PB PAYPOPUP HELP

Bonjour,

j'ai un problème avec mon ordi, depuis quelques jours des fenêtres de pub (avec des messages anglais) s'ouvrent temps tous sens. apparement il s'agit d'un virus ou popup dont j'enten prler sur différent forum.
quelqu'un pourrait t- il me venir en aide SVP

MERCI
KANOT
Configuration: XP

47 réponses

Résumé de la discussion

Des fenêtres publicitaires, des messages en anglais et des redirections apparaissent sur un PC Windows XP, ce qui est perçu comme un possible malware ou adware et suscite l'entraide sur les forums. Des échanges recommandent d'utiliser HijackThis pour repérer entrées douteuses et suppressions ciblées dans le registre, en évitant les clés non confirmées et en restant prudent face aux services suspects qui apparaissent. Les journaux HijackThis montrent de nombreuses entrées au démarrage et des composants publicitaires, et la présence d'outils comme WinFixer 2005 dans les programmes qui démarrent signale une infection complexe nécessitant un nettoyage approfondi.

Bobot (l’IA à votre service)
  1. merci à toutes les personnes qui m'ont aidé a résoudre mon pb, à régis entre autres...cependant je t'avouerais que j'ai laissé tomber sa me prenait beaucoup trop de temps et de stress( et pourtant on dis bien que tout vient a point à qui sait attendre!)
    non sans rire je vais voir si une personne de mon entourage pourra m'aider dans le cas contraire j'aviserai..

    merci encore à vous qui prenez beaucoup de temps pour nous venir en aide.

    KANOT
    0
    1. bonne soirée

      Logfile of HijackThis v1.99.1
      Scan saved at 20:55:44, on 02/10/2005
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\LEXBCES.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\LEXPPS.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      C:\WINDOWS\system32\cisvc.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\windows\system\hpsysdrv.exe
      C:\HP\KBD\KBD.EXE
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\WINDOWS\system32\cidaemon.exe
      C:\Documents and Settings\Propriétaire\Bureau\ANTIVIRUS\HijackThis.exe
      C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\6PEFYZ6V\HijackThis[1].exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
      O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
      O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [Desksite CMA] C:\Program Files\desksite\bin\cma.exe
      O4 - HKLM\..\Run: [ImInstaller_IncrediMail] C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\ImInstaller\IncrediMail\incredimail_install[1].exe -startup -product IncrediMail
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
      O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
      O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
      O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
      O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
      O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
      O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
      O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
      O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
      O16 - DPF: Interface Chat Voila - http://chat4.x-echo.com/version5/Applet/vchatsign.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by15fd.bay15.hotmail.msn.com/resources/MsnPUpld.cab
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
      O16 - DPF: {FC67BB52-AAB6-4282-9D51-2DAFFE73AFD0} - http://download.spyspotter.com/spyspotter/spsp29953.01noopt/spyspottercabinstall.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{1DA58623-2288-42C2-904A-CEFDC0F3F7BA}: NameServer = 212.151.137.170 212.247.156.66
      O17 - HKLM\System\CS1\Services\Tcpip\..\{1DA58623-2288-42C2-904A-CEFDC0F3F7BA}: NameServer = 212.151.137.170 212.247.156.66
      O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\VIAR332.DLL (file missing)
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O20 - Winlogon Notify: Installer - C:\WINDOWS\system32\oqano.dll
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

      ila
      0
      1. Redemarre ton pc et remet un hijack this

        moi je coupe, je verrais ca demain

        a+
        0
        1. re

          désolé je suis allé m'oxygéné le cerveau parce qu'aprés avoir passé le week end sur mon problème j'avoue que j'allais devenir folle.

          pour en revenir a nos moutons je démarre bien en mode sans échec et j'ai beau cliquer dans tous les sens sur l2mfixça ne marche pas ..... et je sens que tu vas bientôt me gronder (lol) car je n'avance pas dans mes devoirs n'est ce pas ??? lol

          en fait je pense faire comme tu dis mais ya rien qui apprarait des la 1ere manip du double clic......

          sauve moi .....
          0
          1. salut,
            en fait il faut pas redemarrer en mode normal lol
            Lorsque tu l as telecharger , tu clik droit dessu, et tout extraire..
            clik sur l2mfix.bat appuie sur n importe quelle touche << tu as appuyé? lol

            Essai de recommencer stp lol

            a+
            0
            1. Bonjour,

              j'ai pas bien compri l'étape 4) a aprtir du moment ou tu dis de lancer L2mfix
              je l'ai bien télécharger par contre qu'est ce que tu entend par "décompresse le double clic sur L2mfix.bat..." ???? comprend pas du tout (lol)

              j'ai une icone (fichier) qui s'appelle l2mfix.exe qui lance l'application (installation) et dans le dossier L2mfix je retrouve bien L2mfix.bat par contre je n'arrive pas à l'ouvrir (seul un écran noir et réduit apparait le temps d'une fraction de seconde) suis je perdue ??? (lol)

              j'aurais de nouveau besoin de tes lumières mon chèr.......

              kanot
              0
              1. Quel con lol
                a force, j oublie des possibilités de reponses...

                ***
                1) telecharge ceci

                lm2fix
                http://www.downloads.subratam.org/l2mfix.exe

                Telecharge: Pocket Killbox ici
                http://www.downloads.subratam.org/KillBox.exe
                regarde la video sur l’utilisation avec le block note, on va s’en servire plus tard:
                http://pageperso.aol.fr/balltrap34/killbox.htm

                mais ne fais rien de plus.

                ¤Démarre en mode sans échec :
                Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                (Si F8 ne marche pas utilise la touche F5).

                4) Lance L2mfix

                decompresse le double clik sur l2mfix.bat appuie sur n importe quelle touche et ensuite choisi l option 2
                à la fin le prog devrait redémarrer ton système, des le lancement du bios, tapote sur la touche F8 afin de basculer en mode sans échec (attention c’est important)

                5) Killbox
                1- Double-clic sur KillBox.exe
                2- ouvre le bloc notes et copie la liste en gras ci-dessous
                3- Sélectionne "Delete on Reboot"
                4- reviens sur le bloc-notes et surligne toute la liste, puis clic droit dessus et clic sur copier
                5- revient sur killbox, et dans le menu du haut clic sur File, puis sur paste from clipboard
                5- clic sur le rond rouge
                6- une fenêtre va apparaître pour confirmation clic sur OUI
                7- une seconde fenêtre te demande si tu veux redémarrer clic sur OUI

                liste

                C:\WINDOWS\system32\VIAR332.DLL
                C:\WINDOWS\system32\oqano.dll
                C:\WINDOWS\system32\kidhu.dll

                quand killbox redémarre le pc, appuie immédiatement sur F8, pour rester en mode sans échec

                6) lance hijackthis et fixe :

                O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\VIAR332.DLL (file missing)

                O20 - Winlogon Notify: OemStartMenuData - C:\WINDOWS\system32\oqano.dll

                O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\kidhu.dll

                8) repasse l2mfix option 2, laisse redemarrer normalement et refait un log hijack

                a+
                0
                1. salut regis

                  ca sent la vx2, l2mfix devrait s'en charger..

                  a++
                  0
                  1. Aurais je rater qqchose??? une 4eme apparait , le comble lol

                    tu peux remettre un silent runner?
                    Moe t es dans le coin?
                    0
                    1. voici mon HJ

                      Logfile of HijackThis v1.99.1
                      Scan saved at 21:07:42, on 01/10/2005
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\LEXBCES.EXE
                      C:\WINDOWS\system32\LEXPPS.EXE
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\system32\rundll32.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                      C:\WINDOWS\system32\cisvc.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\windows\system\hpsysdrv.exe
                      C:\HP\KBD\KBD.EXE
                      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                      C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\WINDOWS\system32\cidaemon.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\EBP\Compta\compta.exe
                      C:\PVSW\BIN\W3DBSMGR.EXE
                      C:\Documents and Settings\Propriétaire\Bureau\ANTIVIRUS\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                      O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                      O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
                      O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [Desksite CMA] C:\Program Files\desksite\bin\cma.exe
                      O4 - HKLM\..\Run: [ImInstaller_IncrediMail] C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\ImInstaller\IncrediMail\incredimail_install[1].exe -startup -product IncrediMail
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
                      O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                      O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                      O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                      O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                      O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
                      O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
                      O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
                      O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                      O16 - DPF: Interface Chat Voila - http://chat4.x-echo.com/version5/Applet/vchatsign.cab
                      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by15fd.bay15.hotmail.msn.com/resources/MsnPUpld.cab
                      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{1DA58623-2288-42C2-904A-CEFDC0F3F7BA}: NameServer = 212.151.137.166 212.247.156.66
                      O17 - HKLM\System\CS1\Services\Tcpip\..\{1DA58623-2288-42C2-904A-CEFDC0F3F7BA}: NameServer = 212.151.137.166 212.247.156.66
                      O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\VIAR332.DLL (file missing)
                      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                      O20 - Winlogon Notify: OemStartMenuData - C:\WINDOWS\system32\oqano.dll
                      O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\kidhu.dll (file missing)
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                      0
                      1. me revoila c'était super long

                        voici mon HJ mais j'ai beau cocher et fixer la ligne
                        04-HKLM... Run : ImInstaller_Incredimail......... il est toujours présent
                        0
                        1. re lol
                          oui presque la meme
                          celle ci est apparue
                          O20 - Winlogon Notify: Explorer - C:\WINDOWS\system32\VIAR332.DLL
                          et donc il fo la supprimer avec kill box, de plus l autre est tjr presente...
                          et j ai ajouter de jamais revenir en mode normal avant la fin de la manipulation

                          a+
                          0
                          1. mais il me semble avoir déja fait cette manip non ??
                            0
                            1. re,

                              ¤Démarre en mode sans échec :
                              Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                              Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                              Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                              (Si F8 ne marche pas utilise la touche F5).
                              ----------------------------------------------------------------------------
                              ¤Affiche tous les fichiers et dossiers :
                              Clique sur démarrer/panneau de configuration/outil/option des dossiers/affichage

                              Coche « afficher les fichiers et dossiers cachés »

                              Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                              Décoche « masquer les extensions dont le type est connu »
                              Puis fais «Ok» pour valider les changements.

                              Et appliquer !
                              ----------------------------------------------------------------------------
                              ¤Vide tes fichiers temps et tempory internet file:

                              utilise cleanup:tu l as telecharger tout a l heure (la chasse d eau lol)
                              ----------------------------------------------------------------------------
                              6/¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

                              O4 - HKLM\..\Run: [ImInstaller_IncrediMail] C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\ImInstaller\IncrediMail\incredimail_install[1].exe -startup -product IncrediMail

                              O20 - Winlogon Notify: Explorer - C:\WINDOWS\system32\VIAR332.DLL

                              O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\kidhu.dll

                              ----------------------------------------------------------------------------
                              ¤Recherche et supprime ceci:
                              attention seulement les fichiers (si présents).

                              C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\ImInstaller
                              C:\Program Files\MyWay
                              C:\Program Files\YourSiteBar

                              ------------

                              Double clic sur killbox.exe (Pocket Killbox)

                              - coche: delete on reboot
                              - Dans "Full Path of File to Delete"
                              copie et colle:

                              C:\WINDOWS\system32\VIAR332.DLL
                              C:\WINDOWS\system32\kidhu.dll

                              - clique sur la croix rouge
                              - une fenêtre va apparaître pour confirmation clique sur YES
                              - une seconde fenêtre te demande si tu veux redémarrer clique sur YES

                              Laisse le pc redémarrer.

                              Ne le laisse pas repartir en mode normal; une fois que ton ordi redemarre tu le relance en sans echec:

                              Démarre en mode sans échec :
                              Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                              Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                              Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                              (Si F8 ne marche pas utilise la touche F5).

                              6/¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

                              O4 - HKLM\..\Run: [ImInstaller_IncrediMail] C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\ImInstaller\IncrediMail\incredimail_install[1].exe -startup -product IncrediMail

                              O20 - Winlogon Notify: Explorer - C:\WINDOWS\system32\VIAR332.DLL

                              O20 - Winlogon Notify: ShellServiceObjectDelayLoad - C:\WINDOWS\system32\kidhu.dll

                              Tu vide ta poubelle,
                              Redemarre en mode normal
                              Et après reposte un log HijackThis.

                              A+
                              0
                              1. je pense que c la bonne maintenant ;-)

                                "Silent Runners.vbs", revision 40.1, http://www.silentrunners.org/
                                Operating System: Windows XP SP2
                                Output limited to non-default values, except where indicated by "{++}"

                                Startup items buried in registry:
                                ---------------------------------

                                HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                                "NVIEW" = "rundll32.exe nview.dll,nViewLoadHook" [MS]
                                "unilex01" = (empty string)

                                HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                                "hpsysdrv" = "c:\windows\system\hpsysdrv.exe" ["Hewlett-Packard Company"]
                                "ATIModeChange" = "Ati2mdxx.exe" ["ATI Technologies, Inc."]
                                "KBD" = "C:\HP\KBD\KBD.EXE" ["Hewlett-Packard Company"]
                                "StorageGuard" = ""C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r" ["Sonic Solutions"]
                                "Recguard" = "C:\WINDOWS\SMINST\RECGUARD.EXE" [empty string]
                                "HotKeysCmds" = "C:\WINDOWS\System32\hkcmd.exe" ["Intel Corporation"]
                                "NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup" [MS]
                                "nwiz" = "nwiz.exe /installquiet /keeploaded /nodetect" ["NVIDIA Corporation"]
                                "ATIPTA" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" ["ATI Technologies, Inc."]
                                "PS2" = "C:\WINDOWS\system32\ps2.exe" ["Hewlett-Packard Company"]
                                "SpeedTouch USB Diagnostics" = ""C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon" ["THOMSON Telecom Belgium"]
                                "Microsoft Works Update Detection" = "C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" ["Microsoft® Corporation"]
                                "TkBellExe" = ""C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]
                                "avast!" = "C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [null data]
                                "Desksite CMA" = "C:\Program Files\desksite\bin\cma.exe" [file not found]
                                "ImInstaller_IncrediMail" = "C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\ImInstaller\IncrediMail\incredimail_install[1].exe -startup -product IncrediMail" [file not found]
                                "QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]

                                HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
                                {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx" [empty string]
                                {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" ["Safer Networking Limited"]
                                {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = "Google Toolbar Helper" [from CLSID]
                                -> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]

                                HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
                                "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
                                "{BB7DF450-F119-11CD-8465-00AA00425D90}" = "Microsoft Access Custom Icon Handler"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office\soa800.dll" [MS]
                                "{59850401-6664-101B-B21C-00AA004BA90B}" = "Séparateur du Classeur Microsoft Office"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office\UNBIND.DLL" [MS]
                                "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office\olkfstub.dll" [MS]
                                "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
                                "{472083B0-C522-11CF-8763-00608CC02F24}" = "avast"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]
                                "{2600A13A-69D3-446E-922B-1086FC744764}" = (no title provided)
                                -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\VIAR332.DLL" [null data]
                                "{AB77609F-2178-4E6F-9C4B-44AC179D937A}" = "a² Context Menu Shell Extension"
                                -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\A2FREE~1\A2CONT~1.DLL" [null data]
                                "{0DFADAC6-FD75-4412-96E0-C1023D432165}" = (no title provided)
                                -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\guard.tmp" [null data]

                                HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
                                INFECTION WARNING! Explorer\DLLName = "C:\WINDOWS\system32\VIAR332.DLL" [null data]
                                INFECTION WARNING! igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"]
                                INFECTION WARNING! Shell Extensions\DLLName = "C:\WINDOWS\system32\kidhu.dll" [file not found]

                                HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
                                avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

                                HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
                                a2ContMenu\(Default) = "{AB77609F-2178-4E6F-9C4B-44AC179D937A}"
                                -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\A2FREE~1\A2CONT~1.DLL" [null data]
                                avast\(Default) = "{472083B0-C522-11CF-8763-00608CC02F24}"
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Alwil Software\Avast4\ashShell.dll" ["ALWIL Software"]

                                Active Desktop and Wallpaper:
                                -----------------------------

                                Active Desktop is disabled at this entry:
                                HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

                                HKCU\Control Panel\Desktop\
                                "Wallpaper" = "C:\Documents and Settings\All Users\Documents\Ma musique\lamia 2\lamia2\Sans titre.bmp"

                                Enabled Screen Saver:
                                ---------------------

                                HKCU\Control Panel\Desktop\
                                "SCRNSAVE.EXE" = "C:\WINDOWS\System32\logon.scr" [MS]

                                Winsock2 Service Provider DLLs:
                                -------------------------------

                                Namespace Service Providers

                                HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
                                000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
                                000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
                                000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

                                Transport Service Providers

                                HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
                                0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
                                %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17
                                %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

                                Toolbars, Explorer Bars, Extensions:
                                ------------------------------------

                                Toolbars

                                HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
                                "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = "&Google" [from CLSID]
                                -> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]

                                HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
                                "{0494D0D9-F8E0-41AD-92A3-14154ECE70AC}" = "My &Search Bar" [from CLSID]
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL" [file not found]

                                "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = "&Google" [from CLSID]
                                -> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]

                                "{86227D9C-0EFE-4F8A-AA55-30386A3F5686}" = "YourSiteBar" [from CLSID]
                                -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\YourSiteBar\ysb.dll" [file not found]

                                HKLM\Software\Microsoft\Internet Explorer\Toolbar\
                                "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = "&Google" [from CLSID]
                                -> {CLSID}\InProcServer32\(Default) = "c:\program files\google\googletoolbar2.dll" ["Google Inc."]

                                Explorer Bars

                                HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\
                                {D6A116E7-5906-42E4-87F6-E7E15936415E}\ = "MoneySide" [from CLSID]
                                -> {CLSID}\InProcServer32\(Default) = "c:\Program Files\Microsoft Money\System\mnyside.dll" [MS]

                                Extensions (Tools menu items, main toolbar menu buttons)

                                HKLM\Software\Microsoft\Internet Explorer\Extensions\
                                {AC9E2541-2814-11D5-BC6D-00B0D0A1DE45}\
                                "ButtonText" = "AIM"
                                "Exec" = "C:\Program Files\AIM95\aim.exe" ["America Online, Inc."]

                                {E023F504-0C5A-4750-A1E7-A9046DEA8A21}\
                                "ButtonText" = "MoneySide"
                                "CLSIDExtension" = "{DD6687B5-CB43-4211-BFC9-2942CCBDCB3E}"
                                -> {CLSID}\InProcServer32\(Default) = "c:\Program Files\Microsoft Money\System\mnyside.dll" [MS]

                                {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}\
                                "ButtonText" = "Yahoo! Messenger"
                                "MenuText" = "Yahoo! Messenger"
                                "Exec" = "C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe" ["Yahoo! Inc."]

                                {FB5F1910-F110-11D2-BB9E-00C04F795683}\
                                "ButtonText" = "Messenger"
                                "MenuText" = "Windows Messenger"
                                "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [file not found]

                                Miscellaneous IE Hijack Points
                                ------------------------------

                                C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

                                Added lines (compared with English-language version):
                                [Strings]: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                                [Strings]: SAFESITE_VALUE="http://home.microsoft.com/intl/fr/"

                                Missing lines (compared with English-language version):
                                [Strings]: 2 lines

                                Running Services (Display Name, Service Name, Path {Service DLL}):
                                ------------------------------------------------------------------

                                avast! Antivirus, avast! Antivirus, ""C:\Program Files\Alwil Software\Avast4\ashServ.exe"" [null data]
                                avast! iAVS4 Control Service, aswUpdSv, ""C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"" [null data]
                                avast! Mail Scanner, avast! Mail Scanner, ""C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service" ["ALWIL Software"]
                                avast! Web Scanner, avast! Web Scanner, ""C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service" ["ALWIL Software"]
                                C-DillaCdaC11BA, C-DillaCdaC11BA, "C:\WINDOWS\system32\drivers\CDAC11BA.EXE" ["Macrovision"]
                                LexBce Server, LexBceS, "C:\WINDOWS\system32\LEXBCES.EXE" ["Lexmark International, Inc."]

                                ----------
                                + This report excludes default entries except where indicated.
                                + To see *everywhere* the script checks and *everything* it finds,
                                launch it from a command prompt or a shortcut with the -all parameter.
                                + To search all directories of local fixed drives for DESKTOP.INI
                                DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
                                use the -supp parameter or answer "No" at the first message box.
                                ---------- (total run time: 34 seconds, including 18 seconds for message boxes)
                                0
                                1. lol
                                  non tu n as pas fait la bonne lol

                                  il faut telecharger ceci
                                  http://www.silentrunners.org/Silent%20Runners.vbs

                                  tu l execute, tu atends quelques minutes, une fois qu il t envoi un message disant qu il a fini, ouvre le dossier qu il a creer, copie/colle ce qu il y a a l interieur

                                  a+
                                  0
                                  1. je sais pas si j'ai fait la bonne manip mais voila mon HJ

                                    Logfile of HijackThis v1.99.1
                                    Scan saved at 17:06:45, on 01/10/2005
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\LEXBCES.EXE
                                    C:\WINDOWS\system32\LEXPPS.EXE
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                                    C:\WINDOWS\system32\cisvc.exe
                                    C:\WINDOWS\system32\rundll32.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\windows\system\hpsysdrv.exe
                                    C:\HP\KBD\KBD.EXE
                                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                    C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
                                    C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    C:\Program Files\QuickTime\qttask.exe
                                    C:\Program Files\eMule\emule.exe
                                    C:\WINDOWS\system32\cidaemon.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    C:\Documents and Settings\Propriétaire\Bureau\ANTIVIRUS\HijackThis.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                                    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                                    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                                    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                                    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                                    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                                    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                                    O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
                                    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKLM\..\Run: [Desksite CMA] C:\Program Files\desksite\bin\cma.exe
                                    O4 - HKLM\..\Run: [ImInstaller_IncrediMail] C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\ImInstaller\IncrediMail\incredimail_install[1].exe -startup -product IncrediMail
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                    O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
                                    O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                                    O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                                    O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                                    O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                                    O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                                    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
                                    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
                                    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
                                    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                                    O16 - DPF: Interface Chat Voila - http://chat4.x-echo.com/version5/Applet/vchatsign.cab
                                    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by15fd.bay15.hotmail.msn.com/resources/MsnPUpld.cab
                                    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
                                    O17 - HKLM\System\CCS\Services\Tcpip\..\{1DA58623-2288-42C2-904A-CEFDC0F3F7BA}: NameServer = 212.151.137.170 212.247.156.66
                                    O17 - HKLM\System\CS1\Services\Tcpip\..\{1DA58623-2288-42C2-904A-CEFDC0F3F7BA}: NameServer = 212.151.137.170 212.247.156.66
                                    O20 - Winlogon Notify: Explorer - C:\WINDOWS\system32\VIAR332.DLL
                                    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                                    O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\kidhu.dll (file missing)
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                                    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                                    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                                    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                                    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                                    0
                                    1. j'ai bien suivi ce que tu m'as indiqué

                                      Logfile of HijackThis v1.99.1
                                      Scan saved at 16:22:20, on 01/10/2005
                                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                                      Running processes:
                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\WINDOWS\system32\LEXBCES.EXE
                                      C:\WINDOWS\system32\LEXPPS.EXE
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                                      C:\WINDOWS\system32\cisvc.exe
                                      C:\WINDOWS\system32\rundll32.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\windows\system\hpsysdrv.exe
                                      C:\HP\KBD\KBD.EXE
                                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                      C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
                                      C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                      C:\Program Files\QuickTime\qttask.exe
                                      C:\Program Files\eMule\emule.exe
                                      C:\WINDOWS\system32\cidaemon.exe
                                      C:\Program Files\Internet Explorer\iexplore.exe
                                      C:\Documents and Settings\Propriétaire\Bureau\ANTIVIRUS\HijackThis.exe

                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                                      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                                      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                                      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                      O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                                      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                                      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                                      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                                      O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
                                      O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                      O4 - HKLM\..\Run: [Desksite CMA] C:\Program Files\desksite\bin\cma.exe
                                      O4 - HKLM\..\Run: [ImInstaller_IncrediMail] C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\ImInstaller\IncrediMail\incredimail_install[1].exe -startup -product IncrediMail
                                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                      O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
                                      O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                                      O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                                      O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                                      O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                                      O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                                      O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
                                      O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
                                      O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
                                      O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
                                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                                      O16 - DPF: Interface Chat Voila - http://chat4.x-echo.com/version5/Applet/vchatsign.cab
                                      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by15fd.bay15.hotmail.msn.com/resources/MsnPUpld.cab
                                      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
                                      O17 - HKLM\System\CCS\Services\Tcpip\..\{1DA58623-2288-42C2-904A-CEFDC0F3F7BA}: NameServer = 212.151.137.170 212.247.156.66
                                      O17 - HKLM\System\CS1\Services\Tcpip\..\{1DA58623-2288-42C2-904A-CEFDC0F3F7BA}: NameServer = 212.151.137.170 212.247.156.66
                                      O20 - Winlogon Notify: Explorer - C:\WINDOWS\system32\VIAR332.DLL
                                      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                                      O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\kidhu.dll (file missing)
                                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                                      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                                      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                                      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                                      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                                      0
                                      • 1
                                      • 2
                                      • 3