Fichier s'éxecute tout seul

Pour commencer, bonjour a toutes et tous.

Voilà j'ai un petit problème actuellement et je ne trouve pas comment le régler. Depuis quelques temps, j'ai un programme, je ne sais pas lequel, qui s'exécute tout seul.

En effet, dans ma barre des taches, une fenetre apparait comme si un programme s'exécute, et disparait aussitot... J'ai fait des scans d'anti-virus (AVG) et anti-spyware (spyboot et ad-aware) mais ils ne trouvent rien.

Je ne vois donc pas d'ou peut venir le problème et c'est la raison pour laquelle je suscite votre aide...

Merci d'avance

Amicalement kripte
Configuration: Windows XP
Firefox 2.0.0.3

31 réponses

Résumé de la discussion

Un utilisateur sous Windows XP observe qu'une fenêtre s'ouvre brièvement dans la barre des tâches puis disparaît, malgré des scans antivirus et antispyware infructueux, à l'origine inconnue. La meilleure réponse identifie le logiciel comme SweetIMBarForIE (Macrogaming) et conseille de le désinstaller via Ajout/Suppression de programmes puis de supprimer le dossier correspondant. Le rapport recommande de vérifier et supprimer les composants liés, notamment la barre d'outils SweetIM et les entrées DLL associées, pour éviter les occurrences récurrentes. En cas de persistance après suppression, la suite de l'intervention peut inclure une vérification des extensions et des scripts lancés au démarrage, ainsi que l'examen des éléments invisibles dans les tâches planifiées.

Bobot (l’IA à votre service)
  1. Contributeur
    bonjour,

    clic ici http://komun.chez-alice.fr/Utilitaires.html , choisis hijackthis pour l'installer et poster un rapport de scan
    a+
    0
    1. merci lance_yien voici le rapport (si c'est cela)

      * HijackThis v1.99.1 *
      Written by Merijn - merijn@spywareinfo.com
      http://www.merijn.org/files/hijackthis.zip
      http://www.merijn.org/index.html

      Traduction française réalisée .

      Par:PC-HELP-BORDEAUX http://pchelpbordeaux.free.fr .
      Retrouvez le tutorial complet sur le site de PC-HELP Poster vos LOG sur le forum d'Assistance Informatique en Live http://belver.free.fr ' '.

      R - Registry, StartPage/SearchPage changes
      R0 - Changed registry value
      R1 - Created registry value
      R2 - Created registry key
      R3 - Created extra registry value where only one should be
      F - IniFiles, autoloading entries
      F0 - Changed inifile value
      F1 - Created inifile value
      F2 - Changed inifile value, mapped to Registry
      F3 - Created inifile value, mapped to Registry
      N - Netscape/Mozilla StartPage/SearchPage changes
      N1 - Change in prefs.js of Netscape 4.x
      N2 - Change in prefs.js of Netscape 6
      N3 - Change in prefs.js of Netscape 7
      N4 - Change in prefs.js of Mozilla
      O - Other, several sections which represent:
      O1 - Hijack of auto.search.msn.com with Hosts file
      O2 - Enumeration of existing MSIE BHO's
      O3 - Enumeration of existing MSIE toolbars
      O4 - Enumeration of suspicious autoloading Registry entries
      O5 - Blocking of loading Internet Options in Control Panel
      O6 - Disabling of 'Internet Options' Main tab with Policies
      O7 - Disabling of Regedit with Policies
      O8 - Extra MSIE context menu items
      O9 - Extra 'Tools' menuitems and buttons
      O10 - Breaking of Internet access by New.Net or WebHancer
      O11 - Extra options in MSIE 'Advanced' settings tab
      O12 - MSIE plugins for file extensions or MIME types
      O13 - Hijack of default URL prefixes
      O14 - Changing of IERESET.INF
      O15 - Trusted Zone Autoadd
      O16 - Download Program Files item
      O17 - Domain hijack
      O18 - Enumeration of existing protocols and filters
      O19 - User stylesheet hijack
      O20 - AppInit_DLLs autorun Registry value, Winlogon Notify Registry keys
      O21 - ShellServiceObjectDelayLoad (SSODL) autorun Registry key
      O22 - SharedTaskScheduler autorun Registry key
      O23 - Enumeration of NT Services

      Command-line parameters:
      * /autolog - Automatically scan the system, save a logfile and open it
      * /ihatewhitelists - ignore all internal whitelists
      * /uninstall - remove all HijackThis Registry entries, backups and quit

      * Version history *

      [v1.99.1]
      * Added Winlogon Notify keys to O20 listing
      * Fixed crashing bug on certain Win2000 and WinXP systems at O23 listing
      * Fixed lots and lots of 'unexpected error' bugs
      * Fixed lots of inproper functioning bugs (i.e. stuff that didn't work)
      * Added 'Delete NT Service' function in Misc Tools section
      * Added ProtocolDefaults to O15 listing
      * Fixed MD5 hashing not working
      * Fixed 'ISTSVC' autorun entries with garbage data not being fixed
      * Fixed HijackThis uninstall entry not being updated/created on new versions
      * Added Uninstall Manager in Misc Tools to manage 'Add/Remove Software' list
      * Added option to scan the system at startup, then show results or quit if nothing found
      [v1.99]
      * Added O23 (NT Services) in light of newer trojans
      * Integrated ADS Spy into Misc Tools section
      * Added 'Action taken' to info in 'More info on this item'
      [v1.98]
      * Definitive support for Japanese/Chinese/Korean systems
      * Added O20 (AppInit_DLLs) in light of newer trojans
      * Added O21 (ShellServiceObjectDelayLoad, SSODL) in light of newer trojans
      * Added O22 (SharedTaskScheduler) in light of newer trojans
      * Backups of fixed items are now saved in separate folder
      * HijackThis now checks if it was started from a temp folder
      * Added a small process manager (Misc Tools section)
      [v1.96]
      * Lots of bugfixes and small enhancements! Among others:
      * Fix for Japanese IE toolbars
      * Fix for searchwww.com fake CLSID trick in IE toolbars and BHO's
      * Attributes on Hosts file will now be restored when scanning/fixing/restoring it.
      * Added several files to the LSP whitelist
      * Fixed some issues with incorrectly re-encrypting data, making R0/R1 go undetected until a restart
      * All sites in the Trusted Zone are now shown, with the exception of those on the nonstandard but safe domain list
      [v1.95]
      * Added a new regval to check for from Whazit hijack (Start Page_bak).
      * Excluded IE logo change tweak from toolbar detection (BrandBitmap and SmBrandBitmap).
      * New in logfile: Running processes at time of scan.
      * Checkmarks for running StartupList with /full and /complete in HijackThis UI.
      * New O19 method to check for Datanotary hijack of user stylesheet.
      * Google.com IP added to whitelist for Hosts file check.
      [v1.94]
      * Fixed a bug in the Check for Updates function that could cause corrupt downloads on certain systems.
      * Fixed a bug in enumeration of toolbars (Lop toolbars are now listed!).
      * Added imon.dll, drwhook.dll and wspirda.dll to LSP safelist.
      * Fixed a bug where DPF could not be deleted.
      * Fixed a stupid bug in enumeration of autostarting shortcuts.
      * Fixed info on Netscape 6/7 and Mozilla saying '%shitbrowser%' (oops).
      * Fixed bug where logfile would not auto-open on systems that don't have .log filetype registered.
      * Added support for backing up F0 and F1 items (d'oh!).
      [v1.93]
      * Added mclsp.dll (McAfee), WPS.DLL (Sygate Firewall), zklspr.dll (Zero Knowledge) and mxavlsp.dll (OnTrack) to LSP safelist.
      * Fixed a bug in LSP routine for Win95.
      * Made taborder nicer.
      * Fixed a bug in backup/restore of IE plugins.
      * Added UltimateSearch hijack in O17 method (I think).
      * Fixed a bug with detecting/removing BHO's disabled by BHODemon.
      * Also fixed a bug in StartupList (now version 1.52.1).
      [v1.92]
      * Fixed two stupid bugs in backup restore function.
      * Added DiamondCS file to LSP files safelist.
      * Added a few more items to the protocol safelist.
      * Log is now opened immediately after saving.
      * Removed rd.yahoo.com from NSBSD list (spammers are starting to use this, no doubt spyware authors will follow).
      * Updated integrated StartupList to v1.52.
      * In light of SpywareNuker/BPS Spyware Remover, any strings relevant to reverse-engineers are now encrypted.
      * Rudimentary proxy support for the Check for Updates function.
      [v1.91]
      * Added rd.yahoo.com to the Nonstandard But Safe Domains list.
      * Added 8 new protocols to the protocol check safelist, as well as showing the file that handles the protocol in the log (O18).
      * Added listing of programs/links in Startup folders (O4).
      * Fixed 'Check for Update' not detecting new versions.
      [v1.9]
      * Added check for Lop.com 'Domain' hijack (O17).
      * Bugfix in URLSearchHook (R3) fix.
      * Improved O1 (Hosts file) check.
      * Rewrote code to delete BHO's, fixing a really nasty bug with orphaned BHO keys.
      * Added AutoConfigURL and proxyserver checks (R1).
      * IE Extensions (Button/Tools menuitem) in HKEY_CURRENT_USER are now also detected.
      * Added check for extra protocols (O18).
      [v1.81]
      * Added 'ignore non-standard but safe domains' option.
      * Improved Winsock LSP hijackers detection.
      * Integrated StartupList updated to v1.4.
      [v1.8]
      * Fixed a few bugs.
      * Adds detecting of free.aol.com in Trusted Zone.
      * Adds checking of URLSearchHooks key, which should have only one value.
      * Adds listing/deleting of Download Program Files.
      * Integrated StartupList into the new 'Misc Tools' section of the Config screen!
      [v1.71]
      * Improves detecting of O6.
      * Some internal changes/improvements.
      [v1.7]
      * Adds backup function! Yay!
      * Added check for default URL prefix
      * Added check for changing of IERESET.INF
      * Added check for changing of Netscape/Mozilla homepage and default search engine.
      [v1.61]
      * Fixes Runtime Error when Hosts file is empty.
      [v1.6]
      * Added enumerating of MSIE plugins
      * Added check for extra options in 'Advanced' tab of 'Internet Options'.
      [v1.5]
      * Adds 'Uninstall & Exit' and 'Check for update online' functions.
      * Expands enumeration of autoloading Registry entries (now also scans for .vbs, .js, .dll, rundll32 and service)
      [v1.4]
      * Adds repairing of broken Internet access (aka Winsock or LSP fix) by New.Net/WebHancer
      * A few bugfixes/enhancements
      [v1.3]
      * Adds detecting of extra MSIE context menu items
      * Added detecting of extra 'Tools' menu items and extra buttons
      * Added 'Confirm deleting/ignoring items' checkbox
      [v1.2]
      * Adds 'Ignorelist' and 'Info' functions
      [v1.1]
      * Supports BHO's, some default URL changes
      [v1.0]
      * Original release

      A good thing to do after version updates is clear your Ignore list and re-add them, as the format of detected items sometimes changes.
      0
      1. Contributeur
        bonjour kripte,

        non, ce n'est pas ça du tout :)
        clic sur ce lien http://komun.chez-alice.fr/Utilitaires.html#hijackthis
        dans la page qui s'affiche
        * lis bien le mode d'utilisation ou imprimes la page si nécessaire (tu va en avoir besoin par la suite)
        * clic sur "hijackthis", puis sur "exécuter", suis les indications pour l'installer sur ton PC,
        qd c'est fini relances-le pour faire un scan et poster le rapport généré (comme expliqué)
        a+
        0
        1. ok ;) désolé... voila donc le rapport

          Logfile of HijackThis v1.99.1
          Scan saved at 13:47:27, on 30.05.2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16441)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
          C:\WINDOWS\Explorer.EXE
          C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
          C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
          C:\WINDOWS\eHome\ehRecvr.exe
          C:\WINDOWS\eHome\ehSched.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
          C:\WINDOWS\ehome\ehtray.exe
          C:\WINDOWS\system32\hkcmd.exe
          C:\WINDOWS\system32\igfxpers.exe
          C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
          C:\Program Files\Dell\Media Experience\DMXLauncher.exe
          C:\WINDOWS\System32\DLA\DLACTRLW.EXE
          C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
          C:\WINDOWS\system32\LVCOMSX.EXE
          C:\Program Files\Logitech\Video\LogiTray.exe
          C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
          C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
          C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
          C:\Program Files\Logitech\Video\FxSvr2.exe
          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\NETGEAR\WPN111\wpn111.exe
          C:\Program Files\Jibreel Inc\AntiCrash\AntiCrash.exe
          C:\Program Files\Canon\CAL\CALMAIN.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\WINDOWS\eHome\ehmsas.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\PROGRA~1\CABLEC~1\SMARTB~1\MotiveSB.exe
          C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.bluewin.ch/de/index.html
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
          O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
          O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O2 - BHO: Bluewin Toolbar - {4E7BD74F-2B8D-469E-DCF7-E869A199B87D} - C:\PROGRA~1\Bluewin\bluewin.dll
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ch\msntb.dll
          O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ch\msntb.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
          O3 - Toolbar: Bluewin Toolbar - {4E7BD74F-2B8D-469E-DCF7-E869A199B87D} - C:\PROGRA~1\Bluewin\bluewin.dll
          O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
          O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
          O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
          O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
          O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
          O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
          O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
          O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
          O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
          O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
          O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
          O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
          O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
          O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
          O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
          O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\CABLEC~1\SMARTB~1\DExec.exe 180000 C:\PROGRA~1\CABLEC~1\SMARTB~1\MotiveSB.exe
          O4 - HKLM\..\Run: [start_cablecom volumecounter] C:\Program Files\cablecom\Compteur de volume hispeed\volumecounter.exe
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - Startup: AntiCrash 5.0.lnk = C:\Program Files\Jibreel Inc\AntiCrash\AntiCrash.exe
          O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
          O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
          O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
          O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
          O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
          O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
          O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
          O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
          O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O11 - Options group: [INTERNATIONAL] International*
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
          O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
          O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
          O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
          O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
          O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
          O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
          O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
          O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
          O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
          O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
          O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
          O23 - Service: m2PacketcounterService (_service) - mquadr.at - C:\Program Files\cablecom\Compteur de volume hispeed\packetservice.exe
          0
          1. Contributeur
            re,

            1°) réfères-toi au lien de téléchargement de hijackthis pour fixer ces lignes:
            R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
            O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
            O2 - BHO: Bluewin Toolbar - {4E7BD74F-2B8D-469E-DCF7-E869A199B87D} - C:\PROGRA~1\Bluewin\bluewin.dll
            O3 - Toolbar: Bluewin Toolbar - {4E7BD74F-2B8D-469E-DCF7-E869A199B87D} - C:\PROGRA~1\Bluewin\bluewin.dll
            O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
            O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
            O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/
            O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

            2°) clic ici http://komun.chez-alice.fr/Utilitaires.html
            ** choisis Ad-fix, exécutes l'option "1" et postes le rapport généré
            ** choisis Navifix, exécutes l'option "1" et postes le rapport généré

            a+
            0
            1. alors voila, j'ai fixé avec hijacksthis

              Pour ad-fix :

              Ad-Fix v0.101a
              by gchris

              OPTION 1 (Scan) :

              »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

              Démarré à :

              16:08:17.68 30.05.2007

              Executé depuis :

              C:\Documents and Settings\Windows\Bureau\Ad-Fix

              Os :

              Microsoft Windows XP [version 5.1.2600]

              »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

              »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

              Recherche de fichier manquant

              »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

              »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

              Fichiers cachés (pas forcément mauvais)

              .exe dans System32 :

              No matches found.

              .dll dans System32 :

              No matches found.

              .dat dans System32 :

              C:\WINDOWS\SYSTEM32\
              zllictbl.dat Wed 4 Apr 2007 17:41:48 ...H. 4'212 4.11 K

              C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM~1\LOCALS~1\APPLIC~1\MICROS~1\WINDOWS\
              usrclass.dat Tue 7 Mar 2006 23:25:18 A..H. 262'144 256.00 K

              2 items found: 2 files, 0 directories.
              Total of file sizes: 266'356 bytes 260.11 K

              »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

              »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

              Analyse du registre

              ---------- USER AGENT -- POST PLATFORM

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
              "SIMBAR={0A31169D-18A5-4389-ACC1-87969A7F9527}"=""

              ----------

              ---------- AppInit_DLLs

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
              "AppInit_DLLs"=""

              ----------
              HKCR\Interface\{48E59292-9880-11CF-9754-00AA00C00908} Détecté !
              HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\media-motor.net Détecté !
              HKLM\SOFTWARE\Classes\Interface\{48E59292-9880-11CF-9754-00AA00C00908} Détecté !

              Complete!

              »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

              »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

              Recherche de fichiers et dossiers

              C:\Progra~1\Everest Poker\cstart-tmp.exe Détecté !
              C:\Progra~1\Everest Poker\CStart.exe Détecté !
              C:\Progra~1\Everest Poker\Everest Poker.exe Détecté !
              C:\Progra~1\MessengerSkinner Détecté !

              C:\WINDOWS\system32\*_nav.dat Détecté !
              C:\WINDOWS\system32\*_navps.dat Détecté !

              »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

              Terminé à 16:12:14.46


              Pour navifix
              :

              Search Navipromo version 2.0.2 commencé le 30.05.2007 à 16:00:11.46

              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
              !!! Poster ce rapport sur le forum pour le faire analyser !!!
              !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

              Fix lancé depuis C:\Program Files\navilog1
              Mise a jour le 17.05.2007 a 23h00 by IL-MAFIOSO

              Executé en mode normal

              *** Recherche Programmes installes ***

              MessengerSkinner

              *** Recherche dossiers dans C:\WINDOWS ***

              *** Recherche dossiers dans C:\Program Files ***

              C:\Program Files\MessengerSkinner trouvé !

              *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

              *** Recherche dossiers dans C:\Documents and Settings\Windows\Application Data ***

              ...\Application Data\MessengerSkinner trouvé !

              *** Recherche avec BlackLight Engine/F-secure ***
              BlackLight Engine est un produit de F-secure, pour + d'infos :
              https://www.f-secure.com/en

              F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
              ======================================

              Copyright 2005-2006 F-Secure Corporation. All rights reserved.
              This is a beta version. It will expire on 1st of April, 2007.
              Version information: 2.2.1061.

              [+] Started on 05/30/07 at 16:00:13.
              [+] Initializing ...
              [+] Starting scan, press Ctrl-C to abort.
              [+] Scanning for hidden items .......................................................................................
              [+] Scan complete.
              [+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
              [+] Exited on 05/30/07 at 16:09:01 (return code = 0).

              *** Recherche fichiers ***

              C:\WINDOWS\pack.epk trouvé !
              C:\WINDOWS\system32\nvs2.inf trouvé !

              *** Recherche cles registre ***

              Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]

              Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]

              Recherche Clé Magic Control

              HKEY_CURRENT_USER\Software\Lanconfig trouvé !

              *** Module de Recherche complémentaire ***
              (Recherche fichiers spécifiques)

              1)Recherche fichiers connus:

              2)Recherche Heuristique :
              *
              C:\WINDOWS\system32\zvtbmkd.dat trouvé !
              **
              C:\WINDOWS\system32\zvtbmkd.dat trouvé !
              ***
              ****
              C:\WINDOWS\system32\zvtbmkd_navps.dat trouvé !
              *****
              C:\WINDOWS\system32\zvtbmkd_nav.dat trouvé !
              ******
              *******
              ********

              *** Analyse Terminé le 30.05.2007 à 16:09:30.79 ***

              Donc voilà, à savoir que le problème est encore la ;( je te remercie du temps que tu me consacre :)

              @++
              0
              1. Contributeur
                re,

                ( je te remercie du temps que tu me consacre :)
                de rien, de rien :)
                Donc voilà, à savoir que le problème est encore la ;
                normal,
                les choses commencent maintenant :)
                ton PC est infecté, fais dans l'ordre:

                1°) réfères-toi aux lien de téléchargement de Ad-fix et de Navifix pour exécuter leurs options de nettoyage (ça se passe en mode sans échec) et postes leur rapport généré respectif.
                2°) clic ici http://komun.chez-alice.fr/Desinfection-Nettoyage.html et fais la procédure (sans adfix et navifix, déjà fait)
                3°) clic ici http://komun.chez-alice.fr/Utilitaires.html , fais le "scan avec bitdefender", enregistre le rapport pour le poster ici avec un nouveau hijackthis et tes commentaires sur ton pb initial

                bon courage ;)
                0
                1. Alors voilà... Avec beaucoup de courage :) et des litres de sueurs ;) j'ai enfin les rapports tant espéré...

                  Pour ad-fix

                  Ad-Fix v0.101a
                  by gchris

                  OPTION 2 (Fix) :

                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                  Démarré à :

                  17:41:59.39 30.05.2007
                  en mode sans échec

                  Executé depuis :

                  C:\Ad-Fix

                  Os :

                  Microsoft Windows XP [version 5.1.2600]

                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                  Recherche de fichier manquant

                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                  Nettoyage du registre

                  HKCR\Interface\{48E59292-9880-11CF-9754-00AA00C00908} Supprimé !
                  HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\media-motor.net Supprimé !

                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                  Suppression des fichiers

                  C:\WINDOWS\system32\*_nav.dat Supprimé !
                  C:\WINDOWS\system32\*_navps.dat Supprimé !
                  C:\Progra~1\Everest Poker\cstart-tmp.exe Supprimé !
                  C:\Progra~1\Everest Poker\CStart.exe Supprimé !
                  C:\Progra~1\Everest Poker\Everest Poker.exe Supprimé !
                  C:\Progra~1\MessengerSkinner Supprimé !

                  »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                  Terminé à 17:46:02.76

                  Redémarrage effectué

                  Pour Navifix

                  Clean Navipromo version 2.0.2 commencé le 30.05.2007 à 17:52:43.25

                  Fix lancé depuis C:\Program Files\navilog1
                  Mise a jour le 17.05.2007 a 23h00 by IL-MAFIOSO

                  Mode suppression automatique avec prise en charge résultats Blacklight

                  *** fsbl1.txt non trouvé ***
                  (Assurez-vous que Blacklight n'avait rien trouvé lors de la recherche)

                  *** Suppression dossiers dans C:\WINDOWS ***

                  *** Suppression dossiers dans C:\Program Files ***

                  *** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***

                  *** Suppression dossiers dans C:\Documents and Settings\Windows\Application Data ***

                  ...\Application Data\MessengerSkinner ...suppression...
                  ...\Application Data\MessengerSkinner supprimé !

                  *** Suppression fichiers ***

                  C:\WINDOWS\pack.epk supprimé !
                  C:\WINDOWS\system32\nvs2.inf supprimé !

                  *** Suppression fichiers temporaires ***

                  Nettoyage contenu C:\WINDOWS\Temp effectué !
                  Nettoyage contenu C:\Documents and Settings\Windows\Local Settings\Temp effectué !

                  *** Sauvegarde du registre vers dossier Backupnavi***

                  sauvegarde du registre réalise avec succes !

                  *** Nettoyage registre ***

                  Nettoyage registre Ok

                  *** Traitement Recherche complémentaire ***
                  (Recherche fichiers spécifiques)

                  1)Recherche fichiers connus:

                  2)Recherche et Suppression Heuristique :

                  *
                  C:\WINDOWS\System32\zvtbmkd.dat trouvé !
                  Copie C:\WINDOWS\system32\zvtbmkd.dat réalise avec succes !
                  C:\WINDOWS\system32\zvtbmkd.dat supprimé !

                  **
                  ***
                  ****
                  *****
                  ******
                  *******
                  ********

                  3)Contrôle présence clés Rootkit dans le registre :

                  Aucune autre clés présente dans le registre !

                  *** Nettoyage termine le 30.05.2007 à 18:03:19.84 ***

                  Pour ce qui concerne la procédure de nettoyage:

                  Pour le dossier Preftech-> ok

                  Pour CCleaner -> ok

                  Pour Spybot -> ok

                  Pour AVG -> Il me détecte deux fichiers : user32.dll et ntoskrnl.exe
                  Je les ai depuis quelques temps et il me semble avoir vu sur un forum (pas sur ce site il me semble) qu'il ne fallait surtout pas les delete sous risque de mauvais fonctionnement de windows. Je laisse ton avis d'expert pour me guider ;)

                  Pour bitdefender ->
                  J'ai bien effectué le scan mais une fois celui-ci terminé, le temps continu de tourner mais pas le reste... je vais donc te noter ce qui était inscrit dans les statistiques :

                  C:\Ad-fix\backup.zip=>backup/folder/messengerskinner.zip=>progra~1/messengerskinner/messengerskinner.exe satut: infected with: Backdoor.skinymes.Agent.A
                  et ensuite pour la meme ligne statut: disinfection failed
                  et toujours pour la meme ligne statut: Deleted

                  Pour hijackthis -> ok

                  Logfile of HijackThis v1.99.1
                  Scan saved at 00:38:28, on 31.05.2007
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16441)

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                  C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                  C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                  C:\WINDOWS\eHome\ehRecvr.exe
                  C:\WINDOWS\eHome\ehSched.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\ehome\ehtray.exe
                  C:\WINDOWS\system32\hkcmd.exe
                  C:\WINDOWS\system32\igfxpers.exe
                  C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                  C:\Program Files\Dell\Media Experience\DMXLauncher.exe
                  C:\WINDOWS\System32\DLA\DLACTRLW.EXE
                  C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                  C:\WINDOWS\system32\LVCOMSX.EXE
                  C:\Program Files\Logitech\Video\LogiTray.exe
                  C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                  C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
                  C:\Program Files\Canon\CAL\CALMAIN.exe
                  C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                  C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                  C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\NETGEAR\WPN111\wpn111.exe
                  C:\Program Files\Jibreel Inc\AntiCrash\AntiCrash.exe
                  C:\WINDOWS\system32\dllhost.exe
                  C:\Program Files\Logitech\Video\FxSvr2.exe
                  C:\WINDOWS\eHome\ehmsas.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\PROGRA~1\CABLEC~1\SMARTB~1\MotiveSB.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\WINDOWS\system32\notepad.exe
                  C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.bluewin.ch/de/index.html
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                  O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ch\msntb.dll
                  O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ch\msntb.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
                  O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                  O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
                  O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
                  O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
                  O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                  O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                  O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                  O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                  O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                  O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                  O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                  O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
                  O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
                  O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                  O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                  O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                  O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\CABLEC~1\SMARTB~1\DExec.exe 180000 C:\PROGRA~1\CABLEC~1\SMARTB~1\MotiveSB.exe
                  O4 - HKLM\..\Run: [start_cablecom volumecounter] C:\Program Files\cablecom\Compteur de volume hispeed\volumecounter.exe
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - Startup: AntiCrash 5.0.lnk = C:\Program Files\Jibreel Inc\AntiCrash\AntiCrash.exe
                  O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
                  O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                  O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
                  O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
                  O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
                  O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
                  O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
                  O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
                  O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
                  O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                  O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O11 - Options group: [INTERNATIONAL] International*
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                  O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                  O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
                  O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                  O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
                  O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                  O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
                  O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
                  O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
                  O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                  O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
                  O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
                  O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                  O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
                  O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                  O23 - Service: m2PacketcounterService (_service) - mquadr.at - C:\Program Files\cablecom\Compteur de volume hispeed\packetservice.exe

                  Malheureusement pour mes commentaires... je suis obligé d'avouer que le problème persiste et dur :(

                  J'attend donc tes prochaines instructions :)

                  Au plaisir et désolé pour tout ce pâté à lire :/

                  @++
                  0
                  1. Contributeur
                    bonjour kripte,

                    pour AVG et les deux fichiers en question, normalement on peut supprimer tout ce qu'il trouve,
                    il faut savoir qu'un fichier donné est ligitime à un endroit et pas dans un autre
                    peux-tu relever les chemins complt de ces 2 fichiers (manuellement ou par l'option "génerer un rapport de AVG")?
                    0
                    1. Re lance_yien

                      Voila les chemins pour AVG:

                      C:\windows\system32\user32.dll

                      C:\windows\system32\ntoskrnl.exe

                      Pour l'anti-crash je l'ai désinstallé vu qu'il n'a aucune utilité

                      J'ai également désactivé toutes les cases que tu m'as notée mais mon fantôme est toujours là... C'est pire qu'une mouche a M****

                      Sur ce j'attends de tes nouvelles

                      @+
                      0
                      1. Contributeur
                        re,

                        ces 2 fichiers sont normalement légitimes là où tu dis, n'y touchons pas.
                        >>> est-ce que tu peux me donner plus de précisions sur cette fenêtre furtive:
                        la fréquence de son apparition, à quel moment?
                        as-tu le temps d'appuyer sur la touche "pause" (ou "imprime écran" et coller dans "paint") de ton clavier pour figer l'écran à ce moment la et pouvoir lire qq chose
                        >>> clic ici http://komun.chez-alice.fr/Utilitaires.html ,
                        - choisis smitfraudfix, exécutes l'option "1" et postes le rapport généré
                        - choisis et exécutes "Lopxp" pour poster le rapport généré

                        a+
                        0
                        1. Et bien cette fenetre apparait dans la barre ou il y a démarrer lorsque je démarre windows et reviens périodiquement toutes les 20min environ. Elle apparait durant à peine une seconde et disparait aussitot. Il y a juste un icone avec la fenetre blanche et la bande bleue dessus (comme un fichier exe) et il n'y a rien de marqué dedans. C'est un peu embetant lorsque je regarde par exemple une vidéo en plein écran, la fenetre se redimentionne en petit et je suis obligé de remettre en plein écran. Quand je travaille sur un prog, peu importe lequelle, sa bloque le temps de l'apparition et la disparition du problème.

                          J'ai essayé de faire un print screen mais durant son execution, il est impossible de faire quoi que ce soit...

                          Smitfraudix

                          SmitFraudFix v2.127

                          Rapport fait à 12:21:09.56, 31.05.2007
                          Executé à partir de C:\Program Files\smitfraudfix\SmitfraudFix\SmitfraudFix
                          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                          Le type du système de fichiers est NTFS
                          Fix executé en mode normal

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Windows

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Windows\Application Data

                          »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Windows\Favoris

                          »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                          »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                          »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                          "Source"="About:Home"
                          "SubscribedURL"="About:Home"
                          "FriendlyName"="Ma page d'accueil"

                          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                          "AppInit_DLLs"=""

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          "System"=""

                          »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Fin

                          Lopxp

                          Rapport lopxpMH2 version 2.0 fait à 12:16:54.85 le 31.05.2007
                          C:\

                          ******************************************
                          ## Répertoires Application Data

                          Le volume dans le lecteur C s'appelle Disque local
                          Le numéro de série du volume est E4AF-B864

                          Répertoire de C:\Documents and Settings\Administrateur\Application Data

                          01.09.2005 08:25 <REP> .
                          01.09.2005 08:25 <REP> ..
                          01.09.2005 08:25 <REP> Identities
                          01.09.2005 08:25 <REP> Microsoft
                          07.03.2006 23:11 <REP> Sun
                          01.09.2005 08:25 62 desktop.ini
                          1 fichier(s) 62 octets
                          5 Rép(s) 55'501'459'456 octets libres
                          Le volume dans le lecteur C s'appelle Disque local
                          Le numéro de série du volume est E4AF-B864

                          Répertoire de C:\Documents and Settings\Administrateur\Local Settings\Application Data

                          01.09.2005 08:25 <REP> .
                          01.09.2005 08:25 <REP> ..
                          07.03.2006 23:10 <REP> {7148F0A6-6813-11D6-A77B-00B0D0142030}
                          01.09.2005 08:27 <REP> ApplicationHistory
                          01.09.2005 08:25 <REP> Microsoft
                          01.09.2005 08:28 137 fusioncache.dat
                          01.09.2005 08:34 3'244'138 IconCache.db
                          2 fichier(s) 3'244'275 octets
                          5 Rép(s) 55'501'455'360 octets libres
                          Le volume dans le lecteur C s'appelle Disque local
                          Le numéro de série du volume est E4AF-B864

                          Répertoire de C:\Documents and Settings\All Users\Application Data

                          01.09.2005 08:04 <REP> .
                          01.09.2005 08:04 <REP> ..
                          25.05.2007 23:11 <REP> {1F3B99AC-CEBE-4773-B067-BCA5B73E8935}
                          07.03.2006 23:18 <REP> Adobe
                          14.03.2006 15:19 <REP> Ahead
                          15.12.2006 14:06 <REP> Apple Computer
                          12.06.2006 20:05 <REP> avg7
                          25.05.2007 23:12 <REP> cablecom
                          14.03.2006 15:02 <REP> CanonBJ
                          22.03.2007 23:09 <REP> Google
                          12.06.2006 20:05 <REP> Grisoft
                          07.03.2006 23:19 <REP> InstallShield
                          07.03.2006 23:21 <REP> McAfee
                          07.03.2006 23:21 <REP> McAfee.com
                          07.03.2006 23:21 <REP> McAfee.com Personal Firewall
                          01.09.2005 08:04 <REP> Microsoft
                          25.05.2007 22:02 <REP> Motive
                          02.04.2006 01:41 <REP> River Past G4
                          03.03.2007 18:53 <REP> Skype
                          07.03.2006 23:16 <REP> Sonic
                          14.03.2006 00:50 <REP> Sony Corporation
                          09.07.2006 02:14 <REP> Spybot - Search & Destroy
                          15.03.2007 14:17 <REP> TEMP
                          14.03.2006 00:12 <REP> Windows Genuine Advantage
                          17.03.2006 00:13 <REP> Yahoo! Companion
                          01.09.2005 08:08 62 desktop.ini
                          14.03.2006 23:30 786 hpzinstall.log
                          05.02.2007 10:27 1'359 QTSBandwidthCache
                          3 fichier(s) 2'207 octets
                          25 Rép(s) 55'501'455'360 octets libres
                          Le volume dans le lecteur C s'appelle Disque local
                          Le numéro de série du volume est E4AF-B864

                          Répertoire de C:\Documents and Settings\Default User\Application Data

                          01.09.2005 08:04 <REP> .
                          01.09.2005 08:04 <REP> ..
                          13.03.2006 19:32 <REP> Identities
                          01.09.2005 08:04 <REP> Microsoft
                          13.03.2006 19:32 <REP> Sun
                          01.09.2005 08:08 62 desktop.ini
                          1 fichier(s) 62 octets
                          5 Rép(s) 55'501'455'360 octets libres
                          Le volume dans le lecteur C s'appelle Disque local
                          Le numéro de série du volume est E4AF-B864

                          Répertoire de C:\Documents and Settings\Default User\Local Settings\Application Data

                          01.09.2005 08:08 <REP> .
                          01.09.2005 08:08 <REP> ..
                          13.03.2006 19:32 <REP> {7148F0A6-6813-11D6-A77B-00B0D0142030}
                          13.03.2006 19:32 <REP> ApplicationHistory
                          01.09.2005 08:17 <REP> Microsoft
                          13.03.2006 19:32 137 fusioncache.dat
                          13.03.2006 19:32 3'244'138 IconCache.db
                          2 fichier(s) 3'244'275 octets
                          5 Rép(s) 55'501'451'264 octets libres
                          Le volume dans le lecteur C s'appelle Disque local
                          Le numéro de série du volume est E4AF-B864

                          Répertoire de C:\Documents and Settings\LocalService\Application Data

                          01.09.2005 08:24 <REP> .
                          01.09.2005 08:24 <REP> ..
                          12.06.2006 20:05 <REP> AVG7
                          13.03.2006 22:57 <REP> McAfee.com Personal Firewall
                          01.09.2005 08:24 <REP> Microsoft
                          17.05.2006 12:55 <REP> Webroot
                          0 fichier(s) 0 octets
                          6 Rép(s) 55'501'451'264 octets libres
                          Le volume dans le lecteur C s'appelle Disque local
                          Le numéro de série du volume est E4AF-B864

                          Répertoire de C:\Documents and Settings\LocalService\Local Settings\Application Data

                          01.09.2005 08:24 <REP> .
                          01.09.2005 08:24 <REP> ..
                          01.09.2005 08:24 <REP> Microsoft
                          0 fichier(s) 0 octets
                          3 Rép(s) 55'501'451'264 octets libres
                          Le volume dans le lecteur C s'appelle Disque local
                          Le numéro de série du volume est E4AF-B864

                          Répertoire de C:\Documents and Settings\NetworkService\Application Data

                          01.09.2005 08:24 <REP> .
                          01.09.2005 08:24 <REP> ..
                          01.09.2005 08:24 <REP> Microsoft
                          0 fichier(s) 0 octets
                          3 Rép(s) 55'501'451'264 octets libres
                          Le volume dans le lecteur C s'appelle Disque local
                          Le numéro de série du volume est E4AF-B864

                          Répertoire de C:\Documents and Settings\NetworkService\Local Settings\Application Data

                          01.09.2005 08:24 <REP> .
                          01.09.2005 08:24 <REP> ..
                          01.09.2005 08:24 <REP> Microsoft
                          0 fichier(s) 0 octets
                          3 Rép(s) 55'501'451'264 octets libres
                          Le volume dans le lecteur C s'appelle Disque local
                          Le numéro de série du volume est E4AF-B864

                          Répertoire de C:\Documents and Settings\Windows\Application Data

                          13.03.2006 19:33 <REP> .
                          13.03.2006 19:33 <REP> ..
                          14.03.2006 04:22 <REP> Adobe
                          14.03.2006 15:29 <REP> Ahead
                          04.05.2006 23:10 <REP> AlbumGV
                          15.12.2006 14:08 <REP> Apple Computer
                          12.06.2006 20:05 <REP> AVG7
                          14.03.2006 00:58 <REP> Azureus
                          14.03.2006 02:08 <REP> FotoWire
                          30.05.2006 01:05 <REP> Help
                          13.03.2006 19:33 <REP> Identities
                          20.06.2006 15:50 <REP> Lavasoft
                          14.03.2006 01:25 <REP> Leadertech
                          17.03.2006 00:12 <REP> Macromedia
                          14.03.2006 03:29 <REP> McAfee
                          13.03.2006 19:33 <REP> McAfee.com Personal Firewall
                          14.03.2006 00:24 <REP> Media Player Classic
                          13.03.2006 19:33 <REP> Microsoft
                          20.06.2006 16:01 <REP> Mozilla
                          15.03.2007 12:52 <REP> PC Tools
                          02.04.2006 01:48 <REP> River Past G4
                          25.05.2007 23:11 <REP> Seven Zip
                          03.03.2007 18:53 <REP> Skype
                          14.03.2006 01:26 <REP> Sonic
                          14.03.2006 00:49 <REP> Sony Corporation
                          13.03.2006 19:33 <REP> Sun
                          04.07.2006 20:05 <REP> vlc
                          18.03.2006 01:58 <REP> X-Chat 2
                          13.03.2006 19:33 62 desktop.ini
                          02.01.2007 16:54 3'584 dvd.bmk
                          18.05.2006 22:01 7'442 GdiplusUpgrade_MSIApproach_Wrapper.log
                          26.03.2006 02:04 187 G-Force Prefs (WindowsMediaPlayer).txt
                          4 fichier(s) 11'275 octets
                          28 Rép(s) 55'501'451'264 octets libres
                          Le volume dans le lecteur C s'appelle Disque local
                          Le numéro de série du volume est E4AF-B864

                          Répertoire de C:\Documents and Settings\Windows\Local Settings\Application Data

                          13.03.2006 19:33 <REP> .
                          13.03.2006 19:33 <REP> ..
                          13.03.2006 19:33 <REP> {7148F0A6-6813-11D6-A77B-00B0D0142030}
                          14.03.2006 04:22 <REP> Adobe
                          15.12.2006 14:08 <REP> Apple Computer
                          13.03.2006 19:33 <REP> ApplicationHistory
                          22.03.2007 23:09 <REP> Google
                          30.05.2006 01:05 <REP> Help
                          14.03.2006 23:47 <REP> HP
                          29.07.2006 00:33 <REP> Identities
                          16.03.2006 21:45 <REP> IsolatedStorage
                          14.03.2006 02:13 <REP> Logitech-LS
                          13.03.2006 19:33 <REP> Microsoft
                          20.06.2006 16:02 <REP> Mozilla
                          14.03.2006 02:26 <REP> WMTools Downloaded Files
                          13.03.2006 19:44 231'936 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
                          13.03.2006 19:33 130 fusioncache.dat
                          14.03.2006 00:15 28'992 GDIPFONTCACHEV1.DAT
                          13.03.2006 19:33 3'174'914 IconCache.db
                          4 fichier(s) 3'435'972 octets
                          15 Rép(s) 55'501'447'168 octets libres
                          Le volume dans le lecteur C s'appelle Disque local
                          Le numéro de série du volume est E4AF-B864

                          Répertoire de C:\WINDOWS\system32\config\systemprofile\Application Data

                          01.09.2005 08:23 <REP> .
                          01.09.2005 08:23 <REP> ..
                          13.03.2006 19:32 <REP> Identities
                          13.03.2006 19:33 <REP> McAfee.com Personal Firewall
                          01.09.2005 08:23 <REP> Microsoft
                          13.03.2006 19:32 <REP> Sun
                          01.09.2005 08:23 62 desktop.ini
                          1 fichier(s) 62 octets
                          6 Rép(s) 55'501'447'168 octets libres
                          Le volume dans le lecteur C s'appelle Disque local
                          Le numéro de série du volume est E4AF-B864

                          Répertoire de C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data

                          01.09.2005 08:23 <REP> .
                          01.09.2005 08:23 <REP> ..
                          13.03.2006 19:32 <REP> {7148F0A6-6813-11D6-A77B-00B0D0142030}
                          13.03.2006 19:32 <REP> ApplicationHistory
                          01.09.2005 08:23 <REP> Microsoft
                          13.03.2006 19:32 137 fusioncache.dat
                          13.03.2006 19:32 3'244'138 IconCache.db
                          2 fichier(s) 3'244'275 octets
                          5 Rép(s) 55'501'447'168 octets libres

                          ******************************************
                          Recherche des taches planifiées dans C:\WINDOWS\tasks

                          C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
                          Kõ‘ÚM¥¾+Lk›Õ£F ê <
                          s €!× + : C : \ P r o g r a m F i l e s \ A p p l e S o f t w a r e U p d a t e \ S o f t w a r e U p d a t e . e x e - T a s k S Y S T E M 0 Ö +
                          ******************************************
                          ## Répertoires de C:\Program Files

                          Le volume dans le lecteur C s'appelle Disque local
                          Le numéro de série du volume est E4AF-B864

                          Répertoire de C:\Program Files

                          31.05.2007 12:13 <REP> .
                          31.05.2007 12:13 <REP> ..
                          07.03.2006 23:18 <REP> Adobe
                          14.03.2006 15:24 <REP> Ahead
                          05.09.2006 13:02 <REP> Alwil Software
                          04.03.2007 18:01 <REP> Apple Software Update
                          30.03.2006 02:01 <REP> Audacity
                          06.03.2007 17:43 <REP> Azureus
                          30.05.2007 15:49 <REP> Bluewin
                          25.05.2007 23:14 <REP> cablecom
                          25.05.2007 23:10 <REP> Cablecom Assistant
                          18.05.2006 21:53 <REP> Canon
                          02.08.2006 22:00 <REP> CartaGoGo
                          29.04.2007 02:53 <REP> CCleaner
                          25.05.2007 22:02 <REP> Common Files
                          08.02.2007 20:41 <REP> Compedia
                          01.09.2005 08:13 <REP> ComPlus Applications
                          07.03.2006 23:16 <REP> Dell
                          02.04.2006 01:50 <REP> DivX
                          22.03.2006 01:40 <REP> DivXcodec
                          28.05.2007 14:58 <REP> eMule
                          08.07.2006 11:55 <REP> ESET
                          25.05.2007 22:02 <REP> Fichiers communs
                          09.07.2006 03:34 <REP> GemMasterFrench
                          14.03.2006 02:36 <REP> Google
                          19.02.2007 15:36 <REP> Grisoft
                          14.03.2006 01:23 <REP> GSpot
                          20.09.2006 15:23 <REP> Guitar Pro 4
                          17.04.2006 18:26 <REP> Hewlett-Packard
                          31.05.2007 00:38 <REP> Hijackthis Version Française
                          17.04.2006 18:26 <REP> HP
                          07.03.2006 23:16 <REP> Intel
                          07.03.2006 23:16 <REP> InterActual
                          09.05.2007 03:02 <REP> Internet Explorer
                          17.03.2006 01:15 <REP> IrfanView
                          12.04.2007 23:15 <REP> Java
                          08.07.2006 18:42 <REP> Jibreel Inc
                          20.06.2006 15:50 <REP> Lavasoft
                          14.03.2006 02:08 <REP> Logitech
                          10.03.2007 18:21 <REP> Macrogaming
                          07.03.2006 23:21 <REP> McAfee
                          07.03.2006 23:11 <REP> Messenger
                          19.03.2006 01:17 <REP> Micro Application
                          20.06.2006 16:18 <REP> Microsoft AntiSpyware
                          01.09.2005 08:18 <REP> microsoft frontpage
                          18.08.2006 17:12 <REP> Microsoft Office
                          07.03.2006 23:17 <REP> Microsoft Visual Studio
                          07.03.2006 23:22 <REP> Microsoft Works
                          07.03.2006 23:17 <REP> Microsoft.NET
                          04.07.2006 10:50 <REP> MobeeSoft
                          25.05.2007 23:10 <REP> Motive
                          01.09.2005 08:12 <REP> Movie Maker
                          07.05.2007 16:49 <REP> Mozilla Firefox
                          31.03.2006 22:16 <REP> MSN
                          14.03.2006 02:20 <REP> MSN Apps
                          01.09.2005 08:12 <REP> MSN Gaming Zone
                          08.03.2007 15:49 <REP> MSN Messenger
                          17.11.2006 04:01 <REP> MSXML 4.0
                          13.04.2007 00:01 <REP> Multi_Media_France
                          30.05.2007 18:03 <REP> Navilog1
                          26.05.2007 00:04 <REP> NETGEAR
                          01.09.2005 08:15 <REP> NetMeeting
                          13.03.2006 19:51 <REP> Netopia
                          01.09.2005 08:13 <REP> Online Services
                          15.12.2006 04:00 <REP> Outlook Express
                          17.04.2006 18:30 <REP> Overland
                          07.04.2007 01:15 <REP> PhotoFiltre Studio
                          09.07.2006 00:59 <REP> RFA
                          07.03.2006 23:19 <REP> Roxio
                          14.03.2006 00:24 <REP> Satsuki Decoder Pack
                          13.03.2006 19:55 <REP> Services en ligne
                          07.03.2006 23:14 <REP> Sigmatel
                          20.05.2007 15:59 <REP> Skype
                          31.05.2007 12:13 <REP> smitfraudfix
                          07.03.2006 23:19 <REP> Sonic
                          29.11.2006 21:30 <REP> Sony
                          14.03.2006 00:51 <REP> Sony Corporation
                          30.05.2007 18:31 <REP> Spybot - Search & Destroy
                          24.03.2007 16:50 <REP> Spyware Doctor
                          18.04.2007 21:46 <REP> Ubisoft
                          09.07.2006 03:29 <REP> VideoLAN
                          22.03.2006 01:19 <REP> virtualDub
                          13.04.2006 22:57 <REP> virtualDubmod
                          31.05.2007 01:09 <REP> Winamp
                          05.02.2007 10:40 <REP> Windows Media Connect 2
                          21.03.2007 01:42 <REP> Windows Media Player
                          01.09.2005 08:12 <REP> Windows NT
                          01.09.2005 08:12 <REP> Windows Plus
                          30.05.2006 01:05 <REP> WinRAR
                          18.03.2006 01:57 <REP> X-Chat 2
                          01.09.2005 08:18 <REP> xerox
                          04.05.2006 23:10 <REP> Xydot
                          17.03.2006 00:12 <REP> Yahoo!
                          13.06.2006 16:52 <REP> Zone Labs
                          0 fichier(s) 0 octets
                          94 Rép(s) 55'501'430'784 octets libres

                          ******************************************
                          ## Popups autorisées

                          * Internet Explorer

                          ! REG.EXE VERSION 3.0

                          HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow
                          www1.euro.dell.com REG_NONE
                          support.euro.dell.com REG_NONE

                          * Mozilla Firefox (1 autorisé 2 interdit)

                          ---------- C:\DOCUMENTS AND SETTINGS\WINDOWS\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\Q9I5ZNXE.DEFAULT\HOSTPERM.1
                          host popup 1 www.t45ol.com
                          host popup 1 www.telecharger-anime.com
                          host popup 1 www.jeuxvideo.com

                          ******************************************
                          ## Registre

                          * [HKEY_CURRENT_USER\\Software\Microsoft\Internet Explorer\Main]
                          Search Bar REG_SZ http://www.google.com/toolbar/ie8/sidebar.html

                          ******************************************
                          ## Zones de sécurité

                          * HKCU Domains (4)

                          * P3P History (5)

                          ******************************************
                          ## Recherche C:\WINDOWS\*.htm, "C:\WINDOWS\*.gif"

                          *************** Fin du rapport ****************

                          voila @+
                          0
                          1. Contributeur
                            re,

                            >> ouvres le dossier C:\WINDOWS\Tasks et supprimes toutes les taches planifiées
                            >> tu as AVG 7 comme AV actif et Zonelabs comme pare-feu, mais tu as des dossiers Mcafee ici:
                            - C:\Program Files
                            - C:\Documents and Settings\All Users\Application Data
                            - C:\Documents and Settings\Windows\Application Data
                            - C:\WINDOWS\system32\config\systemprofile\Application Data
                            >> Webroot (spy sweeper) ici C:\Documents and Settings\LocalService\Application Data
                            >> dans C:\Program Files
                            -Alwil Software (Avast sûrement)
                            - Jibreel Inc (cadavre de anticrash)
                            - Microsoft AntiSpyware (consomme des ressource, tu t'en sert car pas vu sur hijackthis)
                            - Navilog1 (nous avon fini avec)
                            - smitfraudfix (idem)
                            - Spyware Doctor (tu t'en sert car pas vu sur hijackthis)

                            tiens-nous au courant du résultat

                            a+
                            0
                            1. Alors dans C:\windows\tasks => je ne peux pas supprimer les taches... Le dossier uniquement (ce que je n'ai pas encore fait)

                              Pour le reste, j'ai pu tous supprimer sauf pour

                              Webroot (spy sweeper) ici C:\Documents and Settings\LocalService\Application Data

                              il n'y a pas de répertoire localservice directement dans documents and settings

                              Et le problème demeure ;(

                              @+
                              0
                              1. Contributeur
                                re,

                                ((Alors dans C:\windows\tasks => je ne peux pas supprimer les taches... Le dossier uniquement (ce que je n'ai pas encore fait) ))
                                comment ça? clic droit > "supprimer" sur chacune (tu dois avoir au moins celle-ci "C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
                                ((- si tu ne trouves pas affiches les fichiers/dossiers cachés comme indiqué plus bas.
                                - si difficulté passes en mode sans échec)

                                ((il n'y a pas de répertoire localservice directement dans documents and settings ))
                                clic sur "outils"> "option dossiers" > "affichage" et coches "afficher les fichiers et... cachés" pui décoches "masquer les fichiers dossiers système protégés"
                                => n'oublies pas de remettre comme c'était

                                a+
                                0
                                1. re,

                                  J'ai pu effacer ce qu'il y avait dans le répertoire tasks et le dossier webroot également.

                                  J'ai donc relancé windows mais le souci est toujours la, ( A savoir, je ne sais pas si cela va t'aider...) que lorsque j'ai démarré en mode sans échec, la fenetre n'apparaissait pas...

                                  J'attend donc de tes nouvelles ;)

                                  ++

                                  PS : Quand meme une bonne nouvelle... Windows va plus vite ;) c'est déja ca :)

                                  PS2 : Désolé si je saoul mais je souhaite désinstaller yahoo toolbar dans ajouts et suppressions de programme mais impossible... de quoi cela peut-il venir?
                                  0
                                  1. Contributeur
                                    bonjour kripte,

                                    tant mieux si ça tourne mieux :)
                                    désolé mais il va faloir encore en enlever:
                                    après renseignement voilà la réponse que j'ai eu
                                    ((Ici tu as fais fixé la barre d'outil mais pas supprimé : R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                                    Il parait que ce programme (SweetIMBarForIE=Macrogaming) est une saloprie.
                                    ))
                                    donc désinstalles par "ajout &suppr des prog" et supprimes son dossier s'ilpersiste (si difficulté passes en mode sans échec= valable pour yahoo)
                                    -----------------------
                                    quand c'st fini on repart à la chasse du "fantôme" (à moins que.., vérifie s'il est toujours là)
                                    si oui:
                                    ** clic ici pour télécharger (sur ton bureau) clean.zip http://www.malekal.com/download/clean.zip
                                    fermes ton navigateur et dézippes le fichier (clic droit > extraire ici)
                                    ouvres le nouveau dossier clean et clic sur "clan.cmd" (cmd peut ne pas apparaître)
                                    exécute l'option "1", enregistre le rapport pour le poster ici après redémarrage en mode normal.

                                    ** CLIC DROIT sur ce lien https://www.silentrunners.org/Silent%20Runners.vbs
                                    choisis "enregistrer la cible sous...",
                                    dans la fenêtre qui s'ouvre clic sur "bureau" (à gauche) puis sur "enregistrer" (en bas à droite)
                                    clic sur ce nouveau fichier pour le lancer.
                                    Un rapport sera généré, ouvres-le avec le bloc notes, ensuite
                                    clique sur les touches Ctrl et A pour sélectionner tout
                                    clique sur les touches Ctrl et C pour copier
                                    clique enfin sur les touches Ctrl et V pour coller le rapport ici dans une réponse
                                    a+
                                    0
                                    1. salut lance ;)

                                      Alors voilà pour sweetIM => Son compte est bon :)

                                      Pour yahoo toolbar, meme en mode sans échec, rien à faire, il se tape l'incruste (c'est une belle saloperie celui-la aussi)

                                      Quant a mon problème, c'est inchangé...

                                      Rapport pour clean

                                      01.06.2007 a 15:52:26.81

                                      *** Recherche des fichiers dans C:

                                      *** Recherche des fichiers dans C:\WINDOWS\

                                      *** Recherche des fichiers dans C:\WINDOWS\system32
                                      "C:\WINDOWS\Downloaded Program Files\CONFLICT.1" FOUND

                                      *** Recherche des fichiers dans C:\Program Files
                                      *** Fin du rapport !

                                      Pour Runners

                                      "Silent Runners.vbs", revision R50, https://www.silentrunners.org/
                                      Operating System: Windows XP SP2
                                      Output limited to non-default values, except where indicated by "{++}"

                                      Startup items buried in registry:
                                      ---------------------------------

                                      HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
                                      "ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]

                                      HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
                                      "ehTray" = "C:\WINDOWS\ehome\ehtray.exe" [MS]
                                      "HP Component Manager" = ""C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"" ["Hewlett-Packard Company"]
                                      "MSKDetectorExe" = "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall" [file not found]
                                      "AVG7_CC" = "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]
                                      "ZoneAlarm Client" = ""C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"" ["Zone Labs, LLC"]

                                      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
                                      {02478D38-C3F9-4EFB-9B51-7695ECA05670}\(Default) = (no title provided)
                                      -> {HKLM...CLSID} = "Yahoo! Toolbar Helper"
                                      \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]
                                      {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
                                      -> {HKLM...CLSID} = "AcroIEHlprObj Class"
                                      \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
                                      {22BF413B-C6D2-4d91-82A9-A0F997BA588C}\(Default) = "Skype add-on (mastermind)"
                                      -> {HKLM...CLSID} = "Skype add-on (mastermind)"
                                      \InProcServer32\(Default) = "C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll" ["Skype Technologies S.A."]
                                      {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
                                      -> {HKLM...CLSID} = (no title provided)
                                      \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
                                      {5CA3D70E-1895-11CF-8E15-001234567890}\(Default) = (no title provided)
                                      -> {HKLM...CLSID} = "DriveLetterAccess"
                                      \InProcServer32\(Default) = "C:\WINDOWS\System32\DLA\DLASHX_W.DLL" ["Sonic Solutions"]
                                      {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
                                      -> {HKLM...CLSID} = "SSVHelper Class"
                                      \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll" ["Sun Microsystems, Inc."]
                                      {9394EDE7-C8B5-483E-8773-474BF36AF6E4}\(Default) = (no title provided)
                                      -> {HKLM...CLSID} = "ST"
                                      \InProcServer32\(Default) = "C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll" [MS]
                                      {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
                                      -> {HKLM...CLSID} = "Google Toolbar Helper"
                                      \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]
                                      {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\(Default) = (no title provided)
                                      -> {HKLM...CLSID} = "MSNToolBandBHO"
                                      \InProcServer32\(Default) = "C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ch\msntb.dll" [MS]

                                      HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
                                      "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
                                      -> {HKLM...CLSID} = "Extension Affichage Panorama du Panneau de configuration"
                                      \InProcServer32\(Default) = "deskpan.dll" [file not found]
                                      "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
                                      -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
                                      \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
                                      "{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
                                      -> {HKLM...CLSID} = "Microsoft Office Outlook"
                                      \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL" [MS]
                                      "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
                                      -> {HKLM...CLSID} = "Outlook File Icon Extension"
                                      \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL" [MS]
                                      "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
                                      -> {HKLM...CLSID} = (no title provided)
                                      \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll" [MS]
                                      "{5CA3D70E-1895-11CF-8E15-001234567890}" = "DriveLetterAccess"
                                      -> {HKLM...CLSID} = "DriveLetterAccess"
                                      \InProcServer32\(Default) = "C:\WINDOWS\System32\DLA\DLASHX_W.DLL" ["Sonic Solutions"]
                                      "{0561EC90-CE54-4f0c-9C55-E226110A740C}" = "Haali Column Provider"
                                      -> {HKLM...CLSID} = "Haali Column Provider"
                                      \InProcServer32\(Default) = "C:\Program Files\Satsuki Decoder Pack\filtres\divers\mmfinfo.dll" [null data]
                                      "{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3}" = "My Logitech Pictures"
                                      -> {HKLM...CLSID} = "My Logitech Pictures"
                                      \InProcServer32\(Default) = "C:\Program Files\Logitech\Video\Namespc2.dll" ["Logitech Inc."]
                                      "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
                                      -> {HKLM...CLSID} = "WinRAR"
                                      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
                                      "{1530F7EE-5128-43BD-9977-84A4B0FAD7DF}" = "PhotoToys"
                                      -> {HKLM...CLSID} = (no title provided)
                                      \InProcServer32\(Default) = "C:\WINDOWS\system32\phototoys.dll" [MS]
                                      "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
                                      -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
                                      \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."]
                                      "{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
                                      -> {HKLM...CLSID} = "AVG7 Find Extension Class"
                                      \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."]
                                      "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
                                      -> {HKLM...CLSID} = "Mes dossiers de partage"
                                      \InProcServer32\(Default) = "C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll" [MS]
                                      "{D9872D13-7651-4471-9EEE-F0A00218BEBB}" = "Multiscan"
                                      -> {HKLM...CLSID} = "ZLAVShExt Class"
                                      \InProcServer32\(Default) = "C:\Program Files\Zone Labs\ZoneAlarm\zlavscan.dll" ["Zone Labs, LLC"]

                                      HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
                                      "WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
                                      -> {HKLM...CLSID} = "WPDShServiceObj Class"
                                      \InProcServer32\(Default) = "C:\WINDOWS\system32\WPDShServiceObj.dll" [MS]

                                      HKLM\System\CurrentControlSet\Control\Session Manager\
                                      <<!>> "BootExecute" = "autocheck autochk *"|"SsiEfr.e" [file not found]|"SsiEfr.e" [file not found]

                                      HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
                                      <<!>> igfxcui\DLLName = "igfxdev.dll" ["Intel Corporation"]
                                      <<!>> WRNotifier\DLLName = "WRLogonNTF.dll" [file not found]

                                      HKLM\Software\Classes\PROTOCOLS\Filter\
                                      <<!>> text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
                                      -> {HKLM...CLSID} = (no title provided)
                                      \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]

                                      HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
                                      {0561EC90-CE54-4f0c-9C55-E226110A740C}\(Default) = "Haali Column Provider"
                                      -> {HKLM...CLSID} = "Haali Column Provider"
                                      \InProcServer32\(Default) = "C:\Program Files\Satsuki Decoder Pack\filtres\divers\mmfinfo.dll" [null data]

                                      HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
                                      AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
                                      -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
                                      \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."]
                                      WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                                      -> {HKLM...CLSID} = "WinRAR"
                                      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
                                      ZLAVShExt\(Default) = "{D9872D13-7651-4471-9EEE-F0A00218BEBB}"
                                      -> {HKLM...CLSID} = "ZLAVShExt Class"
                                      \InProcServer32\(Default) = "C:\Program Files\Zone Labs\ZoneAlarm\zlavscan.dll" ["Zone Labs, LLC"]

                                      HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
                                      WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                                      -> {HKLM...CLSID} = "WinRAR"
                                      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

                                      HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
                                      AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
                                      -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
                                      \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG7\avgse.dll" ["GRISOFT, s.r.o."]
                                      WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
                                      -> {HKLM...CLSID} = "WinRAR"
                                      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
                                      ZLAVShExt\(Default) = "{D9872D13-7651-4471-9EEE-F0A00218BEBB}"
                                      -> {HKLM...CLSID} = "ZLAVShExt Class"
                                      \InProcServer32\(Default) = "C:\Program Files\Zone Labs\ZoneAlarm\zlavscan.dll" ["Zone Labs, LLC"]

                                      Group Policies {GPedit.msc branch and setting}:
                                      -----------------------------------------------

                                      Note: detected settings may not have any effect.

                                      HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\

                                      "NoCDBurning" = (REG_DWORD) hex:0x00000000
                                      {unrecognized setting}

                                      HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

                                      "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
                                      {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
                                      Shutdown: Allow system to be shut down without having to log on}

                                      "undockwithoutlogon" = (REG_DWORD) hex:0x00000001
                                      {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
                                      Devices: Allow undock without having to log on}

                                      "InstallVisualStyle" = (REG_EXPAND_SZ) C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
                                      {unrecognized setting}

                                      "InstallTheme" = (REG_EXPAND_SZ) C:\WINDOWS\Resources\Themes\Royale.theme
                                      {unrecognized setting}

                                      Active Desktop and Wallpaper:
                                      -----------------------------

                                      Active Desktop may be disabled at this entry:
                                      HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

                                      Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
                                      HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
                                      "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

                                      Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
                                      HKCU\Control Panel\Desktop\
                                      "Wallpaper" = "C:\Documents and Settings\Windows\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

                                      Enabled Screen Saver:
                                      ---------------------

                                      HKCU\Control Panel\Desktop\
                                      "SCRNSAVE.EXE" = "C:\WINDOWS\system32\MA2_5.scr" [null data]

                                      Startup items in "Windows" & "All Users" startup folders:
                                      ---------------------------------------------------------

                                      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
                                      "NETGEAR WPN111 Smart Wizard" -> shortcut to: "C:\Program Files\NETGEAR\WPN111\wpn111.exe" ["NETGEAR"]

                                      Winsock2 Service Provider DLLs:
                                      -------------------------------

                                      Namespace Service Providers

                                      HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
                                      000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
                                      000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
                                      000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

                                      Transport Service Providers

                                      HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
                                      0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
                                      %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
                                      %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

                                      Toolbars, Explorer Bars, Extensions:
                                      ------------------------------------

                                      Toolbars

                                      HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
                                      "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"
                                      -> {HKLM...CLSID} = "MSN"
                                      \InProcServer32\(Default) = "C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ch\msntb.dll" [MS]
                                      "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
                                      -> {HKLM...CLSID} = "&Google"
                                      \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]
                                      "{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
                                      -> {HKLM...CLSID} = "Yahoo! Toolbar"
                                      \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]

                                      HKLM\Software\Microsoft\Internet Explorer\Toolbar\
                                      "{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" = "0"
                                      -> {HKLM...CLSID} = "MSN"
                                      \InProcServer32\(Default) = "C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr-ch\msntb.dll" [MS]
                                      "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
                                      -> {HKLM...CLSID} = "&Google"
                                      \InProcServer32\(Default) = "c:\program files\google\googletoolbar1.dll" ["Google Inc."]
                                      "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
                                      -> {HKLM...CLSID} = "Yahoo! Toolbar"
                                      \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]
                                      "{327C2873-E90D-4C37-AA9D-10AC9BABA46C}" = "Easy-WebPrint"
                                      -> {HKLM...CLSID} = "Easy-WebPrint"
                                      \InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]

                                      Explorer Bars

                                      HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\

                                      HKLM\Software\Classes\CLSID\{03C1C47F-0538-4645-8372-D3109B9FC636}\(Default) = "Easy-WebPrint"
                                      Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
                                      InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]

                                      HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Rechercher"
                                      Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
                                      InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS]

                                      Extensions (Tools menu items, main toolbar menu buttons)

                                      HKLM\Software\Microsoft\Internet Explorer\Extensions\
                                      {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
                                      "MenuText" = "Console Java (Sun)"
                                      "CLSIDExtension" = "{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}"
                                      -> {HKCU...CLSID} = "Java Plug-in 1.6.0_01"
                                      \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll" ["Sun Microsystems, Inc."]
                                      -> {HKLM...CLSID} = "Java Plug-in 1.6.0_01"
                                      \InProcServer32\(Default) = "C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll" ["Sun Microsystems, Inc."]

                                      {77BF5300-1474-4EC7-9980-D32B190E9B07}\
                                      "ButtonText" = "Skype"
                                      "CLSIDExtension" = "{77BF5300-1474-4EC7-9980-D32B190E9B07}"
                                      -> {HKLM...CLSID} = "Skype add-on (button)"
                                      \InProcServer32\(Default) = "C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll" ["Skype Technologies S.A."]

                                      {85D1F590-48F4-11D9-9669-0800200C9A66}\
                                      "MenuText" = "Uninstall BitDefender Online Scanner v8"
                                      "Exec" = "%windir%\bdoscandel.exe" [null data]

                                      {92780B25-18CC-41C8-B9BE-3C9C571A8263}\
                                      "ButtonText" = "Recherche"

                                      {FB5F1910-F110-11D2-BB9E-00C04F795683}\
                                      "ButtonText" = "Messenger"
                                      "MenuText" = "Windows Messenger"
                                      "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]

                                      Running Services (Display Name, Service Name, Path {Service DLL}):
                                      ------------------------------------------------------------------

                                      AVG E-mail Scanner, AVGEMS, "C:\PROGRA~1\Grisoft\AVG7\avgemc.exe" ["GRISOFT, s.r.o."]
                                      AVG7 Alert Manager Server, Avg7Alrt, "C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe" ["GRISOFT, s.r.o."]
                                      AVG7 Update Service, Avg7UpdSvc, "C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe" ["GRISOFT, s.r.o."]
                                      Canon Camera Access Library 8, CCALib8, "C:\Program Files\Canon\CAL\CALMAIN.exe" ["Canon Inc."]
                                      m2PacketcounterService, _service, "C:\Program Files\cablecom\Compteur de volume hispeed\packetservice.exe" ["mquadr.at"]
                                      Machine Debug Manager, MDM, ""C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE"" [MS]
                                      Media Center Extender Service, McrdSvc, "C:\WINDOWS\ehome\mcrdsvc.exe" [MS]
                                      Media Center Receiver Service, ehRecvr, "C:\WINDOWS\eHome\ehRecvr.exe" [MS]
                                      Service de planification Media Center, ehSched, "C:\WINDOWS\eHome\ehSched.exe" [MS]
                                      TrueVector Internet Monitor, vsmon, "C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service" ["Zone Labs, LLC"]

                                      Print Monitors:
                                      ---------------

                                      HKLM\System\CurrentControlSet\Control\Print\Monitors\
                                      Canon BJ Language Monitor iP4200\Driver = "CNMLM78.DLL" ["CANON INC."]
                                      hpzlnt09\Driver = "hpzlnt09.dll" ["HP"]
                                      Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]
                                      Microsoft Shared Fax Monitor\Driver = "FXSMON.DLL" [MS]

                                      ----------
                                      <<!>>: Suspicious data at a malware launch point.

                                      + This report excludes default entries except where indicated.
                                      + To see *everywhere* the script checks and *everything* it finds,
                                      launch it from a command prompt or a shortcut with the -all parameter.
                                      + To search all directories of local fixed drives for DESKTOP.INI
                                      DLL launch points, use the -supp parameter or answer "No" at the
                                      first message box and "Yes" at the second message box.
                                      ---------- (total run time: 50 seconds, including 15 seconds for message boxes)

                                      A bientôt ;)
                                      0
                                      1. Contributeur
                                        bonjour kripte,

                                        désolé pour le délai de réponse,
                                        il ne s'agit pas d'un oubli mais j'ai demandé de l'aide pour l'interprétation de ton dernier et rapport et je n'ai pas encore de réponse (Week end peut être? :)
                                        merci de patienter
                                        a+
                                        0
                                        1. On dit que patience est mère des vertues ;)

                                          Je ne me fait aucun soucis... Il existe bien une vie en dehors et heureusement ;)

                                          Bon week et @+
                                          0
                                          • 1
                                          • 2