Pb virus internet

Bonjour,

Depuis déjà plusieurs semaines j'ai des virus (cheval de troie, logiciels espions et malveillants...) sur mon ordinatuer ainsi que sans arrêt l'affichage de page intempestive "Drive cleaner" qui sont des virus. J'ai essayé de m'en débarasser avec Avast, Ccleaner, spyware doctor mais rien n'y fait mon pc est de plus en plus lent et jen ai assez. Ne sacahant plus trop quoi faire je m'adresse a vous en vous demandant votre aide svp. Je suis loin d'être un expert en informatique.

En attendant votre réponse je vous remercie encore

Jeremich56@wanadoo.fr
Configuration: Windows XP
Internet Explorer 7.0

28 réponses

Résumé de la discussion

Le fil porte sur une infection informatique sous Windows XP associant cheval de Troie, logiciels espions et affichages intempestifs de Drive Cleaner qui ralentissent significativement l’ordinateur. Plusieurs conseils visent à identifier et supprimer les composants malveillants grâce à des outils spécialisés et à des nettoyages manuels, notamment HiJackThis, ComboFix et des rapports d’analyse. Des propositions couvrent la suppression de processus et fichiers douteux, la vérification des entrées de démarrage et des éléments de registre, ainsi que des scans en mode sans échec. En cas de persistance, certains participants recommandent d’établir un plan de nettoyage progressif et de surveiller les restes potentiels dans l’historique des cookies et des fichiers temporaires.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut

    Télécharge ceci sur ton bureau :

    Lien : hijackthis

    Démo : http://pageperso.aol.fr/balltrap34/demohijack.htm

    Choisir l'option "do a scan and a logfile", et faire un copier/coller du rapport ainsi générer sur le forum.

    ++
    0
    1. Voici le rapport :

      Logfile of Trend Micro HijackThis v2.0.0 (BETA)
      Scan saved at 14:01:08, on 21/04/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\Program Files\Spyware Doctor\svcntaux.exe
      C:\Program Files\Spyware Doctor\swdsvc.exe
      C:\WINDOWS\system32\svchost.exe
      c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Spyware Doctor\SDTrayApp.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\alg.exe
      C:\windows\system\hpsysdrv.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\ALCXMNTR.EXE
      C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\HP\KBD\KBD.EXE
      C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
      C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\PROGRA~1\Wanadoo\Watch.exe
      C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
      C:\Program Files\MSN Messenger\usnsvc.exe
      C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
      C:\Program Files\Outlook Express\msimn.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Documents and Settings\HP_Propriétaire\Bureau\HiJackThis_v2.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://store.hp.com/us/en?jumpid=re_r11662_redirect_ETR
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {120B37D9-0A98-4CF5-B25A-A255635D53D0} - C:\WINDOWS\system32\geede.dll
      O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\qlluclsp.dll
      O2 - BHO: (no name) - {733FD72F-103E-4B9E-BCB9-A76064AF3C72} - C:\WINDOWS\system32\gebyabb.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
      O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
      O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\itdyidub.dll",setvm
      O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
      O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
      O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
      O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{34CB4B96-6783-4D74-AC33-1375619936AA}: NameServer = 80.10.246.1 80.10.246.132
      O17 - HKLM\System\CS1\Services\Tcpip\..\{34CB4B96-6783-4D74-AC33-1375619936AA}: NameServer = 80.10.246.1 80.10.246.132
      O20 - Winlogon Notify: gebyabb - C:\WINDOWS\SYSTEM32\gebyabb.dll
      O20 - Winlogon Notify: geede - C:\WINDOWS\system32\geede.dll
      O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
      O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
      O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
      O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
      O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
      O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
      O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
      O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
      O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
      O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
      O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
      O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files\Spyware Doctor\svcntaux.exe
      O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
      O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
      O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
      O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
      O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
      0
      1. Modérateur
        Suite !

        Téléchargez VundoFix.exe (par Atribune) sur ton Bureau :

        http://www.atribune.org/ccount/click.php?id=4

        *Double-clique VundoFix.exe afin de le lancer.
        * Cliquez sur le bouton Scan for Vundo.
        * Lorsque le scan est complété, cliquez sur le bouton Remove Vundo.
        * Une invite vous demandera supprimer les fichiers, clique YES
        * Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
        * le PC va s'éteindre ("shutdown") : clique OK
        * Démarrez votre PC à nouveau
        * Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis! dans ta prochaine réponse.

        ++

        La sagesse, c'est d'avoir des rêves suffisamment grands pour ne pas les
        perdre de vue lorsqu'on les poursuit. (Oscar Wilde)
        0
        1. salut green day ,
          juste une question pour Jeremich,
          c:\Program Files\Fichiers communs\Symantec Shared\Security Center
          tu as un anti-virus dans ton Security center ? tu as un fire-wall ?
          -------------------------------------------------------------------------
          (j'ai vu que tu Avast, ok)
          0
          1. autant pour-moi...LOL
            http://www.superadblocker.com/definition/symwsc/
            ----------------------------
            apparement il inclus un anti-virus ?
            http://service1.symantec.com/SUPPORT/nip.nsf/docid/2002090916035536
            --------------------------------------------------------
            je fais une erreur ?
            0
            1. VundoFix V6.3.19

              Checking Java version...

              Java version is 1.5.0.9
              Old versions of java are exploitable and should be removed.

              Scan started at 15:52:39 22/04/2007

              Listing files found while scanning....

              C:\WINDOWS\system32\bkboxlgw.dll
              C:\WINDOWS\system32\budiydti.ini
              C:\WINDOWS\system32\edeeg.bak1
              C:\WINDOWS\system32\edeeg.bak2
              C:\WINDOWS\system32\edeeg.ini
              C:\WINDOWS\system32\edeeg.ini2
              C:\WINDOWS\system32\edeeg.tmp
              C:\WINDOWS\system32\gebyabb.dll
              C:\WINDOWS\system32\geede.dll
              C:\WINDOWS\system32\iajsddpu.dll
              C:\WINDOWS\system32\idpqbycb.dll
              C:\WINDOWS\system32\imrnotsv.dll
              C:\WINDOWS\system32\inrushjs.dll
              C:\WINDOWS\system32\itdyidub.dll
              C:\WINDOWS\system32\kccpgfkd.dll
              C:\WINDOWS\system32\mcsphway.dll
              C:\WINDOWS\system32\mjopwubb.dll
              C:\WINDOWS\system32\nivagsyb.dll
              C:\WINDOWS\system32\ptfvarem.dll
              C:\WINDOWS\system32\qyjukrht.ini
              C:\WINDOWS\system32\thrkujyq.dll

              Beginning removal...

              Attempting to delete C:\WINDOWS\system32\bkboxlgw.dll
              C:\WINDOWS\system32\bkboxlgw.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\budiydti.ini
              C:\WINDOWS\system32\budiydti.ini Has been deleted!

              Attempting to delete C:\WINDOWS\system32\edeeg.bak1
              C:\WINDOWS\system32\edeeg.bak1 Has been deleted!

              Attempting to delete C:\WINDOWS\system32\edeeg.bak2
              C:\WINDOWS\system32\edeeg.bak2 Has been deleted!

              Attempting to delete C:\WINDOWS\system32\edeeg.ini
              C:\WINDOWS\system32\edeeg.ini Has been deleted!

              Attempting to delete C:\WINDOWS\system32\edeeg.ini2
              C:\WINDOWS\system32\edeeg.ini2 Has been deleted!

              Attempting to delete C:\WINDOWS\system32\edeeg.tmp
              C:\WINDOWS\system32\edeeg.tmp Has been deleted!

              Attempting to delete C:\WINDOWS\system32\gebyabb.dll
              C:\WINDOWS\system32\gebyabb.dll Could not be deleted.

              Attempting to delete C:\WINDOWS\system32\geede.dll
              C:\WINDOWS\system32\geede.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\iajsddpu.dll
              C:\WINDOWS\system32\iajsddpu.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\idpqbycb.dll
              C:\WINDOWS\system32\idpqbycb.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\imrnotsv.dll
              C:\WINDOWS\system32\imrnotsv.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\inrushjs.dll
              C:\WINDOWS\system32\inrushjs.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\itdyidub.dll
              C:\WINDOWS\system32\itdyidub.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\kccpgfkd.dll
              C:\WINDOWS\system32\kccpgfkd.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\mcsphway.dll
              C:\WINDOWS\system32\mcsphway.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\mjopwubb.dll
              C:\WINDOWS\system32\mjopwubb.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\nivagsyb.dll
              C:\WINDOWS\system32\nivagsyb.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\ptfvarem.dll
              C:\WINDOWS\system32\ptfvarem.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\qyjukrht.ini
              C:\WINDOWS\system32\qyjukrht.ini Has been deleted!

              Attempting to delete C:\WINDOWS\system32\thrkujyq.dll
              C:\WINDOWS\system32\thrkujyq.dll Has been deleted!

              Performing Repairs to the registry.
              Done!

              Logfile of Trend Micro HijackThis v2.0.0 (BETA)
              Scan saved at 19:22:59, on 23/04/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
              C:\WINDOWS\System32\FTRTSVC.exe
              C:\Program Files\Spyware Doctor\svcntaux.exe
              C:\windows\system\hpsysdrv.exe
              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\Program Files\Spyware Doctor\swdsvc.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\WINDOWS\ALCXMNTR.EXE
              C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\HP\KBD\KBD.EXE
              C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
              C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
              C:\WINDOWS\system32\rundll32.exe
              C:\Program Files\Spyware Doctor\SDTrayApp.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
              C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              C:\Program Files\MSN Messenger\msnmsgr.exe
              c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
              C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
              C:\PROGRA~1\Wanadoo\ComComp.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              C:\PROGRA~1\Wanadoo\Toaster.exe
              C:\PROGRA~1\Wanadoo\Inactivity.exe
              C:\PROGRA~1\Wanadoo\PollingModule.exe
              C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
              C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
              C:\PROGRA~1\Wanadoo\Watch.exe
              C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\WINDOWS\System32\alg.exe
              C:\Program Files\Outlook Express\msimn.exe
              C:\Documents and Settings\HP_Propriétaire\Bureau\HiJackThis_v2.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://store.hp.com/us/en?jumpid=re_r11662_redirect_ETR
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\qlluclsp.dll
              O2 - BHO: (no name) - {63BE68FF-FE93-4822-818B-B6FDEE03523A} - C:\WINDOWS\system32\geede.dll (file missing)
              O2 - BHO: (no name) - {733FD72F-103E-4B9E-BCB9-A76064AF3C72} - C:\WINDOWS\system32\gebyabb.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: (no name) - {8BD3FF4F-6BC2-4206-A64D-6AB8BD2F048E} - C:\WINDOWS\system32\mljgh.dll
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
              O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
              O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
              O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
              O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
              O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
              O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
              O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\itdyidub.dll",setvm
              O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
              O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\dfytqiua.dll",setvm
              O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
              O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
              O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
              O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
              O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
              O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
              O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
              O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
              O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
              O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{34CB4B96-6783-4D74-AC33-1375619936AA}: NameServer = 80.10.246.130 80.10.246.3
              O17 - HKLM\System\CS1\Services\Tcpip\..\{34CB4B96-6783-4D74-AC33-1375619936AA}: NameServer = 80.10.246.130 80.10.246.3
              O20 - Winlogon Notify: mljgh - C:\WINDOWS\system32\mljgh.dll
              O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
              O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
              O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
              O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
              O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
              O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
              O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
              O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
              O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
              O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
              O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
              O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
              O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files\Spyware Doctor\svcntaux.exe
              O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
              O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
              O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
              O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
              O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
              O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
              0
              1. J'ai également un autre petit souci moins grave mé c'est comme même chiant ! En fait c'est avec MSN je ne sais pas pourquoi toutes les émoticones ne s'affiche plus ?

                Merci encore
                0
                1. Modérateur
                  Salut

                  fais les manips de ce lien stp :

                  virus methode preliminaire de desinfection version fr

                  ++
                  0
                  1. ---------------------------------------------------------
                    AVG Anti-Spyware - Rapport d'analyse
                    ---------------------------------------------------------

                    + Créé à: 14:51:34 01/05/2007

                    + Résultat de l'analyse:

                    HKU\S-1-5-21-1558018719-2868653155-1144433344-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{56F1D444-11BF-4879-A12B-79CF0177F038} -> Adware.180Solutions : Ignoré.
                    C:\Program Files\Error Safe Free\FWraper.dll -> Adware.ErrorSafe : Ignoré.
                    C:\Program Files\Error Safe Free\FxCore.dll -> Adware.ErrorSafe : Ignoré.
                    C:\Program Files\Error Safe Free\InstHelp.exe -> Adware.ErrorSafe : Ignoré.
                    C:\Program Files\Error Safe Free\MMFx.dll -> Adware.ErrorSafe : Ignoré.
                    C:\Program Files\Error Safe Free\emptyERSF.exe -> Adware.ErrorSafe : Ignoré.
                    HKLM\SOFTWARE\WinAntiSpyware 2006 Scanner -> Adware.WinAntiSpyware : Ignoré.
                    C:\Program Files\Error Safe Free\Updater.exe -> Adware.WinFixer : Ignoré.
                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP343\A0163829.exe -> Logger.Winflyer : Ignoré.
                    C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@www.paypal[1].txt -> TrackingCookie.Paypal : Ignoré.
                    C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@weborama[1].txt -> TrackingCookie.Weborama : Ignoré.

                    Fin du rapport

                    BitDefender Online Scanner

                    Rapport d'analyse généré à: Wed, May 02, 2007 - 20:35:27

                    Voie d'analyse: C:\;D:\;E:\;F:\;G:\;H:\;I:\;

                    Statistiques

                    Temps
                    03:51:12

                    Fichiers
                    529605

                    Directoires
                    6977

                    Secteurs de boot
                    3

                    Archives
                    17584

                    Paquets programmes
                    56758

                    Résultats

                    Virus identifiés
                    8

                    Fichiers infectés
                    33

                    Fichiers suspects
                    0

                    Avertissements
                    0

                    Désinfectés
                    0

                    Fichiers effacés
                    29

                    Info sur les moteurs

                    Définition virus
                    503616

                    Version des moteurs
                    AVCORE v1.0 (build 2397) (i386) (Feb 8 2007 14:24:08)

                    Analyse des plugins
                    14

                    Archive des plugins
                    38

                    Unpack des plugins
                    6

                    E-mail plugins
                    6

                    Système plugins
                    1

                    Paramètres d'analyse

                    Première action
                    Désinfecté

                    Seconde Action
                    Supprimé

                    Heuristique
                    Oui

                    Acceptez les avertissements
                    Oui

                    Extensions analysées
                    *;

                    Excludez les extensions

                    Analyse d'emails
                    Oui

                    Analyse des Archives
                    Oui

                    Analyser paquets programmes
                    Oui

                    Analyse des fichiers
                    Oui

                    Analyse de boot
                    Oui

                    Fichier analysé
                    Statut

                    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WR34TBW5\lo1[1]
                    Infecté par: MemScan:Trojan.Vundo.AP

                    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WR34TBW5\lo1[1]
                    Echec de la désinfection

                    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WR34TBW5\lo1[1]
                    Supprimé

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178718.dll
                    Infecté par: Trojan.Vundo.AN

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178718.dll
                    Echec de la désinfection

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178718.dll
                    Supprimé

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178721.dll
                    Infecté par: Trojan.Virtumod.KE

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178721.dll
                    Echec de la désinfection

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178721.dll
                    Supprimé

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178722.dll
                    Infecté par: Trojan.Vundo.AN

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178722.dll
                    Echec de la désinfection

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178722.dll
                    Supprimé

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178723.dll
                    Infecté par: Trojan.Vundo.AN

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178723.dll
                    Echec de la désinfection

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178723.dll
                    Supprimé

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178724.dll
                    Infecté par: Trojan.Vundo.AN

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178724.dll
                    Echec de la désinfection

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178724.dll
                    Supprimé

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178725.dll
                    Infecté par: Trojan.Virtumod.JB

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178725.dll
                    Echec de la désinfection

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178725.dll
                    Supprimé

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178726.dll
                    Infecté par: Trojan.Vundo.AN

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178726.dll
                    Echec de la désinfection

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178726.dll
                    Supprimé

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178727.dll
                    Infecté par: Trojan.Vundo.AN

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178727.dll
                    Echec de la désinfection

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178727.dll
                    Supprimé

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178728.dll
                    Infecté par: Trojan.Vundo.AN

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178728.dll
                    Echec de la désinfection

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178728.dll
                    Supprimé

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178729.dll
                    Infecté par: Trojan.BHO.AU

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178729.dll
                    Echec de la désinfection

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178729.dll
                    Supprimé

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178730.dll
                    Infecté par: Trojan.Vundo.AN

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178730.dll
                    Echec de la désinfection

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178730.dll
                    Supprimé

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP366\A0179110.dll
                    Infecté par: Trojan.Vundo.AN

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP366\A0179110.dll
                    Echec de la désinfection

                    C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP366\A0179110.dll
                    Supprimé

                    C:\VundoFix Backups\bkboxlgw.dll.bad
                    Infecté par: Trojan.Vundo.AN

                    C:\VundoFix Backups\bkboxlgw.dll.bad
                    Echec de la désinfection

                    C:\VundoFix Backups\bkboxlgw.dll.bad
                    Supprimé

                    C:\VundoFix Backups\gebyabb.dll.bad
                    Infecté par: MemScan:Trojan.Vundo.AJ

                    C:\VundoFix Backups\gebyabb.dll.bad
                    Echec de la désinfection

                    C:\VundoFix Backups\gebyabb.dll.bad
                    Supprimé

                    C:\VundoFix Backups\iajsddpu.dll.bad
                    Infecté par: Trojan.Virtumod.KE

                    C:\VundoFix Backups\iajsddpu.dll.bad
                    Echec de la désinfection

                    C:\VundoFix Backups\iajsddpu.dll.bad
                    Supprimé

                    C:\VundoFix Backups\idpqbycb.dll.bad
                    Infecté par: Trojan.Vundo.AN

                    C:\VundoFix Backups\idpqbycb.dll.bad
                    Echec de la désinfection

                    C:\VundoFix Backups\idpqbycb.dll.bad
                    Supprimé

                    C:\VundoFix Backups\imrnotsv.dll.bad
                    Infecté par: Trojan.Vundo.AN

                    C:\VundoFix Backups\imrnotsv.dll.bad
                    Echec de la désinfection

                    C:\VundoFix Backups\imrnotsv.dll.bad
                    Supprimé

                    C:\VundoFix Backups\inrushjs.dll.bad
                    Infecté par: Trojan.Vundo.AN

                    C:\VundoFix Backups\inrushjs.dll.bad
                    Echec de la désinfection

                    C:\VundoFix Backups\inrushjs.dll.bad
                    Supprimé

                    C:\VundoFix Backups\itdyidub.dll.bad
                    Infecté par: Trojan.Virtumod.JB

                    C:\VundoFix Backups\itdyidub.dll.bad
                    Echec de la désinfection

                    C:\VundoFix Backups\itdyidub.dll.bad
                    Supprimé

                    C:\VundoFix Backups\kccpgfkd.dll.bad
                    Infecté par: Trojan.Vundo.AN

                    C:\VundoFix Backups\kccpgfkd.dll.bad
                    Echec de la désinfection

                    C:\VundoFix Backups\kccpgfkd.dll.bad
                    Supprimé

                    C:\VundoFix Backups\mcsphway.dll.bad
                    Infecté par: Trojan.Vundo.AN

                    C:\VundoFix Backups\mcsphway.dll.bad
                    Echec de la désinfection

                    C:\VundoFix Backups\mcsphway.dll.bad
                    Supprimé

                    C:\VundoFix Backups\mjopwubb.dll.bad
                    Infecté par: Trojan.Vundo.AN

                    C:\VundoFix Backups\mjopwubb.dll.bad
                    Echec de la désinfection

                    C:\VundoFix Backups\mjopwubb.dll.bad
                    Supprimé

                    C:\VundoFix Backups\nivagsyb.dll.bad
                    Infecté par: Trojan.BHO.AU

                    C:\VundoFix Backups\nivagsyb.dll.bad
                    Echec de la désinfection

                    C:\VundoFix Backups\nivagsyb.dll.bad
                    Supprimé

                    C:\VundoFix Backups\ptfvarem.dll.bad
                    Infecté par: Trojan.Vundo.AN

                    C:\VundoFix Backups\ptfvarem.dll.bad
                    Echec de la désinfection

                    C:\VundoFix Backups\ptfvarem.dll.bad
                    Supprimé

                    C:\VundoFix Backups\thrkujyq.dll.bad
                    Infecté par: Trojan.Vundo.AN

                    C:\VundoFix Backups\thrkujyq.dll.bad
                    Echec de la désinfection

                    C:\VundoFix Backups\thrkujyq.dll.bad
                    Supprimé

                    C:\WINDOWS\system32\gebyabb.dll
                    Infecté par: MemScan:Trojan.Vundo.AJ

                    C:\WINDOWS\system32\gebyabb.dll
                    Echec de la désinfection

                    C:\WINDOWS\system32\gebyabb.dll
                    Echec de la suppression

                    C:\WINDOWS\system32\lfwwgggh.dll
                    Infecté par: Trojan.Vundo.AN

                    C:\WINDOWS\system32\lfwwgggh.dll
                    Echec de la désinfection

                    C:\WINDOWS\system32\lfwwgggh.dll
                    Supprimé

                    C:\WINDOWS\system32\mljgh.dll
                    Infecté par: MemScan:Trojan.Vundo.AP

                    C:\WINDOWS\system32\mljgh.dll
                    Echec de la désinfection

                    C:\WINDOWS\system32\mljgh.dll
                    Echec de la suppression

                    C:\WINDOWS\system32\nmgyfpse.dll
                    Infecté par: Trojan.Vundo.DLP

                    C:\WINDOWS\system32\nmgyfpse.dll
                    Echec de la désinfection

                    C:\WINDOWS\system32\nmgyfpse.dll
                    Echec de la suppression

                    C:\WINDOWS\system32\pkawxcdt.dll
                    Infecté par: Trojan.Vundo.AN

                    C:\WINDOWS\system32\pkawxcdt.dll
                    Echec de la désinfection

                    C:\WINDOWS\system32\pkawxcdt.dll
                    Supprimé

                    C:\WINDOWS\system32\qlluclsp.dll
                    Infecté par: Trojan.Vundo.AO

                    C:\WINDOWS\system32\qlluclsp.dll
                    Echec de la désinfection

                    C:\WINDOWS\system32\qlluclsp.dll
                    Supprimé

                    C:\WINDOWS\system32\xjrnhngp.dll
                    Infecté par: Trojan.Vundo.AO

                    C:\WINDOWS\system32\xjrnhngp.dll
                    Echec de la désinfection

                    C:\WINDOWS\system32\xjrnhngp.dll
                    Echec de la suppression

                    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                    Scan saved at 20:51:18, on 02/05/2007
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\csrss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    C:\WINDOWS\System32\FTRTSVC.exe
                    C:\Program Files\Spyware Doctor\svcntaux.exe
                    C:\windows\system\hpsysdrv.exe
                    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\WINDOWS\ALCXMNTR.EXE
                    C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    C:\HP\KBD\KBD.EXE
                    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                    C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                    C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
                    C:\WINDOWS\system32\rundll32.exe
                    C:\Program Files\Spyware Doctor\SDTrayApp.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
                    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                    C:\PROGRA~1\Wanadoo\ComComp.exe
                    C:\Program Files\MSN Messenger\msnmsgr.exe
                    C:\PROGRA~1\Wanadoo\Toaster.exe
                    C:\PROGRA~1\Wanadoo\Inactivity.exe
                    C:\PROGRA~1\Wanadoo\PollingModule.exe
                    C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
                    c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                    C:\PROGRA~1\Wanadoo\Watch.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\Program Files\iPod\bin\iPodService.exe
                    C:\WINDOWS\System32\alg.exe
                    C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                    C:\Program Files\Outlook Express\msimn.exe
                    C:\Program Files\Spyware Doctor\swdsvc.exe
                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                    C:\Documents and Settings\HP_Propriétaire\Bureau\HiJackThis_v2.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://store.hp.com/us/en?jumpid=re_r11662_redirect_ETR
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\xjrnhngp.dll
                    O2 - BHO: (no name) - {733FD72F-103E-4B9E-BCB9-A76064AF3C72} - C:\WINDOWS\system32\gebyabb.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                    O2 - BHO: (no name) - {76F94FCB-1281-494D-BC0C-0756C7F7FA47} - C:\WINDOWS\system32\mljgh.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\nmgyfpse.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
                    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                    O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
                    O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\itdyidub.dll",setvm
                    O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
                    O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\irpjjkuq.dll",realset
                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
                    O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                    O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                    O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                    O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                    O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                    O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{34CB4B96-6783-4D74-AC33-1375619936AA}: NameServer = 80.10.246.1 80.10.246.132
                    O17 - HKLM\System\CS1\Services\Tcpip\..\{34CB4B96-6783-4D74-AC33-1375619936AA}: NameServer = 80.10.246.1 80.10.246.132
                    O20 - Winlogon Notify: mljgh - C:\WINDOWS\system32\mljgh.dll
                    O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                    O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
                    O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
                    O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
                    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                    O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
                    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
                    O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                    O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
                    O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
                    O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
                    O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
                    O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files\Spyware Doctor\svcntaux.exe
                    O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
                    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                    O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
                    O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
                    O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
                    O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
                    0
                    1. Modérateur
                      Salut

                      supprime ces deux logiciels :

                      WinAntiSpyware 2006 Scanner
                      Error Safe Free


                      ensuite refais un scan avec avg et poste le ainsi qu'un nouveau hijack

                      ++
                      0
                      1. ---------------------------------------------------------
                        AVG Anti-Spyware - Rapport d'analyse
                        ---------------------------------------------------------

                        + Créé à: 11:45:23 07/05/2007

                        + Résultat de l'analyse:

                        C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180228.dll -> Adware.ErrorSafe : Nettoyé.
                        C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180229.dll -> Adware.ErrorSafe : Nettoyé.
                        C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180230.exe -> Adware.ErrorSafe : Nettoyé.
                        C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180231.dll -> Adware.ErrorSafe : Nettoyé.
                        C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180232.exe -> Adware.ErrorSafe : Nettoyé.
                        C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180233.exe -> Adware.WinFixer : Nettoyé.
                        C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP371\A0180467.dll -> Dropper.Agent.bhc : Nettoyé.
                        C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@ad.adocean[1].txt -> TrackingCookie.Adocean : Nettoyé.
                        C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@searchportal.information[1].txt -> TrackingCookie.Information : Nettoyé.
                        C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@www.paypal[1].txt -> TrackingCookie.Paypal : Nettoyé.
                        C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@revsci[2].txt -> TrackingCookie.Revsci : Nettoyé.
                        C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@specificclick[2].txt -> TrackingCookie.Specificclick : Nettoyé.
                        C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.

                        Fin du rapport

                        Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                        Scan saved at 12:23:35, on 07/05/2007
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\csrss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        C:\WINDOWS\System32\FTRTSVC.exe
                        C:\Program Files\Spyware Doctor\svcntaux.exe
                        C:\Program Files\Spyware Doctor\swdsvc.exe
                        C:\WINDOWS\system32\svchost.exe
                        c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Spyware Doctor\SDTrayApp.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\WINDOWS\System32\alg.exe
                        C:\windows\system\hpsysdrv.exe
                        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\WINDOWS\ALCXMNTR.EXE
                        C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                        C:\HP\KBD\KBD.EXE
                        C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                        C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                        C:\PROGRA~1\Wanadoo\ComComp.exe
                        C:\Program Files\MSN Messenger\msnmsgr.exe
                        C:\PROGRA~1\Wanadoo\Toaster.exe
                        C:\PROGRA~1\Wanadoo\Inactivity.exe
                        C:\PROGRA~1\Wanadoo\PollingModule.exe
                        C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                        C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
                        C:\PROGRA~1\Wanadoo\Watch.exe
                        C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                        C:\Documents and Settings\HP_Propriétaire\Bureau\HiJackThis_v2.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://store.hp.com/us/en?jumpid=re_r11662_redirect_ETR
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\xjrnhngp.dll
                        O2 - BHO: (no name) - {733FD72F-103E-4B9E-BCB9-A76064AF3C72} - C:\WINDOWS\system32\gebyabb.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                        O2 - BHO: (no name) - {7E022C3D-B859-42F0-8AF4-23B986CC26F0} - C:\WINDOWS\system32\mljgh.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\nmgyfpse.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                        O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                        O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                        O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                        O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
                        O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                        O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
                        O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
                        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                        O4 - HKLM\..\Run: [WindowsService] rundll32.exe "C:\WINDOWS\system32\mctddmqm.dll",realset
                        O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
                        O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                        O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                        O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                        O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                        O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                        O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                        O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                        O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                        O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
                        O20 - Winlogon Notify: mljgh - C:\WINDOWS\system32\mljgh.dll
                        O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                        O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
                        O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
                        O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
                        O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                        O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
                        O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
                        O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                        O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                        O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
                        O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
                        O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
                        O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
                        O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files\Spyware Doctor\svcntaux.exe
                        O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
                        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                        O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
                        O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
                        O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
                        O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
                        0
                        1. Modérateur
                          Bonjour :)

                          c'est pas encore fini :)

                          Télécharge ComboFix (par sUBs) d'un de ces liens sur ton bureau:

                          http://www.techsupportforum.com/sectools/combofix.exe

                          http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                          Double clique combofix.exe et suis les invites

                          Poste le rapport stp

                          ++
                          0
                          1. "HP_Propri‚taire" - 2007-05-17 15:17:26 Service Pack 2
                            ComboFix 07-05.17.6.V - Running from: "C:\Documents and Settings\HP_Propri‚taire\Mes documents\"

                            (((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))

                            C:\WINDOWS\system32\nmgyfpse.dll
                            C:\WINDOWS\system32\otujcdkt.dll
                            C:\WINDOWS\system32\ynsjyrro.dll
                            C:\WINDOWS\system32\hgjlm.bak1
                            C:\WINDOWS\system32\hgjlm.bak2
                            C:\WINDOWS\system32\hgjlm.ini
                            C:\WINDOWS\system32\hgjlm.ini2
                            C:\WINDOWS\system32\hgjlm.tmp
                            C:\WINDOWS\system32\tkdcjuto.ini
                            C:\WINDOWS\system32\tkdcjuto.ini2
                            C:\WINDOWS\system32\tkdcjuto.tmp
                            C:\WINDOWS\system32\mljgh.dll

                            * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

                            ((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-17 ))))))))))))))))))))))))))))))))))

                            2007-05-12 09:49 65,536 --a------ C:\WINDOWS\IFinst27.exe
                            2007-05-09 21:02 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
                            2007-05-06 15:58 <REP> d-------- C:\DOCUME~1\HP_PRO~1\APPLIC~1\Hamachi
                            2007-05-06 15:56 26,056 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
                            2007-05-06 15:56 <REP> d-------- C:\Program Files\Hamachi
                            2007-05-02 16:40 <REP> d-------- C:\WINDOWS\BDOSCAN8
                            2007-05-01 12:58 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
                            2007-04-22 15:52 <REP> d-------- C:\VundoFix Backups
                            2007-04-19 14:56 83,536 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
                            2007-04-19 14:56 59,984 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
                            2007-04-19 14:56 52,304 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
                            2007-04-19 14:56 39,248 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys
                            2007-04-19 14:56 26,064 --a------ C:\WINDOWS\system32\drivers\kcom.sys
                            2007-04-19 14:56 <REP> d-------- C:\Program Files\Spyware Doctor
                            2007-04-19 14:56 <REP> d-------- C:\DOCUME~1\HP_PRO~1\APPLIC~1\PC Tools
                            2007-04-19 14:55 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll

                            (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

                            2007-05-17 13:27:53 -------- d-----w C:\Program Files\Wanadoo
                            2007-05-16 16:52:04 -------- d-----w C:\Program Files\Gravity
                            2007-05-12 09:02:10 -------- d-----w C:\Program Files\Windows Live Safety Center
                            2007-05-06 14:15:33 -------- d-----w C:\Program Files\Warcraft III
                            2007-05-01 14:44:32 -------- d-----w C:\Program Files\Brochette Online V2
                            2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
                            2007-04-30 15:41:55 85,952 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
                            2007-04-30 15:41:42 94,552 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
                            2007-04-30 15:39:41 23,416 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
                            2007-04-30 15:38:51 43,176 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
                            2007-04-30 15:37:23 26,888 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
                            2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr
                            2007-04-08 17:36:49 -------- d-----w C:\DOCUME~1\HP_PRO~1\APPLIC~1\Screenshot Sender
                            2007-04-02 07:42:34 -------- d-----w C:\Program Files\MyProduct
                            2007-03-31 08:54:20 -------- d-----w C:\Program Files\FRose
                            2007-03-25 13:18:44 84,156 ----a-w C:\WINDOWS\system32\perfc00C.dat
                            2007-03-25 13:18:44 506,460 ----a-w C:\WINDOWS\system32\perfh00C.dat
                            2007-03-24 21:01:00 64,776 ----a-w C:\DOCUME~1\HP_PRO~1\APPLIC~1\GDIPFONTCACHEV1.DAT
                            2007-03-20 17:11:04 -------- d-----w C:\Program Files\Fichiers communs\LogiShrd
                            2007-03-18 13:46:42 -------- d-----w C:\Program Files\Logitech
                            2007-03-17 13:44:47 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
                            2007-03-14 16:15:12 -------- d-----w C:\Program Files\Messenger Plus! Live
                            2007-03-08 15:37:50 578,560 ----a-w C:\WINDOWS\system32\user32.dll
                            2007-03-08 15:37:50 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
                            2007-03-08 15:37:50 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
                            2007-03-08 15:33:58 1,843,712 ----a-w C:\WINDOWS\system32\win32k.sys
                            2007-02-23 13:23:32 28 ----a-w C:\WINDOWS\mscpt.dat
                            2007-02-12 09:56:55 111,992 ----a-w C:\WINDOWS\War3Unin.dat
                            2007-02-07 23:24:46 323,624 ----a-w C:\WINDOWS\system32\wiaaut.dll
                            2007-02-05 20:19:06 185,344 ----a-w C:\WINDOWS\system32\upnphost.dll

                            (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

                            *Note* empty entries & legit default entries are not shown

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
                            {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 09:56]
                            {733FD72F-103E-4B9E-BCB9-A76064AF3C72}=C:\WINDOWS\system32\gebyabb.dll []
                            {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll [2006-10-12 03:25]
                            {9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-04-17 13:32]
                            {AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar3.dll [2007-01-20 00:56]
                            {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=C:\Program Files\Windows Live Toolbar\msntb.dll [2006-09-27 18:45]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2006-10-07 14:20]
                            "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04]
                            "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-08 05:05]
                            "HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 08:35]
                            "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-05-05 01:21]
                            "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 22:43]
                            "AlcxMonitor"="ALCXMNTR.EXE" []
                            "HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 07:12]
                            "WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49]
                            "WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55]
                            "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 17:42]
                            "KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44]
                            "LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 02:12]
                            "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2007-02-08 02:13]
                            "SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-04-27 16:26]

                            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            "WOOKIT"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55]
                            "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 20:00]
                            "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-01-31 18:39]
                            "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:55]

                            [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
                            "^SetupICWDesktop"=""

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                            "{733FD72F-103E-4B9E-BCB9-A76064AF3C72}"="C:\WINDOWS\system32\gebyabb.dll" []
                            "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 16:13]

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                            Authentication Packages msv1_0
                            Security Packages kerberos msv1_0 schannel wdigest
                            Notification Packages scecli

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice]

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice]

                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                            HTTPFilter HTTPFilter
                            LocalService Alerter WebClient LmHosts RemoteRegistry upnphost SSDPSRV
                            NetworkService DnsCache
                            DcomLaunch DcomLaunch TermService
                            rpcss RpcSs
                            imgsvc StiSvc
                            termsvcs TermService
                            WudfServiceGroup WUDFSvc

                            HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

                            Contents of the 'Scheduled Tasks' folder
                            C:\WINDOWS\tasks\Symantec NetDetect.job
                            C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job

                            ********************************************************************

                            catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
                            Rootkit scan 2007-05-17 15:27:19
                            Windows 5.1.2600 Service Pack 2 NTFS

                            scanning hidden processes ...

                            scanning hidden autostart entries ...

                            scanning hidden files ...

                            scan completed successfully
                            hidden files: 0

                            ********************************************************************

                            Completion time: 2007-05-17 15:33:02 - machine was rebooted
                            C:\ComboFix-quarantined-files.txt ... 2007-05-17 15:33

                            --- E O F ---

                            Et Maintenant ? rien est arrangé.
                            0
                            1. Modérateur
                              Salut :)

                              télécharge l2mfix ici:
                              http://www.downloads.subratam.org/l2mfix.exe
                              Double-cliquer sur l2mfix.exe pour lancer l'extraction
                              Dans le dossier l2mfix, double clic sur l2mfix.bat, appuyer sur n'importe quelle touche puis choisir l'option #1 (et pas autre chose) et valider avec la touche entre.
                              Le bloc note va s'ouvrir avec le résultat du scan.copie/colles le rapport ici

                              ++
                              0
                              1. L2MFIX find log 051206
                                These are the registry keys present
                                **********************************************************************************
                                Winlogon/notify:
                                Windows Registry Editor Version 5.00

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
                                "DLLName"="Ati2evxx.dll"
                                "Asynchronous"=dword:00000000
                                "Impersonate"=dword:00000001
                                "Lock"="AtiLockEvent"
                                "Logoff"="AtiLogoffEvent"
                                "Logon"="AtiLogonEvent"
                                "Disconnect"="AtiDisConnectEvent"
                                "Reconnect"="AtiReConnectEvent"
                                "Safe"=dword:00000000
                                "Shutdown"="AtiShutdownEvent"
                                "StartScreenSaver"="AtiStartScreenSaverEvent"
                                "StartShell"="AtiStartShellEvent"
                                "Startup"="AtiStartupEvent"
                                "StopScreenSaver"="AtiStopScreenSaverEvent"
                                "Unlock"="AtiUnLockEvent"

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
                                "Asynchronous"=dword:00000000
                                "Impersonate"=dword:00000000
                                "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
                                6c,00,00,00
                                "Logoff"="ChainWlxLogoffEvent"

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
                                "Asynchronous"=dword:00000000
                                "Impersonate"=dword:00000000
                                "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
                                6c,00,6c,00,00,00
                                "Logoff"="CryptnetWlxLogoffEvent"

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
                                "DLLName"="cscdll.dll"
                                "Logon"="WinlogonLogonEvent"
                                "Logoff"="WinlogonLogoffEvent"
                                "ScreenSaver"="WinlogonScreenSaverEvent"
                                "Startup"="WinlogonStartupEvent"
                                "Shutdown"="WinlogonShutdownEvent"
                                "StartShell"="WinlogonStartShellEvent"
                                "Impersonate"=dword:00000000
                                "Asynchronous"=dword:00000001

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
                                "DLLName"="wlnotify.dll"
                                "Logon"="SCardStartCertProp"
                                "Logoff"="SCardStopCertProp"
                                "Lock"="SCardSuspendCertProp"
                                "Unlock"="SCardResumeCertProp"
                                "Enabled"=dword:00000001
                                "Impersonate"=dword:00000001
                                "Asynchronous"=dword:00000001

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
                                "Asynchronous"=dword:00000000
                                "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                                6c,00,6c,00,00,00
                                "Impersonate"=dword:00000000
                                "StartShell"="SchedStartShell"
                                "Logoff"="SchedEventLogOff"

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
                                "Logoff"="WLEventLogoff"
                                "Impersonate"=dword:00000000
                                "Asynchronous"=dword:00000001
                                "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
                                6c,00,6c,00,00,00

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
                                "DLLName"="WlNotify.dll"
                                "Lock"="SensLockEvent"
                                "Logon"="SensLogonEvent"
                                "Logoff"="SensLogoffEvent"
                                "Safe"=dword:00000001
                                "MaxWait"=dword:00000258
                                "StartScreenSaver"="SensStartScreenSaverEvent"
                                "StopScreenSaver"="SensStopScreenSaverEvent"
                                "Startup"="SensStartupEvent"
                                "Shutdown"="SensShutdownEvent"
                                "StartShell"="SensStartShellEvent"
                                "PostShell"="SensPostShellEvent"
                                "Disconnect"="SensDisconnectEvent"
                                "Reconnect"="SensReconnectEvent"
                                "Unlock"="SensUnlockEvent"
                                "Impersonate"=dword:00000001
                                "Asynchronous"=dword:00000001

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
                                "Asynchronous"=dword:00000000
                                "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                                6c,00,6c,00,00,00
                                "Impersonate"=dword:00000000
                                "Logoff"="TSEventLogoff"
                                "Logon"="TSEventLogon"
                                "PostShell"="TSEventPostShell"
                                "Shutdown"="TSEventShutdown"
                                "StartShell"="TSEventStartShell"
                                "Startup"="TSEventStartup"
                                "MaxWait"=dword:00000258
                                "Reconnect"="TSEventReconnect"
                                "Disconnect"="TSEventDisconnect"

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
                                "Logon"="WLEventLogon"
                                "Logoff"="WLEventLogoff"
                                "Startup"="WLEventStartup"
                                "Shutdown"="WLEventShutdown"
                                "StartScreenSaver"="WLEventStartScreenSaver"
                                "StopScreenSaver"="WLEventStopScreenSaver"
                                "Lock"="WLEventLock"
                                "Unlock"="WLEventUnlock"
                                "StartShell"="WLEventStartShell"
                                "PostShell"="WLEventPostShell"
                                "Disconnect"="WLEventDisconnect"
                                "Reconnect"="WLEventReconnect"
                                "Impersonate"=dword:00000001
                                "Asynchronous"=dword:00000000
                                "SafeMode"=dword:00000001
                                "MaxWait"=dword:ffffffff
                                "DllName"=hex(2):57,00,67,00,61,00,4c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,\
                                6c,00,6c,00,00,00
                                "Event"=dword:00000002
                                "EulaAccepted"=dword:00000000

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings]
                                "Data"=hex:01,00,00,00,d0,8c,9d,df,01,15,d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,\
                                00,00,fc,7d,35,12,1a,d0,ae,4e,bd,9a,7b,21,c3,27,79,46,04,00,00,00,04,00,00,\
                                00,53,00,00,00,03,66,00,00,a8,00,00,00,10,00,00,00,ab,a3,c0,77,84,9a,a2,c9,\
                                c1,9d,12,dc,30,a8,76,0c,00,00,00,00,04,80,00,00,a0,00,00,00,10,00,00,00,a1,\
                                cb,7c,f5,49,3d,59,22,4b,8c,e3,b2,30,5a,6a,64,b0,01,00,00,e3,81,6d,55,c1,0e,\
                                ed,77,3f,8c,83,ca,51,e3,17,9c,2b,b1,f3,ab,a0,db,cb,d2,d0,26,74,8b,e8,2d,6f,\
                                7f,1d,73,aa,d9,16,1d,e4,3f,9a,e9,83,3b,40,13,4b,50,83,39,c7,64,00,71,e0,d4,\
                                b9,3d,c2,f2,f7,4a,b3,3f,95,12,80,8c,3a,7d,0d,db,26,b7,01,d0,94,00,91,ae,b7,\
                                29,32,c1,d2,cd,0b,c7,c6,09,4d,d2,55,46,66,64,6d,a0,fe,0d,0a,19,90,ae,85,0c,\
                                7a,76,26,d7,5d,b3,05,65,77,2e,5c,c1,c0,9f,5d,67,0b,0c,3e,3f,4c,35,cc,e0,8c,\
                                8b,fc,e5,a9,f3,51,c1,60,17,28,5b,6d,eb,4a,7f,2b,7e,f6,e9,37,77,b1,02,76,0e,\
                                88,d5,ab,4f,d7,a3,5a,41,99,e0,41,43,69,f1,67,13,46,c6,96,11,28,0a,30,ef,3b,\
                                fb,a4,9c,2c,06,0a,c1,1f,fd,f5,39,14,03,15,c1,06,d2,b3,c7,1c,b6,0b,18,75,71,\
                                e7,16,2e,18,39,42,78,62,54,43,4a,7d,ec,54,18,4c,41,c7,36,05,81,4d,70,c3,3a,\
                                f6,70,ff,91,c6,9b,1e,10,aa,e3,5f,0f,26,77,3c,33,e2,1e,6c,18,8f,b1,c1,9b,6e,\
                                a2,a0,fa,21,2d,ae,2c,72,86,6e,d8,3b,70,e7,b2,14,cd,75,cb,88,ef,eb,76,2d,54,\
                                49,23,78,5f,14,ae,5b,b3,6d,0c,f5,d9,7d,64,1d,49,f1,2b,f9,cf,56,c5,49,6b,cb,\
                                b2,ce,d8,43,f2,44,47,c7,ce,f1,1c,be,17,20,ac,64,cf,b2,b8,50,51,dc,18,cd,96,\
                                94,53,56,e3,76,80,90,39,62,b3,03,a1,63,4a,74,1b,73,74,35,ab,75,2c,ed,0f,79,\
                                01,de,09,43,9e,44,79,1d,f3,44,ea,09,02,1c,fc,a3,75,f9,f7,51,0c,70,64,df,8a,\
                                f4,8c,cf,87,2d,32,95,79,f2,77,1c,c9,16,7f,a8,db,92,3c,42,69,57,06,88,c3,ca,\
                                c3,bf,15,fc,86,00,f2,1a,04,e1,df,dd,33,73,c6,e8,b0,58,0a,36,06,55,ae,4d,47,\
                                8f,14,00,00,00,f7,21,dc,ec,9b,09,b8,cf,2c,3b,c7,49,fe,6d,ad,e1,fd,36,38,6b

                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
                                "DLLName"="wlnotify.dll"
                                "Logon"="RegisterTicketExpiredNotificationEvent"
                                "Logoff"="UnregisterTicketExpiredNotificationEvent"
                                "Impersonate"=dword:00000001
                                "Asynchronous"=dword:00000001

                                **********************************************************************************
                                useragent:
                                Windows Registry Editor Version 5.00

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                                "Wanadoo 7.1 ; NaviWoo1.1"="IEAKFT"

                                **********************************************************************************
                                Shell Extension key:
                                Windows Registry Editor Version 5.00

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
                                "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
                                "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
                                "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
                                "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
                                "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                                "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
                                "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
                                "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
                                "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
                                "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
                                "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Page de compatibilit‚"
                                "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'environnement"
                                "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
                                "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'environnement pour les objets r‚seau de Microsoft Windows"
                                "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
                                "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
                                "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensions de l'environnement de compression de fichiers"
                                "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension de l'environnement d'imprimante Web"
                                "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
                                "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu contextuel de cryptage"
                                "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
                                "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extension ic“ne HyperTerminal"
                                "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
                                "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
                                "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
                                "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                                "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
                                "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
                                "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
                                "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau"
                                "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Connexions r‚seau"
                                "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Scanneurs et appareils photo"
                                "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Scanneurs et appareils photo"
                                "{905667aa-acd6-11d2-8080-00805f6596d2}"="&Scanneurs et appareils photo"
                                "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Scanneurs et appareils photo"
                                "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Scanneurs et appareils photo"
                                "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
                                "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensions de l'interpr‚teur de commandes pour l'environnement d'ex‚cution de scripts Windows"
                                "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Liaison de donn‚es Microsoft"
                                "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
                                "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
                                "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
                                "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
                                "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
                                "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barre des tƒches et menu D‚marrer"
                                "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Rechercher"
                                "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                                "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                                "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ex‚cuter..."
                                "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
                                "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Courrier ‚lectronique"
                                "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Polices"
                                "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Outils d'administration"
                                "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Page de propri‚t‚s des versions pr‚c‚dentes"
                                "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Versions pr‚c‚dentes"
                                "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
                                "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
                                "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
                                "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
                                "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
                                "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
                                "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
                                "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
                                "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
                                "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
                                "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
                                "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
                                "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="IE Search Band"
                                "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
                                "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
                                "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
                                "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
                                "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
                                "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
                                "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
                                "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
                                "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
                                "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
                                "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
                                "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
                                "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
                                "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
                                "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
                                "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
                                "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
                                "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
                                "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
                                "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
                                "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
                                "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
                                "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
                                "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
                                "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
                                "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
                                "{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
                                "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                                "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                                "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
                                "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
                                "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
                                "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
                                "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
                                "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
                                "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
                                "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
                                "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                                "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                                "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
                                "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
                                "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
                                "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
                                "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
                                "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
                                "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
                                "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
                                "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
                                "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
                                "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
                                "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'applications d'environnement"
                                "{0B124F8F-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
                                "{CFCCC7A0-A282-11D1-9082-006008059382}"="Publication d'application Darwin"
                                "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
                                "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
                                "{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow"
                                "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extracteur de miniatures de fichier + GDI"
                                "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Gestionnaire de miniatures - Informations de r‚sum‚ (DOCFILES)"
                                "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
                                "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
                                "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Assistant Publication de sites Web"
                                "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Commande d'impressions via le Web"
                                "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objet Assistant de publication Shell"
                                "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Assistant Obtenir une identit‚ Passport"
                                "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Comptes d'utilisateurs"
                                "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
                                "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
                                "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
                                "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
                                "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
                                "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
                                "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
                                "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
                                "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
                                "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
                                "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
                                "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
                                "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
                                "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
                                "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
                                "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
                                "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
                                "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
                                "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
                                "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
                                "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
                                "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
                                "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
                                "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
                                "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
                                "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
                                "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
                                "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
                                "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Burn Audio CD Context Menu Handler"
                                "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Play as Playlist Context Menu Handler"
                                "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
                                "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
                                "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
                                "{7F67036B-66F1-411A-AD85-759FB9C5B0DB}"="SampleView"
                                "{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"
                                "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Dossiers Web"
                                "{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
                                "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
                                "{472083B0-C522-11CF-8763-00608CC02F24}"="avast"
                                "{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
                                "{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
                                "{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
                                "{E0D79307-84BE-11CE-9641-444553540000}"="WinZip"
                                "{acb4a560-3606-11d3-aef4-00104bd0f92d}"="KodakShellExtension"
                                "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
                                "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}"="Messenger Sharing Folders"
                                "{07C45BB1-4A8C-4642-A1F5-237E7215FF66}"="IE Microsoft BrowserBand"
                                "{1C1EDB47-CE22-4bbb-B608-77B48F83C823}"="IE Fade Task"
                                "{205D7A97-F16D-4691-86EF-F3075DCCA57D}"="IE Menu Desk Bar"
                                "{3028902F-6374-48b2-8DC6-9725E775B926}"="IE AutoComplete"
                                "{43886CD5-6529-41c4-A707-7B3C92C05E68}"="IE Navigation Bar"
                                "{44C76ECD-F7FA-411c-9929-1B77BA77F524}"="IE Menu Site"
                                "{4B78D326-D922-44f9-AF2A-07805C2A3560}"="IE Menu Band"
                                "{6038EF75-ABFC-4e59-AB6F-12D397F6568D}"="IE Microsoft History AutoComplete List"
                                "{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}"="IE Tracking Shell Menu"
                                "{6CF48EF8-44CD-45d2-8832-A16EA016311B}"="IE IShellFolderBand"
                                "{73CFD649-CD48-4fd8-A272-2070EA56526B}"="IE BandProxy"
                                "{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}"="IE MRU AutoComplete List"
                                "{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}"="IE RSS Feeder Folder"
                                "{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}"="IE Microsoft Shell Folder AutoComplete List"
                                "{B31C5FAE-961F-415b-BAF0-E697A5178B94}"="IE Microsoft Multiple AutoComplete List Container"
                                "{BC476F4C-D9D7-4100-8D4E-E043F6DEC409}"="Microsoft Browser Architecture"
                                "{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}"="IE Shell Rebar BandSite"
                                "{E6EE9AAC-F76B-4947-8260-A9F136138E11}"="IE Shell Band Site Menu"
                                "{F2CF5485-4E02-4f68-819C-B92DE9277049}"="&Links"
                                "{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}"="IE Registry Tree Options Utility"
                                "{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}"="IE User Assist"
                                "{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}"="IE Custom MRU AutoCompleted List"
                                "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
                                "{35786D3C-B075-49b9-88DD-029876E11C01}"="Portable Devices"
                                "{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8}"="Portable Devices Menu"
                                "{e82a2d71-5b2f-43a0-97b8-81be15854de8}"="ShellLink for Application References"
                                "{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}"="Shell Icon Handler for Application References"
                                "{45670FA8-ED97-4F44-BC93-305082590BFB}"="Microsoft.XPS.Shell.Metadata.1"
                                "{44121072-A222-48f2-A58A-6D9AD51EBBE9}"="Microsoft.XPS.Shell.Thumbnail.1"
                                "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"

                                **********************************************************************************
                                HKEY ROOT CLASSIDS:
                                **********************************************************************************
                                Files Found are not all bad files:

                                C:\WINDOWS\SYSTEM32\
                                advpack.dll Tue 27 Feb 2007 15:25:02 A.... 124 928 122,00 K
                                extmgr.dll Tue 27 Feb 2007 15:25:02 A.... 132 608 129,50 K
                                gdi32.dll Thu 8 Mar 2007 17:37:50 A.... 281 600 275,00 K
                                ieakeng.dll Tue 27 Feb 2007 15:25:02 A.... 153 088 149,50 K
                                ieaksie.dll Tue 27 Feb 2007 15:25:04 A.... 230 400 225,00 K
                                ieakui.dll Wed 21 Feb 2007 10:00:54 A.... 161 792 158,00 K
                                ieapfltr.dll Tue 3 Apr 2007 16:29:24 A.... 383 488 374,50 K
                                iedkcs32.dll Tue 27 Feb 2007 15:25:10 A.... 384 000 375,00 K
                                ieframe.dll Tue 27 Feb 2007 15:25:32 A.... 6 054 400 5,77 M
                                iernonce.dll Tue 27 Feb 2007 15:25:32 A.... 44 544 43,50 K
                                iertutil.dll Tue 27 Feb 2007 15:25:34 A.... 266 752 260,50 K
                                jsproxy.dll Tue 27 Feb 2007 15:25:44 A.... 27 136 26,50 K
                                legitc~1.dll Thu 15 Mar 2007 18:19:28 ..... 1 476 992 1,41 M
                                mf3216.dll Thu 8 Mar 2007 17:37:50 A.... 40 960 40,00 K
                                msfeeds.dll Tue 27 Feb 2007 15:25:46 A.... 458 752 448,00 K
                                msfeed~1.dll Tue 27 Feb 2007 15:25:46 A.... 51 712 50,50 K
                                mshtml.dll Tue 27 Feb 2007 15:25:58 A.... 3 581 952 3,41 M
                                mshtmled.dll Tue 27 Feb 2007 15:25:58 A.... 477 696 466,50 K
                                msrating.dll Tue 27 Feb 2007 15:25:58 A.... 193 024 188,50 K
                                mstime.dll Tue 27 Feb 2007 15:26:04 A.... 670 720 655,00 K
                                occache.dll Tue 27 Feb 2007 15:26:06 A.... 102 400 100,00 K
                                url.dll Tue 27 Feb 2007 15:26:06 A.... 105 984 103,50 K
                                urlmon.dll Tue 27 Feb 2007 15:26:14 A.... 1 150 464 1,09 M
                                user32.dll Thu 8 Mar 2007 17:37:50 A.... 578 560 565,00 K
                                webcheck.dll Tue 27 Feb 2007 15:26:16 A.... 232 960 227,50 K
                                wgalogon.dll Thu 15 Mar 2007 18:16:48 A.... 236 928 231,38 K
                                wininet.dll Tue 27 Feb 2007 15:26:24 A.... 822 784 803,50 K
                                winsrv.dll Sat 17 Mar 2007 15:44:48 A.... 293 376 286,50 K
                                xpsp3res.dll Fri 9 Mar 2007 13:51:20 A.... 265 216 259,00 K

                                29 items found: 29 files, 0 directories.
                                Total of file sizes: 18 985 216 bytes 18,11 M
                                Locate .tmp files:

                                C:\WINDOWS\SYSTEM32\
                                mcrh.tmp Sun 8 Apr 2007 22:27:30 A.... 97 0,09 K

                                1 item found: 1 file, 0 directories.
                                Total of file sizes: 97 bytes 0,09 K
                                **********************************************************************************
                                Directory Listing of system files:
                                Le volume dans le lecteur C s'appelle HP_PAVILION
                                Le num‚ro de s‚rie du volume est 947E-5624

                                R‚pertoire de C:\WINDOWS\System32

                                11/05/2007 16:06 1ÿ488ÿ819 mqmddtcm.ini
                                03/05/2007 19:39 1ÿ184 qukjjpri.ini
                                27/04/2007 16:36 534 auiqtyfd.ini
                                3 fichier(s) 1ÿ490ÿ537 octets
                                0 R‚p(s) 63ÿ093ÿ006ÿ336 octets libres

                                A quoi servent tous ces rapports ? et Maintenant ? merci
                                0
                                1. recherches ceci dans ton PC:
                                  --------------------------------------------
                                  mqmddtcm.ini
                                  qukjjpri.ini
                                  auiqtyfd.ini
                                  supprimes-les
                                  si ça ne vas pas, fais le en mode sans échec
                                  https://leblogdeclaude.blogspot.com/2007/04/informatique-rebooter-xp-en-mode-sans.html

                                  ---------------------------------------
                                  download ceci:
                                  http://www.malekal.com/download/clean.zip
                                  Décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier dénommé "clean ".
                                  Redémarre en mode sans échec. ( note bien ce que tu as à faire ).
                                  Ouvre le dossier « clean » qui se trouve sur ton bureau.
                                  Double-clic sur « clean.cmd ».
                                  Une fenêtre noire va apparaître, suis les consignes
                                  fais l'option1 et 2
                                  poste le log
                                  Où est le rapport clean ? : « Poste de travail » / double clic sur disque « C / » double-clic sur « rapport_clean.txt » et « copier/coller le contenu » sur le forum.

                                  0
                                  • 1
                                  • 2