Problème de pop up, et trojan, surement!!

Résolu
bonsoir,

voila! je vais souvent sur votre site depuis un bon moment déjà et je dois avouer qu'il m'a aidée a résoudre pas mal de petits problèmes....

j'ai un nouveau souci qui commence a devenir très genant et treees énervant!.......les fenetres de pubs qui s'ouvrent constement.

J'ai cru voir que je ne suis pas la seule!! mais également j'ai cru comprendre que vos analyses étaient personnalisées, c'est pour cela que je me permets de vous solliciter.

voila ce quej'ai déja installé sur mon ordi:
avast
ccleaner
spybot
ad aware se
a² free
AVG
et zone alarm pour le fire wall

je fais des scans et mises a jour tous les jour, et meme plusieurs fois par jour!!! (au cas ou!!)
J'aime bien que mon ordi soit "clean", mais visiblement la, c'est plus le cas!! et pui comme je ne suis pas la seule a l'utiliser, je ne peux pas tout surveiller!!

je vous remercie de bien vouloir m'aider, parceque la, je désespère!!!

Merci a ceux qui voudront bien me filer un petit coup de main...
bonne soirée
Configuration: Windows XP
Internet Explorer 7.0

39 réponses

Résumé de la discussion

Des fenêtres publicitaires récurrentes et des soupçons d’infection malware dominent le fil, sur fond de Windows XP et d’Internet Explorer 7, tandis que plusieurs antivirus et outils anti‑spyware sont utilisés quotidiennement. Les rapports de scan affichent des éléments suspects et des traces comme Vundo et Win32:VBStat, avec des instructions d’analyse et d’attention avant toute désinfection préconisée. Des éléments signalés nécessitent un redémarrage pour compléter le retrait du rootkit Vundo via des outils spécifiques, la mise en quarantaine de fichiers détectés et l’analyse des journaux HijackThis. Certains échanges insistent sur le fait qu’une désinfection précipitée peut aggraver les dommages et préconisent une analyse détaillée des rapports par un spécialiste avant toute action corrective.

Bobot (l’IA à votre service)
  1. Télécharge un anti pop-up !!!!!

    +
    0
    1. bonsoir, pas besoin d'en télécharger un vérifie si celui de ton navigateur est bien activé, clique sur propriétés et active le; mets également le réglage des cookies sur haut; si c pas ca alors tu as peu etre un spyware, va sur www.pctools.com et fais un scan avec spywware doctor, il devrait te donner le nom de l'intrus
      0
      1. non non mon anti pop up est activé, normalement mes réglages sont ok....

        snif!
        pas d'autre moyen??
        0
        1. j'ai oublié de préciser que récemment j'ai été infectée par win32:VBstat et un autre truc adware.vitumonde ou qqch comme ca......

          help!
          0
          1. oiri alors il faut procéder autrement; faire un hijackthis et coller le rapport ici pour analyse aidera a y voir plus clar
            0
            1. oups désolée pour le retard!!!!
              merci pour la réponse.
              voici le log

              Logfile of Trend Micro HijackThis v2.0.0 (BETA)
              Scan saved at 00:18:20, on 21/04/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
              C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
              C:\WINDOWS\system32\ZoneLabs\vsmon.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              C:\WINDOWS\eHome\ehRecvr.exe
              C:\WINDOWS\eHome\ehSched.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\WINDOWS\system32\HPZipm12.exe
              C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
              c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\mqsvc.exe
              C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
              C:\WINDOWS\system32\mqtgsvc.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\system32\dllhost.exe
              C:\WINDOWS\ehome\ehtray.exe
              C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
              C:\WINDOWS\eHome\ehmsas.exe
              C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
              C:\WINDOWS\system32\RUNDLL32.EXE
              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              C:\Program Files\HP\QuickPlay\QPService.exe
              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
              C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
              C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
              C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
              C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
              C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
              C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
              C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
              C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Windows Media Player\WMPNSCFG.exe
              C:\PROGRA~1\FICHIE~1\PCSuite\Services\SERVIC~1.EXE
              C:\Program Files\MSN Messenger\msnmsgr.exe
              C:\Program Files\MSN Messenger\usnsvc.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\WINDOWS\explorer.exe
              C:\Documents and Settings\cyril raclet\Temporary Internet Files\Content.IE5\L8B8GC3J\HiJackThis_v2[1].exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - (no file)
              O2 - BHO: (no name) - {35AF7D59-B3DE-4B4B-A6CB-501EEE22FDAC} - C:\WINDOWS\system32\mljgh.dll
              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: (no name) - {6148028B-D532-4417-8C0B-5A4A0B745393} - C:\WINDOWS\system32\byxvuss.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: (no name) - {8F3A4756-B8DE-4E80-AFB1-8B32CF6894Ef} - C:\WINDOWS\system32\uyrxacnc.dll
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
              O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
              O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
              O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
              O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
              O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
              O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
              O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
              O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
              O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
              O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
              O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
              O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
              O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
              O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
              O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
              O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
              O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
              O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} - https://www.snapfish.fr/2/home
              O16 - DPF: {5308E02B-4ABA-48E4-AA9E-8A7693661473} (GameCtl Class) - http://jeuxenligne.orange.fr/GisActiveX/Ax/GameAx.cab
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
              O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
              O16 - DPF: {C9E17F58-564C-41C6-989F-AB0FE0D2C9D1} (PopcapLoader Object) - http://jeuxenligne.orange.fr/orange2.0/OnlineHSS/zuma/Popcap.cab
              O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs-beta.jeu.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
              O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://fortunelounge.microgaming.com/generic/FlashAX.cab
              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
              O20 - Winlogon Notify: byxvuss - C:\WINDOWS\SYSTEM32\byxvuss.dll
              O20 - Winlogon Notify: mljgh - C:\WINDOWS\system32\mljgh.dll
              O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
              O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
              O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
              O23 - Service: Service de planification Media Center (ehSched) - Unknown owner - C:\WINDOWS\eHome\ehSched.exe
              O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
              O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
              O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
              O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
              O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
              O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
              O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
              O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
              O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
              O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
              O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
              O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
              0
              1. c rien, c not.malware win32virtumond.ha le second, je vais btot dormir, c pas grave c un forum donc klk1 d'autre va t'aider ou si pas je répondrai plus tard, en attendant si ton passes par ton wifi mets le cryptage wpa plutot que wep ca limitera un peu les spams, a+
                0
                1. merci pour ce début d'aide.......mais je ne sais toujours pas quoi faire...

                  En + excuse, mais j'ai pas bien compris ton message....dsl

                  bon ben bonne nuit, moi je vais faire un tour de forum, voir si je trouve mon bonheur.

                  re-merci

                  A +
                  0
                  1. tu fais démarrer, connexions, puis sans fil et afficher la tu changes le code d cryptage réseau, le wep est le moins sécurisé; pour avancer un peu tu peux faire un scan en mode ss échec avec spybot et coller le rapport, bonne nuit
                    0
                    1. merci pour le conseil, mais je ne peux pas changer la cle car ma connection est gérée par un programme que hp nous a fait installer car sinon ca marchait pas (intel PROset/wireless) et on peu pas faire la modif (a moins que je me trompe).

                      bon, je fais un coup de spybot et je reviens.
                      j'en ai deja fait un ce matin, mise a jour, vaccination et scan, il m'a trouvé deux trois trucs, mais rien de méchant je pense.
                      je vais tester en mode sans echec sur ton conseil...

                      +
                      0
                  2. Ras avec spybot

                    rapport avec adaware:

                    Ad-Aware SE Build 1.06r1
                    Fichier journal créé le :samedi 21 avril 2007 01:51:52
                    Created with Ad-Aware SE Personal, free for private use.
                    Utilisation du fichier de définitions :SE1R166 16.04.2007
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Références détectées lors de l’analyse :
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    MRU List(Index TAC :0):2 Nombre total de références
                    Tracking Cookie(Index TAC :3):25 Nombre total de références
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Ad-Aware SE Settings
                    ===========================
                    Définir : Rechercher les entrées à risque négligeable
                    Définir : Search for low-risk threats
                    Définir : Mode sécurisé (tjrs demander confirm.)
                    Définir : Analyser les processus actifs
                    Définir : Scan registry
                    Définir : Analyser en profondeur le registre
                    Définir : Analyser mes favoris IE pour rech. URL interdites
                    Définir : Analyser dans les archives
                    Définir : Analyser mon fichier Hosts

                    Extended Ad-Aware SE Settings
                    ===========================
                    Définir : Décharger les modules et les processus reconnus pendant l’analyse
                    Définir : Anal. reg. pr tous utili. et non pr utili. actuel uniqmnt
                    Définir : Toujours essayer de décharger les modules avant la suppression
                    Définir : Lors de la suppression, décharger l’Explorateur et IE si nécessaire
                    Définir : Perm. Win. supp. fich. en cours au proch. démar.
                    Définir : Supprimer les objets en quarantaine après la restauration
                    Définir : Inclure les paramètres de base d'Ad-Aware dans le fichier journal
                    Définir : Inclure les paramètres de base d'Ad-Aware dans le fichier journal
                    Définir : Inclure un récapitulatif des références dans le fichier journal
                    Définir : Inclure les détails des données ADS dans le fichier journal
                    Définir : Émettre un son à la fin de l’analyse en cas de détection d'objets critiques

                    21-04-2007 01:51:52 - L’analyse a démarré. (Mode accéléré)

                    Affichage des processus en cours d'exécution
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    #:1 [smss.exe]
                    FilePath : \SystemRoot\System32\
                    ProcessID : 268
                    ThreadCreationTime : 20-04-2007 23:48:48
                    BasePriority : Normal

                    #:2 [csrss.exe]
                    FilePath : \??\C:\WINDOWS\system32\
                    ProcessID : 324
                    ThreadCreationTime : 20-04-2007 23:48:53
                    BasePriority : Normal

                    #:3 [winlogon.exe]
                    FilePath : \??\C:\WINDOWS\system32\
                    ProcessID : 348
                    ThreadCreationTime : 20-04-2007 23:48:55
                    BasePriority : High

                    #:4 [services.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 396
                    ThreadCreationTime : 20-04-2007 23:48:58
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Système d'exploitation Microsoft® Windows®
                    CompanyName : Microsoft Corporation
                    FileDescription : Applications Services et Contrôleur
                    InternalName : services.exe
                    LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                    OriginalFilename : services.exe

                    #:5 [lsass.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 408
                    ThreadCreationTime : 20-04-2007 23:48:58
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : LSA Shell (Export Version)
                    InternalName : lsass.exe
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : lsass.exe

                    #:6 [svchost.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 560
                    ThreadCreationTime : 20-04-2007 23:49:00
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : Generic Host Process for Win32 Services
                    InternalName : svchost.exe
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : svchost.exe

                    #:7 [svchost.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 624
                    ThreadCreationTime : 20-04-2007 23:49:01
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : Generic Host Process for Win32 Services
                    InternalName : svchost.exe
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : svchost.exe

                    #:8 [svchost.exe]
                    FilePath : C:\WINDOWS\system32\
                    ProcessID : 676
                    ThreadCreationTime : 20-04-2007 23:49:02
                    BasePriority : Normal
                    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 5.1.2600.2180
                    ProductName : Microsoft® Windows® Operating System
                    CompanyName : Microsoft Corporation
                    FileDescription : Generic Host Process for Win32 Services
                    InternalName : svchost.exe
                    LegalCopyright : © Microsoft Corporation. All rights reserved.
                    OriginalFilename : svchost.exe

                    #:9 [explorer.exe]
                    FilePath : C:\WINDOWS\
                    ProcessID : 940
                    ThreadCreationTime : 20-04-2007 23:49:21
                    BasePriority : Normal
                    FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
                    ProductVersion : 6.00.2900.2180
                    ProductName : Système d'exploitation Microsoft® Windows®
                    CompanyName : Microsoft Corporation
                    FileDescription : Explorateur Windows
                    InternalName : explorer
                    LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                    OriginalFilename : EXPLORER.EXE

                    #:10 [spybotsd.exe]
                    FilePath : C:\Program Files\Spybot - Search & Destroy\
                    ProcessID : 1060
                    ThreadCreationTime : 20-04-2007 23:49:33
                    BasePriority : Normal
                    FileVersion : 1.4.0.3
                    ProductVersion : 1, 4, 0, 3
                    ProductName : SpyBot-S&D
                    CompanyName : Safer Networking Limited
                    FileDescription : Spybot - Search & Destroy
                    InternalName : SpybotSD
                    LegalCopyright : © 2000-2005 Patrick M. Kolla / Safer Networking Limited. Alle Rechte vorbehalten.
                    LegalTrademarks : "Spybot" und "Spybot - Search & Destroy" sind registrierte Warenzeichen.
                    OriginalFilename : SpyBotSD.exe
                    Comments : Software zum Entfernen von Spyware und ähnlichen Bedrohungen.

                    #:11 [avgas.exe]
                    FilePath : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\
                    ProcessID : 1196
                    ThreadCreationTime : 20-04-2007 23:50:26
                    BasePriority : Normal
                    FileVersion : 7, 5, 0, 50
                    ProductVersion : 7, 5, 0, 50
                    ProductName : AVG Anti-Spyware
                    CompanyName : Anti-Malware Development a.s.
                    FileDescription : AVG Anti-Spyware
                    InternalName : AVG Anti-Spyware
                    LegalCopyright : Copyright © 2006 Anti-Malware Development a.s.
                    OriginalFilename : avgas.exe

                    #:12 [ccleaner.exe]
                    FilePath : C:\Program Files\CCleaner\
                    ProcessID : 1288
                    ThreadCreationTime : 20-04-2007 23:50:47
                    BasePriority : Normal
                    FileVersion : 1.38.0485
                    ProductVersion : 1.38.0485
                    ProductName : CCleaner
                    CompanyName : Piriform Ltd
                    FileDescription : CCleaner
                    InternalName : ccleaner
                    LegalCopyright : Copyright 2005-2007 Piriform Ltd
                    OriginalFilename : ccleaner.exe
                    Comments : CCleaner

                    #:13 [ad-aware.exe]
                    FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
                    ProcessID : 1336
                    ThreadCreationTime : 20-04-2007 23:51:40
                    BasePriority : Normal
                    FileVersion : 6.2.0.236
                    ProductVersion : SE 106
                    ProductName : Lavasoft Ad-Aware SE
                    CompanyName : Lavasoft Sweden
                    FileDescription : Ad-Aware SE Core application
                    InternalName : Ad-Aware.exe
                    LegalCopyright : Copyright © Lavasoft AB Sweden
                    OriginalFilename : Ad-Aware.exe
                    Comments : All Rights Reserved

                    Résultat de l’analyse de la mémoire :
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    Nouv. obj. critiques : 0
                    Objets détectés jusqu'à présent : 0

                    Analyse du registre démarrée
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Résultat de l’analyse du registre :
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    Nouv. obj. critiques : 0
                    Objets détectés jusqu'à présent : 0

                    Analyse approfondie du registre démarrée
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Résultat de l’analyse approfondie du registre :
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    Nouv. obj. critiques : 0
                    Objets détectés jusqu'à présent : 0

                    Analyse des cookies de suivi lancée
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@ads.addynamix[1].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:1
                    Valeur : Cookie:cyril raclet@ads.addynamix.com/
                    Expires : 21-04-2007 13:55:44
                    LastSync : Hits:1
                    UseCount : 0
                    Hits : 1

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@statcounter[2].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:4
                    Valeur : Cookie:cyril raclet@statcounter.com/
                    Expires : 18-04-2012 15:22:58
                    LastSync : Hits:4
                    UseCount : 0
                    Hits : 4

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@estat[1].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:1
                    Valeur : Cookie:cyril raclet@estat.com/
                    Expires : 17-04-2017 21:29:10
                    LastSync : Hits:1
                    UseCount : 0
                    Hits : 1

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@adultfriendfinder[2].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:3
                    Valeur : Cookie:cyril raclet@adultfriendfinder.com/
                    Expires : 20-05-2007 21:40:02
                    LastSync : Hits:3
                    UseCount : 0
                    Hits : 3

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@hitbox[2].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:8
                    Valeur : Cookie:cyril raclet@hitbox.com/
                    Expires : 19-04-2008 13:51:12
                    LastSync : Hits:8
                    UseCount : 0
                    Hits : 8

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@insightexpressai[1].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:5
                    Valeur : Cookie:cyril raclet@insightexpressai.com/
                    Expires : 20-04-2012 13:54:08
                    LastSync : Hits:5
                    UseCount : 0
                    Hits : 5

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@www.cibleclick[1].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:1
                    Valeur : Cookie:cyril raclet@www.cibleclick.com/
                    Expires : 12-04-2037 21:29:04
                    LastSync : Hits:1
                    UseCount : 0
                    Hits : 1

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@bluestreak[2].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:2
                    Valeur : Cookie:cyril raclet@bluestreak.com/
                    Expires : 17-04-2017 17:33:10
                    LastSync : Hits:2
                    UseCount : 0
                    Hits : 2

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@weborama[2].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:2
                    Valeur : Cookie:cyril raclet@weborama.fr/
                    Expires : 18-04-2012 10:18:58
                    LastSync : Hits:2
                    UseCount : 0
                    Hits : 2

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@banner.goldenpalace[2].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:3
                    Valeur : Cookie:cyril raclet@banner.goldenpalace.com/
                    Expires : 23-04-2007 13:59:06
                    LastSync : Hits:3
                    UseCount : 0
                    Hits : 3

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@doubleclick[2].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:12
                    Valeur : Cookie:cyril raclet@doubleclick.net/
                    Expires : 19-04-2010 13:18:30
                    LastSync : Hits:12
                    UseCount : 0
                    Hits : 12

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@www.smartadserver[1].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:11
                    Valeur : Cookie:cyril raclet@www.smartadserver.com/
                    Expires : 16-04-2027 01:28:40
                    LastSync : Hits:11
                    UseCount : 0
                    Hits : 11

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@247realmedia[1].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:2
                    Valeur : Cookie:cyril raclet@247realmedia.com/
                    Expires : 01-01-2021 02:00:00
                    LastSync : Hits:2
                    UseCount : 0
                    Hits : 2

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@adtech[2].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:2
                    Valeur : Cookie:cyril raclet@adtech.de/
                    Expires : 17-04-2017 21:33:08
                    LastSync : Hits:2
                    UseCount : 0
                    Hits : 2

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@2o7[1].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:151
                    Valeur : Cookie:cyril raclet@2o7.net/
                    Expires : 19-04-2012 00:09:28
                    LastSync : Hits:151
                    UseCount : 0
                    Hits : 151

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@advertising[1].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:1
                    Valeur : Cookie:cyril raclet@advertising.com/
                    Expires : 18-04-2012 00:55:02
                    LastSync : Hits:1
                    UseCount : 0
                    Hits : 1

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@ehg-hollywoodmedia.hitbox[2].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:2
                    Valeur : Cookie:cyril raclet@ehg-hollywoodmedia.hitbox.com/
                    Expires : 19-04-2008 13:47:52
                    LastSync : Hits:2
                    UseCount : 0
                    Hits : 2

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@media.adrevolver[2].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:4
                    Valeur : Cookie:cyril raclet@media.adrevolver.com/adrevolver/
                    Expires : 28-12-2009 06:17:42
                    LastSync : Hits:4
                    UseCount : 0
                    Hits : 4

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@ehg-hollywood.hitbox[2].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:2
                    Valeur : Cookie:cyril raclet@ehg-hollywood.hitbox.com/
                    Expires : 19-04-2008 13:51:12
                    LastSync : Hits:2
                    UseCount : 0
                    Hits : 2

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@adrevolver[1].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:3
                    Valeur : Cookie:cyril raclet@adrevolver.com/
                    Expires : 19-04-2008 06:49:06
                    LastSync : Hits:3
                    UseCount : 0
                    Hits : 3

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@atdmt[2].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:9
                    Valeur : Cookie:cyril raclet@atdmt.com/
                    Expires : 18-04-2012 02:00:00
                    LastSync : Hits:9
                    UseCount : 0
                    Hits : 9

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@mediaplex[1].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:2
                    Valeur : Cookie:cyril raclet@mediaplex.com/
                    Expires : 22-06-2009 02:00:00
                    LastSync : Hits:2
                    UseCount : 0
                    Hits : 2

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@serving-sys[1].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:5
                    Valeur : Cookie:cyril raclet@serving-sys.com/
                    Expires : 01-01-2038
                    LastSync : Hits:5
                    UseCount : 0
                    Hits : 5

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@bs.serving-sys[1].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:1
                    Valeur : Cookie:cyril raclet@bs.serving-sys.com/
                    Expires : 01-01-2038
                    LastSync : Hits:1
                    UseCount : 0
                    Hits : 1

                    Tracking Cookie Objet reconnu !
                    Type : IECache Entry
                    Données : cyril_raclet@zedo[1].txt
                    Notation TAC : 3
                    Catégorie : Data Miner
                    Commentaire : Hits:12
                    Valeur : Cookie:cyril raclet@zedo.com/
                    Expires : 17-04-2017 13:55:40
                    LastSync : Hits:12
                    UseCount : 0
                    Hits : 12

                    Résultat de l’analyse des cookies de suivi :
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    Nouv. obj. critiques : 25
                    Objets détectés jusqu'à présent : 25

                    Analyse et examen approfondis des fichiers...
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Résultat de l’analyse du disque pour C:\WINDOWS
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    Nouv. obj. critiques : 0
                    Objets détectés jusqu'à présent : 25

                    Résultat de l’analyse du disque pour C:\WINDOWS\system32
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    Nouv. obj. critiques : 0
                    Objets détectés jusqu'à présent : 25

                    Résultat de l’analyse du disque pour C:\DOCUME~1\CYRILR~1\LOCALS~1\Temp\
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    Nouv. obj. critiques : 0
                    Objets détectés jusqu'à présent : 25

                    Analyse du fichier Hosts…...
                    Emplacement du fichier Hosts :"C:\WINDOWS\system32\drivers\etc\hosts".
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Résultat d’analyse du fichier Hosts :
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    1 entrées analysées.
                    Nouv. obj. critiques :0
                    Objets détectés jusqu'à présent : 25

                    MRU List Objet reconnu !
                    Emplacement : : C:\Documents and Settings\cyril raclet\recent
                    Description : list of recently opened documents

                    MRU List Objet reconnu !
                    Emplacement : : S-1-5-21-2185542506-2417831049-1098800765-1005\software\microsoft\windows media\wmsdk\general
                    Description : windows media sdk

                    Analyses conditionnelles en cours...
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                    Résultat d’analyse conditionnelle :
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    Nouv. obj. critiques : 0
                    Objets détectés jusqu'à présent : 27

                    01:54:52 Analyse terminée

                    Récap. de cette anal.
                    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                    Durée tot. analyse :00:03:00.453
                    Objets analysés :90622
                    Objets identifiés :25
                    Objets ignorés :0
                    Nouv. obj. critiques :25

                    rapport avec AVG:

                    VG Anti-Spyware - Rapport d'analyse
                    ---------------------------------------------------------

                    + Créé à: 02:07:00 21/04/2007

                    + Résultat de l'analyse:

                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@247realmedia[1].txt -> TrackingCookie.247realmedia : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@adrevolver[1].txt -> TrackingCookie.Adrevolver : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@adtech[2].txt -> TrackingCookie.Adtech : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@atdmt[2].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@bluestreak[2].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@doubleclick[2].txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@estat[1].txt -> TrackingCookie.Estat : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@banner.goldenpalace[2].txt -> TrackingCookie.Goldenpalace : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@goldenpalace[2].txt -> TrackingCookie.Goldenpalace : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@ehg-hollywood.hitbox[2].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@ehg-hollywoodmedia.hitbox[2].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@hitbox[2].txt -> TrackingCookie.Hitbox : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@mediaplex[1].txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@statcounter[2].txt -> TrackingCookie.Statcounter : Aucune action entreprise.
                    C:\Documents and Settings\cyril raclet\Cookies\cyril_raclet@zedo[1].txt -> TrackingCookie.Zedo : Aucune action entreprise.

                    Fin du rapport

                    Voili voilou

                    je constate que j'ai de + en +de problèmes: lenteur du pc et problèmes de connection a internet.

                    c'est grave docteur???
                    help plizzzz

                    merci bye
                    0
                    1. ca commence a le devenir, normalement avast aurait du les neutraliser avant l'infection, un problème de mise ajour probablement; le hic c que c un ver que tu as, il faut d'abord faire un nettoyage avec CCleaner pour éliminer les cookies indésirables, voir aussi cbien fichiers ils ne peut éliminer(dans chercher des erreurs) si ton pc ralentit trop désinstalle tout sf avast et le pare feu et fais une restauration, ensuite faire un scan avec avg rootkit et coller un rapport, plus un hijackthis pour repérer la clé de registre infectée et qui se lance au démarrage; pour la suite il faudra des utilitaires spéciaux et peu etre changer de "docteur" car cela dépassera mes "pouvoirs"; mais ne désespère pas le stud c qu'il ne faut plus se tromper dans la suite pour ne plus aggraver le cas, a+
                      0
                      1. Contributeur sécurité
                        Bonjour baby77,

                        oublie tout ce que l'on t'a conseillé jusqu'à présent;

                        1) Rends toi sur ce site :
                        http://www.virustotal.com/xhtml/virustotal_en.html

                        Clique sur parcourir et cherche ce fichier : C:\WINDOWS\system32\uyrxacnc.dll

                        Clique sur send.

                        Un rapport va s'élaborer ligne à ligne.

                        Attends la fin. Il doit comprendre la taille du fichier envoyé.

                        Sauvegarde le rapport avec le bloc-note.

                        Copie le dans ta réponse.

                        2) Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
                        http://www.atribune.org/ccount/click.php?id=4
                        Double-clique VundoFix.exe afin de le lancer.

                        Clique sur le bouton Scan for Vundo.
                        Lorsque le scan est complété, clique sur le bouton Remove Vundo.
                        Une invite te demandera si tu veux supprimer les fichiers, clique YES
                        Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
                        Tu verras une invite qui t'annonce que ton PC va s'éteindre ("shutdown") ; clique OK
                        Démarre ton PC à nouveau.

                        3) Remets un log (un rapport) Hijackthis

                        @+
                        0
                        1. merci pour le conseil!!

                          je vais faire ca tout de suite...
                          0
                          1. bon, alors pour virus total, il me dit:

                            Your file "uyrxacnc.dll" is queued in position: 12. Estimated start time is between 140 and 200 seconds.

                            STATUTS: QUEUED
                            je dois faire quelquechose????

                            j'attend la fin du scan VUNDO.....
                            0
                            1. Alors...
                              Y a du nouveau...

                              A lafin du scan vundo il me dit:

                              c:\windows\system32\mljgh.dll could not be detected, vundofx will load on reboot to attempt removal. Please click remove vundo once your machine has rebooted.

                              c'est normal?? et quand mon ordi a redémarré il me dit un message d'erreur comme quoi explorer ne trouve pas vundo ou quelquechose comme ca (j'ai pas eu le temps d noter)

                              De plus, quand l'ordi a redémarré, avast a trouvé quelquechose:

                              c:\DOCUME~1\CYRILR~1\LOCALS~1\Temp\eredilmm.dll
                              infecté par Win32:VBStat-C

                              je l'ai mis en quarantaine.

                              voici le log:

                              Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                              Scan saved at 13:30:25, on 21/04/2007
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\csrss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\system32\msdtc.exe
                              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              C:\WINDOWS\eHome\ehRecvr.exe
                              C:\WINDOWS\eHome\ehSched.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                              c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
                              C:\WINDOWS\system32\nvsvc32.exe
                              C:\WINDOWS\system32\HPZipm12.exe
                              C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                              c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
                              c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\mqsvc.exe
                              C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                              C:\WINDOWS\ehome\mcrdsvc.exe
                              C:\Program Files\Windows Media Player\WMPNetwk.exe
                              C:\WINDOWS\system32\mqtgsvc.exe
                              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              C:\WINDOWS\system32\dllhost.exe
                              C:\WINDOWS\System32\alg.exe
                              C:\WINDOWS\ehome\ehtray.exe
                              C:\WINDOWS\eHome\ehmsas.exe
                              C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                              C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
                              C:\WINDOWS\system32\wbem\wmiprvse.exe
                              C:\WINDOWS\system32\RUNDLL32.EXE
                              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              C:\Program Files\HP\QuickPlay\QPService.exe
                              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
                              C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
                              C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
                              C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
                              C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                              C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
                              C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                              C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Windows Media Player\WMPNSCFG.exe
                              C:\PROGRA~1\FICHIE~1\PCSuite\Services\SERVIC~1.EXE
                              C:\Program Files\HiJackThis_v2.exe
                              C:\WINDOWS\system32\wbem\wmiprvse.exe
                              C:\Program Files\Internet Explorer\iexplore.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - (no file)
                              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O2 - BHO: (no name) - {6148028B-D532-4417-8C0B-5A4A0B745393} - C:\WINDOWS\system32\byxvuss.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O2 - BHO: (no name) - {8F3A4756-B8DE-4E80-AFB1-8B32CF6894Ef} - C:\WINDOWS\system32\uyrxacnc.dll
                              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: (no name) - {94F71B07-2EFA-40D7-A9FF-C167E4ECDA34} - C:\WINDOWS\system32\mljgh.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                              O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                              O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                              O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
                              O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
                              O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
                              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                              O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
                              O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
                              O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                              O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
                              O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
                              O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
                              O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                              O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                              O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                              O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                              O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\ydkexqjj.dll",setvm
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                              O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                              O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
                              O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
                              O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} - https://www.snapfish.fr/2/home
                              O16 - DPF: {5308E02B-4ABA-48E4-AA9E-8A7693661473} (GameCtl Class) - http://jeuxenligne.orange.fr/GisActiveX/Ax/GameAx.cab
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                              O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
                              O16 - DPF: {C9E17F58-564C-41C6-989F-AB0FE0D2C9D1} (PopcapLoader Object) - http://jeuxenligne.orange.fr/orange2.0/OnlineHSS/zuma/Popcap.cab
                              O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs-beta.jeu.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
                              O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://fortunelounge.microgaming.com/generic/FlashAX.cab
                              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                              O20 - Winlogon Notify: byxvuss - C:\WINDOWS\SYSTEM32\byxvuss.dll
                              O20 - Winlogon Notify: mljgh - C:\WINDOWS\system32\mljgh.dll
                              O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                              O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                              O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
                              O23 - Service: Service de planification Media Center (ehSched) - Unknown owner - C:\WINDOWS\eHome\ehSched.exe
                              O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
                              O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                              O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                              O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
                              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                              O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
                              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                              O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
                              O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                              O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                              O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
                              O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                              O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
                              O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                              O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
                              O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
                              O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
                              0
                              1. oups je recommence j'avais pas vu que virus total étai pas fini dsl....

                                j'ai voulu aller trop vite, et moi quand c'est pas en francais....
                                0
                                1. donc, le scan virustotal dit:

                                  Complete scanning result of "uyrxacnc.dll", received in VirusTotal at 04.21.2007, 13:50:26 (CET).

                                  Antivirus Version Update Result
                                  AhnLab-V3 2007.4.21.0 04.20.2007 no virus found
                                  AntiVir 7.3.1.53 04.20.2007 TR/Agent.125460
                                  Authentium 4.93.8 04.20.2007 no virus found
                                  Avast 4.7.981.0 04.21.2007 no virus found
                                  AVG 7.5.0.464 04.20.2007 no virus found
                                  BitDefender 7.2 04.21.2007 no virus found
                                  CAT-QuickHeal 9.00 04.20.2007 no virus found
                                  ClamAV devel-20070416 04.21.2007 no virus found
                                  DrWeb 4.33 04.21.2007 no virus found
                                  eSafe 7.0.15.0 04.19.2007 Suspicious Trojan/Worm
                                  eTrust-Vet 30.7.3585 04.21.2007 no virus found
                                  Ewido 4.0 04.20.2007 no virus found
                                  FileAdvisor 1 04.21.2007 no virus found
                                  Fortinet 2.85.0.0 04.21.2007 no virus found
                                  F-Prot 4.3.2.48 04.20.2007 no virus found
                                  F-Secure 6.70.13030.0 04.21.2007 no virus found
                                  Ikarus T3.1.1.5 04.21.2007 MalwareScope.Trojan-Spy.BZub.1
                                  Kaspersky 4.0.2.24 04.21.2007 no virus found
                                  McAfee 5014 04.20.2007 no virus found
                                  Microsoft 1.2405 04.21.2007 no virus found
                                  NOD32v2 2208 04.21.2007 Win32/Adware.BHO.NAW
                                  Norman 5.80.02 04.20.2007 no virus found
                                  Panda 9.0.0.4 04.21.2007 Suspicious file
                                  Prevx1 V2 04.21.2007 no virus found
                                  Sophos 4.16.0 04.20.2007 no virus found
                                  Sunbelt 2.2.907.0 04.19.2007 no virus found
                                  Symantec 10 04.21.2007 Infostealer
                                  TheHacker 6.1.6.095 04.15.2007 no virus found
                                  VBA32 3.11.4 04.21.2007 Application.Win32.Adware.BHO.NAW
                                  VirusBuster 4.3.7:9 04.20.2007 no virus found
                                  Webwasher-Gateway 6.0.1 04.21.2007 Trojan.Agent.125460

                                  Aditional Information
                                  File size: 125460 bytes
                                  MD5: b840916f694b8d6eab2e7b8fee725b2e
                                  SHA1: 1669844d422218d2ff5e1464d50ca2b44fe4129d
                                  packers: MORPHINE

                                  je reposte un log??
                                  0
                                  1. bon je remets un nouveau log, parce que je'ai vu que j'avais tout fait de travers....

                                    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                                    Scan saved at 14:17:17, on 21/04/2007
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    C:\WINDOWS\eHome\ehRecvr.exe
                                    C:\WINDOWS\eHome\ehSched.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                    C:\WINDOWS\system32\nvsvc32.exe
                                    C:\WINDOWS\system32\HPZipm12.exe
                                    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\mqsvc.exe
                                    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                    C:\WINDOWS\system32\mqtgsvc.exe
                                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    C:\WINDOWS\system32\dllhost.exe
                                    C:\WINDOWS\ehome\ehtray.exe
                                    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                                    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
                                    C:\WINDOWS\eHome\ehmsas.exe
                                    C:\WINDOWS\system32\RUNDLL32.EXE
                                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                    C:\Program Files\HP\QuickPlay\QPService.exe
                                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
                                    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
                                    C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
                                    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
                                    C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE
                                    C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                                    C:\WINDOWS\system32\wuauclt.exe
                                    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                    C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                                    C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
                                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                    C:\PROGRA~1\FICHIE~1\PCSuite\Services\SERVIC~1.EXE
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Program Files\HiJackThis_v2.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - (no file)
                                    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O2 - BHO: (no name) - {6148028B-D532-4417-8C0B-5A4A0B745393} - C:\WINDOWS\system32\byxvuss.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                    O2 - BHO: (no name) - {8F3A4756-B8DE-4E80-AFB1-8B32CF6894Ef} - C:\WINDOWS\system32\uyrxacnc.dll
                                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: (no name) - {94F71B07-2EFA-40D7-A9FF-C167E4ECDA34} - C:\WINDOWS\system32\mljgh.dll (file missing)
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                                    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
                                    O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
                                    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
                                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                                    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
                                    O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
                                    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                                    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
                                    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
                                    O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.EXE -autorun
                                    O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                                    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                                    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                                    O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\ydkexqjj.dll",setvm
                                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                                    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                                    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                                    O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
                                    O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
                                    O16 - DPF: {2EF3FB47-7B1E-4536-BA4D-51427BD45DFA} - https://www.snapfish.fr/2/home
                                    O16 - DPF: {5308E02B-4ABA-48E4-AA9E-8A7693661473} (GameCtl Class) - http://jeuxenligne.orange.fr/GisActiveX/Ax/GameAx.cab
                                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                                    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                                    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                                    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                                    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                                    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
                                    O16 - DPF: {C9E17F58-564C-41C6-989F-AB0FE0D2C9D1} (PopcapLoader Object) - http://jeuxenligne.orange.fr/orange2.0/OnlineHSS/zuma/Popcap.cab
                                    O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs-beta.jeu.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
                                    O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://fortunelounge.microgaming.com/generic/FlashAX.cab
                                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                                    O20 - Winlogon Notify: byxvuss - C:\WINDOWS\SYSTEM32\byxvuss.dll
                                    O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                                    O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                                    O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
                                    O23 - Service: Service de planification Media Center (ehSched) - Unknown owner - C:\WINDOWS\eHome\ehSched.exe
                                    O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
                                    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                    O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
                                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                    O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
                                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                    O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
                                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                    O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
                                    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                    O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
                                    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                    O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
                                    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                    O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
                                    O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                    O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
                                    0
                                    1. Contributeur sécurité
                                      Bonjour,

                                      1) rends toi sur ce site :
                                      http://secubox.gateweb.org/mad.php

                                      clique sur parcourir et cherche C:\WINDOWS\system32\uyrxacnc.dll

                                      dans le message (fenêtre en dessous), mets ceci :
                                      "Lyonnais92 de ccm a demandé que ce fichier infecté par MalwareScope.Trojan-Spy.BZub.1
                                      selon Ikarus vous soit envoyé. I n'a pas le même MD5 que celui identifié dans votre base de données. référence du post : probleme de pop up et trojan surement "

                                      2) Télécharge VirtumundoBegone sur le bureau:
                                      http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

                                      Double clique ensuite sur VirtumundoBeGone.exe et suis les instructions.
                                      Une fois terminé, redémarre et poste le rapport VBG.TXT créé sur le bureau dans ta prochaine réponse avec un nouveau rapport HijackThis.
                                      Ne t'inquiète pas si tu vois un message Ecran bleu "Erreur fatale", c'est normal et attendu

                                      3) soumets aussi à Virustotal ce fichier :
                                      C:\WINDOWS\system32\ydkexqjj.dll

                                      4) remets un rapport Hijackthis

                                      @+
                                      0
                                      1. euh....c'est normal que ce soit aussi long l'étape1??

                                        au bout d'un moment il me dit "impossible d'afficher la page, blablabla..."

                                        je peux passer direct a l'étape2??
                                        0
                                    2. Contributeur sécurité
                                      Re,

                                      oui, passe à l'étape suivante.

                                      Quand tu auras fini, rends toi ici :
                                      http://www.malekal.com/Trojan.Zapchast.CA_Trojan-Spy.BZub.1.php.

                                      fais ce qui est entre :
                                      Suppression Trojan.Zapchast.CA / Trojan-Spy.BZub.1
                                      Téléchargez clean.zip ...

                                      et

                                      Afin de supprimer toutes traces du spyware et d'autres élements qu'il aurait pu installer, scannez votre ordinateur avec :
                                      AVG Antispyware : anti-malware recommandé
                                      Redémarrez l'ordinateur

                                      Tu postes tous les rapports des outils (en particulier clean et SDFix)

                                      et tu remets un rapport Hijackthis.
                                      @+
                                      0
                                      • 1
                                      • 2