Infection

Résolu
Bonjour,

Suite à plusieurs virus sur le pc de ma femme j'ai fait du nettoyage et j'aurais voulu savoir s'il n'y a plus de virus
Je joins le rapport HijackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:27:29, on 28/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Documents and Settings\Romain\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Documents and Settings\Romain\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fimg%2ffr%2ffr-fr%2fdivertissement%2fcelebrites%2fgalery%2fwentworth02.jpg%3f
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: GamesBar - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - C:\Program Files\GamesBar\oberontb.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdafg.exe] C:\WINDOWS\system32\kdafg.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [IETI] C:\Program Files\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [IETI] C:\Program Files\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'Default user')
O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\Romain\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra 'Tools' menuitem: GamesBar - {1A93C934-025B-4c3a-B38E-9654A7003239} - C:\Program Files\GamesBar\oberontb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} (ITPPDiagIE Class) - http://data.jeuxclassiques.com/npwwg.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5A33F028-3E2D-4102-8F14-CB72AF49D60E}: NameServer = 85.255.112.147;85.255.112.143
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL nlpqyc.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PsExec (PSEXESVC) - Unknown owner - C:\WINDOWS\PSEXESVC.EXE (file missing)

--
End of file - 12949 bytes

merci d'avance pour les reponses
Configuration: Windows XP
Firefox 3.0.4

25 réponses

  1. slt pour être sur fait une analyse de ton système
    0
    1. je joins egalement le rapport navilog

      Search Navipromo version 3.6.9 commencé le 28/11/2008 à 22:43:07,42

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Session actuelle : "Romain"

      Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO

      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.13
      Système de fichiers : NTFS

      Recherche executé en mode normal

      *** Recherche Programmes installés ***

      *** Recherche dossiers dans "C:\WINDOWS" ***

      *** Recherche dossiers dans "C:\Program Files" ***

      *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

      *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

      *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

      *** Recherche dossiers dans "C:\Documents and Settings\Romain\applic~1" ***

      *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

      *** Recherche dossiers dans "C:\Documents and Settings\Romain\locals~1\applic~1" ***

      *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

      *** Recherche dossiers dans "C:\Documents and Settings\Romain\menudm~1\progra~1" ***

      *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***

      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans "C:\WINDOWS\system32" *

      * Recherche dans "C:\Documents and Settings\Romain\locals~1\applic~1" *

      * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

      *** Recherche fichiers ***

      *** Recherche clés spécifiques dans le Registre ***

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :

      2)Recherche Heuristique :

      * Dans "C:\WINDOWS\system32" :

      * Dans "C:\Documents and Settings\Romain\locals~1\applic~1" :

      * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :

      3)Recherche Certificats :

      Certificat Egroup absent !
      Certificat Electronic-Group absent !
      Certificat Montorgueil absent !
      Certificat OOO-Favorit absent !
      Certificat Sunny-Day-Design-Ltd absent !

      4)Recherche fichiers connus :

      C:\WINDOWS\system32\eNnWFfhk.ini2 trouvé ! infection Vundo possible non traitée par cet outil !

      *** Analyse terminée le 28/11/2008 à 22:53:05,23 ***

      J'ai bien compris que j'etais infecté par un vundo mais comment l'enlever
      Quand je suis sur mozilla j'ai des pages qui s'ouvre seule et il est indiqué connexion en cours
      le probleme ne se passe pas avec internet explorer

      merci
      0
      1. voila c'est desinstaller
        0
        1. MalwareByte's
          Télécharges MalwareByte's :
          ici ftp://ftp.commentcamarche.com/download/mbam-setup.exe
          ou ici : http://www.malwarebytes.org/mbam.php

          Installes le ( choisis bien "francais" ; ne modifies pas les paramètres d'installe ) et mets le à jour .

          (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharges le ici : https://www.malekal.com/tutorial-aboutbuster/ )

          Potasses le tuto pour te familiariser avec le prg :
          https://forum.pcastuces.com/sujet.asp?f=31&s=3
          https://www.androidworld.fr/
          ( cela dis, il est très simple d'utilisation ).
          0
          1. Contributeur sécurité
            bonjour, passes malwarebytes en mode sans echec , Merci

            Télécharge Malwarebytes' Anti-Malware: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

            . sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
            . enregistres le sur le bureau
            . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
            . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
            . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
            . Une fois la mise à jour terminée,fermes Malwarebytes
            . redemarres en mode sans échec pour savoir comment au cas ou tu ne saurrais pas regarde plus bas
            . une fois en mode sans echec tu double-cliques sur l'icône de malwarebytes
            . une fois ouvert rend-toi dans l'onglet, Recherche
            . Sélectionnes Exécuter un examen complet
            . Cliques sur Rechercher
            . Le scan démarre.
            . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
            . Cliques sur Ok pour poursuivre.
            . Si des malwares ont été détectés, cliques sur Afficher les résultats
            . Sélectionnes tout (ou laisses cochés)

            . cliques sur Supprimer la sélection

            . Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
            . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
            . redemarre le pc
            . une fois redémarré en mode normal double-cliques sur malwarebytes
            . rends toi dans l'onglet rapport/log
            . tu cliques dessus pour l'afficher une fois affiché
            . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
            . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
            . tu cliques droit dans le cadre de la reponse et coller

            Si tu as besoin d'aide regarde ces tutoriels :
            https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
            https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

            (attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...)

            pour redémarrer en mode sans échec : /!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

            . Cliques sur Démarrer
            . Cliques sur Arrêter
            . Sélectionnes Redémarrer et au redémarrage
            . Appuis sur la touche F8 sans discontinuer "1 appuis seconde" dès qu'un écran de texte apparaît puis disparaît
            . Utilises les touches de direction pour sélectionner mode sans échec
            . puis appuis sur ENTRÉE des fois cela peut prendre plusieurs minute entre la validation et l'affichage
            . Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou une autre
            une fois démarré ne t'inquiette pas si les couleurs et les icônes ne sont pas comme d'abitude

            tuto:http://www.vista-xp.fr/forum/topic93.html
            0
            1. voila le rapport

              Malwarebytes' Anti-Malware 1.30
              Version de la base de données: 1433
              Windows 5.1.2600 Service Pack 3

              29/11/2008 00:06:36
              mbam-log-2008-11-29 (00-06-36).txt

              Type de recherche: Examen complet (C:\|)
              Eléments examinés: 140662
              Temps écoulé: 38 minute(s), 36 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 2
              Clé(s) du Registre infectée(s): 17
              Valeur(s) du Registre infectée(s): 0
              Elément(s) de données du Registre infecté(s): 7
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 16

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              C:\WINDOWS\system32\khfFWnNe.dll (Trojan.Vundo.H) -> Delete on reboot.
              C:\WINDOWS\system32\znhcms.dll (Trojan.Vundo.H) -> Delete on reboot.

              Clé(s) du Registre infectée(s):
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6451e2ca-0e58-48c5-974c-ca8a8622a68c} (Trojan.Vundo.H) -> Delete on reboot.
              HKEY_CLASSES_ROOT\CLSID\{6451e2ca-0e58-48c5-974c-ca8a8622a68c} (Trojan.Vundo.H) -> Delete on reboot.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91e9766e-ccd0-42bb-9069-e52dc15a3b16} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              HKEY_CLASSES_ROOT\CLSID\{91e9766e-ccd0-42bb-9069-e52dc15a3b16} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{91262c60-dd10-46fa-a09b-ae14902eca11} (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1a93c934-025b-4c3a-b38e-9654a7003239} (Adware.Gamesbar) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

              Valeur(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Elément(s) de données du Registre infecté(s):
              HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\khffwnne -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System (Rootkit.DNSChanger.H) -> Data: kdafg.exe -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\khffwnne -> Delete on reboot.
              HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5a33f028-3e2d-4102-8f14-cb72af49d60e}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.147;85.255.112.143 -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{5a33f028-3e2d-4102-8f14-cb72af49d60e}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.147;85.255.112.143 -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{5a33f028-3e2d-4102-8f14-cb72af49d60e}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.147;85.255.112.143 -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\Tcpip\Parameters\Interfaces\{5a33f028-3e2d-4102-8f14-cb72af49d60e}\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.147;85.255.112.143 -> Quarantined and deleted successfully.

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              C:\WINDOWS\system32\khfFWnNe.dll (Trojan.Vundo.H) -> Delete on reboot.
              C:\WINDOWS\system32\eNnWFfhk.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\eNnWFfhk.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\znhcms.dll (Trojan.Vundo.H) -> Delete on reboot.
              C:\Documents and Settings\Romain\Local Settings\Temporary Internet Files\Content.IE5\P4AG40UY\index[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{5393AAB5-8B67-4C33-8A5C-8C5DEB17228E}\RP154\A0038027.exe (Rogue.LivePlayer) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{5393AAB5-8B67-4C33-8A5C-8C5DEB17228E}\RP205\A0054385.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\VundoFix Backups\fccbXnop.dll.bad (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\jkrcgxal.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\TDSSoipa.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\tgninshw.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\yspidz.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
              C:\Program Files\Mozilla Firefox\components\iamfamous.dll (Trojan.Agent) -> Quarantined and deleted successfully.
              C:\WINDOWS\BM7fc44552.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\drivers\TDSSmxoe.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
              0
              1. Télécharger sur le Bureau.
                http://www.atribune.org/public-beta/VundoFix.exe

                = Double-clic VundoFix.exe.
                =Clic Scan for Vundo
                = le scan t peut être assez long (1à2h) comme très rapide , à la fin
                =Clic Fix Vundo
                = Puis yes
                = Le Bureau disparaît un moment lors de la suppression des fichiers.
                =Message shutdown
                =clic oui
                =Redémarrage auto
                Note : il peut y avoir plusieurs redémarrages
                =copier le rapport qui est dans C:\vundofix.txt
                0
                1. Voici le rapport

                  VundoFix V7.0.6

                  Scan started at 08:38:09 29/11/2008

                  Listing files found while scanning....

                  No infected files were found.

                  Beginning removal...
                  0
                  1. j'ai également fait un scan en ligne avec bitdefender dont voici le rapport

                    BitDefender Online Scanner

                    Rapport d'analyse généré à: Sat, Nov 29, 2008 - 12:52:24

                    Voie d'analyse: A:\;C:\;D:\;E:\;F:\;

                    Statistiques

                    Temps

                    00:53:14

                    Fichiers

                    185886

                    Directoires

                    10274

                    Secteurs de boot

                    0

                    Archives

                    2295

                    Paquets programmes

                    23463

                    Résultats

                    Virus identifiés
                    4

                    Fichiers infectés
                    7

                    Fichiers suspects
                    0

                    Avertissements
                    0

                    Désinfectés
                    0

                    Fichiers effacés
                    7

                    Info sur les moteurs

                    Définition virus

                    2277862

                    Version des moteurs

                    AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

                    Analyse des plugins
                    16

                    Archive des plugins
                    43

                    Unpack des plugins
                    7

                    E-mail plugins
                    6

                    Système plugins
                    4

                    Parramètres d'analyse

                    Première action

                    Désinfecté

                    Seconde Action

                    Supprimé

                    Heuristique

                    Oui

                    Acceptez les avertissements

                    Oui

                    Extensions analysées

                    exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

                    Excludez les extensions

                    Analyse d'emails
                    Oui

                    Analyse des Archives
                    Oui

                    Analyser paquets programmes
                    Oui

                    Analyse des fichiers

                    Oui

                    Analyse de boot
                    Oui

                    Fichier analysé

                    Statut

                    C:\Documents and Settings\Romain\Application Data\Microsoft\Live Search\Suppression-Live-Search.exe

                    Infecté par: Trojan.Generic.1133786

                    C:\Documents and Settings\Romain\Application Data\Microsoft\Live Search\Suppression-Live-Search.exe

                    Supprimé

                    C:\jnoejlk.exe

                    Infecté par: Trojan.Srizbi.Dropper.1.Gen

                    C:\jnoejlk.exe

                    Echec de la désinfection

                    C:\jnoejlk.exe

                    Supprimé

                    C:\System Volume Information\_restore{5393AAB5-8B67-4C33-8A5C-8C5DEB17228E}\RP205\A0054491.exe

                    Infecté par: Trojan.Agent.ALED

                    C:\System Volume Information\_restore{5393AAB5-8B67-4C33-8A5C-8C5DEB17228E}\RP205\A0054491.exe

                    Supprimé

                    C:\System Volume Information\_restore{5393AAB5-8B67-4C33-8A5C-8C5DEB17228E}\RP205\A0054498.exe

                    Infecté par: Trojan.Agent.ALED

                    C:\System Volume Information\_restore{5393AAB5-8B67-4C33-8A5C-8C5DEB17228E}\RP205\A0054498.exe

                    Supprimé

                    C:\System Volume Information\_restore{5393AAB5-8B67-4C33-8A5C-8C5DEB17228E}\RP206\A0054626.exe

                    Infecté par: Trojan.Generic.1133786

                    C:\System Volume Information\_restore{5393AAB5-8B67-4C33-8A5C-8C5DEB17228E}\RP206\A0054626.exe

                    Supprimé

                    C:\System Volume Information\_restore{5393AAB5-8B67-4C33-8A5C-8C5DEB17228E}\RP206\A0054627.exe

                    Infecté par: Trojan.Srizbi.Dropper.1.Gen

                    C:\System Volume Information\_restore{5393AAB5-8B67-4C33-8A5C-8C5DEB17228E}\RP206\A0054627.exe

                    Echec de la désinfection

                    C:\System Volume Information\_restore{5393AAB5-8B67-4C33-8A5C-8C5DEB17228E}\RP206\A0054627.exe

                    Supprimé

                    C:\WINDOWS\system32\drivers\tlrqqvpv.sys

                    Infecté par: Rootkit.Agent.AIXB

                    C:\WINDOWS\system32\drivers\tlrqqvpv.sys

                    Supprimé
                    0
                    1. Contributeur sécurité
                      bonjour, pour l'infection qui est signalé ici C:\System Volume Information\_restore une simple manippe suffit pour les supprimer définitivement la purge de la restauration système
                      0
                      1. j'ai refais un bitdefender

                        BitDefender Online Scanner

                        Rapport d'analyse généré à: Sat, Nov 29, 2008 - 20:43:50

                        Voie d'analyse: A:\;C:\;D:\;E:\;F:\;

                        Statistiques

                        Temps
                        00:38:09

                        Fichiers
                        169287

                        Directoires
                        10199

                        Secteurs de boot
                        0

                        Archives
                        1947

                        Paquets programmes
                        23130

                        Résultats

                        Virus identifiés
                        2

                        Fichiers infectés
                        3

                        Fichiers suspects
                        0

                        Avertissements
                        0

                        Désinfectés
                        0

                        Fichiers effacés
                        3

                        Info sur les moteurs

                        Définition virus
                        2283300

                        Version des moteurs

                        AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

                        Analyse des plugins
                        16

                        Archive des plugins
                        43

                        Unpack des plugins
                        7

                        E-mail plugins
                        6

                        Système plugins
                        4

                        Paramètres d'analyse

                        Première action

                        Désinfecté

                        Seconde Action

                        Supprimé

                        Heuristique
                        Oui

                        Acceptez les avertissements
                        Oui

                        Extensions analysées

                        exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

                        Excludez les extensions

                        Analyse d'emails
                        Oui

                        Analyse des Archives
                        Oui

                        Analyser paquets programmes
                        Oui

                        Analyse des fichiers
                        Oui

                        Analyse de boot
                        Oui

                        Fichier analysé

                        Statut

                        C:\System Volume Information\_restore{5393AAB5-8B67-4C33-8A5C-8C5DEB17228E}\RP206\A0054632.sys

                        Infecté par: Rootkit.Agent.AIXB

                        C:\System Volume Information\_restore{5393AAB5-8B67-4C33-8A5C-8C5DEB17228E}\RP206\A0054632.sys

                        Supprimé

                        C:\WINDOWS\system32\nlpqyc.dll

                        Infecté par: Trojan.Vundo.Gen.4

                        C:\WINDOWS\system32\nlpqyc.dll

                        Echec de la désinfection

                        C:\WINDOWS\system32\nlpqyc.dll

                        Supprimé

                        C:\WINDOWS\system32\phtxhhcw.dll

                        Infecté par: Trojan.Vundo.Gen.4

                        C:\WINDOWS\system32\phtxhhcw.dll

                        Echec de la désinfection

                        C:\WINDOWS\system32\phtxhhcw.dll

                        Supprimé
                        0
                        1. Contributeur sécurité
                          ok , je te dit de purger la restauration système dans le message 11 et dans le 12 tu me répond "ok c'est fait " mais qu'est ce que tu as fais puisque toujours la si tu as déactivé et réactivé la restauration système normalement il n'aurait rien retrouvé dedans si tu as un souci pour la restauration système tu le dis et je de mets la procédure
                          0
                          1. j'ai fais demarrer/tout les programmes/accessoires/outils systeme/nettoyage du disque/ ensuite autres options/restauration systeme/nettoyer
                            0
                            1. Contributeur sécurité
                              fais comme ça , tu supprimes les anciens point de restauration , tu fais otmoveit, et tu passes Ccleaner avec les réglage donné, et tu pourras refaire un bitdéfender pour controler

                              Supprimer les anciens points de restauration pour supprimer ce qui peut être dedans C:\System Volume Information\_restore

                              (1) Désactiver la Restauration du système

                              cliques sur Démarrer
                              Cliques droit sur Poste de travail
                              cliques sur Propriétés
                              Cliques sur l'onglet Restauration du système
                              Coches Désactiver la Restauration du système sur tous les lecteurs
                              Cliques sur Appliquer, Lorsque le message de confirmation apparaît,
                              cliques sur Oui.
                              Cliques sur OK.

                              (2) Activer la Restauration du système

                              cliques sur Démarrer
                              Cliques droit sur Poste de travail
                              cliques sur Propriétés
                              Cliques sur l'onglet Restauration du système
                              Décoches Désactiver la Restauration du système sur tous les lecteurs
                              Cliques sur Appliquer, Lorsque le message de confirmation apparaît,
                              cliques sur Oui.
                              Cliques sur OK.

                              ******************************************************************************************

                              Télécharge OTMoveIt3 de OldTimer sur ton Bureau en cliquant sur ce lien :

                              http://oldtimer.geekstogo.com/OTMoveIt3.exe

                              Double-clique sur OTMoveIt3.exe pour le lancer.

                              Vérifie que la case devant "Unregister Dll's and Ocx's est bien cochée.

                              Copie la liste qui se trouve en gras ci-dessous,

                              et colle-la dans le cadre de gauche de OTMoveIt : "Paste instructions for item to be moved".

                              :files
                              C:\WINDOWS\system32\nlpqyc.dll
                              C:\WINDOWS\system32\phtxhhcw.dll

                              :Commands
                              [emptytemp]
                              [reboot]


                              Clique sur "MoveIt!" pour lancer la suppression.

                              Le résultat apparaitra dans le cadre "Results".

                              Clique sur "Exit" pour fermer.

                              Poste le rapport situé dans C:\_OTMoveIt\MovedFiles sous le nom xxxxxx_xxxxxxxxxx.log .

                              Il te sera peut-être demander de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.

                              ******************************************************************************************

                              Redémarres le PC et passes Ccleaner avec ces réglages LA

                              télécharge Ccleaner à partir de cette adresses

                              .enregistres le sur le bureau
                              .double-cliques sur le fichier pour lancer l'installation
                              .sur la fenêtre de l'installation langage bien choisir français et OK
                              .cliques sur suivant
                              .lis la licence et j'accepte
                              .cliques sur suivant
                              .la tu ne gardes de coché que mettre un raccourci sur le bureau et puis contrôler automatiquement les mises à jour de Ccleaner
                              .cliques sur intaller
                              .cliques sur fermer
                              .double-cliques sur l'icône de Ccleaner pour l'ouvrir
                              .une fois ouvert tu cliques sur option et puis avancé
                              .tu décoches effacer uniquement les fichiers, du dossier temp de windows plus vieux que 48 heures
                              .cliques sur nettoyeur
                              .cliques sur windows et dans la colonne avancé
                              .cochesla première case vieilles données du perfetch que celle-la ce qui te donnes la case vielles données du perfetch et la case avancé qui c'est coché automatiquement mais que celle-la
                              .cliques sur analyse une fois l'analyse terminé
                              .cliques sur lancer le nettoyage et sur la demande de confirmation OK il vas falloir que tu le refasses une autre fois une fois fini vériffis en appuiant de nouveau sur analyse pour être sur qu'il n'y est plus rien
                              .cliques maintenant sur registre et puis sur rechercher les erreurs
                              .laisses tout cochées et cliques sur réparrer les erreurs sélectionnées
                              .il te demande de sauvegarder OUI
                              .tu lui donnes un nom pour pouvoir la retrouver et enregistre
                              .cliques sur corriger toutes les erreurs sélectionnées et sur la demande de confirmation OK
                              .il supprime et fermer tu vériffis en relancant rechercher les erreurs
                              .tu retournes dans option et tu recoches la case effacer uniquement les fichiers, du dossier temp de windows plus vieux que 48 heures et sur nettoyeur, windows sous avancé tu décoches la première case vieilles données du perfetch
                              .tu peux fermer Ccleaner

                              pour aider si besion tutoriel: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
                              0
                              1. ========== FILES ==========
                                File/Folder C:\WINDOWS\system32\nlpqyc.dll not found.
                                File/Folder C:\WINDOWS\system32\phtxhhcw.dll not found.
                                ========== COMMANDS ==========
                                File delete failed. C:\DOCUME~1\Romain\LOCALS~1\Temp\etilqs_2RRSY4riAUNKNj2E6sMl scheduled to be deleted on reboot.
                                File delete failed. C:\DOCUME~1\Romain\LOCALS~1\Temp\~DF92D6.tmp scheduled to be deleted on reboot.
                                File delete failed. C:\DOCUME~1\Romain\LOCALS~1\Temp\~DF961F.tmp scheduled to be deleted on reboot.
                                File delete failed. C:\DOCUME~1\Romain\LOCALS~1\Temp\~DFC7B8.tmp scheduled to be deleted on reboot.
                                File delete failed. C:\DOCUME~1\Romain\LOCALS~1\Temp\~DFCE06.tmp scheduled to be deleted on reboot.
                                User's Temp folder emptied.
                                User's Temporary Internet Files folder emptied.
                                User's Internet Explorer cache folder emptied.
                                Local Service Temp folder emptied.
                                File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                                Local Service Temporary Internet Files folder emptied.
                                File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
                                File delete failed. C:\WINDOWS\temp\LVCOMSX.LOG scheduled to be deleted on reboot.
                                File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_60c.dat scheduled to be deleted on reboot.
                                File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_770.dat scheduled to be deleted on reboot.
                                Windows Temp folder emptied.
                                Java cache emptied.
                                File delete failed. C:\Documents and Settings\Romain\Local Settings\Application Data\Mozilla\Firefox\Profiles\itdnqoae.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
                                File delete failed. C:\Documents and Settings\Romain\Local Settings\Application Data\Mozilla\Firefox\Profiles\itdnqoae.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
                                File delete failed. C:\Documents and Settings\Romain\Local Settings\Application Data\Mozilla\Firefox\Profiles\itdnqoae.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
                                File delete failed. C:\Documents and Settings\Romain\Local Settings\Application Data\Mozilla\Firefox\Profiles\itdnqoae.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
                                File delete failed. C:\Documents and Settings\Romain\Local Settings\Application Data\Mozilla\Firefox\Profiles\itdnqoae.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
                                File delete failed. C:\Documents and Settings\Romain\Local Settings\Application Data\Mozilla\Firefox\Profiles\itdnqoae.default\XUL.mfl scheduled to be deleted on reboot.
                                FireFox cache emptied.
                                Temp folders emptied.

                                OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11292008_222515

                                Files moved on Reboot...
                                File C:\DOCUME~1\Romain\LOCALS~1\Temp\etilqs_2RRSY4riAUNKNj2E6sMl not found!
                                File C:\DOCUME~1\Romain\LOCALS~1\Temp\~DF92D6.tmp not found!
                                File C:\DOCUME~1\Romain\LOCALS~1\Temp\~DF961F.tmp not found!
                                File C:\DOCUME~1\Romain\LOCALS~1\Temp\~DFC7B8.tmp not found!
                                File C:\DOCUME~1\Romain\LOCALS~1\Temp\~DFCE06.tmp not found!
                                File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
                                File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
                                C:\WINDOWS\temp\LVCOMSX.LOG moved successfully.
                                C:\WINDOWS\temp\Perflib_Perfdata_60c.dat moved successfully.
                                File C:\WINDOWS\temp\Perflib_Perfdata_770.dat not found!
                                C:\Documents and Settings\Romain\Local Settings\Application Data\Mozilla\Firefox\Profiles\itdnqoae.default\Cache\_CACHE_001_ moved successfully.
                                C:\Documents and Settings\Romain\Local Settings\Application Data\Mozilla\Firefox\Profiles\itdnqoae.default\Cache\_CACHE_002_ moved successfully.
                                C:\Documents and Settings\Romain\Local Settings\Application Data\Mozilla\Firefox\Profiles\itdnqoae.default\Cache\_CACHE_003_ moved successfully.
                                C:\Documents and Settings\Romain\Local Settings\Application Data\Mozilla\Firefox\Profiles\itdnqoae.default\Cache\_CACHE_MAP_ moved successfully.
                                C:\Documents and Settings\Romain\Local Settings\Application Data\Mozilla\Firefox\Profiles\itdnqoae.default\urlclassifier3.sqlite moved successfully.
                                C:\Documents and Settings\Romain\Local Settings\Application Data\Mozilla\Firefox\Profiles\itdnqoae.default\XUL.mfl moved successfully.

                                ccleaner est fait
                                0
                                1. bon le pc a l'air clean

                                  j'ai refais un bitdefender et il n'y a rien

                                  BitDefender Online Scanner

                                  Rapport d'analyse généré à: Sun, Nov 30, 2008 - 10:40:13

                                  Voie d'analyse: A:\;C:\;D:\;E:\;F:\;

                                  Statistiques

                                  Temps
                                  00:46:58

                                  Fichiers
                                  169677

                                  Directoires
                                  10130

                                  Secteurs de boot
                                  0

                                  Archives
                                  1974

                                  Paquets programmes
                                  23249

                                  Résultats

                                  Virus identifiés
                                  0

                                  Fichiers infectés
                                  0

                                  Fichiers suspects
                                  0

                                  Avertissements
                                  0

                                  Désinfectés
                                  0

                                  Fichiers effacés
                                  0

                                  Info sur les moteurs

                                  Définition virus
                                  2292037

                                  Version des moteurs
                                  AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

                                  Analyse des plugins
                                  16

                                  Archive des plugins
                                  43

                                  Unpack des plugins
                                  7

                                  E-mail plugins
                                  6

                                  Système plugins
                                  4

                                  Paramètres d'analyse

                                  Première action

                                  Désinfecté

                                  Seconde Action

                                  Supprimé

                                  Heuristique
                                  Oui

                                  Acceptez les avertissements
                                  Oui

                                  Extensions analysées

                                  exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

                                  Excludez les extensions

                                  Analyse d'emails
                                  Oui

                                  Analyse des Archives
                                  Oui

                                  Analyser paquets programmes
                                  Oui

                                  Analyse des fichiers
                                  Oui

                                  Analyse de boot
                                  Oui

                                  Fichier analysé

                                  Statut

                                  Aucun virus trouvé.

                                  Merci beaucoup de m'avoir aidé
                                  0
                                  1. Contributeur sécurité
                                    ok je mange et je reviens pour la finaliser le nettoyage si tu pouvais remettre un dernier hijackthis, Merci
                                    0
                                    1. Voila le rapport

                                      Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 14:39:40, on 30/11/2008
                                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                                      MSIE: Internet Explorer v7.00 (7.00.6000.16735)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                      C:\Program Files\Java\jre6\bin\jusched.exe
                                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                      C:\WINDOWS\system32\RUNDLL32.EXE
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                                      C:\WINDOWS\system32\ctfmon.exe
                                      C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
                                      C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                                      C:\WINDOWS\system32\cisvc.exe
                                      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
                                      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
                                      C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                                      C:\WINDOWS\System32\FTRTSVC.exe
                                      C:\Documents and Settings\Romain\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
                                      C:\Documents and Settings\Romain\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
                                      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                      C:\PROGRA~1\Wanadoo\ComComp.exe
                                      C:\Program Files\Java\jre6\bin\jqs.exe
                                      C:\WINDOWS\system32\nvsvc32.exe
                                      C:\PROGRA~1\Wanadoo\Toaster.exe
                                      C:\PROGRA~1\Wanadoo\Inactivity.exe
                                      C:\PROGRA~1\Wanadoo\PollingModule.exe
                                      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
                                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\PROGRA~1\Wanadoo\Watch.exe
                                      C:\Program Files\Skype\Phone\Skype.exe
                                      C:\Program Files\Skype\Plugin Manager\skypePM.exe
                                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                      C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                      C:\WINDOWS\system32\cidaemon.exe
                                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                      C:\Program Files\Mozilla Firefox\firefox.exe
                                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fimg%2ffr%2ffr-fr%2fdivertissement%2fcelebrites%2fgalery%2fwentworth02.jpg%3f
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                      O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                      O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
                                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                                      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                                      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
                                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                      O4 - HKUS\S-1-5-18\..\RunOnce: [IETI] C:\Program Files\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'SYSTEM')
                                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                      O4 - HKUS\.DEFAULT\..\RunOnce: [IETI] C:\Program Files\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'Default user')
                                      O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\Romain\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
                                      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                      O4 - Global Startup: hp psc 1000 series.lnk = ?
                                      O4 - Global Startup: hpoddt01.exe.lnk = ?
                                      O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
                                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                      O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                                      O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                                      O16 - DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} (ITPPDiagIE Class) - http://data.jeuxclassiques.com/npwwg.cab
                                      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                                      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                                      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                                      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                                      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                                      O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
                                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                                      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL znhcms.dll
                                      O20 - Winlogon Notify: mljjgdd - mljjgdd.dll (file missing)
                                      O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                                      O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                      0
                                      • 1
                                      • 2