PC infecté

Résolu
Bonjour à tous,

Voila j'ai de nouveau un gros probléme sur mon PC.
Je pense à un gros virus....
Ma confg: Mon PC à 4 ans, j'ai Windows XP family, pas d'antivirus, mais KERIO en firewall..

j'ai déjà executer AD AWARE, SPYBOT et CLEAN UP..

Je viens de faire un HijackThis et voila le resultat:

Logfile of HijackThis v1.99.1
Scan saved at 20:29:42, on 11/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\FileZilla Server\FileZilla Server.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\Rar$EX00.625\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr8.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr8.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr8.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr8.hpwis.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "C:\WINDOWS\system32\nqksxfvx.dll",realset
O4 - HKLM\..\RunServices: [MCX Update] wisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photoways.com/clients/uploader_v2.1.0.56.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - (no CLSID) - (no file)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
Configuration: Windows XP
Internet Explorer 7.0

46 réponses

Résumé de la discussion

Problème de sécurité sur Windows XP après un scan HijackThis, le log révélant de multiples éléments suspects dans Internet Explorer, des BHO et des entrées Run susceptibles d’indiquer une infection. Des réponses préconisent d’installer un pare-feu fiable et d’employer des outils tels qu’Ad-Aware, Spybot, CCleaner et Ewido, puis de relancer un scan pour identifier et supprimer les éléments malveillants. Il est conseillé de démarrer en mode sans échec, de cocher les éléments repérés et de fixer les points problématiques dans HijackThis, puis de vider les fichiers temporaires et le cache. Certaines entrées proviennent toutefois de composants légitimes comme Google Toolbar, Messenger ou FileZilla, ce qui souligne l’importance de vérifier les programmes avant toute suppression.

Bobot (l’IA à votre service)
  1. salut

    alala pas d'antivirus , bon commence par telecharger Avast ici :
    http://www.commentcamarche.net/download/telecharger-151-avast

    il est bien et gratuit

    bizz fais ceci et on vois la suite
    1. Je ne remet aucune en doute tes compétences, qui sont sans hesiter bien meilleur que les miennes...
      Mais je n'utilise jamais d'antivirus,par choix personnel, même si je sais qu'il en faut un, je fais uniquement un scan via internet 1 fois par mois...
      J'éspere que cela m'empechera pas d'obtenir ton aide...
      Il y a an, j'ai eu le même probléme et je sais que sur ce site on m'avais aider... sans antivirus... grace au log d'HijackThis notament.

      Merci d'avance et j'espere sincerement que mon choix de ne pas mettre d'antivirus ne te pose pas un reel probléme...
      1. Oui je sais bien, mais en 4 ans j'en suis à mon deuxieme prob, car je m'y conné comme même un petit peu et je fais relativement attention...

        Tu veux quand même bien m'aider???? STP .... aller STP .....
        1. Slt

          C'est difficile de faire des dépannes sans anti-virus.
          Car s'il y a un problème durant les téléchargements de logiciels de désinfection....

          Sinon tu installes Avast, durant la désinfection

          A++

      2. Pour l'instant je n'ais encore aucun probléme de telechargement... mais c'est vrai que internet rame de plus en plus...

        Est ce que vous voulez bien m'aider, ou il faut vraiment que j'instal avast..??..
        1. ou il faut vraiment que j'instal avast..??..

          C'est préférable

          A++
      3. re

        pour t'aider oui no probleme mais STP installes 1 antivirus c'est + que primordial

        bizz
        1. Comme je n'ais pas envie de faire ma mule, j'ai insallé avast, et un scan minutieux est en cours... Je pense qu'il se finira en 2010...

          J'espere que d'ici là on m'aura donné 2 ou 3 info sur les ligne à supprimer sur HijackThis...

          Bisous
          1. Faudra que tu en refasses un

        2. Un HijackThis ???....
          Pourquoi tu veux verifier si j'ai bien instalé avast????

          Je plaisante.. Ok, par contre j'ai changé d'option et j'ai obté pour un scan rapide....
          1. mdr

            oui pour voir si t'as installé 1 antivirus ihihihih mais nan alala^^

            bizz a toi Marie et toi aussi que si t'as mis 1 antivirus lool
            1. Chouette tu me repare mon PC et en plus tu m'envois une bise...

              C'est pomis il est bien insallé, il a même deja detecté une merde... pas contre j'ai pas dis que je lasserais apres...

              Moi aussi je te fas une bizzzzz
              1. Ok,

                Bha !! Après tu fais comme tu le sent.

                Mais, pour la sécurité de la dépan, faut un anti-virus
                En plus il t'a détecté une merdouille.
                On verra demain avec le new log

                Bizz

            2. Voila premier scan fini... 2 fichier supprimés...

              Nouveau HijackThis:

              Et oui AVAST est bien là........

              Logfile of HijackThis v1.99.1
              Scan saved at 22:52:27, on 11/05/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16414)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\FileZilla Server\FileZilla Server.exe
              C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
              C:\WINDOWS\system32\HPZipm12.exe
              C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
              C:\WINDOWS\system32\wscntfy.exe
              C:\WINDOWS\explorer.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
              C:\Program Files\WinRAR\WinRAR.exe
              C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\Rar$EX00.234\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr8.hpwis.com/
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr8.hpwis.com/
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr8.hpwis.com/
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr8.hpwis.com/
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
              O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "C:\WINDOWS\system32\nqksxfvx.dll",realset
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\RunServices: [MCX Update] wisp.exe
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
              O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (HKCU)
              O11 - Options group: [INTERNATIONAL] International*
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
              O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
              O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photoways.com/clients/uploader_v2.1.0.56.cab
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
              O18 - Filter: text/html - (no CLSID) - (no file)
              O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
              O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
              O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
              O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
              1. OK

                C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\Rar$EX00.234\HijackThis.exe

                Il est mal placé

                Regarde la démo

                F - Hijackthis - Outil de diagnostic et réparation

                télécharge HijackThis ici:
                http://telechargement.zebulon.fr/138-hijackthis-1991.html

                Dézippe le dans un dossier prévu à cet effet.
                Par exemple C:\hijackthis < Enregistre le bien dans c : !
                Démo : (Merci a Balltrap34 pour cette réalisation)
                http://pageperso.aol.fr/balltrap34/Hijenr.gif

                Lance le puis:
                clique sur "do a system scan and save logfile" (cf démo)
                faire un copier coller du log entier sur le forum

                Démo : (Merci a Balltrap34 pour cette réalisation)
                http://pageperso.aol.fr/balltrap34/demohijack.htm

                Bon courage

                A+

                A demain

            3. Je ne savais pas que son emplacement été important... Soit, voila le resultat:

              Logfile of HijackThis v1.99.1
              Scan saved at 23:03:10, on 11/05/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16414)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\FileZilla Server\FileZilla Server.exe
              C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
              C:\WINDOWS\system32\HPZipm12.exe
              C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
              C:\WINDOWS\system32\wscntfy.exe
              C:\WINDOWS\explorer.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr8.hpwis.com/
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr8.hpwis.com/
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr8.hpwis.com/
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr8.hpwis.com/
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
              O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "C:\WINDOWS\system32\nqksxfvx.dll",realset
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\RunServices: [MCX Update] wisp.exe
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
              O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (HKCU)
              O11 - Options group: [INTERNATIONAL] International*
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
              O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
              O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photoways.com/clients/uploader_v2.1.0.56.cab
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
              O18 - Filter: text/html - (no CLSID) - (no file)
              O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
              O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
              O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
              O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
              1. Ca doit etre grave ce qu il a mon ordi....
                Personne n'ose m'annoncer le verdict....
                1. Salut

                  Fais un clic droit sur hijackthis, choisis "renommer" marque : abcde.exe
                  Puis remet un rapport stp
              2. et voila:

                Logfile of HijackThis v1.99.1
                Scan saved at 11:08:56, on 12/05/2007
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16414)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\FileZilla Server\FileZilla Server.exe
                C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
                C:\WINDOWS\system32\HPZipm12.exe
                C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                C:\Program Files\Messenger\msmsgs.exe
                C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
                C:\WINDOWS\system32\wscntfy.exe
                C:\WINDOWS\explorer.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\PROGRA~1\MI3AA1~1\rapimgr.exe
                C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\abcde.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr8.hpwis.com/
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr8.hpwis.com/
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr8.hpwis.com/
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr8.hpwis.com/
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                O2 - BHO: (no name) - {35845E32-35D9-46BB-9240-258AB96391C5} - C:\WINDOWS\system32\ljjggfe.dll
                O2 - BHO: (no name) - {3D723B89-C5AB-44AD-B0A5-467A9A4322E8} - C:\WINDOWS\system32\jkklk.dll
                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                O2 - BHO: (no name) - {D1AF67A5-9EB1-4502-8FFC-B2B544CEFE98} - C:\WINDOWS\system32\tghueykq.dll
                O2 - BHO: (no name) - {E2EE5C44-C66D-499d-BEAE-A2A79189A63A} - C:\WINDOWS\system32\jlmduicj.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "C:\WINDOWS\system32\nqksxfvx.dll",realset
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\RunServices: [MCX Update] wisp.exe
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
                O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (HKCU)
                O11 - Options group: [INTERNATIONAL] International*
                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photoways.com/clients/uploader_v2.1.0.56.cab
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                O18 - Filter: text/html - (no CLSID) - (no file)
                O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                O20 - Winlogon Notify: jkklk - C:\WINDOWS\system32\jkklk.dll
                O20 - Winlogon Notify: ljjggfe - C:\WINDOWS\SYSTEM32\ljjggfe.dll
                O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
                O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                1. OK

                  Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
                  http://www.atribune.org/ccount/click.php?id=4

                  * Double-clique VundoFix.exe afin de le lancer.

                  * Lorsque l'outil se lance à nouveau,

                  * Clique sur le bouton Scan for Vundo.

                  * Lorsque le scan est complété, clique sur le bouton Remove Vundo

                  * Une invite te demandera si tu veux supprimer les fichiers, clique YES

                  * Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.

                  * Tu verras une invite qui t'annonce que ton PC va s'éteindre
                  ("shutdown"); clique OK

                  * Démarre ton PC à nouveau.

                  * Copie/colle le contenu du rapport situé dans C:\vundofix.txt
                  ainsi qu'un nouveau rapport HijackThis! dans ta prochaine réponse.
                  1. Voila:

                    VundoFix V6.3.21

                    Checking Java version...

                    Sun Java not detected
                    Scan started at 11:23:31 12/05/2007

                    Listing files found while scanning....

                    C:\WINDOWS\system32\awtqn.dll
                    C:\WINDOWS\system32\awtqo.dll
                    C:\WINDOWS\system32\awtqp.dll
                    C:\WINDOWS\system32\awtqq.dll
                    C:\WINDOWS\system32\awtqr.dll
                    C:\WINDOWS\system32\awtsp.dll
                    C:\WINDOWS\system32\awtsq.dll
                    C:\WINDOWS\system32\awtsr.dll
                    C:\WINDOWS\system32\awtss.dll
                    C:\WINDOWS\system32\awtst.dll
                    C:\WINDOWS\system32\awvtq.dll
                    C:\WINDOWS\system32\awvtr.dll
                    C:\WINDOWS\system32\awvts.dll
                    C:\WINDOWS\system32\awvtt.dll
                    C:\WINDOWS\system32\awvtu.dll
                    C:\WINDOWS\system32\awvvs.dll
                    C:\WINDOWS\system32\awvvt.dll
                    C:\WINDOWS\system32\awvvu.dll
                    C:\WINDOWS\system32\awvvv.dll
                    C:\WINDOWS\system32\awvvw.dll
                    C:\WINDOWS\system32\bbadd.ini
                    C:\WINDOWS\system32\bfscayap.dll
                    C:\WINDOWS\system32\ddaba.dll
                    C:\WINDOWS\system32\ddabb.dll
                    C:\WINDOWS\system32\ddabc.dll
                    C:\WINDOWS\system32\ddabx.dll
                    C:\WINDOWS\system32\ddaby.dll
                    C:\WINDOWS\system32\ddaya.dll
                    C:\WINDOWS\system32\ddayv.dll
                    C:\WINDOWS\system32\ddayw.dll
                    C:\WINDOWS\system32\ddayx.dll
                    C:\WINDOWS\system32\ddayy.dll
                    C:\WINDOWS\system32\ddcca.dll
                    C:\WINDOWS\system32\ddccb.dll
                    C:\WINDOWS\system32\ddccc.dll
                    C:\WINDOWS\system32\ddccd.dll
                    C:\WINDOWS\system32\ddccy.dll
                    C:\WINDOWS\system32\ddcya.dll
                    C:\WINDOWS\system32\ddcyv.dll
                    C:\WINDOWS\system32\ddcyw.dll
                    C:\WINDOWS\system32\ddcyx.dll
                    C:\WINDOWS\system32\ddcyy.dll
                    C:\WINDOWS\system32\efcdaay.dll
                    C:\WINDOWS\system32\eniaokhu.dll
                    C:\WINDOWS\system32\eymgxeai.dll
                    C:\WINDOWS\system32\gebca.dll
                    C:\WINDOWS\system32\gebcb.dll
                    C:\WINDOWS\system32\gebcc.dll
                    C:\WINDOWS\system32\gebcd.dll
                    C:\WINDOWS\system32\gebcy.dll
                    C:\WINDOWS\system32\gebya.dll
                    C:\WINDOWS\system32\gebyv.dll
                    C:\WINDOWS\system32\gebyw.dll
                    C:\WINDOWS\system32\gebyx.dll
                    C:\WINDOWS\system32\gebyy.dll
                    C:\WINDOWS\system32\geeba.dll
                    C:\WINDOWS\system32\geebb.dll
                    C:\WINDOWS\system32\geebc.dll
                    C:\WINDOWS\system32\geebx.dll
                    C:\WINDOWS\system32\geeby.dll
                    C:\WINDOWS\system32\geeda.dll
                    C:\WINDOWS\system32\geedb.dll
                    C:\WINDOWS\system32\geedc.dll
                    C:\WINDOWS\system32\geedd.dll
                    C:\WINDOWS\system32\geede.dll
                    C:\WINDOWS\system32\jkhfc.dll
                    C:\WINDOWS\system32\jkhfd.dll
                    C:\WINDOWS\system32\jkhfe.dll
                    C:\WINDOWS\system32\jkhff.dll
                    C:\WINDOWS\system32\jkhfg.dll
                    C:\WINDOWS\system32\jkhhe.dll
                    C:\WINDOWS\system32\jkhhf.dll
                    C:\WINDOWS\system32\jkhhg.dll
                    C:\WINDOWS\system32\jkhhh.dll
                    C:\WINDOWS\system32\jkhhi.dll
                    C:\WINDOWS\system32\jkkjg.dll
                    C:\WINDOWS\system32\jkkjh.dll
                    C:\WINDOWS\system32\jkkji.dll
                    C:\WINDOWS\system32\jkkjj.dll
                    C:\WINDOWS\system32\jkkjk.dll
                    C:\WINDOWS\system32\jkkli.dll
                    C:\WINDOWS\system32\jkklk.dll
                    C:\WINDOWS\system32\jkkll.dll
                    C:\WINDOWS\system32\jkklm.dll
                    C:\WINDOWS\system32\klkkj.bak1
                    C:\WINDOWS\system32\klkkj.bak2
                    C:\WINDOWS\system32\klkkj.ini
                    C:\WINDOWS\system32\klkkj.ini2
                    C:\WINDOWS\system32\ljjggfe.dll
                    C:\WINDOWS\system32\mljgd.dll
                    C:\WINDOWS\system32\mljge.dll
                    C:\WINDOWS\system32\mljgf.dll
                    C:\WINDOWS\system32\mljgg.dll
                    C:\WINDOWS\system32\mljgh.dll
                    C:\WINDOWS\system32\mljjg.dll
                    C:\WINDOWS\system32\mljjh.dll
                    C:\WINDOWS\system32\mljji.dll
                    C:\WINDOWS\system32\mljjj.dll
                    C:\WINDOWS\system32\mljjk.dll
                    C:\WINDOWS\system32\mlljg.dll
                    C:\WINDOWS\system32\mlljh.dll
                    C:\WINDOWS\system32\mllji.dll
                    C:\WINDOWS\system32\mlljj.dll
                    C:\WINDOWS\system32\mlljk.dll
                    C:\WINDOWS\system32\mllmj.dll
                    C:\WINDOWS\system32\mllmk.dll
                    C:\WINDOWS\system32\mllml.dll
                    C:\WINDOWS\system32\mllmm.dll
                    C:\WINDOWS\system32\mllmn.dll
                    C:\WINDOWS\system32\moipghdl.dll
                    C:\WINDOWS\system32\payacsfb.ini
                    C:\WINDOWS\system32\pmkhe.dll
                    C:\WINDOWS\system32\pmkhf.dll
                    C:\WINDOWS\system32\pmkhg.dll
                    C:\WINDOWS\system32\pmkhh.dll
                    C:\WINDOWS\system32\pmkhi.dll
                    C:\WINDOWS\system32\pmkjg.dll
                    C:\WINDOWS\system32\pmkjh.dll
                    C:\WINDOWS\system32\pmkji.dll
                    C:\WINDOWS\system32\pmkjj.dll
                    C:\WINDOWS\system32\pmkjk.dll
                    C:\WINDOWS\system32\pmnli.dll
                    C:\WINDOWS\system32\pmnlj.dll
                    C:\WINDOWS\system32\pmnlk.dll
                    C:\WINDOWS\system32\pmnll.dll
                    C:\WINDOWS\system32\pmnlm.dll
                    C:\WINDOWS\system32\pmnnk.dll
                    C:\WINDOWS\system32\pmnnl.dll
                    C:\WINDOWS\system32\pmnnm.dll
                    C:\WINDOWS\system32\pmnnn.dll
                    C:\WINDOWS\system32\pmnno.dll
                    C:\WINDOWS\system32\qsubjuyy.dll
                    C:\WINDOWS\system32\rrhbjpps.ini
                    C:\WINDOWS\system32\sppjbhrr.dll
                    C:\WINDOWS\system32\ssqpm.dll
                    C:\WINDOWS\system32\ssqpn.dll
                    C:\WINDOWS\system32\ssqpo.dll
                    C:\WINDOWS\system32\ssqpp.dll
                    C:\WINDOWS\system32\ssqpq.dll
                    C:\WINDOWS\system32\ssqro.dll
                    C:\WINDOWS\system32\ssqrp.dll
                    C:\WINDOWS\system32\ssqrq.dll
                    C:\WINDOWS\system32\ssqrr.dll
                    C:\WINDOWS\system32\ssqrs.dll
                    C:\WINDOWS\system32\sstqn.dll
                    C:\WINDOWS\system32\sstqo.dll
                    C:\WINDOWS\system32\sstqp.dll
                    C:\WINDOWS\system32\sstqq.dll
                    C:\WINDOWS\system32\sstqr.dll
                    C:\WINDOWS\system32\ssttq.dll
                    C:\WINDOWS\system32\ssttr.dll
                    C:\WINDOWS\system32\sstts.dll
                    C:\WINDOWS\system32\ssttt.dll
                    C:\WINDOWS\system32\ssttu.dll
                    C:\WINDOWS\system32\vtsqn.dll
                    C:\WINDOWS\system32\vtsqo.dll
                    C:\WINDOWS\system32\vtsqp.dll
                    C:\WINDOWS\system32\vtsqq.dll
                    C:\WINDOWS\system32\vtsqr.dll
                    C:\WINDOWS\system32\vtstq.dll
                    C:\WINDOWS\system32\vtstr.dll
                    C:\WINDOWS\system32\vtsts.dll
                    C:\WINDOWS\system32\vtstt.dll
                    C:\WINDOWS\system32\vtstu.dll
                    C:\WINDOWS\system32\vturo.dll
                    C:\WINDOWS\system32\vturp.dll
                    C:\WINDOWS\system32\vturq.dll
                    C:\WINDOWS\system32\vturr.dll
                    C:\WINDOWS\system32\vturs.dll
                    C:\WINDOWS\system32\vtutq.dll
                    C:\WINDOWS\system32\vtutr.dll
                    C:\WINDOWS\system32\vtuts.dll
                    C:\WINDOWS\system32\vtutt.dll
                    C:\WINDOWS\system32\vtutu.dll

                    Beginning removal...

                    Attempting to delete C:\WINDOWS\system32\awtqn.dll
                    C:\WINDOWS\system32\awtqn.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awtqo.dll
                    C:\WINDOWS\system32\awtqo.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awtqp.dll
                    C:\WINDOWS\system32\awtqp.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awtqq.dll
                    C:\WINDOWS\system32\awtqq.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awtqr.dll
                    C:\WINDOWS\system32\awtqr.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awtsp.dll
                    C:\WINDOWS\system32\awtsp.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awtsq.dll
                    C:\WINDOWS\system32\awtsq.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awtsr.dll
                    C:\WINDOWS\system32\awtsr.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awtss.dll
                    C:\WINDOWS\system32\awtss.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awtst.dll
                    C:\WINDOWS\system32\awtst.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awvtq.dll
                    C:\WINDOWS\system32\awvtq.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awvtr.dll
                    C:\WINDOWS\system32\awvtr.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awvts.dll
                    C:\WINDOWS\system32\awvts.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awvtt.dll
                    C:\WINDOWS\system32\awvtt.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awvtu.dll
                    C:\WINDOWS\system32\awvtu.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awvvs.dll
                    C:\WINDOWS\system32\awvvs.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awvvt.dll
                    C:\WINDOWS\system32\awvvt.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awvvu.dll
                    C:\WINDOWS\system32\awvvu.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awvvv.dll
                    C:\WINDOWS\system32\awvvv.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\awvvw.dll
                    C:\WINDOWS\system32\awvvw.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\bbadd.ini
                    C:\WINDOWS\system32\bbadd.ini Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\bfscayap.dll
                    C:\WINDOWS\system32\bfscayap.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddaba.dll
                    C:\WINDOWS\system32\ddaba.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddabb.dll
                    C:\WINDOWS\system32\ddabb.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddabc.dll
                    C:\WINDOWS\system32\ddabc.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddabx.dll
                    C:\WINDOWS\system32\ddabx.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddaby.dll
                    C:\WINDOWS\system32\ddaby.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddaya.dll
                    C:\WINDOWS\system32\ddaya.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddayv.dll
                    C:\WINDOWS\system32\ddayv.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddayw.dll
                    C:\WINDOWS\system32\ddayw.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddayx.dll
                    C:\WINDOWS\system32\ddayx.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddayy.dll
                    C:\WINDOWS\system32\ddayy.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddcca.dll
                    C:\WINDOWS\system32\ddcca.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddccb.dll
                    C:\WINDOWS\system32\ddccb.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddccc.dll
                    C:\WINDOWS\system32\ddccc.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddccd.dll
                    C:\WINDOWS\system32\ddccd.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddccy.dll
                    C:\WINDOWS\system32\ddccy.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddcya.dll
                    C:\WINDOWS\system32\ddcya.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddcyv.dll
                    C:\WINDOWS\system32\ddcyv.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddcyw.dll
                    C:\WINDOWS\system32\ddcyw.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddcyx.dll
                    C:\WINDOWS\system32\ddcyx.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ddcyy.dll
                    C:\WINDOWS\system32\ddcyy.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\efcdaay.dll
                    C:\WINDOWS\system32\efcdaay.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\eniaokhu.dll
                    C:\WINDOWS\system32\eniaokhu.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\eymgxeai.dll
                    C:\WINDOWS\system32\eymgxeai.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\gebca.dll
                    C:\WINDOWS\system32\gebca.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\gebcb.dll
                    C:\WINDOWS\system32\gebcb.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\gebcc.dll
                    C:\WINDOWS\system32\gebcc.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\gebcd.dll
                    C:\WINDOWS\system32\gebcd.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\gebcy.dll
                    C:\WINDOWS\system32\gebcy.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\gebya.dll
                    C:\WINDOWS\system32\gebya.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\gebyv.dll
                    C:\WINDOWS\system32\gebyv.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\gebyw.dll
                    C:\WINDOWS\system32\gebyw.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\gebyx.dll
                    C:\WINDOWS\system32\gebyx.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\gebyy.dll
                    C:\WINDOWS\system32\gebyy.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\geeba.dll
                    C:\WINDOWS\system32\geeba.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\geebb.dll
                    C:\WINDOWS\system32\geebb.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\geebc.dll
                    C:\WINDOWS\system32\geebc.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\geebx.dll
                    C:\WINDOWS\system32\geebx.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\geeby.dll
                    C:\WINDOWS\system32\geeby.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\geeda.dll
                    C:\WINDOWS\system32\geeda.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\geedb.dll
                    C:\WINDOWS\system32\geedb.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\geedc.dll
                    C:\WINDOWS\system32\geedc.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\geedd.dll
                    C:\WINDOWS\system32\geedd.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\geede.dll
                    C:\WINDOWS\system32\geede.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkhfc.dll
                    C:\WINDOWS\system32\jkhfc.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkhfd.dll
                    C:\WINDOWS\system32\jkhfd.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkhfe.dll
                    C:\WINDOWS\system32\jkhfe.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkhff.dll
                    C:\WINDOWS\system32\jkhff.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkhfg.dll
                    C:\WINDOWS\system32\jkhfg.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkhhe.dll
                    C:\WINDOWS\system32\jkhhe.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkhhf.dll
                    C:\WINDOWS\system32\jkhhf.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkhhg.dll
                    C:\WINDOWS\system32\jkhhg.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkhhh.dll
                    C:\WINDOWS\system32\jkhhh.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkhhi.dll
                    C:\WINDOWS\system32\jkhhi.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkkjg.dll
                    C:\WINDOWS\system32\jkkjg.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkkjh.dll
                    C:\WINDOWS\system32\jkkjh.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkkji.dll
                    C:\WINDOWS\system32\jkkji.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkkjj.dll
                    C:\WINDOWS\system32\jkkjj.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkkjk.dll
                    C:\WINDOWS\system32\jkkjk.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkkli.dll
                    C:\WINDOWS\system32\jkkli.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkklk.dll
                    C:\WINDOWS\system32\jkklk.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkkll.dll
                    C:\WINDOWS\system32\jkkll.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\jkklm.dll
                    C:\WINDOWS\system32\jkklm.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\klkkj.bak1
                    C:\WINDOWS\system32\klkkj.bak1 Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\klkkj.bak2
                    C:\WINDOWS\system32\klkkj.bak2 Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\klkkj.ini
                    C:\WINDOWS\system32\klkkj.ini Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\klkkj.ini2
                    C:\WINDOWS\system32\klkkj.ini2 Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ljjggfe.dll
                    C:\WINDOWS\system32\ljjggfe.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mljgd.dll
                    C:\WINDOWS\system32\mljgd.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mljge.dll
                    C:\WINDOWS\system32\mljge.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mljgf.dll
                    C:\WINDOWS\system32\mljgf.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mljgg.dll
                    C:\WINDOWS\system32\mljgg.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mljgh.dll
                    C:\WINDOWS\system32\mljgh.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mljjg.dll
                    C:\WINDOWS\system32\mljjg.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mljjh.dll
                    C:\WINDOWS\system32\mljjh.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mljji.dll
                    C:\WINDOWS\system32\mljji.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mljjj.dll
                    C:\WINDOWS\system32\mljjj.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mljjk.dll
                    C:\WINDOWS\system32\mljjk.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mlljg.dll
                    C:\WINDOWS\system32\mlljg.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mlljh.dll
                    C:\WINDOWS\system32\mlljh.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mllji.dll
                    C:\WINDOWS\system32\mllji.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mlljj.dll
                    C:\WINDOWS\system32\mlljj.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mlljk.dll
                    C:\WINDOWS\system32\mlljk.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mllmj.dll
                    C:\WINDOWS\system32\mllmj.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mllmk.dll
                    C:\WINDOWS\system32\mllmk.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mllml.dll
                    C:\WINDOWS\system32\mllml.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mllmm.dll
                    C:\WINDOWS\system32\mllmm.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\mllmn.dll
                    C:\WINDOWS\system32\mllmn.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\payacsfb.ini
                    C:\WINDOWS\system32\payacsfb.ini Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmkhe.dll
                    C:\WINDOWS\system32\pmkhe.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmkhf.dll
                    C:\WINDOWS\system32\pmkhf.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmkhg.dll
                    C:\WINDOWS\system32\pmkhg.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmkhh.dll
                    C:\WINDOWS\system32\pmkhh.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmkhi.dll
                    C:\WINDOWS\system32\pmkhi.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmkjg.dll
                    C:\WINDOWS\system32\pmkjg.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmkjh.dll
                    C:\WINDOWS\system32\pmkjh.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmkji.dll
                    C:\WINDOWS\system32\pmkji.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmkjj.dll
                    C:\WINDOWS\system32\pmkjj.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmkjk.dll
                    C:\WINDOWS\system32\pmkjk.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmnli.dll
                    C:\WINDOWS\system32\pmnli.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmnlj.dll
                    C:\WINDOWS\system32\pmnlj.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmnlk.dll
                    C:\WINDOWS\system32\pmnlk.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmnll.dll
                    C:\WINDOWS\system32\pmnll.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmnlm.dll
                    C:\WINDOWS\system32\pmnlm.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmnnk.dll
                    C:\WINDOWS\system32\pmnnk.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmnnl.dll
                    C:\WINDOWS\system32\pmnnl.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmnnm.dll
                    C:\WINDOWS\system32\pmnnm.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmnnn.dll
                    C:\WINDOWS\system32\pmnnn.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\pmnno.dll
                    C:\WINDOWS\system32\pmnno.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\qsubjuyy.dll
                    C:\WINDOWS\system32\qsubjuyy.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\rrhbjpps.ini
                    C:\WINDOWS\system32\rrhbjpps.ini Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\sppjbhrr.dll
                    C:\WINDOWS\system32\sppjbhrr.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ssqpm.dll
                    C:\WINDOWS\system32\ssqpm.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ssqpn.dll
                    C:\WINDOWS\system32\ssqpn.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ssqpo.dll
                    C:\WINDOWS\system32\ssqpo.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ssqpp.dll
                    C:\WINDOWS\system32\ssqpp.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ssqpq.dll
                    C:\WINDOWS\system32\ssqpq.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ssqro.dll
                    C:\WINDOWS\system32\ssqro.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ssqrp.dll
                    C:\WINDOWS\system32\ssqrp.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ssqrq.dll
                    C:\WINDOWS\system32\ssqrq.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ssqrr.dll
                    C:\WINDOWS\system32\ssqrr.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ssqrs.dll
                    C:\WINDOWS\system32\ssqrs.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\sstqn.dll
                    C:\WINDOWS\system32\sstqn.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\sstqo.dll
                    C:\WINDOWS\system32\sstqo.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\sstqp.dll
                    C:\WINDOWS\system32\sstqp.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\sstqq.dll
                    C:\WINDOWS\system32\sstqq.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\sstqr.dll
                    C:\WINDOWS\system32\sstqr.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ssttq.dll
                    C:\WINDOWS\system32\ssttq.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ssttr.dll
                    C:\WINDOWS\system32\ssttr.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\sstts.dll
                    C:\WINDOWS\system32\sstts.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ssttt.dll
                    C:\WINDOWS\system32\ssttt.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\ssttu.dll
                    C:\WINDOWS\system32\ssttu.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtsqn.dll
                    C:\WINDOWS\system32\vtsqn.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtsqo.dll
                    C:\WINDOWS\system32\vtsqo.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtsqp.dll
                    C:\WINDOWS\system32\vtsqp.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtsqq.dll
                    C:\WINDOWS\system32\vtsqq.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtsqr.dll
                    C:\WINDOWS\system32\vtsqr.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtstq.dll
                    C:\WINDOWS\system32\vtstq.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtstr.dll
                    C:\WINDOWS\system32\vtstr.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtsts.dll
                    C:\WINDOWS\system32\vtsts.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtstt.dll
                    C:\WINDOWS\system32\vtstt.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtstu.dll
                    C:\WINDOWS\system32\vtstu.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vturo.dll
                    C:\WINDOWS\system32\vturo.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vturp.dll
                    C:\WINDOWS\system32\vturp.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vturq.dll
                    C:\WINDOWS\system32\vturq.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vturr.dll
                    C:\WINDOWS\system32\vturr.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vturs.dll
                    C:\WINDOWS\system32\vturs.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtutq.dll
                    C:\WINDOWS\system32\vtutq.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtutr.dll
                    C:\WINDOWS\system32\vtutr.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtuts.dll
                    C:\WINDOWS\system32\vtuts.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtutt.dll
                    C:\WINDOWS\system32\vtutt.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\vtutu.dll
                    C:\WINDOWS\system32\vtutu.dll Has been deleted!

                    Performing Repairs to the registry.
                    Done!

                    et voila:

                    Logfile of HijackThis v1.99.1
                    Scan saved at 11:29:45, on 12/05/2007
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16441)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
                    C:\Program Files\FileZilla Server\FileZilla Server.exe
                    C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\WINDOWS\system32\HPZipm12.exe
                    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                    C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
                    C:\WINDOWS\system32\NOTEPAD.EXE
                    C:\abcde.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr8.hpwis.com/
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr8.hpwis.com/
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr8.hpwis.com/
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr8.hpwis.com/
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                    O2 - BHO: (no name) - {3D723B89-C5AB-44AD-B0A5-467A9A4322E8} - C:\WINDOWS\system32\jkklk.dll (file missing)
                    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                    O2 - BHO: (no name) - {D1AF67A5-9EB1-4502-8FFC-B2B544CEFE98} - C:\WINDOWS\system32\tghueykq.dll
                    O2 - BHO: (no name) - {E2EE5C44-C66D-499d-BEAE-A2A79189A63A} - C:\WINDOWS\system32\jlmduicj.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                    O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "C:\WINDOWS\system32\nqksxfvx.dll",realset
                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    O4 - HKLM\..\RunServices: [MCX Update] wisp.exe
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                    O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
                    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                    O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (HKCU)
                    O11 - Options group: [INTERNATIONAL] International*
                    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                    O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photoways.com/clients/uploader_v2.1.0.56.cab
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                    O18 - Filter: text/html - (no CLSID) - (no file)
                    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                    O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                    O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
                    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                    1. Bonjour,

                      Méthode à suivre dans l'ordre...
                      ----------------------------------------------------------------------------
                      Télécharger ces logiciels (sauf si tu les as)
                      A utiliser plus tard

                      A - ad-aware version 1.06
                      (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
                      voir demo
                      http://pageperso.aol.fr/balltrap34/adwseflash.zip

                      B - spybot version 1.4
                      (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
                      voir demo d utilisation
                      http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

                      C - Ccleaner : ( nettoyeur de registre, cookies+temps+tempos+prefetch+historique+etc..)
                      Télécharge ici :
                      https://www.ccleaner.com/ccleaner/download
                      Tutorial ici:
                      https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

                      D - Ewido
                      https://www.malekal.com/tutorial-et-guide-ewido-v4/
                      ----------------------------------------------------------------------------
                      ¤Affiche tous les fichiers et dossiers :
                      Clique sur démarrer/panneau de configuration/outil/option des dossiers/affichage

                      Coche « afficher les fichiers et dossiers cachés »

                      Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                      Décoche « masquer les extensions dont le type est connu »
                      Puis fais «Ok» pour valider les changements.

                      Et appliquer !
                      =================================
                      Relance HijackThis, choisis " do a scan only" coche la case devant les lignes ci-dessous et clique en bas sur "fix checked"

                      O2 - BHO: (no name) - {3D723B89-C5AB-44AD-B0A5-467A9A4322E8} - C:\WINDOWS\system32\jkklk.dll (file missing)
                      O2 - BHO: (no name) - {D1AF67A5-9EB1-4502-8FFC-B2B544CEFE98} - C:\WINDOWS\system32\tghueykq.dll
                      E2EE5C44-C66D-499d-BEAE-A2A79189A63A
                      O4 - HKLM\..\RunServices: [MCX Update] wisp.exe
                      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/
                      O18 - Filter: text/html - (no CLSID) - (no file)

                      Cherche et supprime ce qui est en gras
                      demarrer /rechercher et tape
                      O4 - HKLM\..\RunServices: [MCX Update] wisp.exe
                      ============ ============================
                      ¤Démarre en mode sans échec :
                      Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                      Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                      Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                      (Si F8 ne marche pas utilise la touche F5).
                      ----------------------------------------------------------------------------
                      ¤Vide tes fichiers temps et temporary internet file:

                      Maintenant tu lances
                      A/ Ad-Aware supprime quarantaine
                      B/ Spybot Supprime quarantaine
                      C/ Ccleaner
                      D/ Ewido Copier/coller le rapport

                      ----------------------------------------------------------------------------
                      ¤ Vide ta Corbeille.
                      ----------------------------------------------------------------------------
                      ¤ Redémarre en mode normal, relance Hijackthis et copie/colle un nouveau rapport sur le forum.

                      Tiens nous au courant

                      A+
                      1. rebonjour,

                        voila:

                        Logfile of HijackThis v1.99.1
                        Scan saved at 15:55:23, on 12/05/2007
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16441)

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        C:\Program Files\FileZilla Server\FileZilla Server.exe
                        C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\WINDOWS\system32\HPZipm12.exe
                        C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                        C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                        C:\Program Files\Messenger\msmsgs.exe
                        C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                        C:\PROGRA~1\MI3AA1~1\rapimgr.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4gui.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\abcde.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\WINDOWS\system32\wuauclt.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr8.hpwis.com/
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr8.hpwis.com/
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr8.hpwis.com/
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr8.hpwis.com/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr8.hpwis.com/
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                        O2 - BHO: (no name) - {E2EE5C44-C66D-499d-BEAE-A2A79189A63A} - C:\WINDOWS\system32\jlmduicj.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                        O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O4 - HKLM\..\Run: [WindowsUpdate] rundll32.exe "C:\WINDOWS\system32\nqksxfvx.dll",realset
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                        O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
                        O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                        O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (HKCU)
                        O11 - Options group: [INTERNATIONAL] International*
                        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                        O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photoways.com/clients/uploader_v2.1.0.56.cab
                        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                        O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                        O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                        O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall 4\kpf4ss.exe
                        O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                        O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                        1. Je passe juste prendre la température de ton pc ?

                          Alors ! Quoi de neuf ?

                          lol
                      2. Et bien j'ai fait tout ce que tu m'as demandé....

                        Ca a l'air d'aller, mais je pense que tu dois pouvoir en dire plus que moi car je n'ais aucune idée de comment interpreter le dernier HijackThis que j'ai poster....
                      • 1
                      • 2
                      • 3