Spyware encombrant

Bonjour,

J'ai depuis hier des spywares très encombrants du nom de "webdialer", "dso exploit", "coolwebsearch" et "allcybersearch".
Spybot et ad-aware SE ne réussisse pas à les éliminer.
J'ai lancé Hijack this mais je ne sais pas ce qu'il faut fixer.

voici le log affiché :

Logfile of HijackThis v1.99.1
Scan saved at 14:44:05, on 10/04/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\rundll32.exe
C:\Documents and Settings\Daniel\Mes documents\Vincent\internet\HijackThis.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\System32\ctfmon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {CBC5014C-CC96-4316-9A04-EA3A6D5108D9} - C:\WINDOWS\System32\clfl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gknhmurpb] c:\windows\system32\gknhmurpb.exe -start
O4 - HKLM\..\Run: [Anti Spyware] "C:\Program Files\SinEspias\No-Spy.exe" /autorun
O4 - HKLM\..\Run: [Sans Espions] "C:\Program Files\SinEspias\No-Spy.exe" /autorun
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll,DllInstall
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {DDF44FD9-749F-4761-89BB-E8A59339E459} - http://akamai.downloadv3.com/binaries/LiveService/LiveService_9_FR_XP.cab
O18 - Filter: text/html - {CC2DAD45-523A-4F12-9D78-8055E365C561} - C:\WINDOWS\System32\clfl.dll
O18 - Filter: text/plain - {CC2DAD45-523A-4F12-9D78-8055E365C561} - C:\WINDOWS\System32\clfl.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Quelqu'un peut il m'aider s'il vous plait.

merci d'avance
Configuration: PC Packard Bell
avec windows XP

18 réponses

  1. en espérant que ca reponde à ta question:

    pour éviter pas mal de problemes.

    - Windows Update parfaitement à jour (catégorie critique, Services Pack)
    http://v5.windowsupdate.microsoft.com

    - Un firewall bien paramétré.
    http://www.firewall-net.com/
    http://www.commentcamarche.net/protect/firewall.php3

    - Un antivirus bien paramétré et mis à jour regulièrement et un scan complet régulier.
    + de temps en temps un scan en ligne.
    Liste scans AV en ligne ici:
    http://assiste.free.fr/p/antivirus_gratuits_en_ligne/antivirus_en_ligne.php

    - scan régulier avec antispywares à jours.

    - une attitude prudente en surfant (téléchargements) et vis à vis de la messagerie (les fichiers joints aux messages doivent etre scannés avant d'etre ouvert).

    - Pour Internet explorer, un bon réglage de la gestion des controles activex.
    http://gerard.melone.free.fr/IT/IT-AM0.html
    ou envisager de passer à un autre navigateur comme mozilla, firefox...
    http://frenchmozilla.sourceforge.net/

    - Être vigilant aux fonctionnements inhabituels de ton système.

    - nettoyage régulier du système (suppression des fichiers inutiles, nettoyage de la base de registre, defragmentation).

    _______________________

    Antispywares:

    * Spybot S&D:
    http://spybot.safer-networking.de/fr/download/index.html
    l'aide:
    http://www.zebulon.fr/articles/spybot_1.php
    http://assiste.free.fr/p/internet_utilitaires/spybot_search_destroy.php#ssd_02

    * Ad-aware:
    http://www.lavasoftusa.com/french/support/download/
    l'aide:
    http://www.ordi-netfr.org/tutorialadaware.php

    * A² free
    http://www.emsisoft.net/fr/software/free/

    * Spysweeper (gratuit 30 jours):
    http://www.webroot.com/fr/products/spysweeper/

    Pour la prévention:
    * SpywareBlaster :
    http://www.javacoolsoftware.com/downloads.html

    Bien lire l'aide, et mettre à jours avant de les utiliser.

    Pour sécuriser un peu plus son pc:
    Safe XP:
    http://theorica.click-now.net/download.htm

    Nettoyage du registre:

    * Regseeker(gratuit)
    lire l'aide avant d'utiliser:
    http://www.ordi-netfr.com/regseeker.html

    Nettoyage fichiers internet, temps, cookies...

    * CCleaner (gratuit)
    http://www.ccleaner.com/ccdownload.asp

    * Cleanup:
    http://pageperso.aol.fr/Balltrap34/CleanUp312.exe

    A lire de toute urgence:
    http://sebsauvage.net/safehex.html
    http://assiste.free.fr

    a+
    0
    1. Salut,

      merci beaucoup pour toutes ces infos et encore merci pour l'après-midi passée à soigner mon PC.

      A+
      0
  2. ça y est, logiquement c'est terminé, je vous remercie beaucoup !!!!

    Par contre, comment faire pour que ce genre de truc n'arrive plus ?????

    Encore merci

    A+
    0
    1. argghh!! grillé !
      0
      1. Contributeur sécurité
        ca brule moe
        0
    2. le hijack est ok
      pour le rapport de rav:

      le 1er est dans les elements supprimés d'outlook
      vide le contenu des elements supprimés

      pour celui là, supprime le C:\WINDOWS\system32\msklive.dll
      si tu n'y arrives pas en mode normal, supprime le en mode sans echecs.

      a+
      0
      1. Contributeur sécurité
        celui la tu recherche et tu suppr
        C:\WINDOWS\system32\msklive.dll
        por l autre tu vas dans ta messageries sur message suppr et tu vire tous
        0
        1. salut

          tu peux fixer celles ci (pas besoin de redemarrer en sans echec):
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
          R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

          sinon pour moi c'est ok.

          Pour le scan av, ca bloque?
          sinon essaye ici:
          http://www.bitdefender.com/scan/licence.php

          a+
          0
          1. Salut,

            ça y est, scan AV a terminé. voici le rapport ainsi que celui de hijackthis après avoir fixé les dernières lignes.

            Scan started at 10/04/2005 18:32:47

            Scanning memory...
            Scanning boot sectors...
            Scanning files...
            C:\Documents and Settings\Daniel\Local Settings\Application Data\Identities\{050CEDE1-32C5-41E7-BE5C-3FDF69A8197D}\Microsoft\Outlook Express\Éléments supprimés.dbx->Message.0: (MAILER-DAEMON@wanadoo.fr (Mail Delivery System) [Undelivered Mail Returned to S... - Win32/Netsky.C@mm -> Suspicious
            C:\WINDOWS\system32\msklive.dll - TrojanSpy:Win32/Mslagent -> Infected

            Scanned
            ============================
            Objects: 43884
            Directories: 4433
            Archives: 6936
            Size(Kb): -1993131
            Infected files: 2

            Found
            ============================
            Viruses found: 1
            Suspicious files: 1
            Disinfected files: 0
            Mail files: 129

            Logfile of HijackThis v1.99.1
            Scan saved at 20:08:30, on 10/04/2005
            Platform: Windows XP SP1 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\System32\drivers\CDAC11BA.EXE
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\cisvc.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
            C:\WINDOWS\system32\slserv.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
            C:\WINDOWS\wanmpsvc.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\Program Files\Winamp\winampa.exe
            C:\Program Files\Fichiers communs\Real\Update_OB\rnathchk.exe
            C:\PROGRA~1\Wanadoo\CnxMon.exe
            C:\PROGRA~1\MESSAG~1\StartMessager.exe
            C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
            C:\VSTASCAN\vsaccess.exe
            C:\Program Files\Wanadoo\EspaceWanadoo.exe
            C:\Program Files\Wanadoo\ComComp.exe
            C:\Program Files\Wanadoo\Watch.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\WINDOWS\system32\cidaemon.exe
            C:\WINDOWS\bdonlinescan\avxLive.exe
            C:\Documents and Settings\Daniel\Mes documents\Vincent\internet\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.wanadoo.fr/
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
            O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
            O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
            O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
            O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
            O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - Startup: UMAX VistaAccess.lnk = C:\VSTASCAN\vsaccess.exe
            O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
            O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
            O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
            O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
            O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
            O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
            O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
            O17 - HKLM\System\CCS\Services\Tcpip\..\{482B124D-CC2C-442B-B760-0D6A0F508EA4}: NameServer = 80.10.246.1 80.10.246.132
            O17 - HKLM\System\CS1\Services\Tcpip\..\{482B124D-CC2C-442B-B760-0D6A0F508EA4}: NameServer = 80.10.246.1 80.10.246.132
            O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
            O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
            O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

            merci encore
            A+
            0
        2. merci beaucoup les gars

          j'ai effectué la manip de Moe mais certaines lignes à fixer n'étaient plus présentes et je n'ai pas retrouvé le fichier clfl.dll lorsque je devais le supprimer en rebootant.
          j'ai alors redémarrer simplement.

          voici le rapport de Hijackthis, scan AV est lancé depuis plus d'une heure, y'en a pour combien de temps ????

          Logfile of HijackThis v1.99.1
          Scan saved at 19:45:28, on 10/04/2005
          Platform: Windows XP SP1 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\System32\drivers\CDAC11BA.EXE
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\cisvc.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
          C:\WINDOWS\system32\slserv.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
          C:\WINDOWS\wanmpsvc.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Winamp\winampa.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\rnathchk.exe
          C:\PROGRA~1\Wanadoo\CnxMon.exe
          C:\PROGRA~1\MESSAG~1\StartMessager.exe
          C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
          C:\VSTASCAN\vsaccess.exe
          C:\Program Files\Wanadoo\EspaceWanadoo.exe
          C:\Program Files\Wanadoo\ComComp.exe
          C:\Program Files\Wanadoo\Watch.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\WINDOWS\system32\cidaemon.exe
          C:\Documents and Settings\Daniel\Mes documents\Vincent\internet\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
          R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.wanadoo.fr/
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
          O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
          O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
          O4 - Startup: UMAX VistaAccess.lnk = C:\VSTASCAN\vsaccess.exe
          O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
          O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
          O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
          O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
          O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
          O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
          O17 - HKLM\System\CCS\Services\Tcpip\..\{482B124D-CC2C-442B-B760-0D6A0F508EA4}: NameServer = 80.10.246.1 80.10.246.132
          O17 - HKLM\System\CS1\Services\Tcpip\..\{482B124D-CC2C-442B-B760-0D6A0F508EA4}: NameServer = 80.10.246.1 80.10.246.132
          O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
          O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
          O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
          O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
          0
          1. Contributeur sécurité
            oki j avais pas repris le debut du post
            peut etre si elle exixte toujour clik droit dessus et decocher lecture seul
            0
            1. elle apparait dans le premier log en 018, et vincent n'a pas reussi à la supprimer.
              elle n'est plus là dans le dernier log, mais bon.... toujours dans system32.
              0
              1. Contributeur sécurité
                fait celle de moe pas grave

                pour moe
                tu la sort d ou celle ci
                clic sur clfl.dll
                0
                1. Merci les gars,

                  mais je quelle manip, car les deux semble assez diférente ????
                  0
                  1. Contributeur sécurité
                    pas grave la preuve j en avait sauter un
                    0
                    1. salut balltrap

                      j'avais pas vu ton post, dsl
                      0
                      1. Contributeur sécurité
                        oups j avais sauter l administrateur
                        je rajoute lance deux fois de suite about buster
                        0
                        1. Salut vincent

                          toujours les memes...

                          -> Rend visible les fichiers cachés et systeme
                          panneau de configuration > options des dossiers > onglet affichage
                          cocher " afficher les fichiers et dossiers cachés "
                          décocher " masquer les extentions des fichiers dont le type est connu
                          décocher " masquer les fichiers protégés du système"

                          -> désactive la restauration systéme
                          Clic droit sur poste de travail > propriétés > onglet restauration système
                          puis cocher "désactiver la restauration système".

                          Puis important:
                          - Redémarre en mode sans échec en appuyant sur la touche F8 au démarrage de ton PC (apres l'ecran du bios)

                          ---------------------------------------------

                          Lance hijackthis et Fixe:
                          (cocher au début de chaques lignes valider avec fix checked)

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Daniel\LOCALS~1\Temp\se.dll/spage.html
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

                          O4 - HKLM\..\Run: [gknhmurpb] c:\windows\system32\gknhmurpb.exe -start

                          Rechercher et supprimer si présent:

                          c:\windows\system32\gknhmurpb.exe

                          C:\Documents and Settings\administrateur\Local Settings\Temp\se.dll

                          C:\Documents and Settings\Daniel\Local Settings\Temp\se.dll

                          Ensuite:

                          Supprimer tout les fichiers à l'intérieur des dossiers suivants:

                          * C:\Temp
                          * C:\Windows\Temp
                          * C:\WINDOWS\Prefetch <= sauf le fichier layout.ini
                          * C:\Documents and Settings\tous les utilisateurs\Local Settings\Temp
                          * C:\Documents and Settings\tous les utilisateurs \Local Settings\Temporary Internet Files
                          * C:\Documents and Settings\tous les utilisateurs \Cookies
                          * Vider la corbeille !

                          Nettoyage du disque:
                          Démarrer > Tous les programmes > accessoires > outils système > nettoyage du disque
                          cocher:
                          - fichiers et programmes téléchargés
                          - fichiers internet temporaires
                          - corbeille
                          - fichier temporaires
                          valider ok

                          relance hijackthis et clic sur "open the misc tool section"
                          clic sur "delete file on reboot"
                          deplace toi jusqu' a C:\WINDOWS\System32\
                          clic sur clfl.dll
                          et valide "ouvrir"
                          accepte le redemarrage

                          une fois redemarré , fais un scan AV ici:
                          http://www.ravantivirus.com/scan/
                          Clic sur "To continue without subscribing click here"
                          Lorsque "Ready" est affiché dans "status", clic sur "Scan my PC".
                          A la fin de l'analyse, copier/coller le rapport ici + un nouveau rapport hijackthis

                          Ne pas oublier après les manips de recocher " masquer les fichiers protégés du système" dans les options des dossiers

                          a+
                          0
                          1. Contributeur sécurité
                            salut
                            imprime ceci pour ne rien oublier et tous faire
                            tous faire dans l ordre imperativement
                            -------------------------
                            tous da bord telecharge ces programmes si tu ne les a pas et met les a jour mais ne les utilise pas encore
                            adaware (1)
                            spyboot (2)
                            (ici) http://www.florensac-chasse-trap.com/ section virus
                            et aussi ceci
                            CleanUp312.exe (3)

                            ----------------

                            demarre en mode sans echec
                            mode sans echec pour cela tu tapote la touche f8
                            des le debut de l allumage du pc sans t arreter
                            une fenetre vas souvrir tute deplace avec les fleches du clavier sur demarreren mode sans echec
                            une fois sur le bureau il ni auras pas toutes les couleurs et autres c est normal.si f8 ne marche pas utilise la touche f5
                            -------------------------
                            desactive ta restauration systeme
                            pour ça tu fais clic droit sur poste de travail
                            propriété tu clique sur onglet restauration système
                            tu coche la case désactiver la restauration et applique
                            ------------

                            assure toi de ceci
                            Affiche tous les fichiers et dossiers :
                            cliquer sur démarrer/panneau de configuration/option des dossiers/affichage
                            Cocher afficher les dossiers cacher

                            Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                            Décocher masquer les extensions dont le type est connu
                            Puis fais «Ok» pour valider les changements.

                            Et appliquer
                            ----------------------
                            vide tes fichiers temps et tempory internet file sur tous les utilisateur
                            utilise ceci pour le faire
                            http://pageperso.aol.fr/Balltrap34/CleanUp312.exe

                            --------------------
                            relance hijack coche ces lignes et ensuite clik sur fix

                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Daniel\LOCALS~1\Temp\se.dll/spage.html
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
                            O4 - HKLM\..\Run: [gknhmurpb] c:\windows\system32\gknhmurpb.exe -start
                            O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
                            O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab

                            la ligne si dessous c est toi qui la mis en zone de confiance
                            O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm

                            ----------------------
                            recherche et suppr ceci
                            attention seulement les fichiers
                            C:\DOCUME~1\Daniel\LOCALS~1\Temp\se.dll/spage.html
                            c:\windows\system32\gknhmurpb.exe

                            ---------------
                            passe adaware et vire tous se qu il trouve
                            ----------
                            passe spy boot et vire tous se qu il trouvent
                            -------------

                            -------------
                            tu vide ta poubelle et tu redemarre en mode normal et refait un hijack

                            --
                            0
                            1. salut vincent

                              Commence par mettre à jours ad-aware et spybot (ne pas oublier de revacciner apres).
                              ensuite telecharge:
                              - CWShredder:
                              http://cwshredder.net/bin/CWShredder.exe
                              et met le à jour immediatement (update).
                              ne l'utilise pas pour l'instant.

                              -------------

                              -> Rend visible les fichiers cachés et systeme
                              panneau de configuration > options des dossiers > onglet affichage
                              cocher " afficher les fichiers et dossiers cachés "
                              décocher " masquer les extentions des fichiers dont le type est connu
                              décocher " masquer les fichiers protégés du système"

                              -> désactive la restauration systéme
                              Clic droit sur poste de travail > propriétés > onglet restauration système
                              puis cocher "désactiver la restauration système".

                              Lance hijackthis et Fixe:
                              (cocher au début de chaques lignes valider avec fix checked)

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

                              O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - (no file)
                              O2 - BHO: (no name) - {CBC5014C-CC96-4316-9A04-EA3A6D5108D9} - C:\WINDOWS\System32\clfl.dll

                              O4 - HKLM\..\Run: [gknhmurpb] c:\windows\system32\gknhmurpb.exe -start
                              O4 - HKLM\..\Run: [Anti Spyware] "C:\Program Files\SinEspias\No-Spy.exe" /autorun
                              O4 - HKLM\..\Run: [Sans Espions] "C:\Program Files\SinEspias\No-Spy.exe" /autorun
                              O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll,DllInstall

                              O16 - DPF: {DDF44FD9-749F-4761-89BB-E8A59339E459} - http://akamai.downloadv3.com/binaries/LiveService/LiveService_9_FR_XP.cab

                              O18 - Filter: text/html - {CC2DAD45-523A-4F12-9D78-8055E365C561} - C:\WINDOWS\System32\clfl.dll
                              O18 - Filter: text/plain - {CC2DAD45-523A-4F12-9D78-8055E365C561} - C:\WINDOWS\System32\clfl.dll

                              Puis:
                              - Redémarre en mode sans échec en appuyant sur la touche F8 au démarrage de ton PC (apres l'ecran du bios)

                              Rechercher et supprimer si présent:

                              C:\WINDOWS\System32\clfl.dll
                              C:\Program Files\SinEspias<= tout le dossier
                              c:\windows\system32\gknhmurpb.exe
                              C:\Documents and Settings\administrateur\Local Settings\Temp<= vide tout le contenu du dossier

                              Supprimer tout les fichiers à l'intérieur des dossiers suivants:

                              * C:\Temp
                              * C:\Windows\Temp
                              * C:\WINDOWS\Prefetch <= sauf le fichier layout.ini
                              * C:\Documents and Settings\pour chaques utilisateurs\Local Settings\Temp
                              * C:\Documents and Settings\pour chaques utilisateurs \Local Settings\Temporary Internet Files
                              * C:\Documents and Settings\pour chaques utilisateurs \Cookies

                              * Vider la corbeille !

                              lance cwshredder (clic sur FIX)

                              Profite d'être en mode sans echecs pour lancer le scan de ad-aware, spybot... et supprime tout ce qu'ils trouvent.

                              Redemarre normalement et reposte un log hijack pour vérifier l'évolution

                              tu peux telecharger cet utilitaire pour nettoyer ton registre:
                              regseeker
                              http://www.hoverdesk.net/freeware.htm
                              lance le, puis clic sur nettoyage registre et ne supprime que les entrées en vert (attention !)

                              Ne pas oublier après les manips de recocher " masquer les fichiers protégés du système" dans les options des dossiers

                              a+
                              0
                              1. voici le nouveau log Hijack, j'espère que c'est mieux :

                                par contre, je n'ai pas réussi à supprimer un fichier :

                                C:\WINDOWS\System32\clfl.dll

                                Logfile of HijackThis v1.99.1
                                Scan saved at 16:51:25, on 10/04/2005
                                Platform: Windows XP SP1 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                                C:\WINDOWS\Explorer.EXE
                                C:\WINDOWS\system32\cisvc.exe
                                C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                                C:\WINDOWS\system32\slserv.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                C:\WINDOWS\wanmpsvc.exe
                                C:\WINDOWS\SOUNDMAN.EXE
                                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                C:\Program Files\Winamp\winampa.exe
                                C:\PROGRA~1\Wanadoo\CnxMon.exe
                                C:\PROGRA~1\MESSAG~1\StartMessager.exe
                                C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                                C:\Program Files\QuickTime\qttask.exe
                                C:\Program Files\MSN Messenger\MsnMsgr.Exe
                                C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                                C:\VSTASCAN\vsaccess.exe
                                C:\Documents and Settings\Daniel\Mes documents\Vincent\internet\HijackThis.exe
                                C:\WINDOWS\System32\wuauclt.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Daniel\LOCALS~1\Temp\se.dll/spage.html
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
                                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.wanadoo.fr/
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                                O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                                O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                                O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                                O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
                                O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                                O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                O4 - HKLM\..\Run: [gknhmurpb] c:\windows\system32\gknhmurpb.exe -start
                                O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                                O4 - Startup: UMAX VistaAccess.lnk = C:\VSTASCAN\vsaccess.exe
                                O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                                O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                                O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
                                O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                                O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
                                O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
                                O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                                O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                                O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

                                merci

                                A+
                                0