[Troyan+Barniere pub]

Résolu
Salutation,

En surfant, je me suis ramassé quelques troyans. J'ai utilisé donc : Clean Up ; ensuite, en Mode sans echec, j'ai appliqué Ad-Adware et a-squared. Mais il me reste quelques bricoles, comme la barniere de pub et d'autres chose que mes soft non pas détecté.

Voici les log ci-joints :

Logfile of HijackThis v1.99.1
Scan saved at 16:56:09, on 23/12/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Wanadoo\CnxMon.exe
C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [dmvcu.exe] C:\WINDOWS\System32\dmvcu.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [desktop] C:\WINDOWS\System32\idemlog.exe
O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"
O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {7DA181BB-EF8D-4A7E-8C53-7BFC718EF71D} (Upload Class) - http://photos.wanadoo.fr/al/presentation/pc/resources/activex/Ephoto.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photoways.com/clients/ImageUploader3.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{47E7FC26-403B-4079-9626-FEA7EDB05B20}: NameServer = 85.255.114.75,85.255.112.148
O17 - HKLM\System\CS1\Services\Tcpip\..\{47E7FC26-403B-4079-9626-FEA7EDB05B20}: NameServer = 85.255.114.75,85.255.112.148
O20 - Winlogon Notify: style2 - C:\WINDOWS\q174546093_disk.dll (file missing)
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

Par avance, Merci.

27 réponses

Résumé de la discussion

Question : suite à une navigation, une infection par troyans subsiste malgré l'usage de Clean Up, Ad-Adware et a-squared, avec des éléments résiduels tels qu'une barre de pub non détectée. Plusieurs interventions évoquées incluent la suppression manuelle d'une clé de registre ZPMODEMSYSNTDRVNT et l'usage de RegEdit, ainsi que des outils comme SmitFraudFix pour cibler les débris restants. D'autres messages présentent des rapports HijackThis et des résultats détaillés des scans, montrant des listes longues d'entrées de démarrage et d'extensions variables à nettoyer. En parallèle, les échanges soulignent que certains éléments malveillants peuvent persister dans le registre et que les solutions proposées nécessitent vérification et précision pour éviter des réinfections.

Bobot (l’IA à votre service)
  1. Ah ok, Merci bcp pour tout.

    Bonnes fêtes de fin d'année

    A + regis
    1. salut
      ah excuse si on ne t as pas repondu

      En fait on cree une manipulation de suppression:
      Explication:

      Voici la clé dans ton registre qui est lié a l infection:
      HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT

      En ouvrant le bloc note, on note ceci:
      [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT]

      Le petit tiret juste avant la clé permet lorsque tu fais la fusion avec le registre, la suppression de cette clé

      1/Tu as compris ou je reexplique?

      2/Ou en sont tes soucis?

      a+
      1. Slt Regis,

        Après la manip avec le fichier www.reg (J'ai déja posé la qestion, à koi ça servé mais on m'a tjrs pas répondu - peux-tu m'éclairer ?), le programme RegSrch n'a rien détecté.

        Voici un Hijack : Logfile of HijackThis v1.99.1
        Scan saved at 15:38:04, on 27/12/2005
        Platform: Windows XP SP1 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Intel\ASF Agent\ASFAgent.exe
        C:\WINDOWS\System32\CTsvcCDA.exe
        C:\Program Files\ewido anti-malware\ewidoctrl.exe
        C:\Program Files\Norton AntiVirus\navapsvc.exe
        C:\WINDOWS\System32\nvsvc32.exe
        C:\WINDOWS\System32\MsPMSPSv.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\System32\DSentry.exe
        C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
        C:\PROGRA~1\Wanadoo\CnxMon.exe
        C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
        C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
        C:\PROGRA~1\NORTON~1\navapw32.exe
        C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
        C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\Winamp\winampa.exe
        C:\WINDOWS\System32\ctfmon.exe
        C:\Program Files\eMule\emule.exe
        C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe
        C:\Program Files\Digital Line Detect\DLG.exe
        C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
        C:\PROGRA~1\Livecom\Toaster\Toaster.exe
        C:\PROGRA~1\Livecom\APPLIC~1\eConfv4\ftplayer.exe
        C:\WINDOWS\System32\wuauclt.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
        O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
        O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
        O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
        O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
        O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
        O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
        O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
        O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
        O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
        O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
        O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
        O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
        O4 - Global Startup: Digital Line Detect.lnk = ?
        O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
        O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
        O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
        O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
        O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
        O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
        O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
        O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
        O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
        O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
        O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
        O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

        Merci à toi (et tout le monde)
        1. Ouvre le bloc note et copie colle ceci entre les étoiles
          Met bien regedit4 sur la 1ere ligne !!!!!!!!!!!!
          **********
          REGEDIT4

          [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT]

          [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Enum]

          [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT]

          [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT]

          [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Enum]

          ************
          enregistre le sur ton bureau et nomme le www.reg
          et dans la case en dessous type met sur tous fichiers

          la vas sur ton bureau et double click sur se fichier que tu vient de faire et accepte la fusion avec le registre.
          1. slt,

            Je n'ai plus (depuis pas mal de tps ) ma bar de pub (pour info).

            Juste une p'tite question sur la manip de moe (et de regis - d'un peu tout le monde). PS : Grand Merci, en passant (Pas mal d'infos interessantes).

            Je supprime tous mes registres qui contiennent "ZPMODEMSYSNTDRVNT" ?

            Il me reste 5 registes (je les ai identifié/repéré ....) Mais .... je ne sais pas si je les supprime ou pas.

            -------------------------

            REGEDIT4
            ; RegSrch.vbs © Bill James

            ; Registry search results for string "ZPMODEMSYSNTDRVNT" 27/12/2005 04:19:25

            ; NOTE: This file will be deleted when you close WordPad.
            ; You must manually save this file to a new location if you want to refer to it again later.
            ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)

            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT]

            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Enum]

            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT]

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT]

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Enum]

            -------------------------------

            Logfile of HijackThis v1.99.1
            Scan saved at 04:36:26, on 27/12/2005
            Platform: Windows XP SP1 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Intel\ASF Agent\ASFAgent.exe
            C:\WINDOWS\System32\CTsvcCDA.exe
            C:\Program Files\ewido anti-malware\ewidoctrl.exe
            C:\Program Files\Norton AntiVirus\navapsvc.exe
            C:\WINDOWS\System32\nvsvc32.exe
            C:\WINDOWS\System32\MsPMSPSv.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\System32\DSentry.exe
            C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
            C:\PROGRA~1\Wanadoo\CnxMon.exe
            C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
            C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
            C:\PROGRA~1\NORTON~1\navapw32.exe
            C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
            C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\Winamp\winampa.exe
            C:\WINDOWS\System32\ctfmon.exe
            C:\Program Files\eMule\emule.exe
            C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe
            C:\Program Files\Digital Line Detect\DLG.exe
            C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
            C:\PROGRA~1\Livecom\Toaster\Toaster.exe
            C:\PROGRA~1\Livecom\APPLIC~1\eConfv4\ftplayer.exe
            C:\WINDOWS\System32\wuauclt.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\WINDOWS\regedit.exe
            C:\Program Files\Winamp\winamp.exe
            C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
            O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
            O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
            O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
            O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
            O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
            O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
            O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
            O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
            O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
            O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
            O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
            O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
            O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
            O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
            O4 - Global Startup: Digital Line Detect.lnk = ?
            O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
            O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
            O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
            O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
            O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
            O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
            O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
            O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
            O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
            O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
            O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
            O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
            O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
            O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
            O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
            1. Slt,

              Merci pour tes réponses et merci à moe31 et regis (donc)

              Voici le log :
              REGEDIT4
              ; RegSrch.vbs © Bill James

              ; Registry search results for string "ZPMODEMSYSNTDRVNT" 26/12/2005 16:36:31

              ; NOTE: This file will be deleted when you close WordPad.
              ; You must manually save this file to a new location if you want to refer to it again later.
              ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)

              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
              "Service"="ZPMODEMSYSNTDRVNT"

              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
              "DeviceDesc"="ZPMODEMSYSNTDRVNT"

              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000\Control]

              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT]

              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Enum]

              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
              "Service"="ZPMODEMSYSNTDRVNT"

              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
              "DeviceDesc"="ZPMODEMSYSNTDRVNT"

              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT]

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
              "Service"="ZPMODEMSYSNTDRVNT"

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
              "DeviceDesc"="ZPMODEMSYSNTDRVNT"

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000\Control]

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT]

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Enum]

              et le hijack :
              Logfile of HijackThis v1.99.1
              Scan saved at 16:39:30, on 26/12/2005
              Platform: Windows XP SP1 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Intel\ASF Agent\ASFAgent.exe
              C:\WINDOWS\System32\CTsvcCDA.exe
              C:\Program Files\ewido anti-malware\ewidoctrl.exe
              C:\Program Files\Norton AntiVirus\navapsvc.exe
              C:\WINDOWS\System32\nvsvc32.exe
              C:\WINDOWS\System32\MsPMSPSv.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\System32\DSentry.exe
              C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
              C:\PROGRA~1\Wanadoo\CnxMon.exe
              C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
              C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
              C:\PROGRA~1\NORTON~1\navapw32.exe
              C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
              C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\Winamp\winampa.exe
              C:\WINDOWS\System32\ctfmon.exe
              C:\Program Files\eMule\emule.exe
              C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe
              C:\Program Files\Digital Line Detect\DLG.exe
              C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
              C:\PROGRA~1\Livecom\Toaster\Toaster.exe
              C:\PROGRA~1\Livecom\APPLIC~1\eConfv4\ftplayer.exe
              C:\WINDOWS\System32\wuauclt.exe
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\WINDOWS\system32\NOTEPAD.EXE
              C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
              O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
              O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
              O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
              O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
              O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
              O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
              O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
              O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
              O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
              O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
              O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
              O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
              O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
              O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
              O4 - Global Startup: Digital Line Detect.lnk = ?
              O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
              O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
              O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
              O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
              O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
              O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
              O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
              O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
              O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
              O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
              O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
              O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
              O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
              O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
              O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
              1. salut,

                je passe sur le log de Hcscrch car je pense qu'il a rien trouvé (?!?).
                Si c est le cas, tant mieux

                Je te donne le log de Hijack (cierto), Mais le log de l'autre prog (Registry searsh tools), tu en as besoin ?
                Si quand tu tapes dans ta recherches, il te dis no instance found, tu poses pas sinon oui tu le dones a regis

                Les p'tits reg que tu me donnes sert (+/-) à quoi (c'est de la simple curiosité) ?

                Il servent a generer des rapports
                registry searsh tool permet de chercher dans ton registre les infection et par une manip avec le bloc note permet de le supprimer
                Hcsearsh sert a detecter des infections speciales, ce prog a ete creer par moe31 et avec regis afin de detecter les infections lié a cette barre

                tu as toujours cette barre?
                Remet juste registry searsh tools stp

                a+
                1. Slt,

                  Questions :

                  PS : je passe sur le log de Hcscrch car je pense qu'il a rien trouvé (?!?).
                  Je te donne le log de Hijack (cierto), Mais le log de l'autre prog (Registry searsh tools), tu en as besoin ?

                  Les p'tits reg que tu me donnes sert (+/-) à quoi (c'est de la simple curiosité) ? Génèrer des registres (un truc comme ça) ?
                  1. re,

                    tutoie moi, je suis certainement plus jeune que toi lol

                    ouvre le bloc note et copie colle ceci entre les etoiles
                    **********
                    REGEDIT4

                    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                    "Service"=-

                    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                    "DeviceDesc"=-

                    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000\Control]

                    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT]

                    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT]
                    "DisplayName"=-

                    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Security]

                    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Enum]

                    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Enum]
                    "0"=-

                    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                    "Service"=-

                    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                    "DeviceDesc"=-

                    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT]

                    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT]
                    "DisplayName"=-

                    [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT\Security]

                    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                    "Service"=-

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                    "DeviceDesc"=-

                    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000\Control]

                    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT]

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT]
                    "DisplayName"=-

                    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Security]

                    [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Enum]

                    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Enum]
                    "0"=-

                    ************
                    enregistre le sur ton bureau et nomme le xxx.reg
                    et dans la case en dessous type met sur tous fichiers

                    la vas sur ton bureau et double clik sur se fichier que tu vient de faire et accepte la fusion avec le registre

                    puis relance le prog, retape le meme et remet un rapport

                    a+
                    1. Slt à vous,

                      Voici les log,

                      1) Hcscrch

                      Rapport fait à 22:09:54,01 le 25/12/2005
                      Executé à partir de C:\Documents and Settings\Alexandre
                      OS: Microsoft Windows XP [version 5.1.2600]

                      *********************************************

                      Vérification HKLM\...\...\...\...\ruins

                      *********************************************

                      Fichiers détectés :

                      *********************************************

                      Recherche des processus aleatoires
                      d'après les modèles : cs***.exe, dm***.exe, ya***.exe

                      C:\WINDOWS\System32
                      CSRSS.EXE

                      *********************************************

                      Recherche presence C:\WINDOWS\System32\idemlog.exe...

                      non trouvé...
                      2) Hijack

                      Logfile of HijackThis v1.99.1
                      Scan saved at 22:11:12, on 25/12/2005
                      Platform: Windows XP SP1 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                      C:\WINDOWS\System32\CTsvcCDA.exe
                      C:\Program Files\ewido anti-malware\ewidoctrl.exe
                      C:\Program Files\Norton AntiVirus\navapsvc.exe
                      C:\WINDOWS\System32\nvsvc32.exe
                      C:\WINDOWS\System32\MsPMSPSv.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\System32\DSentry.exe
                      C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                      C:\PROGRA~1\Wanadoo\CnxMon.exe
                      C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                      C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                      C:\PROGRA~1\NORTON~1\navapw32.exe
                      C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
                      C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\Program Files\Winamp\winampa.exe
                      C:\WINDOWS\System32\ctfmon.exe
                      C:\Program Files\Messenger\msmsgs.exe
                      C:\Program Files\eMule\emule.exe
                      C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe
                      C:\Program Files\Digital Line Detect\DLG.exe
                      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                      C:\PROGRA~1\Livecom\Toaster\Toaster.exe
                      C:\PROGRA~1\Livecom\APPLIC~1\eConfv4\ftplayer.exe
                      C:\WINDOWS\System32\wuauclt.exe
                      C:\WINDOWS\system32\NOTEPAD.EXE
                      C:\Program Files\Internet Explorer\IEXPLORE.EXE
                      C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
                      O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                      O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
                      O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
                      O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                      O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                      O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
                      O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
                      O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
                      O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
                      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                      O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
                      O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                      O4 - Global Startup: Digital Line Detect.lnk = ?
                      O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                      O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                      O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                      O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
                      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                      O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
                      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                      O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                      O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

                      3) Registry searsh tools

                      REGEDIT4
                      ; RegSrch.vbs © Bill James

                      ; Registry search results for string "ZPMODEMSYSNTDRVNT" 25/12/2005 22:05:39

                      ; NOTE: This file will be deleted when you close WordPad.
                      ; You must manually save this file to a new location if you want to refer to it again later.
                      ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                      "Service"="ZPMODEMSYSNTDRVNT"

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                      "DeviceDesc"="ZPMODEMSYSNTDRVNT"

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000\Control]

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT]

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT]
                      "DisplayName"="ZPMODEMSYSNTDRVNT"

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Security]

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Enum]

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ZPMODEMSYSNTDRVNT\Enum]
                      "0"="Root\\LEGACY_ZPMODEMSYSNTDRVNT\\0000"

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                      "Service"="ZPMODEMSYSNTDRVNT"

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                      "DeviceDesc"="ZPMODEMSYSNTDRVNT"

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT]

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT]
                      "DisplayName"="ZPMODEMSYSNTDRVNT"

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ZPMODEMSYSNTDRVNT\Security]

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT]

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                      "Service"="ZPMODEMSYSNTDRVNT"

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000]
                      "DeviceDesc"="ZPMODEMSYSNTDRVNT"

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ZPMODEMSYSNTDRVNT\0000\Control]

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT]

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT]
                      "DisplayName"="ZPMODEMSYSNTDRVNT"

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Security]

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Enum]

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ZPMODEMSYSNTDRVNT\Enum]
                      "0"="Root\\LEGACY_ZPMODEMSYSNTDRVNT\\0000"

                      Merci à vous.
                      1. salut

                        1/Télécharge: Pocket Killbox ici
                        http://www.downloads.subratam.org/KillBox.exe

                        :: Démo d utilisation (merci a Balltrap34 pour cette réalisation) ::
                        http://pageperso.aol.fr/balltrap34/killbox.htm

                        2/Télécharge Registry Search Tool, ici
                        http://www.billsway.com/vbspage/vbsfiles/RegSrch.zip

                        -----------------------------------------------------------------
                        ¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

                        O4 - HKCU\..\Run: [desktop] C:\WINDOWS\System32\idemlog.exe

                        -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

                        Déconnecte toi d'internet c'est important

                        puis vérifie ceci:
                        demarrer > connection > clic droit sur ta connection > propriétés
                        gestion de reseau
                        assure toi que protocole internet tcp/ip est en surbrillance (attention, ne décoche pas la case)> clic sur propriétés > selectionne "obtenir les adresses des serveurs automatiquement"
                        valide avec ok

                        -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

                        ouvre le bloc note et copie et colle ceci à l'interieur:
                        Regedit4 doit etre sur la 1er ligne de ton bloc note
                        *****************************
                        REGEDIT4

                        [-HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\HCLEAN32.EXE]

                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\Windows\CurrentVersion\ruins]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion]
                        "Disabled"=-

                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins]

                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WareOut]

                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                        "System"=-
                        "System"=""

                        [-HKEY_LOCAL_MACHINE\SOFTWARE\WareOut]

                        ***********************
                        Puis enregistrer sous et dans:
                        Nom du fichier, met fix.reg
                        Type de fichier: selectionne "tous les fichiers"
                        clic sur enregistrer

                        ensuite double clic sur fix.reg et accepte de fusionner

                        -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

                        1- Double-clic sur KillBox.exe (Pocket Killbox)

                        Avec la methode du bloc note (voir video)
                        voici la liste:

                        C:\WINDOWS\System32\idesk.conf
                        C:\WINDOWS\System32\idemlog.exe

                        Si le pc ne redemarre pas automatiquement ou si killbox t'envois ce message:
                        "Pending file Rename Operations Registry Data has been Removed by External Process"
                        ignore le et redemarre le pc normallement

                        _-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

                        décompresse Registry Search Tool et tape ou colle
                        ZPMODEMSYSNTDRVNT

                        et copie colle le résultat dans le bloc note et donne le nous

                        a+

                        Note:Une fois toute cette manip effectué, met nous 3 rapports:
                        Hcscrch
                        Hijack this
                        Registry searsh tools

                        1. Tu veux peut être le log de smithfraud ..... Je suis perdu entre les fêtes de fin d'année et le décalage avec la France. Je te redonne le tout.

                          SmitFraudFix v2.08

                          Rapport fait à 20:56:51,59 le 25/12/2005
                          Executé à partir de C:\Documents and Settings\Alexandre\Mes documents\alex.dave\Info\SmitfraudFix\SmitfraudFix
                          OS: Microsoft Windows XP [version 5.1.2600]

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32\LogFiles

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Alexandre\Application Data

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                          "Source"="C:\\WINDOWS\\warnhp.html"
                          "SubscribedURL"=""
                          "FriendlyName"="Warning homepage"

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                          "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pr‚-chargeur Browseui"
                          "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="D‚mon de cache des cat‚gories de composant"
                          "{6AC3806F-8B39-4746-9C38-6B01CB7331FF}"="Memory monitor"

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

                          Logfile of HijackThis v1.99.1
                          Scan saved at 20:49:34, on 25/12/2005
                          Platform: Windows XP SP1 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\System32\DSentry.exe
                          C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                          C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
                          C:\PROGRA~1\Wanadoo\CnxMon.exe
                          C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                          C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                          C:\PROGRA~1\NORTON~1\navapw32.exe
                          C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
                          C:\Program Files\QuickTime\qttask.exe
                          C:\Program Files\Winamp\winampa.exe
                          C:\WINDOWS\System32\ctfmon.exe
                          C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe
                          C:\Program Files\Digital Line Detect\DLG.exe
                          C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                          C:\PROGRA~1\Livecom\Toaster\Toaster.exe
                          C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                          C:\WINDOWS\System32\CTsvcCDA.exe
                          C:\Program Files\ewido anti-malware\ewidoctrl.exe
                          C:\PROGRA~1\Livecom\APPLIC~1\eConfv4\ftplayer.exe
                          C:\Program Files\Norton AntiVirus\navapsvc.exe
                          C:\WINDOWS\System32\nvsvc32.exe
                          C:\WINDOWS\System32\MsPMSPSv.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\WINDOWS\System32\wuauclt.exe
                          C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
                          C:\Program Files\Internet Explorer\IEXPLORE.EXE
                          C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                          O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
                          O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                          O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
                          O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
                          O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                          O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
                          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                          O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
                          O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
                          O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
                          O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
                          O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                          O4 - HKCU\..\Run: [desktop] C:\WINDOWS\System32\idemlog.exe
                          O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
                          O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                          O4 - Global Startup: Digital Line Detect.lnk = ?
                          O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                          O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                          O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                          O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                          O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                          O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
                          O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                          O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                          O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                          O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
                          O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                          O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                          O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                          O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                          O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                          O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                          O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

                          Merci encore
                          1. Houps .....,

                            J'avais pas lu la fin de ta phrase, désolé.

                            Rapport fait à 20:54:12,68 le 25/12/2005
                            Executé à partir de C:\Documents and Settings\Alexandre
                            OS: Microsoft Windows XP [version 5.1.2600]

                            *********************************************

                            Vérification HKLM\...\...\...\...\ruins

                            Windows Registry Editor Version 5.00

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins]
                            "xedocne"=hex:5d,43,00,00,57,56,65,61,74,7f,10,46,17,08,27,13,00,00,00
                            "repiwoh"=hex:bd,49,00,00,b0,b1,91,8b,98,9f,ea,26,f7,e8,c7,13,00,00,00
                            "23plhps"=hex:87,4d,00,00,6f,6a,4a,5e,42,07,7c,78,39,22,09,13,00,00,00
                            "mgcppp"=hex:55,4e,00,00,50,58,60,15,09,7f,46,77,18,67,12,00,00,00
                            "tesvaf"=hex:b9,4f,00,00,8a,87,8a,81,ab,90,22,d3,e4,c3,12,00,00,00
                            "golmedi"=hex:83,50,00,00,79,7a,4d,5d,5a,4f,2f,7c,3d,26,0d,13,00,00,00
                            "32refaselif"=hex:51,51,00,00,22,27,18,1b,71,0f,72,7b,16,5e,61,92,43,34,b3,17,\
                            00,00,00
                            "ucvmd"=hex:8d,15,00,00,64,67,a6,5d,b7,06,37,c8,27,11,00,00,00

                            *********************************************

                            Fichiers détectés :

                            C:\WINDOWS\System32\idesk.conf Présent !

                            *********************************************

                            Recherche des processus aleatoires
                            d'après les modèles : cs***.exe, dm***.exe, ya***.exe

                            C:\WINDOWS\System32
                            CSRSS.EXE

                            *********************************************

                            Recherche presence C:\WINDOWS\System32\idemlog.exe...

                            non trouvé...
                            1. Slt,

                              Voici le log :

                              Logfile of HijackThis v1.99.1
                              Scan saved at 20:49:34, on 25/12/2005
                              Platform: Windows XP SP1 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\System32\DSentry.exe
                              C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                              C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
                              C:\PROGRA~1\Wanadoo\CnxMon.exe
                              C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                              C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                              C:\PROGRA~1\NORTON~1\navapw32.exe
                              C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
                              C:\Program Files\QuickTime\qttask.exe
                              C:\Program Files\Winamp\winampa.exe
                              C:\WINDOWS\System32\ctfmon.exe
                              C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe
                              C:\Program Files\Digital Line Detect\DLG.exe
                              C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                              C:\PROGRA~1\Livecom\Toaster\Toaster.exe
                              C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                              C:\WINDOWS\System32\CTsvcCDA.exe
                              C:\Program Files\ewido anti-malware\ewidoctrl.exe
                              C:\PROGRA~1\Livecom\APPLIC~1\eConfv4\ftplayer.exe
                              C:\Program Files\Norton AntiVirus\navapsvc.exe
                              C:\WINDOWS\System32\nvsvc32.exe
                              C:\WINDOWS\System32\MsPMSPSv.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\WINDOWS\System32\wuauclt.exe
                              C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
                              C:\Program Files\Internet Explorer\IEXPLORE.EXE
                              C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                              O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                              O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
                              O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                              O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
                              O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
                              O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                              O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                              O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                              O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                              O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
                              O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
                              O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
                              O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
                              O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                              O4 - HKCU\..\Run: [desktop] C:\WINDOWS\System32\idemlog.exe
                              O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
                              O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                              O4 - Global Startup: Digital Line Detect.lnk = ?
                              O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                              O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                              O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                              O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                              O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                              O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
                              O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                              O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                              O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                              O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
                              O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                              O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                              O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                              O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                              O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                              O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                              O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

                              Merci et Bonnes fêtes de noel
                              1. ok

                                tu peux me remettre un hijack this + le programme stp

                                merci

                                a+
                                1. Slt,

                                  Voici le Post de Smitfraut :

                                  SmitFraudFix v2.08

                                  Rapport fait à 21:44:43,14 le 24/12/2005
                                  Executé à partir de C:\Documents and Settings\Alexandre\Mes documents\alex.dave\Info\SmitfraudFix\SmitfraudFix
                                  OS: Microsoft Windows XP [version 5.1.2600]

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32\LogFiles

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Alexandre\Application Data

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau

                                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                                  "Source"="C:\\WINDOWS\\warnhp.html"
                                  "SubscribedURL"=""
                                  "FriendlyName"="Warning homepage"

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                                  "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pr‚-chargeur Browseui"
                                  "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="D‚mon de cache des cat‚gories de composant"
                                  "{6AC3806F-8B39-4746-9C38-6B01CB7331FF}"="Memory monitor"

                                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                                  »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

                                  Merci à vous et Bonnes fêtes de fin d'année.
                                  1. Salut,
                                    J'ai quelques News. En surfant sur quelques forums, j'ai effectué quelques autres manip :

                                    1) Un Scan sous Panda antivirus

                                    Incident Statut Analyse

                                    Adware:adware/securityerror Non désinfecté C:\WINDOWS\SYSTEM32\ot.ico
                                    Spyware:spyware/smitfraud Non désinfecté Registre Windows
                                    A la suite de cela, j'ai supprimé le fichier ot.ico (un icone infecté qui ne servait à rien pour moi - Icone de pseudo antispyware ...)

                                    2)Sous un même forum, une personne préconisait d'utiliser (pour la même infection) Ewido anti-malware. Tout en suivant les consignes, voici le rapport :

                                    ---------------------------------------------------------
                                    ewido anti-malware - Rapport de scan
                                    ---------------------------------------------------------

                                    + Créé le: 17:37:11, 24/12/2005
                                    + Somme de contrôle: 5BCA6917

                                    + Résultats du scan:

                                    C:\Documents and Settings\Alexandre\Cookies\alexandre@247realmedia[1].txt -> Spyware.Cookie.247realmedia : Nettoyer et sauvegarder
                                    C:\Documents and Settings\Alexandre\Cookies\alexandre@adtech[2].txt -> Spyware.Cookie.Adtech : Nettoyer et sauvegarder
                                    C:\Documents and Settings\Alexandre\Cookies\alexandre@estat[1].txt -> Spyware.Cookie.Estat : Nettoyer et sauvegarder
                                    C:\WINDOWS\sites.ini -> Spyware.PSGuard : Nettoyer et sauvegarder
                                    C:\WINDOWS\SYSTEM32\favset.exe -> Trojan.Favadd.an : Nettoyer et sauvegarder

                                    ::Fin du rapport

                                    3) Rapport HKML :

                                    Rapport fait à 17:50:21,62 le 24/12/2005
                                    Executé à partir de C:\Documents and Settings\Alexandre
                                    OS: Microsoft Windows XP [version 5.1.2600]

                                    *********************************************

                                    Vérification HKLM\...\...\...\...\ruins

                                    Windows Registry Editor Version 5.00

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins]
                                    "xedocne"=hex:5d,43,00,00,57,56,65,61,74,7f,10,46,17,08,27,13,00,00,00
                                    "repiwoh"=hex:bd,49,00,00,b0,b1,91,8b,98,9f,ea,26,f7,e8,c7,13,00,00,00
                                    "23plhps"=hex:87,4d,00,00,6f,6a,4a,5e,42,07,7c,78,39,22,09,13,00,00,00
                                    "mgcppp"=hex:55,4e,00,00,50,58,60,15,09,7f,46,77,18,67,12,00,00,00
                                    "tesvaf"=hex:b9,4f,00,00,8a,87,8a,81,ab,90,22,d3,e4,c3,12,00,00,00
                                    "golmedi"=hex:83,50,00,00,79,7a,4d,5d,5a,4f,2f,7c,3d,26,0d,13,00,00,00
                                    "32refaselif"=hex:51,51,00,00,22,27,18,1b,71,0f,72,7b,16,5e,61,92,43,34,b3,17,\
                                    00,00,00
                                    "ucvmd"=hex:8d,15,00,00,64,67,a6,5d,b7,06,37,c8,27,11,00,00,00

                                    *********************************************

                                    Fichiers détectés :

                                    C:\WINDOWS\System32\idesk.conf Présent !

                                    *********************************************

                                    Recherche des processus aleatoires
                                    d'après les modèles : cs***.exe, dm***.exe, ya***.exe

                                    C:\WINDOWS\System32
                                    CSRSS.EXE

                                    *********************************************

                                    Recherche presence C:\WINDOWS\System32\idemlog.exe...

                                    non trouvé...

                                    4) Revoici, le log de Hijack :
                                    Logfile of HijackThis v1.99.1
                                    Scan saved at 17:39:56, on 24/12/2005
                                    Platform: Windows XP SP1 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\WINDOWS\System32\DSentry.exe
                                    C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
                                    C:\PROGRA~1\Wanadoo\CnxMon.exe
                                    C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                                    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
                                    C:\PROGRA~1\NORTON~1\navapw32.exe
                                    C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
                                    C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
                                    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
                                    C:\Program Files\QuickTime\qttask.exe
                                    C:\Program Files\Winamp\winampa.exe
                                    C:\WINDOWS\System32\ctfmon.exe
                                    C:\Program Files\Messenger\msmsgs.exe
                                    C:\Program Files\Digital Line Detect\DLG.exe
                                    C:\PROGRA~1\Livecom\APPLIC~1\Exe\Livecom.exe
                                    C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                                    C:\PROGRA~1\Livecom\Toaster\Toaster.exe
                                    C:\PROGRA~1\Livecom\APPLIC~1\eConfv4\ftplayer.exe
                                    C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                                    C:\WINDOWS\System32\CTsvcCDA.exe
                                    C:\Program Files\ewido anti-malware\ewidoctrl.exe
                                    C:\Program Files\Norton AntiVirus\navapsvc.exe
                                    C:\WINDOWS\System32\nvsvc32.exe
                                    C:\WINDOWS\System32\MsPMSPSv.exe
                                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                    C:\Documents and Settings\Alexandre\Bureau\Raccourcis Bureau non utilisés\HijackThis.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                                    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
                                    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                                    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
                                    O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
                                    O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                                    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                                    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                                    O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
                                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                    O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
                                    O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
                                    O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
                                    O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
                                    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                    O4 - HKCU\..\Run: [desktop] C:\WINDOWS\System32\idemlog.exe
                                    O4 - HKCU\..\Run: [Livecom] "C:\PROGRA~1\Livecom\APPLIC~1\Exe\..\..\Launcher\Exe\SilentLauncher.exe"
                                    O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                                    O4 - Global Startup: Digital Line Detect.lnk = ?
                                    O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                    O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                                    O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                                    O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                                    O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
                                    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                                    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                                    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                                    O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
                                    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
                                    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                                    O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                                    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                                    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                                    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                                    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                                    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

                                    Merci (par avance).
                                    • 1
                                    • 2