Geebx devra être détruite !

Résolu
Bonjour à tous !
Je suis un petit nouveau (voir mon profil por les infos essentielles me concernant) et j'ai un gros souci (ô surprise :-)) sur mon ordi .
(XP home avec SP1 à jour, Trend Intenet security 12).

Amis docteurs, voici ler symptômes :
- affichage intempestif de fenetres pub avec un contour design... (presque jolies, tiens)
- IE ouvert, envoi vers des pages type OAS.CENTRAL ou PAYPOPUP (principalement...)
- surchage du proc'....
- lutte de titan à la AOM contre winfixer 2005 qui veut s'installer...

IL y a quatre jours que je galère en lisant beaucoup de forums et le problème que j'ai trouvé le plus proche est celui que Real Mona et Regis59 ont parfaitement traité ici , à propos du problème de Cédric...
J'ai la geebx.dll (+ au moins, une de ses DLL conséquentes) qui est invirable...

J'ai à peu près le schéma à faiure en tête, mais, si quelqu'un pouvait m'aider, ce serait fantastique et très sympa.

Donc, là aussi , surprise... , je vous copie mon log' HJT ci-dessous et vous remercie par avance !

Logfile of HijackThis v1.99.1
Scan saved at 07:57:11, on 16/11/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\TRENDM~1\INTERN~2\PccGuide.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\The Cleaner\tca.exe
C:\Program Files\The Cleaner\tcm.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Outlook Express\msimn.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Alain\Mes documents\Unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\System32\geebx.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure/connexion/archives/ie4n4/teleir_cert.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119644501453
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102501/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
O20 - Winlogon Notify: geebx - C:\WINDOWS\System32\geebx.dll
O20 - Winlogon Notify: URL - C:\WINDOWS\system32\q486lels1hq6.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Local Security Authority Server (LSA Server) - Unknown owner - C:\WINDOWS\System32\lsasrv.exe (file missing)
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\WINDOWS\lsass.exe (file missing)
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
O23 - Service: MS Dns Service (WinNet) - Unknown owner - C:\WINDOWS\system32\wincntrl.exe (file missing)

----------------------
A plus ! Je ne reviendrai devant la machine qu'en soirée (21h15 au plus tard), pour quelques heures, au moins :-))))))
Configuration: Windows XP familial avec SP1 à jour.
AV Trend Internet Security 12

23 réponses

Résumé de la discussion

Un utilisateur Windows XP SP1 est confronté à une infection publicitaire et à des redirections IE, avec surcharge du processeur et l’installation potentielle de WinFixer 2005, caractérisée par geebx.dll. Le log HijackThis révèle des éléments suspects tels que O2/BHO geebx.dll et O16 teleir_cert, ainsi que des entrées WinlogonNotify, avec une suggestion de suppression et d’outils anti‑spyware. Plusieurs recommandations évoquent L2MFix (ou l2mfix.exe) en mode normal, l’analyse des clés de démarrage et des extensions ActiveX, ainsi que des scans en ligne pour obtenir un rapport clair. En outre, le fil illustre l’entraide communautaire autour du problème, avec des échanges de liens et d’exemples de rapports, tout en restant sans verdict unique sur l’état final.

Bobot (l’IA à votre service)
  1. J'ai résolu mon gros problème !

    Sur un autre forum du net, on m'a conseillé un logiciel qui éradique sans manipulation compliquée le tandem mortel VUNDO + L2M
    et ce soft a pour nom : SPYSWEEPER de WebRoot...

    (sur les SweepOptions par défaut, décocher "do not sweep system restore folder" et vérifier la coche sur tous les autres)

    Je remercie sincèrement tous ceux qui m'ont aidé sur CCM ! A bientôt !
    0
    1. Contributeur sécurité
      oki
      relance le et cette fois passe l option 2
      il vas normalement faire redemarrer ton pc
      apres redemarrage repasse le toujours option 2 redemarrage et refait l option 1 et donne le rapport et un nouvel hijack
      a partir de la ne redemmarre pas
      0
      1. Salut Balltrap !

        Voici sur ta manip' , exécutée en mode normal ...

        L2MFIX find log 1.04a
        These are the registry keys present
        **********************************************************************************
        Winlogon/notify:
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
        "DLLName"="Ati2evxx.dll"
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000001
        "Lock"="AtiLockEvent"
        "Logoff"="AtiLogoffEvent"
        "Logon"="AtiLogonEvent"
        "Disconnect"="AtiDisConnectEvent"
        "Reconnect"="AtiReConnectEvent"
        "Safe"=dword:00000000
        "Shutdown"="AtiShutdownEvent"
        "StartScreenSaver"="AtiStartScreenSaverEvent"
        "StartShell"="AtiStartShellEvent"
        "Startup"="AtiStartupEvent"
        "StopScreenSaver"="AtiStopScreenSaverEvent"
        "Unlock"="AtiUnLockEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
        6c,00,00,00
        "Logoff"="ChainWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Logoff"="CryptnetWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
        "DLLName"="cscdll.dll"
        "Logon"="WinlogonLogonEvent"
        "Logoff"="WinlogonLogoffEvent"
        "ScreenSaver"="WinlogonScreenSaverEvent"
        "Startup"="WinlogonStartupEvent"
        "Shutdown"="WinlogonShutdownEvent"
        "StartShell"="WinlogonStartShellEvent"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\CSCSettings]
        "Asynchronous"=dword:00000000
        "DllName"="C:\\WINDOWS\\system32\\j42qlef51h2.dll"
        "Impersonate"=dword:00000000
        "Logon"="WinLogon"
        "Logoff"="WinLogoff"
        "Shutdown"="WinShutdown"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\geebx]
        "Asynchronous"=dword:00000001
        "DllName"="C:\\WINDOWS\\System32\\geebx.dll"
        "Impersonate"=dword:00000000
        "Startup"="SysLogon"
        "Logoff"="SysLogoff"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
        "DLLName"="wlnotify.dll"
        "Logon"="SCardStartCertProp"
        "Logoff"="SCardStopCertProp"
        "Lock"="SCardSuspendCertProp"
        "Unlock"="SCardResumeCertProp"
        "Enabled"=dword:00000001
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "StartShell"="SchedStartShell"
        "Logoff"="SchedEventLogOff"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
        "Logoff"="WLEventLogoff"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001
        "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
        "DLLName"="WlNotify.dll"
        "Lock"="SensLockEvent"
        "Logon"="SensLogonEvent"
        "Logoff"="SensLogoffEvent"
        "Safe"=dword:00000001
        "MaxWait"=dword:00000258
        "StartScreenSaver"="SensStartScreenSaverEvent"
        "StopScreenSaver"="SensStopScreenSaverEvent"
        "Startup"="SensStartupEvent"
        "Shutdown"="SensShutdownEvent"
        "StartShell"="SensStartShellEvent"
        "PostShell"="SensPostShellEvent"
        "Disconnect"="SensDisconnectEvent"
        "Reconnect"="SensReconnectEvent"
        "Unlock"="SensUnlockEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
        "Asynchronous"=dword:00000000
        "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Impersonate"=dword:00000000
        "Logoff"="TSEventLogoff"
        "Logon"="TSEventLogon"
        "PostShell"="TSEventPostShell"
        "Shutdown"="TSEventShutdown"
        "StartShell"="TSEventStartShell"
        "Startup"="TSEventStartup"
        "MaxWait"=dword:00000258
        "Reconnect"="TSEventReconnect"
        "Disconnect"="TSEventDisconnect"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
        "DLLName"="wlnotify.dll"
        "Logon"="RegisterTicketExpiredNotificationEvent"
        "Logoff"="UnregisterTicketExpiredNotificationEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
        "DLLName"="wzcdlg.dll"
        "Logon"="WZCEventLogon"
        "Logoff"="WZCEventLogoff"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000000

        RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
        Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
        This program is Freeware, use it on your own risk!

        Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
        (NI) ALLOW Full access AUTORITE NT\SYSTEM
        (IO) ALLOW Full access AUTORITE NT\SYSTEM
        (NI) ALLOW Full access AUTORITE NT\SYSTEM
        (IO) ALLOW Full access AUTORITE NT\SYSTEM
        (ID-CI) DENY --C------- BUILTIN\Administrateurs
        (ID-NI) ALLOW Read BUILTIN\Utilisateurs
        (ID-IO) ALLOW Read BUILTIN\Utilisateurs
        (ID-NI) ALLOW Full access BUILTIN\Administrateurs
        (ID-IO) ALLOW Full access BUILTIN\Administrateurs
        (ID-NI) ALLOW Full access AUTORITE NT\SYSTEM
        (ID-IO) ALLOW Full access AUTORITE NT\SYSTEM
        (ID-IO) ALLOW Full access CREATEUR PROPRIETAIRE

        **********************************************************************************
        useragent:
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
        "{8BC52E93-7A1D-8DA4-135A-76E107BE2C1D}"=""

        **********************************************************************************
        Shell Extension key:
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
        "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
        "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
        "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
        "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
        "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
        "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
        "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
        "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
        "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
        "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
        "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Page de compatibilit‚"
        "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'environnement"
        "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
        "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'environnement pour les objets r‚seau de Microsoft Windows"
        "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
        "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
        "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension de l'environnement d'imprimante Web"
        "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
        "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
        "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extension ic“ne HyperTerminal"
        "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
        "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
        "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
        "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
        "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
        "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
        "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
        "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau"
        "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Connexions r‚seau"
        "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Scanneurs et appareils photo"
        "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Scanneurs et appareils photo"
        "{905667aa-acd6-11d2-8080-00805f6596d2}"="&Scanneurs et appareils photo"
        "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Scanneurs et appareils photo"
        "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Scanneurs et appareils photo"
        "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
        "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
        "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensions de l'interpr‚teur de commandes pour l'environnement d'ex‚cution de scripts Windows"
        "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Liaison de donn‚es Microsoft"
        "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
        "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
        "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
        "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barre des tƒches et menu D‚marrer"
        "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Rechercher"
        "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
        "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
        "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ex‚cuter..."
        "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
        "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Courrier ‚lectronique"
        "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Polices"
        "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Outils d'administration"
        "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
        "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
        "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
        "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
        "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
        "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
        "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
        "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
        "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
        "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
        "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
        "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
        "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Bande de recherche"
        "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
        "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
        "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
        "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
        "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
        "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
        "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
        "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
        "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
        "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
        "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
        "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
        "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Analyseur de la barre d'adresses"
        "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
        "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
        "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
        "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
        "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
        "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
        "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
        "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
        "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
        "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
        "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
        "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
        "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
        "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
        "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
        "{FF393560-C2A7-11CF-BFF4-444553540000}"="Historique"
        "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
        "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
        "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
        "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
        "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
        "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
        "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
        "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
        "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
        "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
        "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
        "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
        "{88C6C381-2E85-11D0-94DE-444553540000}"="Dossier ActiveX Cache"
        "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
        "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
        "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Dossier Inscription"
        "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
        "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
        "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
        "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
        "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
        "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
        "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
        "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'applications d'environnement"
        "{0B124F8F-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
        "{CFCCC7A0-A282-11D1-9082-006008059382}"="Publication d'application Darwin"
        "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
        "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
        "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extracteur de miniatures de fichier + GDI"
        "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Gestionnaire de miniatures - Informations de r‚sum‚ (DOCFILES)"
        "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
        "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
        "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Assistant Publication de sites Web"
        "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Commande d'impressions via le Web"
        "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objet Assistant de publication Shell"
        "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Assistant Obtenir une identit‚ Passport"
        "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Comptes d'utilisateurs"
        "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
        "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
        "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
        "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
        "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
        "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
        "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
        "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
        "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
        "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
        "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
        "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
        "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
        "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
        "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
        "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
        "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
        "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
        "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
        "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
        "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
        "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
        "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
        "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
        "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
        "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
        "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
        "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
        "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
        "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
        "{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
        "{97FA8AA2-EE77-4FF2-9449-424D8924EF21}"="IntelliType Pro Zooming Control Panel Property Page"
        "{111D8120-25EB-4E1C-A4DF-C9EE5FCA35CB}"="IntelliType Pro Scrolling Control Panel Property Page"
        "{ED6E87C6-8A83-43aa-8208-8DBC8247F4D2}"="IntelliType Pro Key Settings Control Panel Property Page"
        "{A2569D1F-4E06-43EC-9825-0088B471BE47}"="IntelliType Pro Wireless Control Panel Property Page"
        "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Dossiers Web"
        "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
        "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
        "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
        "{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
        "{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
        "{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
        "{E0D79307-84BE-11CE-9641-444553540000}"="WinZip"
        "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
        "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
        "{1EBC3533-B289-409F-9924-B84B3F0717D2}"="AceFTP Context Menu Shell Extension"
        "{C25E3A7D-4EEC-438C-AA57-02D4E4834973}"=""
        "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Fichier de chaŒne"
        "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Raccourci de chaŒne"
        "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
        "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
        "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
        "{48F45200-91E6-11CE-8A4F-0080C81A28D4}"="TMD Shell Extension"
        "{771A9DA0-731A-11CE-993C-00AA004ADB6C}"="VBPropSheet"
        "{63547F9B-81A3-4B42-B86E-6CB4971E8C8B}"=""
        "{6C19D0F8-0E02-4B62-95A8-61F1F75A8097}"=""
        "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
        "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"

        **********************************************************************************
        HKEY ROOT CLASSIDS:
        Windows Registry Editor Version 5.00

        [HKEY_CLASSES_ROOT\CLSID\{C25E3A7D-4EEC-438C-AA57-02D4E4834973}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{C25E3A7D-4EEC-438C-AA57-02D4E4834973}\Implemented Categories]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{C25E3A7D-4EEC-438C-AA57-02D4E4834973}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{C25E3A7D-4EEC-438C-AA57-02D4E4834973}\InprocServer32]
        @="C:\\WINDOWS\\system32\\wanhttp.dll"
        "ThreadingModel"="Apartment"

        Windows Registry Editor Version 5.00

        [HKEY_CLASSES_ROOT\CLSID\{63547F9B-81A3-4B42-B86E-6CB4971E8C8B}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{63547F9B-81A3-4B42-B86E-6CB4971E8C8B}\Implemented Categories]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{63547F9B-81A3-4B42-B86E-6CB4971E8C8B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{63547F9B-81A3-4B42-B86E-6CB4971E8C8B}\InprocServer32]
        @="C:\\WINDOWS\\system32\\mjvcirt.dll"
        "ThreadingModel"="Apartment"

        Windows Registry Editor Version 5.00

        [HKEY_CLASSES_ROOT\CLSID\{6C19D0F8-0E02-4B62-95A8-61F1F75A8097}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{6C19D0F8-0E02-4B62-95A8-61F1F75A8097}\Implemented Categories]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{6C19D0F8-0E02-4B62-95A8-61F1F75A8097}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
        @=""

        [HKEY_CLASSES_ROOT\CLSID\{6C19D0F8-0E02-4B62-95A8-61F1F75A8097}\InprocServer32]
        @="C:\\WINDOWS\\system32\\viscript.dll"
        "ThreadingModel"="Apartment"

        **********************************************************************************
        Files Found are not all bad files:

        C:\WINDOWS\SYSTEM32\
        aesldp.dll Mon 14 Nov 2005 22:54:44 ..S.R 234 429 228,93 K
        ati2cqag.dll Wed 31 Aug 2005 2:42:50 A.... 233 472 228,00 K
        ati2dvag.dll Wed 31 Aug 2005 3:42:54 A.... 238 592 233,00 K
        ati2edxx.dll Wed 31 Aug 2005 3:37:22 A.... 39 936 39,00 K
        ati2evxx.dll Wed 31 Aug 2005 3:37:12 A.... 46 080 45,00 K
        ati3duag.dll Wed 31 Aug 2005 3:28:36 A.... 2 429 824 2,32 M
        atiddc.dll Wed 31 Aug 2005 3:35:46 A.... 53 248 52,00 K
        atidemgr.dll Wed 31 Aug 2005 5:33:32 A.... 258 048 252,00 K
        atiiiexx.dll Wed 31 Aug 2005 6:08:36 A.... 307 200 300,00 K
        atikvmag.dll Wed 31 Aug 2005 3:10:36 A.... 147 456 144,00 K
        atioglx1.dll Wed 31 Aug 2005 4:57:50 A.... 6 684 672 6,38 M
        atioglxx.dll Wed 31 Aug 2005 3:57:00 A.... 4 718 592 4,50 M
        atipdlxx.dll Wed 31 Aug 2005 3:37:44 A.... 106 496 104,00 K
        atitvo32.dll Wed 31 Aug 2005 2:47:46 A.... 17 408 17,00 K
        ativvaxx.dll Wed 31 Aug 2005 3:23:04 A.... 600 672 586,59 K
        cdosys.dll Sat 10 Sep 2005 3:06:04 A.... 2 025 984 1,93 M
        danim.dll Fri 2 Sep 2005 11:08:16 A.... 988 672 965,50 K
        ddaba.dll Sun 13 Nov 2005 9:46:36 ..SH. 28 173 27,51 K
        dlaba.dll Mon 14 Nov 2005 1:28:28 ..S.R 235 119 229,61 K
        dnj201~1.dll Mon 14 Nov 2005 22:57:44 ..S.R 234 640 229,14 K
        dxtrans.dll Fri 2 Sep 2005 16:35:16 A.... 192 000 187,50 K
        dzcprop2.dll Fri 18 Nov 2005 7:31:42 ..S.R 236 510 230,96 K
        fpp803~1.dll Fri 18 Nov 2005 14:26:36 ..S.R 236 434 230,89 K
        gdi32(~1.dll Thu 6 Oct 2005 4:21:30 A.... 260 608 254,50 K
        gdi32.dll Thu 6 Oct 2005 4:21:30 A.... 260 608 254,50 K
        geebx.dll Sat 12 Nov 2005 18:00:16 ..... 544 788 532,02 K
        gpj2l3~1.dll Wed 16 Nov 2005 12:54:48 ..S.R 233 854 228,37 K
        hosetup.dll Tue 15 Nov 2005 21:57:14 ..S.R 233 402 227,93 K
        hrrq05~1.dll Sun 13 Nov 2005 22:11:38 ..S.R 235 714 230,19 K
        iletmib1.dll Mon 14 Nov 2005 1:38:00 ..S.R 235 119 229,61 K
        j42qle~1.dll Fri 18 Nov 2005 14:19:06 ..S.R 235 561 230,04 K
        jkkjh.dll Fri 11 Nov 2005 16:59:50 A.SH. 28 173 27,51 K
        k0lqla~1.dll Thu 17 Nov 2005 20:06:26 ..S.R 234 013 228,53 K
        k6260g~1.dll Mon 14 Nov 2005 22:37:54 ..S.R 233 795 228,31 K
        kt6sl7~1.dll Mon 14 Nov 2005 22:54:44 ..S.R 236 196 230,66 K
        legitc~1.dll Mon 29 Aug 2005 12:27:12 A.... 520 968 508,76 K
        linkinfo.dll Thu 1 Sep 2005 2:50:42 A.... 16 384 16,00 K
        linkin~1.dll Thu 1 Sep 2005 2:50:42 A.... 16 384 16,00 K
        mcr2cenu.dll Mon 14 Nov 2005 22:00:26 ..S.R 237 235 231,67 K
        meicda.dll Fri 18 Nov 2005 8:05:32 ..S.R 235 483 229,96 K
        mjvcirt.dll Mon 14 Nov 2005 1:15:06 ..S.R 235 918 230,39 K
        mljjh.dll Fri 11 Nov 2005 22:09:44 A.SH. 28 173 27,51 K
        mljjj.dll Fri 11 Nov 2005 17:13:12 A.SH. 28 173 27,51 K
        moc40u.dll Mon 14 Nov 2005 22:32:54 ..S.R 233 795 228,31 K
        mpc40u.dll Thu 17 Nov 2005 22:21:20 ..S.R 236 199 230,66 K
        mqidntld.dll Wed 16 Nov 2005 22:07:04 ..S.R 235 708 230,18 K
        mshtml.dll Tue 4 Oct 2005 12:34:14 A.... 2 700 288 2,57 M
        mstask.dll Tue 15 Nov 2005 7:26:02 A.... 266 240 260,00 K
        mstime.dll Fri 2 Sep 2005 17:32:12 A.... 496 128 484,50 K
        mv8ql9~1.dll Mon 14 Nov 2005 1:15:06 ..S.R 234 042 228,55 K
        mvr(4).dll Mon 14 Nov 2005 23:06:54 ..S.R 234 429 228,93 K
        n66qlg~1.dll Sun 13 Nov 2005 19:16:16 ..S.R 234 031 228,54 K
        n84s0i~1.dll Thu 17 Nov 2005 22:34:56 ..S.R 236 199 230,66 K
        netapi32.dll Tue 15 Nov 2005 7:26:02 A.... 306 688 299,50 K
        netman.dll Mon 22 Aug 2005 19:37:10 A.... 154 624 151,00 K
        netman~1.dll Mon 22 Aug 2005 19:35:10 A.... 197 632 193,00 K
        netman~2.dll Mon 22 Aug 2005 19:37:10 A.... 154 624 151,00 K
        netman~4.dll Mon 22 Aug 2005 19:37:10 A.... 154 624 151,00 K
        oemdspif.dll Wed 31 Aug 2005 3:37:34 A.... 73 728 72,00 K
        prrfos.dll Tue 15 Nov 2005 23:08:04 ..S.R 236 679 231,13 K
        quartz.dll Tue 30 Aug 2005 9:26:24 A.... 1 233 920 1,18 M
        schedsvc.dll Tue 15 Nov 2005 7:26:02 A.... 174 592 170,50 K
        sempapi.dll Mon 14 Nov 2005 1:17:12 ..S.R 235 119 229,61 K
        sgeio.dll Fri 18 Nov 2005 7:53:22 ..S.R 234 037 228,55 K
        sh9637~1.dll Fri 23 Sep 2005 4:28:40 A.... 8 405 504 8,02 M
        shell32.dll Fri 23 Sep 2005 4:28:40 A.... 8 405 504 8,02 M
        shell3~1.dll Fri 23 Sep 2005 4:07:00 A.... 8 506 880 8,11 M
        shell3~2.dll Fri 23 Sep 2005 4:28:40 A.... 8 405 504 8,02 M
        shell3~3.dll Fri 23 Sep 2005 4:28:40 A.... 8 405 504 8,02 M
        shell3~4.dll Fri 23 Sep 2005 4:28:40 A.... 8 405 504 8,02 M
        shlwapi.dll Wed 31 Aug 2005 18:50:42 A.... 409 600 400,00 K
        shlwap~1.dll Sat 3 Sep 2005 1:06:12 A.... 474 112 463,00 K
        shlwap~2.dll Wed 31 Aug 2005 17:50:42 A.... 409 600 400,00 K
        shlwap~4.dll Wed 31 Aug 2005 17:50:42 A.... 409 600 400,00 K
        sintf16.dll Sun 11 Sep 2005 10:54:06 A.... 12 067 11,78 K
        sintf32.dll Sun 11 Sep 2005 10:54:06 A.... 17 212 16,81 K
        sintfnt.dll Sun 11 Sep 2005 10:54:06 A.... 21 840 21,33 K
        ssqpn.dll Fri 11 Nov 2005 22:56:44 A.SH. 28 173 27,51 K
        sstqp.dll Fri 11 Nov 2005 22:20:44 A.SH. 28 173 27,51 K
        sstqq.dll Fri 11 Nov 2005 22:39:04 A.SH. 28 173 27,51 K
        umf208~1.dll Tue 23 Aug 2005 4:52:22 A.... 112 640 110,00 K
        umpnpmgr.dll Tue 23 Aug 2005 4:52:22 A.... 112 640 110,00 K
        umpnpm~1.dll Tue 23 Aug 2005 4:39:36 A.... 124 928 122,00 K
        umpnpm~2.dll Tue 23 Aug 2005 4:52:22 A.... 112 640 110,00 K
        umpnpm~3.dll Tue 23 Aug 2005 4:52:22 A.... 112 640 110,00 K
        uqthem~1.dll Tue 15 Nov 2005 22:53:04 ..S.R 236 464 230,92 K
        urlmon.dll Fri 2 Sep 2005 17:32:12 A.... 459 264 448,50 K
        urlmon~3.dll Fri 2 Sep 2005 16:32:12 A.... 459 264 448,50 K
        uvipla~1.dll Tue 15 Nov 2005 21:53:54 ..S.R 237 257 231,70 K
        viscript.dll Mon 14 Nov 2005 1:59:26 ..S.R 236 372 230,83 K
        vturo.dll Fri 11 Nov 2005 17:18:12 A.SH. 28 173 27,51 K
        vturs.dll Sun 13 Nov 2005 9:41:30 ..SH. 28 173 27,51 K
        vtutt.dll Sun 13 Nov 2005 9:46:38 ..SH. 28 173 27,51 K
        w95inf16.dll Sun 18 Sep 2005 7:42:52 A.... 2 272 2,22 K
        w95inf32.dll Sun 18 Sep 2005 7:42:52 A.... 4 608 4,50 K
        wanhttp.dll Fri 18 Nov 2005 14:26:36 ..S.R 235 561 230,04 K
        winsrv.dll Thu 1 Sep 2005 2:50:42 A.... 278 528 272,00 K
        winsrv~1.dll Thu 1 Sep 2005 2:43:38 A.... 292 352 285,50 K
        wxi(2).dll Thu 17 Nov 2005 22:33:56 ..S.R 236 199 230,66 K
        xpsp2res.dll Tue 27 Sep 2005 1:41:24 A.... 612 864 598,50 K

        100 items found: 100 files (41 H/S), 0 directories.
        Total of file sizes: 89 171 494 bytes 85,04 M
        Locate .tmp files:

        No matches found.
        **********************************************************************************
        Directory Listing of system files:
        Le volume dans le lecteur C n'a pas de nom.
        Le num‚ro de s‚rie du volume est 8426-A397

        R‚pertoire de C:\WINDOWS\System32

        18/11/2005 17:05 394ÿ868 xbeeg.ini
        18/11/2005 14:26 235ÿ561 wanhttp.dll
        18/11/2005 14:26 236ÿ434 fpp8037ue.dll
        18/11/2005 14:19 235ÿ561 j42qlef51h2.dll
        18/11/2005 08:05 235ÿ483 meicda.dll
        18/11/2005 07:53 234ÿ037 sgeio.dll
        18/11/2005 07:31 236ÿ510 dzcprop2.dll
        17/11/2005 22:34 236ÿ199 n84s0ih7e84.dll
        17/11/2005 22:33 236ÿ199 wxi(2).dll
        17/11/2005 22:21 236ÿ199 mpc40u.dll
        17/11/2005 20:26 <REP> dllcache
        17/11/2005 20:06 234ÿ013 k0lqla351d.dll
        16/11/2005 22:07 235ÿ708 mqidntld.dll
        16/11/2005 12:54 233ÿ854 gpj2l31o1.dll
        15/11/2005 23:08 236ÿ679 prrfos.dll
        15/11/2005 22:53 236ÿ464 uqtheme(4).dll
        15/11/2005 21:57 233ÿ402 hosetup.dll
        15/11/2005 21:53 237ÿ257 uviplat(2).dll
        14/11/2005 23:06 234ÿ429 mvr(4).dll
        14/11/2005 22:57 234ÿ640 dnj2011oe.dll
        14/11/2005 22:54 234ÿ429 aesldp.dll
        14/11/2005 22:54 236ÿ196 kt6sl7j71.dll
        14/11/2005 22:37 233ÿ795 k6260gfse6260.dll
        14/11/2005 22:32 233ÿ795 moc40u.dll
        14/11/2005 22:00 237ÿ235 mcr2cenu.dll
        14/11/2005 01:59 236ÿ372 viscript.dll
        14/11/2005 01:37 235ÿ119 iletmib1.dll
        14/11/2005 01:28 235ÿ119 dlaba.dll
        14/11/2005 01:17 235ÿ119 sempapi.dll
        14/11/2005 01:15 235ÿ918 mjvcirt.dll
        14/11/2005 01:15 234ÿ042 mv8ql9l51.dll
        13/11/2005 22:11 235ÿ714 hrrq0595e.dll
        13/11/2005 19:16 234ÿ031 n66qlgj516o.dll
        13/11/2005 09:46 28ÿ173 vtutt.dll
        13/11/2005 09:46 28ÿ173 ddaba.dll
        13/11/2005 09:41 28ÿ173 vturs.dll
        11/11/2005 22:56 28ÿ173 ssqpn.dll
        11/11/2005 22:39 28ÿ173 sstqq.dll
        11/11/2005 22:20 28ÿ173 sstqp.dll
        11/11/2005 22:09 28ÿ173 mljjh.dll
        11/11/2005 17:18 28ÿ173 vturo.dll
        11/11/2005 17:13 28ÿ173 mljjj.dll
        11/11/2005 16:59 28ÿ173 jkkjh.dll
        26/03/2005 00:46 <REP> Microsoft
        42 fichier(s) 7ÿ972ÿ111 octets
        2 R‚p(s) 30ÿ031ÿ896ÿ576 octets libres
        0
        1. Contributeur sécurité
          salut
          fait ceci
          telecharge ceci
          http://www.downloads.subratam.org/l2mfix.exe
          decompresse le double clik sur l2mfix.bat appuie sur n importe quelle touche et ensuite choisi l option 1
          attend il vas faire un rapport fait un copier coller de celui ci
          ne fait surtout rien d autres
          0
          1. J'ai également fait ta manip' boulepate.
            Rien de vu de spécial dans les services démarrage de msconfig
            0
            1. Re,

              je comprends pas pourquoi malgrès que tu les fixe elles sont encore là:

              O20 - Winlogon Notify: CSCSettings - C:\WINDOWS\system32\j42qlef51h2.dll
              O20 - Winlogon Notify: geebx - C:\WINDOWS\System32\geebx.dll

              Quelqu'un à une idée ?
              0
          2. Je viens de refaire en safe, en supprimant des sauvegardes qui traiaient dans les backups de hijack et j'arriv etjs à

            Logfile of HijackThis v1.99.1
            Scan saved at 14:27:38, on 18/11/2005
            Platform: Windows XP SP1 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\System32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Microsoft IntelliType Pro\type32.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
            C:\Program Files\The Cleaner\tca.exe
            C:\Program Files\The Cleaner\tcm.exe
            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
            C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
            C:\WINDOWS\System32\svchost.exe
            C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
            C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
            C:\Documents and Settings\Alain\Mes documents\Unzipped\hijackthis\HijackThis.exe
            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
            C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
            C:\WINDOWS\System32\HPZipm12.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.news.yahoo.com/
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\System32\geebx.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
            O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
            O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
            O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
            O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
            O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
            O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
            O4 - Global Startup: hpoddt01.exe.lnk = ?
            O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
            O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
            O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
            O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
            O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
            O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
            O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119644501453
            O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102501/housecall.trendmicro.com/housecall/xscan53.cab
            O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
            O20 - Winlogon Notify: CSCSettings - C:\WINDOWS\system32\j42qlef51h2.dll
            O20 - Winlogon Notify: geebx - C:\WINDOWS\System32\geebx.dll
            O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: Local Security Authority Server (LSA Server) - Logitech, Inc. - (no file)
            O23 - Service: Local Security Authority Subsystem Service (lsass) - Logitech, Inc. - (no file)
            O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
            O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
            O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
            O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
            0
            1. Salut Régis59,

              Oui...
              J'ai tout fait
              killé 4 lignes geebx sous xpprocess dans explorer
              aucvune ligne présente dans winlogon
              killbox ensuite, après avoir supprimé le parametre de sauvegarde de la dll
              ave c le fix aussi
              dans l'ordre ...
              0
              1. salut
                les 2 lignes 020 sont independantes,
                tu as bien fait la manip que jte demande?
                Tu as bien supprimer tous dans process xp, puis fixer les lignes et ensuite kill box?

                a+
                0
                1. Salut !

                  Je ne fixe pas la ligne 02 ?
                  Parce que fixer, en safe, 02 et les 2 lignes 20 winlogon (geebx.dll + aleatoire.dll), çafait plusieurs soirées depuis 8 jours que je le fais ;-) :-) et elles ne disparaissent pas.

                  Y aurait-il un réglage particulier de Hijack ?
                  0
                  1. Merde, si tu as raison fixe la 02 puis les deux 020, desactive la restauration du systeme puis redemarre en mode sans eche et fixe ces trois lignes puis remet un rapport.
                    En meme temps va voir la-abs si elles ce lancent pas au demarrage:
                    demarrer, executer, tape msconfig, onglet demarrage, puis desactive si tu vois une ligne ressemblante ;)
                    0
                2. Salut Régis59 ! merci !

                  Bilan de la nuit...

                  NOuveau scan Bitdefender + spyware-scan de Trend
                  ta manip' ce matin, deplus executée en sans échec, ace restaur desac + fichiers non -masqu"s etc... et cela donne, oh misère, toujours la même chose....

                  Logfile of HijackThis v1.99.1
                  Scan saved at 08:06:40, on 18/11/2005
                  Platform: Windows XP SP1 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\System32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
                  C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
                  C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
                  C:\WINDOWS\system32\rundll32.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\PROGRA~1\TRENDM~1\INTERN~2\PccGuide.exe
                  C:\Program Files\Microsoft IntelliType Pro\type32.exe
                  C:\WINDOWS\SOUNDMAN.EXE
                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                  C:\Program Files\The Cleaner\tca.exe
                  C:\PROGRA~1\TRENDM~1\INTERN~2\TSC.EXE
                  C:\Program Files\The Cleaner\tcm.exe
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
                  C:\WINDOWS\System32\wuauclt.exe
                  C:\Documents and Settings\Alain\Mes documents\Unzipped\hijackthis\HijackThis.exe
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
                  C:\WINDOWS\System32\HPZipm12.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.news.yahoo.com/
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\System32\geebx.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                  O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                  O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                  O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
                  O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
                  O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
                  O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
                  O4 - Global Startup: hpoddt01.exe.lnk = ?
                  O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
                  O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                  O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                  O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                  O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                  O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                  O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                  O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119644501453
                  O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102501/housecall.trendmicro.com/housecall/xscan53.cab
                  O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                  O20 - Winlogon Notify: App Paths - C:\WINDOWS\system32\k644lghq164e.dll
                  O20 - Winlogon Notify: geebx - C:\WINDOWS\System32\geebx.dll
                  O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                  O23 - Service: Local Security Authority Server (LSA Server) - Logitech, Inc. - (no file)
                  O23 - Service: Local Security Authority Subsystem Service (lsass) - Logitech, Inc. - (no file)
                  O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                  O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
                  O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
                  O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe

                  La geebx + une autre qui varie à chaque boot...

                  Merci à Balltrap pour le tuto : super bien fait...

                  Je serai là en non-stop cet aprèm' (RTT.....)

                  Merci de votre aide, en tous cas ! Maintenant, j'y crois un peu...
                  0
                  1. Salut,
                    désactive la restauration du systéme puis redemarre en mode sans echec et fixe ceci:

                    O20 - Winlogon Notify: App Paths - C:\WINDOWS\system32\k644lghq164e.dll
                    O20 - Winlogon Notify: geebx - C:\WINDOWS\System32\geebx.dll
                    0
                3. Re,
                  Je te met uniquement la manip pour ton geebx mais il en restera a virer...boulepate ou moi le fera...

                  ****

                  Imprime, ou enregistre ceci dans le bloc note pour ne rien oublier.

                  1/

                  télécharge : process xp ici:
                  http://www.sysinternals.com/files/procexpnt.zip

                  Télécharge: Pocket Killbox ici
                  http://www.downloads.subratam.org/KillBox.exe

                  :: Démo d utilisation (merci a Balltrap34 pour cette réalisation) ::
                  http://pageperso.aol.fr/balltrap34/killbox.htm

                  2/

                  Déconnecte toi du net.
                  Ferme tous les programmes en cours (média player, internet explorer, ...etc)

                  Dézippe (clic droit > extraire) process xp et double clic sur processxp.exe

                  * Dans la fenêtre principale de processxp double clic sur winlogon.exe
                  Dans la nouvelle fenêtre qui s'ouvre clique sur threads
                  sélectionne seulement les lignes qui contiennent geebx.dll puis clique sur kill pour chacune des lignes trouvées.
                  une fois fait, valide avec ok

                  * Dans la fenêtre principale de processxp double clic sur explorer.exe
                  Dans la nouvelle fenêtre qui s'ouvre clique sur threads
                  sélectionner seulement les lignes qui contiennent geebx.dll puis clique sur kill pour chacune des lignes trouvées.
                  une fois fait, valide avec ok

                  3/

                  puis lancer HijackThis:

                  clique sur "do a system scan only"

                  * Cocher la case au début de ces lignes:

                  O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\System32\geebx.dll

                  O20 - Winlogon Notify: geebx - C:\WINDOWS\System32\geebx.dll

                  * Valider avec fix checked

                  5/

                  Double clic sur killbox.exe (Pocket Killbox)

                  - coche: delete on reboot
                  - Dans "Full Path of File to Delete"
                  copie et colle:

                  C:\WINDOWS\System32\geebx.dll

                  - clique sur la croix rouge
                  - une fenêtre va apparaître pour confirmation clique sur YES
                  - une seconde fenêtre te demande si tu veux redémarrer clique sur YES

                  Laisse le pc redémarrer.
                  Et après reposte un log HijackThis.

                  A+
                  0
                  1. salut
                    met le en entier

                    a+
                    0
                    1. Logfile of HijackThis v1.99.1
                      Scan saved at 23:11:59, on 17/11/2005
                      Platform: Windows XP SP1 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\System32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\system32\rundll32.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
                      C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
                      C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
                      C:\Program Files\Microsoft IntelliType Pro\type32.exe
                      C:\WINDOWS\SOUNDMAN.EXE
                      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                      C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
                      C:\Program Files\The Cleaner\tca.exe
                      C:\Program Files\The Cleaner\tcm.exe
                      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
                      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
                      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
                      C:\WINDOWS\System32\HPZipm12.exe
                      C:\WINDOWS\System32\wuauclt.exe
                      C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
                      C:\Documents and Settings\Alain\Mes documents\Unzipped\hijackthis\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\System32\geebx.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                      O4 - HKLM\..\Run: [type32]
                      0
                      1. MERCI !
                        Je teste... ça va être un peu long, j'ai 60 go de données pour le scan des AV...
                        Je te tiens au courant .
                        Bonne soirée ...
                        0
                        1. Je suis vacciné Spybot 1.4 (enfin, avant les probs, je n'avais qu'un 1.3) et ad-aware pour nettoyer...

                          Sinon, je n'ai rien de plus en protection résidente, hormis Trend Security 12 (qui a été désactivé 1/2 heure, pendant laquelle je me suis chopé des merdes pas croyables...)

                          Je rentre à la casa à 17h45 et je fixe ça.

                          Tu peux me détailler un peu l'ordre de la procédure d'accompagnement (entre Killbox, xpprocess, clean40, hijack, les modes sans echec, puis normaux, la restaur' desactiveé, l'internet coupé, les services arrêtés.... ben..... devine, je me mélange et jusqu'à présent, je les ai pas eu dans le bon ordre ;-))

                          Merci de ta sollicitude, boulepate !
                          0
                          1. Alors, si je devais te proposer un ordre je te conseillerais celui ci:

                            1. Desactiver le restauration du systeme
                            2. Afficher les fichiers et dossiers masqués
                            3. Ce debarrasser des fichiers temporaires avec Cleanup40
                            4. Nettoyer ta base de registre avec Regseeker
                            ( http://www.01net.com/telecharger/windows/Utilitaire/systeme/fiches/29399.html )
                            5. Faire un scan avec ton anti-virus et tes logiciels anti-spyware (spybot, a²free , ad-aware , ect.. )
                            6. En profiter pour faire un scan anti-virus en ligne
                            - http://www.bitdefender.fr
                            7. Puis faire ce scan en ligne anti-spyware
                            - http://www.trendmicro.com/spyware-scan/
                            8. Faire un scan avec Hijack colle le rapport sur le forum pour une verification si tu ne comprends rien avec les lignes.
                            9. Si ton rapport est correct, reactiver la restauration du systeme, puis recacher les fichiers.
                            10. le mode sans echec utilise le, si tu as un fichier persistant detecté par spybot ou autre.

                            Voilà, j'espere que c'est un peu plus clair comme ça,
                            0
                        2. Re,
                          tu peux fixer ceci:

                          O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\System32\geebx.dll
                          O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure/connexion/archives/ie4n4/teleir_cert.cab
                          O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
                          O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
                          O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
                          O20 - Winlogon Notify: geebx - C:\WINDOWS\System32\geebx.dll
                          O20 - Winlogon Notify: ShellCompatibility - C:\WINDOWS\system32\ktpsl7771.dll

                          Tu as quoi comme logiciels anti-spyware?
                          0
                          1. La scoumoune !
                            Le log complet...

                            Logfile of HijackThis v1.99.1
                            Scan saved at 15:14:53, on 17/11/2005
                            Platform: Windows XP SP1 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\System32\Ati2evxx.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\system32\rundll32.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\System32\svchost.exe
                            C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
                            C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
                            C:\Program Files\Microsoft IntelliType Pro\type32.exe
                            C:\WINDOWS\SOUNDMAN.EXE
                            C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                            C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
                            C:\Program Files\The Cleaner\tca.exe
                            C:\Program Files\The Cleaner\tcm.exe
                            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
                            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
                            C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
                            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
                            C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
                            C:\Program Files\Outlook Express\msimn.exe
                            C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
                            C:\Program Files\Microsoft Works\WkDStore.exe
                            C:\Documents and Settings\Alain\Mes documents\Unzipped\hijackthis\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.news.yahoo.com/
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\System32\geebx.dll
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                            O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                            O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
                            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                            O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                            O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
                            O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
                            O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
                            O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
                            O4 - Global Startup: hpoddt01.exe.lnk = ?
                            O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
                            O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                            O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                            O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                            O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                            O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                            O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                            O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure/connexion/archives/ie4n4/teleir_cert.cab
                            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
                            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
                            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1119644501453
                            O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005102501/housecall.trendmicro.com/housecall/xscan53.cab
                            O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                            O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
                            O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
                            O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IncrediMail) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
                            O20 - Winlogon Notify: geebx - C:\WINDOWS\System32\geebx.dll
                            O20 - Winlogon Notify: ShellCompatibility - C:\WINDOWS\system32\ktpsl7771.dll
                            O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
                            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                            O23 - Service: Local Security Authority Server (LSA Server) - Unknown owner - C:\WINDOWS\System32\lsasrv.exe (file missing)
                            O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\WINDOWS\lsass.exe (file missing)
                            O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
                            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                            O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
                            O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
                            O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
                            O23 - Service: MS Dns Service (WinNet) - Unknown owner - C:\WINDOWS\system32\wincntrl.exe (file missing)
                            0
                            1. Ouin, ouin... :-)
                              J'ai tout contre moi, un mauvais titre de topic, un empêchement pro.. enfin, voilà le dernier log, Boulepate...

                              Logfile of HijackThis v1.99.1
                              Scan saved at 15:14:53, on 17/11/2005
                              Platform: Windows XP SP1 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\System32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\system32\rundll32.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\System32\svchost.exe
                              C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
                              C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
                              C:\Program Files\Microsoft IntelliType Pro\type32.exe
                              C:\WINDOWS\SOUNDMAN.EXE
                              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
                              C:\Program Files\The Cleaner\tca.exe
                              C:\Program Files\The Cleaner\tcm.exe
                              C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
                              C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
                              C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
                              C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
                              C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
                              C:\Program Files\Outlook Express\msimn.exe
                              C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
                              C:\Program Files\Microsoft Works\WkDStore.exe
                              C:\Documents and Settings\Alain\Mes documents\Unzipped\hijackthis\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.news.yahoo.com/
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\System32\geebx.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                              O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                              O4 - HKLM\..\Run: [type32]
                              0
                              1. Salut Boulepate,

                                Je te colle ça d'ici une demi-heure maxi, je suis pas devant la bécane...

                                Merci de te réponse !
                                0
                                1. Pas de probléme j'serais encore là ;)
                                  0
                              2. Un petit up... j'espère n'embeter personne avec...
                                C'est sûr que mon log ressemble à d'autres, mais je crains d'appliquer des soluces préconisées par Régis59 sur de mauvaises lignes du log (ou pas toutes).

                                Merci de votre aide .
                                0
                                1. Salut,
                                  remet un rapport hijack s'il te plait .
                                  0
                              • 1
                              • 2