Remove toolbar

J'ai désintaller REmove toolbar a l'aide de HjackThis et Cleanup40,la barre est partie mais j'aimerais savoir si mon pc est clean.Voissi mon Hjckthis:
Logfile of HijackThis v1.99.1
Scan saved at 12:13:40, on 10/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sitecom\Logiciel Bluetooth\BTTray.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\God\Mes documents\Nouveau dossier\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O1 - Hosts: 222.111.150.111 gwgt1.joymax.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [UnSpyPC] "C:\Program Files\UnSpyPC\UnSpyPC.exe"
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie_ctx.htm
O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Télécharger le site web avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: Télécharger sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Télécharger tout avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Sitecom\Logiciel Bluetooth\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5DDCC37F-7C6B-48B8-9664-97C537920CA0} (aecviz Class) - http://www.maisonfamiliale.com/AECVIZ/npaecviz.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/fr/check/qdiagh.cab?326
O17 - HKLM\System\CCS\Services\Tcpip\..\{5ACE17C7-9295-4026-BFC9-E0AC225A6FC2}: NameServer = 85.255.116.170,85.255.112.213
O17 - HKLM\System\CCS\Services\Tcpip\..\{A59316D6-7634-4CE6-B660-C122F100F753}: NameServer = 85.255.116.170,85.255.112.213
O17 - HKLM\System\CCS\Services\Tcpip\..\{CDC1CBF7-B191-448C-934B-AC41C611BF49}: NameServer = 85.255.116.170,85.255.112.213
O17 - HKLM\System\CS1\Services\Tcpip\..\{5ACE17C7-9295-4026-BFC9-E0AC225A6FC2}: NameServer = 85.255.116.170,85.255.112.213
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\System32\btxppanel.dll
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\Sitecom\Logiciel Bluetooth\bin\btwdins.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

J'aimerais savoir si il reste des lignes a fixer.
Merci d'avance.

11 réponses

  1. Mon pare-feu c'est celui intégré dans windows xp.
    0
    1. Salut,

      le pare-feu de Windows ne vaut pas grand chose remplace le par celui-ci il est grauit et bien plus performant ;-)

      Kerio:
      Pare-feu Kerio
      -tutoriel: pour configurer et comprendre Kerio
      https://kerio.probb.fr/
      0
  2. Contributeur
    hello

    RAS ds ce log

    tu peux fixer cette ligne inutile au run :

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    ======
    tu as kasper comme antivirus
    mais quoi comme pare-feu ??
    0
    1. J'ai fais tous ce que tu m'as dit et pour le moment on dirais bien que mon probleme est résolu,je ne suis plus envoyé vers des sites bidons quand j'utilise google.
      Je mets mon nouveau HijackThis pour que tu puisse voir si tous est en regle.

      Logfile of HijackThis v1.99.1
      Scan saved at 14:32:08, on 13/04/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      C:\Program Files\ewido anti-malware\ewidoctrl.exe
      C:\Program Files\ewido anti-malware\ewidoguard.exe
      C:\WINDOWS\System32\nvsvc32.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
      O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
      O8 - Extra context menu item: Télécharger le site web avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
      O8 - Extra context menu item: Télécharger sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
      O8 - Extra context menu item: Télécharger tout avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
      O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
      0
      1. Contributeur
        re

        fixe cette méchante ligne :

        O1 - Hosts: 222.111.150.111 gwgt1.joymax.com

        + ceci pour le plaisir

        O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

        O4 - HKLM\..\Run: [O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd

        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

        O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe

        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

        O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"

        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

        ==============
        précise tes blems à présent
        0
        1. Contributeur
          re

          Voici mon Hijackthis:
          Logfile of HijackThis v1.99.1
          Scan saved at 13:51:22, on 11/04/2006
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          C:\WINDOWS\System32\nvsvc32.exe
          C:\WINDOWS\system32\wdfmgr.exe
          C:\WINDOWS\System32\alg.exe
          C:\Program Files\ewido anti-malware\ewidoguard.exe
          C:\Program Files\ewido anti-malware\ewidoctrl.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\RunDll32.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
          C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\WINDOWS\system32\NOTEPAD.EXE
          C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

          O1 - Hosts: 222.111.150.111 gwgt1.joymax.com

          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

          O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
          O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
          O8 - Extra context menu item: Télécharger le site web avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
          O8 - Extra context menu item: Télécharger sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
          O8 - Extra context menu item: Télécharger tout avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm

          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)

          O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
          O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
          O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
          O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
          0
          1. Contributeur
            hello
            =====

            p:r rapport à Ewido, tu fais ceci pour solutionner l' erreur

            7/ - * Erreur de nettoyage dans ewido

            Si vous rencontrez ce genre de probleme avec ewido:

            [2660] VM_00890000 -> Downloader.Agent.uj : Erreur durant le nettoyage
            [2728] VM_00BA0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
            [2984] VM_009A0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
            [3048] VM_00950000 -> Downloader.Agent.uj : Erreur durant le nettoyage

            Télécharger ceci :
            http://downloads.subratam.org/Fixwareout.exe
            Installer le et suivre la procédure,
            puis refaire un scan avec ewido en mode sans échec ; et de nouveau en mode normal.

            ===============

            p/r au rapport de bitdefender

            8/ - * System volume information

            Si à la suite d'analyse, l'infection se situe dans :

            C:\system volume information\_Restore....

            Cela signifie que c'est un point de restauration qui est infecté (à savoir que l'infection est inactive). Pour résoudre le souci :

            ¤Désactive la restauration système (uniquement si tu es sous XP):
            Cliquer droit sur poste de travail puis,
            propriété, tu cliques sur onglet restauration système
            Cocher la case « désactiver la restauration » et applique.

            Puis,

            ¤Réactiver la restauration système (uniquement si tu es sous XP):
            Cliquer droit sur poste de travail puis,
            propriété, tu cliques sur onglet restauration système
            Décocher la case « désactiver la restauration » et applique.

            ================

            p:r au rapport Hijack
            je présume que ton FAI n est en Biélorussie ?
            http://www.dnsstuff.com/tools/whois.ch?ip=85.255.116.170
            non ?
            alors tu fixes les lignes suivantes :

            O17 - HKLM\System\CCS\Services\Tcpip\..\{5ACE17C7-9295-4026-BFC9-E0AC225A6FC2}: NameServer = 85.255.116.170,85.255.112.213
            O17 - HKLM\System\CCS\Services\Tcpip\..\{CDC1CBF7-B191-448C-934B-AC41C611BF49}: NameServer = 85.255.116.170,85.255.112.213
            O17 - HKLM\System\CS1\Services\Tcpip\..\{5ACE17C7-9295-4026-BFC9-E0AC225A6FC2}: NameServer = 85.255.116.170,85.255.112.213

            tu coches aussi ceci

            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
            O16 - DPF: {5DDCC37F-7C6B-48B8-9664-97C537920CA0} (aecviz Class) - http://www.maisonfamiliale.com/AECVIZ/npaecviz.cab
            O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
            O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/fr/check/qdiagh.cab?326

            ==========

            je vais déplacer ton log par commodité de lecture

            0
            1. J'ai fais tous ce que tu as demandé et j'ai tjs le meme probleme,voici les rapports que tu as demandé:

              Ewido
              ewido anti-malware - Rapport de scan
              ---------------------------------------------------------

              + Créé le: 11:33:29, 11/04/2006
              + Somme de contrôle: 3BFA3C3

              + Résultats du scan:

              [500] VM_00D70000 -> Downloader.Agent.uj : Erreur durant le nettoyage
              [528] VM_00DE0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
              [1620] VM_009D0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
              [1804] VM_009A0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
              [1860] VM_008A0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
              [1908] VM_00390000 -> Downloader.Agent.uj : Erreur durant le nettoyage
              [1924] VM_008C0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
              [2020] VM_003E0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
              [3204] VM_003F0000 -> Downloader.Agent.uj : Erreur durant le nettoyage
              C:\Documents and Settings\God\Cookies\god@247realmedia[1].txt -> TrackingCookie.247realmedia : Nettoyer et sauvegarder
              C:\Documents and Settings\God\Cookies\god@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyer et sauvegarder

              ::Fin du rapport

              BitDefender
              Time
              01:43:50

              Files
              355888

              Folders
              3423

              Boot Sectors
              2

              Archives
              1943

              Packed Files
              43452

              Results

              Identified Viruses
              1

              Infected Files
              7

              Suspect Files
              0

              Warnings
              0

              Disinfected
              0

              Deleted Files
              7

              Engines Info

              Virus Definitions
              369495

              Engine build
              AVCORE v1.0 (build 2292) (i386) (Mar 3 2005 11:57:29)

              Scan plugins
              13

              Archive plugins
              39

              Unpack plugins
              4

              E-mail plugins
              6

              System plugins
              1

              Scan Settings

              First Action
              Disinfect

              Second Action
              Delete

              Heuristics
              Yes

              Enable Warnings
              Yes

              Scanned Extensions
              *;

              Exclude Extensions

              Scan Emails
              Yes

              Scan Archives
              Yes

              Scan Packed
              Yes

              Scan Files
              Yes

              Scan Boot
              Yes

              Scanned File
              Status

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0179985.exe
              Infected with: Trojan.Downloader.FFZ

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0179985.exe
              Disinfection failed

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0179985.exe
              Deleted

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0180144.exe
              Infected with: Trojan.Downloader.FFZ

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0180144.exe
              Disinfection failed

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0180144.exe
              Deleted

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0180781.exe
              Infected with: Trojan.Downloader.FFZ

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0180781.exe
              Disinfection failed

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0180781.exe
              Deleted

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0181325.exe
              Infected with: Trojan.Downloader.FFZ

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0181325.exe
              Disinfection failed

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0181325.exe
              Deleted

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0181950.exe
              Infected with: Trojan.Downloader.FFZ

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0181950.exe
              Disinfection failed

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0181950.exe
              Deleted

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0182400.exe
              Infected with: Trojan.Downloader.FFZ

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0182400.exe
              Disinfection failed

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP104\A0182400.exe
              Deleted

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP105\A0183731.exe
              Infected with: Trojan.Downloader.FFZ

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP105\A0183731.exe
              Disinfection failed

              C:\System Volume Information\_restore{25630064-D061-4D26-97CC-155484F899D1}\RP105\A0183731.exe
              Deleted

              Voici mon Hijackthis:
              Logfile of HijackThis v1.99.1
              Scan saved at 13:51:22, on 11/04/2006
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\drivers\CDAC11BA.EXE
              C:\WINDOWS\System32\nvsvc32.exe
              C:\WINDOWS\system32\wdfmgr.exe
              C:\WINDOWS\System32\alg.exe
              C:\Program Files\ewido anti-malware\ewidoguard.exe
              C:\Program Files\ewido anti-malware\ewidoctrl.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\RunDll32.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
              C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\WINDOWS\system32\NOTEPAD.EXE
              C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O1 - Hosts: 222.111.150.111 gwgt1.joymax.com
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
              O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe" /minimize
              O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
              O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
              O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
              O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
              O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
              O8 - Extra context menu item: Télécharger le site web avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
              O8 - Extra context menu item: Télécharger sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
              O8 - Extra context menu item: Télécharger tout avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
              O16 - DPF: {5DDCC37F-7C6B-48B8-9664-97C537920CA0} (aecviz Class) - http://www.maisonfamiliale.com/AECVIZ/npaecviz.cab
              O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
              O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/fr/check/qdiagh.cab?326
              O17 - HKLM\System\CCS\Services\Tcpip\..\{5ACE17C7-9295-4026-BFC9-E0AC225A6FC2}: NameServer = 85.255.116.170,85.255.112.213
              O17 - HKLM\System\CCS\Services\Tcpip\..\{CDC1CBF7-B191-448C-934B-AC41C611BF49}: NameServer = 85.255.116.170,85.255.112.213
              O17 - HKLM\System\CS1\Services\Tcpip\..\{5ACE17C7-9295-4026-BFC9-E0AC225A6FC2}: NameServer = 85.255.116.170,85.255.112.213
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
              O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
              O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
              O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
              O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kavsvc.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

              Bon courage a toi aussi pour trouver ce qui vas pas.
              0
              1. Contributeur
                hum
                possible
                dance cas, suivre ceci pour en savoir plus et éventuellement corriger
                ============
                CCM
                Merci de procéder dans l’ordre,
                Télécharge TOUS ces programmes (si tu n’as pas), installe-les.
                Fais les mises à jour des progr 1/, 2/, 3/
                Scan avec TOUS, COLLE les rapports de 3/ & 6/

                1/ -Ad-Aware (gratuit) :
                https://forums.cnetfrance.fr

                2/ - Spybot (gratuit) :
                http://telecharger.01net.com/windows/Internet/internet_utlitaire/fiches/26157.html

                3/ - Ewido (dowload)- gratuit même après 14 jours d’essai
                http://perso.wanadoo.fr/entraide-hijackthis/Ewido/
                Copie/COLLE le rapport généré sur ce forum

                4/ - regcleaner ( nettoyeur de registre)
                http://www.01net.com/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/4894.html
                Son tuto
                http://www.softastuces.com/tuto/maint/regcleaner/index.php

                5/ - cleanup40 (nettoyeur de cookies+temps+tempos+prefetch+historique+etc..)
                http://pageperso.aol.fr/Balltrap34/CleanUp40.exe
                Démo
                http://pageperso.aol.fr/balltrap34/democleanup.htm

                6/ - Scan online avec BitDefender – fonctionne uniquement sous Internet Explorer en acceptant l’activX (à défaut de réussite, essaie avec Kasper et Panda )
                https://assiste.com/404_La_page_demandee_n_existe_pas.php
                Copie/COLLE le rapport entier

                7/ - Hijackthis – outil de diagnostic et réparation
                lire démo
                http://pageperso.aol.fr/balltrap34/Hijenr.gif
                http://pageperso.aol.fr/balltrap34/demohijack.htm
                Téléchargement version française
                http://telechargement.zebulon.fr/160-patch-francais-pour-hijackthis-1991.html

                Au boulot – Bon courage
                0
                1. Merci de ton aide,j'ai bien retrouver le theme xp,par contre lorsque fais des recherches sur google losque je clique sur lien il ne m'envois pas sur le site demandé mais vers un site bidon.J'aimerais savoir si c'est parce qu'il me reste des fichiers de remove toolbar.
                  0
                  1. Contributeur
                    bjr
                    9/ - *Perte du thème XP
                    Suite à une infection, vous perdez votre thème Xp et il est impossible de le remettre dans les options puisqu'il n'apparait plus? Pas de panique...
                    Télécharger ceci et le décompresser
                    http://pageperso.aol.fr/Balltrap34/luna.zip
                    Ensuite le mettre le dans C:\WINDOWS\Resources\Themes\Luna
                    et double cliquer dessus
                    Ensuite réessayer de remettre le style xp
                    0
                    1. J'aimerais savoir aussi comment retrouver mon affichage xp car une fois cleanup éffectué c un affichage classique et pas moyen de retrouver l'xp.
                      0