitch.exe"
            O4 - HKLM\..\Run: [BDOESRV] "C:\Program Files\BitDefender9\bdoesrv.exe"
            O4 - HKLM\..\Run: [BDNewsAgent] "C:\PROGRA~1\BITDEF~1\bdnagent.exe"
            O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\BITDEF~1\bdmcon.exe
            O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
            O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
            O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
            O4 - HKLM\..\Run: [UVS10 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 10\uvPL.exe
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
            O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
            O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
            O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O11 - Options group: [INTERNATIONAL] International*
            O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
            O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
            O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
            O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender9\vsserv.exe" /service (file missing)
            O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

            Script execute en mode sans echec
            Rapport clean par Malekal_morte - http://www.malekal.com
            Option 2, executee le 18/03/2007 a 0:43:04,17

            Microsoft Windows XP [version 5.1.2600]

            *** Suppression de fichiers sur C:

            *** Suppression des fichiers dans C:\WINDOWS\

            *** Suppression des fichiers dans C:\WINDOWS\system32
            tentative de suppression de C:\WINDOWS\system32\bdod.bin

            *** Suppression des clefs du registre effectuee..
            *** Fin du rapport !

            et voilà les deux rapports demandés...
        4. Contributeur
          Re,

          Tu vas télécharger SmitFraudFix :
          http://siri.urz.free.fr/Fix/SmitfraudFix.exe

          Suis ces procédures:

          Double-clique sur smitfraudfix.exe
          Sélectionne 1 (MAIS SURTOUT PAS LE 2 JE TE DIRAIS QUAND TU POURRA LE FAIRE ) puis appuie "entrer" ensuite un rapport sera généré dans ce chemin :

          C:\rapport.txt

          Puis tu le colle dans ton prochain post

          Remarque:

          Process.exe est detecter par certain antivirus.
          Ce n'est pas un virus, mais il peut arreter des logiciel de securiter avec certaine manipulation.
          C'est pour cela qu'il est detecter par les antivirus.
          1. SmitFraudFix v2.148

            Rapport fait à 1:35:33,31, 18/03/2007
            Executé à partir de C:\Documents and Settings\HP_Propri‚taire\Mes documents\mes t‚l‚chargements\SmitfraudFix
            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
            Le type du système de fichiers est NTFS
            Fix executé en mode normal

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Propri‚taire

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Propri‚taire\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HP_PRO~1\Favoris

            »»»»»»»»»»»»»»»»»»»»»»»» Bureau

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

            »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
            "Source"="About:Home"
            "SubscribedURL"="About:Home"
            "FriendlyName"="Ma page d'accueil"

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"="sockspy.dll"

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32

            »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin

            voilà encore un rapport de fait...je suis désolée de te prendre autant de temps... merci
        5. Contributeur sécurité
          Bonsoir

          à avoir des problèmes avec ces pages intempestives qui s'ouvrent et vous disent que vos fichiers sont infectés et vous proposent d'installer drivecleaner, spyware secure errorsafe ou autre chose.


          peut être ceci non ? plus approprié que smitfraud. Mais peut être que je fais fausse route...

          * Télécharge Blacklight
          https://europe.f-secure.com/exclude/blacklight/index.shtml
          (de F-Secure)
          (le premier de la page)

          Enregistre le sur ton Bureau.
          Double-clique blbeta.exe
          Clique sur "I ACCEPT" .
          clique Scan puis Next<*gras>

          Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport,
          sur ton Bureau, nommé <gras>fsbl.xxxxxxx.log
          (les xxxxxxx sont des chiffres).

          Copie et colle le contenu de ce rapport dans ta prochaine réponse.
          NE PAS choisir l'option "Rename" de suite : nous devons analyser le rapport,
          car des fichiers légitimes peuvent être présents, tel wbemtest.exe

          1. bonjour philae83 et merci de venir à mon aide à la suite de darkiller.
            voici donc le rapport fsbl

            03/18/07 12:51:56 [Info]: BlackLight Engine 1.0.55 initialized
            03/18/07 12:51:56 [Info]: OS: 5.1 build 2600 (Service Pack 2)
            03/18/07 12:51:57 [Note]: 7019 4
            03/18/07 12:51:57 [Note]: 7005 0
            03/18/07 12:52:16 [Note]: 7006 0
            03/18/07 12:52:16 [Note]: 7011 1356
            03/18/07 12:52:16 [Note]: 7026 0
            03/18/07 12:52:16 [Note]: 7026 0
            03/18/07 12:52:16 [Note]: 7024 3
            03/18/07 12:52:16 [Info]: Hidden process: C:\windows\system32\gvpjxndk.exe
            03/18/07 12:52:29 [Note]: FSRAW library version 1.7.1021
            03/18/07 12:55:57 [Info]: Hidden file: c:\WINDOWS\system32\gvpjxndk.dat
            03/18/07 12:55:57 [Note]: 10002 1
            03/18/07 12:55:57 [Info]: Hidden file: C:\windows\system32\gvpjxndk.exe
            03/18/07 12:55:58 [Note]: 10002 1
            03/18/07 12:55:58 [Info]: Hidden file: c:\WINDOWS\system32\gvpjxndk_nav.dat
            03/18/07 12:55:58 [Note]: 10002 1
            03/18/07 12:55:59 [Info]: Hidden file: c:\WINDOWS\system32\gvpjxndk_navps.dat
            03/18/07 12:55:59 [Note]: 10002 1
          2. Contributeur sécurité
            @jibibonjour

            peux tu faire ceci maintenant

            ces manips sont à faire dans l'ordre stp, imprime car il te faudra les faire en mode sans échec

            * Télécharge CCleaner

            http://www.filehippo.com/download_ccleaner.html

            ("Download Latest Version", sur la droite).

            Ce logiciel va permettre de supprimer tous les fichiers temporaires. Avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.

            * télécharge Brute Force Uninstaller

            http://www.merijn.org/files/bfu.zip

            * FAIS UN CLIC-DROIT sur le lien ci dessous

            http://metallica.geekstogo.com/EGDACCESS.bfu

            et choisis "Enregistrer sous" (dans IE c'est "Enregistrer le lien sous..")

            afin de télécharger EGDACCESS.bfu, Type "Tous les fichiers".

            Sauvegarde dans le dossier créé (c:\BFU)

            * FAIS UN CLIC-DROIT sur le lien ci dessous

            http://perso.numericable.fr/~altshift/Info/Fichiers/Winsoftware.bfu

            et choisis "Enregistrer sous" (dans IE c'est "Enregistrer le lien sous..")

            afin de télécharger Winsoftware.bfu, Type "Tous les fichiers".

            Sauvegarde dans le dossier créé (c:\BFU)

            * télécharge Navipromo.zip (par lazzzy)

            http://perso.numericable.fr/~altshift/Info/Fichiers/Navipromo07H.zip
            et décompresse-le sur ton bureau

            * Copie la suite des instructions dans un fichier texte, sur ton bureau. et redémarre en mode sans échec comme indiqué ici

            https://forum.pcastuces.com/default.asp#haut

            à la lettre C

            Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou autre.

            * lance le fichier Navipromo.bat qui se trouve dans le dossier Navipromo, sur ton bureau.
            * Sélectionne l'option "Recherche et suppression automatique". Patiente.
            S'il trouve quelque chose, tu verras défiler des lignes dans la fenêtre de commande et au bout de quelques instants, il faudra que tu appuies sur une touche pour que le nettoyage soit lancé. Lorsqu'il a terminé, ferme le rapport qui s'est ouvert

            * Relance l'outil, Sélectionne l'option "Suppression Heuristique", et patiente quelques minutes.
            Lorsqu'il a terminé, ferme le rapport qui s'est ouvert

            * Démarre le "Brute Force Uninstaller" en double-cliquant sur BFU.exe.
            Clique sur le petit dossier jaune, à la droite de la boîte "Scriptline to execute", et double-clique sur : EGDACCESS.bfu
            - Dans la boîte "Scriptline to execute", tu devrais maintenant voir ceci : C:\BFU\EGDACCESS.bfu
            Clique sur "Execute" et laisse-le faire son travail.
            Attendre que "Complete script execution" apparaîsse et clique sur OK.
            Clique exit pour fermer le programme BFU.
            Recommence encore une fois.

            * Démarre encore le "Brute Force Uninstaller" en double-cliquant sur BFU.exe.
            * Clique sur le petit dossier jaune, à la droite de la boîte "Scriptline to execute", et double-clique sur : Winsoftware.bfu
            - Dans la boîte "Scriptline to execute", tu devrais maintenant voir ceci : C:\BFU\Winsoftware.bfu
            * Clique sur "Execute" et laisse-le faire son travail.
            Attendre que "Complete script execution" apparaîsse et clique sur OK.
            * Clique exit pour fermer le programme BFU.
            Recommence encore une fois

            * Démarrer -> panneau de configuration -> options internet

            Clique sur l'onglet "Contenu" puis onglet "Certificats" et si tu trouves ceci, en particulier dans "éditeurs approuvés" :

            electronic-group - egroup - Montorgueil - VIP - "Sunny Day Design Ltd"

            => Supprime-les tous

            * lance Ccleaner pour un nettoyage complet.

            * redémarre normalement et poste le contenu du fichier Navipromo.txt qui se trouve dans Poste de travail > disque C:\

            Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.

          3. @philae83je viens de télécharger BFU.. dois-je cliquer sur BFU.exe? parce que quand je passe à l'étape suivante: enregistrer le lien sous, je ne trouve pas de dossier créé c:\BFU
          4. @philae83si je demande déjà des explications à ce stade, cela ne va pas être une sinécure pour toi... désolée,
          5. Contributeur sécurité
            @jibic'est toi qui le créé le dossier jaune dans C
            tu le nommes : BFU
        6. bonjours,
          j'ai le meme probleme avec c saloperie de fenetre ( spyware-secure, erro stafy, casino, etc) j'ai telecharger hijackthis et ca me donne ca:
          Logfile of HijackThis v1.99.1
          Scan saved at 15:05:23, on 18/03/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16414)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Windows Defender\MsMpEng.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\WINDOWS\system32\VTtrayp.exe
          C:\WINDOWS\system32\VTTimer.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
          C:\Apps\Powercinema\PCMService.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          C:\WINDOWS\system32\LVCOMSX.EXE
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\MSN Messenger\MsnMsgr.Exe
          C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\MessengerSkinner\MessengerSkinner.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
          C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
          C:\WINDOWS\system32\slserv.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\Program Files\MSN Messenger\usnsvc.exe
          C:\APPS\RecordNow\RecordNow.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\DOCUME~1\adrien\LOCALS~1\Temp\Répertoire temporaire 1 pour hijackthis.zip\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
          O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
          O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
          O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
          O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
          O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
          O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
          O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
          O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
          O4 - HKLM\..\Run: [jkuvlfcrt] c:\windows\system32\jkuvlfcrt.exe jkuvlfcrt
          O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -masquer
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
          O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
          O4 - HKCU\..\Run: [Cdiscount Alert] "C:\Program Files\Cdiscount\Cdiscount Alert\launcher.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [messengerskinner] C:\Program Files\MessengerSkinner\MessengerSkinner.exe
          O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
          O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
          O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
          O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra button: Alice ADSL - {DE49784C-DB57-4E38-868C-3698C0B15F31} - https://portail.free.fr/ (file missing) (HKCU)
          O11 - Options group: [INTERNATIONAL] International*
          O14 - IERESET.INF: START_PAGE_URL=https://portail.free.fr/
          O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
          O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
          O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSetup1.0.0.15-3.cab
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by127w.bay127.mail.live.com/mail/resources/MsnPUpld.cab
          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
          O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
          O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cab
          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cab
          O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
          O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
          O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

          merci d'avance pour votre aide car je ne sais pas quoi faire
          1. Contributeur sécurité
            Bonjour didiox

            pour répondre correctement à ta demande, tu dois te créer un "nouveau sujet" stp. Sinon on ne se retrouve plus dans les différentes posts. Merci
          2. @philae83bonjour,
            comment je fais pour creer un nouveau sujet? desole pour cette question mais je vien juste de m'inscrire chez vous
        7. au faite mon anti virus et avast et j'ai intaler aussi kerio personal firewall 4 pour remplacer mon par feu windows.
          1. Contributeur sécurité
            tu vas ici :
            virus securite
            et tu cliques sur
            Ecrire un nouveau message
            en bas de la page
        8. je suis aussi infectés par des spywares je ne sais pas comment les supprimés malgres que j'ai spybot
          j'ai installé hijack this voici le rapport

          Logfile of HijackThis v1.99.1
          Scan saved at 18:32:33, on 12/07/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
          C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
          C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
          c:\APPS\HIDSERVICE\HIDSERVICE.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\slserv.exe
          C:\WINDOWS\system32\svchost.exe
          c:\APPS\Powercinema\Kernel\TV\CLSched.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\rundll32.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
          C:\Apps\Powercinema\PCMService.exe
          C:\apps\ABoard\ABoard.exe
          C:\apps\ABoard\AOSD.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\system32\V0230Mon.exe
          C:\Program Files\Winamp\winampa.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\windows\system32\sylqfkwdpu.exe
          C:\Program Files\Fichiers communs\AOL\1184158946\ee\AOLSoftware.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
          C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe
          C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          c:\program files\fichiers communs\aol\1184158946\ee\services\antiSpywareApp\ver2_0_28_1\AOLSP Scheduler.exe
          c:\program files\fichiers communs\aol\1184158946\ee\aolsoftware.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Documents and Settings\karim\Bureau\videos flv\clips poursuite\hijackthis\scan.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
          O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
          O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
          O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
          O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
          O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
          O4 - HKLM\..\Run: [C:\WINDOWS\system32\V0230Cvw.dll] C:\WINDOWS\system32\RegSvr32.exe /s C:\WINDOWS\system32\V0230Cvw.dll
          O4 - HKLM\..\Run: [V0230Mon.exe] C:\WINDOWS\system32\V0230Mon.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
          O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [AVFX Engine] C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe
          O4 - HKLM\..\Run: [SW20] C:\WINDOWS\system32\sw20.exe
          O4 - HKLM\..\Run: [SW24] C:\WINDOWS\system32\sw24.exe
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [HostManager] C:\Program Files\Fichiers communs\AOL\1184158946\ee\AOLSoftware.exe
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
          O4 - HKCU\..\Run: [Creative Live! Cam Manager] "C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
          O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?fe3214e8360142eb81e7fa737149bb55
          O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?fe3214e8360142eb81e7fa737149bb55
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
          O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
          O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
          O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
          O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
          O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
          O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
          O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
          O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe