Toolbar mirar avec hijackthis (j'ai mon log)

Bonjour! j'ai vu la démarche a suivre sur un autre forum pour se débarrasser du programme MIRAR, j'ai donc installé "hijackthis" et voici mon log:

Logfile of HijackThis v1.99.1
Scan saved at 11:37:31, on 2006-05-29
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\defender24.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\RGF2aWQ\command.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\wuauclt.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\hijackthis\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hugedomains.com/domain_profile.cfm?d=meloco&e=com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.ieplugin.com/q.cgi?q=%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: (no name) - {69135BDE-5FDC-4B61-98AA-82AD2091BCCC} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\System32\WinNB57.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [defender] C:\\defender24.exe
O4 - HKLM\..\Run: [keyboard] C:\\keyboard24.exe
O4 - HKLM\..\Run: [newname] C:\\newname24.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [irssyncd] C:\WINDOWS\System32\irssyncd.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Startup: Morpheus.lnk = C:\Program Files\Morpheus\Morpheus.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {A80F2DB2-80A9-4834-8F5A-4AB70F4EF4C3} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: IMI - {A80F2DB2-80A9-4834-8F5A-4AB70F4EF4C3} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.media-motor.com
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mediatickets.net
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.snipernet.us
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone: *.yazzle.net
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
O15 - Trusted Zone: *.errorsafe.com (HKLM)
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.media-motor.net (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O15 - Trusted Zone: *.snipernet.us (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O15 - Trusted Zone: *.winfixer.com (HKLM)
O15 - Trusted Zone: *.yazzle.net (HKLM)
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://promo.dollarrevenue.com/activex/promocache/3138302D2D2D.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} (mm06ocx.mm06ocxf) - mk:@MSITStore:C:\DOCUME~1\DAVIDS\LOCALS~1\Temp\mma.chm::/alien.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20060104/qtinstall.info.apple.com/snape/us/wi...
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - mk:@MSITStore:C:\DOCUME~1\DAVIDS\LOCALS~1\Temp\mta.chm::/MediaTicketsInstaller.cab
O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} (Progetto1.int_ver34) - http://advnt01.com/dialer/int_ver34.CAB
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: SideBySide - C:\WINDOWS\system32\l08mlal11dq.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGF2aWQ\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

Répondez moi vite SVP j'en ai marre de ce foutu programme à la con!

13 réponses

  1. Contributeur
    De rien,

    ce fut un plaisir

    a+
    0
    1. Oui tout est okay! il n'y a plus de pop-up et ce même quand je suis sur internet explorer!

      Merci beaucoup! infiniment! (dire que je prévoyais formater mon disque lol)
      0
      1. Contributeur
        Bonsoir,

        Ton log me parait ok.

        Où en sont tes soucis ?

        A+
        0
        1. Salut! J'ai fait toutes les étapes qui tu m'as dis seulement je n'ai pas pu supprimer les deux fichier .dll que tu m'as montré parce qu'ils n'étaient tout simplement pas là. J'ai fait une recherche sans succès. Le reste est okay! Voici mon nouveau log par Hijackthis:

          Logfile of HijackThis v1.99.1
          Scan saved at 09:23:45, on 2006-05-31
          Platform: Windows XP (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 (6.00.2600.0000)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\System32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\System32\LVCOMSX.EXE
          C:\Program Files\Logitech\Video\LogiTray.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
          c:\progra~1\mcafee.com\vso\mcvsescn.exe
          C:\PROGRA~1\mcafee.com\agent\mcagent.exe
          C:\WINDOWS\System32\ctfmon.exe
          C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
          C:\Program Files\Logitech\Video\FxSvr2.exe
          C:\Program Files\ewido anti-malware\ewidoctrl.exe
          c:\program files\mcafee.com\agent\mcdetect.exe
          c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
          c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
          C:\WINDOWS\System32\svchost.exe
          c:\PROGRA~1\mcafee.com\vso\mcshield.exe
          C:\WINDOWS\System32\wuauclt.exe
          c:\progra~1\mcafee.com\vso\mcvsftsn.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Real\RealPlayer\RealPlay.exe
          C:\hijackthis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - Default URLSearchHook is missing
          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
          O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
          O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
          O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\Video\ISStart.exe
          O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
          O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
          O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
          O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
          O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
          O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
          O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
          O4 - Startup: Morpheus.lnk = C:\Program Files\Morpheus\Morpheus.exe
          O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
          O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
          O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
          O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
          O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
          O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
          O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
          O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
          O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20060104/qtinstall.info.apple.com/snape/us/wi...
          O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} (Progetto1.int_ver34) - http://advnt01.com/dialer/int_ver34.CAB
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
          O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
          O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
          O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
          O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
          O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

          J'attend ton diagnostic, merci!

          dayvee
          0
          1. Contributeur
            Re,

            1 - Affiche tous les fichiers et dossiers :
            Clique sur démarrer/panneau de configuration/outil/option des dossiers/affichage

            Coche « afficher les fichiers et dossiers cachés »

            Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

            Décoche « masquer les extensions dont le type est connu »
            Puis fais «Ok» pour valider les changements.

            Et appliquer !

            2 - Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

            O2 - BHO: RieMon Class - {70F6A776-579A-4C95-BA88-134253907752} - C:\WINDOWS\System32\irsmzenz.dll

            O4 - HKCU\..\Run: [irssyncd] C:\WINDOWS\System32\irssyncd.exe

            O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe

            O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe

            O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)

            O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)

            O15 - Trusted Zone: *.adgate.info
            O15 - Trusted Zone: *.dollarrevenue.com
            O15 - Trusted Zone: *.imagesrvr.com
            O15 - Trusted Zone: *.media-motor.com
            O15 - Trusted Zone: *.mediatickets.net
            O15 - Trusted Zone: *.snipernet.biz
            O15 - Trusted Zone: *.snipernet.us
            O15 - Trusted Zone: *.systemdoctor.com
            O15 - Trusted Zone: *.winantivirus.com
            O15 - Trusted Zone: *.yazzle.net
            O15 - Trusted Zone: *.adgate.info (HKLM)
            O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
            O15 - Trusted Zone: http://click.getmirar.com (HKLM)
            O15 - Trusted Zone: *.imagesrvr.com (HKLM)
            O15 - Trusted Zone: *.media-motor.com (HKLM)
            O15 - Trusted Zone: *.mediatickets.net (HKLM)
            O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
            O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
            O15 - Trusted Zone: *.snipernet.biz (HKLM)
            O15 - Trusted Zone: *.snipernet.us (HKLM)
            O15 - Trusted Zone: *.systemdoctor.com (HKLM)
            O15 - Trusted Zone: *.winantivirus.com (HKLM)
            O15 - Trusted Zone: *.yazzle.net (HKLM)

            O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} (mm06ocx.mm06ocxf) - mk:@MSITStore:C:\DOCUME~1\DAVIDS\LOCALS~1\Temp\mma.chm::/alien.cab

            O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\d2j02c1mgf.dll (file missing)

            3 - Démarre en mode sans échec :
            Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
            Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
            Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
            (Si F8 ne marche pas utilise la touche F5).
            ----------------------------------------------------------------------------
            ¤Recherche et supprime ceci:
            attention seulement les fichiers (si présents).

            C:\WINDOWS\System32\irsmzenz.dll

            C:\WINDOWS\System32\irssyncd.exe

            C:\WINDOWS\system32\d2j02c1mgf.dll

            vide la corbeille, passe ewido et Ccleaner.

            Redémarre en mode normal et refait un hijackthis, stp.

            Bon courage.

            A+
            0
            1. Voici le log que j'ai eu avec Hijackthis:

              Logfile of HijackThis v1.99.1
              Scan saved at 15:53:21, on 2006-05-30
              Platform: Windows XP (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 (6.00.2600.0000)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\System32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\System32\LVCOMSX.EXE
              C:\Program Files\Logitech\Video\LogiTray.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
              c:\progra~1\mcafee.com\vso\mcvsescn.exe
              C:\PROGRA~1\mcafee.com\agent\mcagent.exe
              C:\WINDOWS\System32\ctfmon.exe
              C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
              C:\Program Files\Logitech\Video\FxSvr2.exe
              C:\Program Files\ewido anti-malware\ewidoctrl.exe
              c:\program files\mcafee.com\agent\mcdetect.exe
              c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
              c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
              C:\WINDOWS\System32\svchost.exe
              c:\PROGRA~1\mcafee.com\vso\mcshield.exe
              C:\WINDOWS\System32\wuauclt.exe
              C:\WINDOWS\System32\wuauclt.exe
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\hijackthis\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - Default URLSearchHook is missing
              O2 - BHO: RieMon Class - {70F6A776-579A-4C95-BA88-134253907752} - C:\WINDOWS\System32\irsmzenz.dll
              O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
              O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
              O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
              O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
              O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
              O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\Video\ISStart.exe
              O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
              O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
              O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
              O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
              O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
              O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
              O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
              O4 - HKCU\..\Run: [irssyncd] C:\WINDOWS\System32\irssyncd.exe
              O4 - Startup: Morpheus.lnk = C:\Program Files\Morpheus\Morpheus.exe
              O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
              O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
              O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
              O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
              O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
              O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
              O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
              O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
              O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
              O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
              O15 - Trusted Zone: *.adgate.info
              O15 - Trusted Zone: *.dollarrevenue.com
              O15 - Trusted Zone: *.imagesrvr.com
              O15 - Trusted Zone: *.media-motor.com
              O15 - Trusted Zone: *.mediatickets.net
              O15 - Trusted Zone: *.snipernet.biz
              O15 - Trusted Zone: *.snipernet.us
              O15 - Trusted Zone: *.systemdoctor.com
              O15 - Trusted Zone: *.winantivirus.com
              O15 - Trusted Zone: *.yazzle.net
              O15 - Trusted Zone: *.adgate.info (HKLM)
              O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
              O15 - Trusted Zone: http://click.getmirar.com (HKLM)
              O15 - Trusted Zone: *.imagesrvr.com (HKLM)
              O15 - Trusted Zone: *.media-motor.com (HKLM)
              O15 - Trusted Zone: *.mediatickets.net (HKLM)
              O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
              O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
              O15 - Trusted Zone: *.snipernet.biz (HKLM)
              O15 - Trusted Zone: *.snipernet.us (HKLM)
              O15 - Trusted Zone: *.systemdoctor.com (HKLM)
              O15 - Trusted Zone: *.winantivirus.com (HKLM)
              O15 - Trusted Zone: *.yazzle.net (HKLM)
              O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
              O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} (mm06ocx.mm06ocxf) - mk:@MSITStore:C:\DOCUME~1\DAVIDS\LOCALS~1\Temp\mma.chm::/alien.cab
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
              O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20060104/qtinstall.info.apple.com/snape/us/wi...
              O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} (Progetto1.int_ver34) - http://advnt01.com/dialer/int_ver34.CAB
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
              O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\d2j02c1mgf.dll (file missing)
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
              O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
              O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
              O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
              O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

              ------------------------------------------------------------------------

              Merci!

              dayvee
              0
              1. Contributeur
                Re,

                ferme toutes les applications,

                relance l2mfix et choisis l'option 2
                accepte le redémarrage du pc

                puis refait un hijackthis stp.

                Bon courage.

                A+
                0
                1. Salut! voici le rapport que le scan de l2mfix a fait:

                  L2MFIX find log 051206
                  These are the registry keys present
                  **********************************************************************************
                  Winlogon/notify:
                  Windows Registry Editor Version 5.00

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
                  "DLLName"="Ati2evxx.dll"
                  "Asynchronous"=dword:00000000
                  "Impersonate"=dword:00000001
                  "Lock"="AtiLockEvent"
                  "Logoff"="AtiLogoffEvent"
                  "Logon"="AtiLogonEvent"
                  "Disconnect"="AtiDisConnectEvent"
                  "Reconnect"="AtiReConnectEvent"
                  "Safe"=dword:00000000
                  "Shutdown"="AtiShutdownEvent"
                  "StartScreenSaver"="AtiStartScreenSaverEvent"
                  "StartShell"="AtiStartShellEvent"
                  "Startup"="AtiStartupEvent"
                  "StopScreenSaver"="AtiStopScreenSaverEvent"
                  "Unlock"="AtiUnLockEvent"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
                  "Asynchronous"=dword:00000000
                  "Impersonate"=dword:00000000
                  "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
                  6c,00,00,00
                  "Logoff"="ChainWlxLogoffEvent"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
                  "Asynchronous"=dword:00000000
                  "Impersonate"=dword:00000000
                  "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
                  6c,00,6c,00,00,00
                  "Logoff"="CryptnetWlxLogoffEvent"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
                  "DLLName"="cscdll.dll"
                  "Logon"="WinlogonLogonEvent"
                  "Logoff"="WinlogonLogoffEvent"
                  "ScreenSaver"="WinlogonScreenSaverEvent"
                  "Startup"="WinlogonStartupEvent"
                  "Shutdown"="WinlogonShutdownEvent"
                  "StartShell"="WinlogonStartShellEvent"
                  "Impersonate"=dword:00000000
                  "Asynchronous"=dword:00000001

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Dynamic Directory]
                  "Asynchronous"=dword:00000000
                  "DllName"="C:\\WINDOWS\\system32\\d2j02c1mgf.dll"
                  "Impersonate"=dword:00000000
                  "Logon"="WinLogon"
                  "Logoff"="WinLogoff"
                  "Shutdown"="WinShutdown"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
                  "DLLName"="wlnotify.dll"
                  "Logon"="SCardStartCertProp"
                  "Logoff"="SCardStopCertProp"
                  "Lock"="SCardSuspendCertProp"
                  "Unlock"="SCardResumeCertProp"
                  "Enabled"=dword:00000001
                  "Impersonate"=dword:00000001
                  "Asynchronous"=dword:00000001

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
                  "Asynchronous"=dword:00000000
                  "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                  6c,00,6c,00,00,00
                  "Impersonate"=dword:00000000
                  "StartShell"="SchedStartShell"
                  "Logoff"="SchedEventLogOff"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
                  "Logoff"="WLEventLogoff"
                  "Impersonate"=dword:00000000
                  "Asynchronous"=dword:00000001
                  "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
                  6c,00,6c,00,00,00

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
                  "DLLName"="WlNotify.dll"
                  "Lock"="SensLockEvent"
                  "Logon"="SensLogonEvent"
                  "Logoff"="SensLogoffEvent"
                  "Safe"=dword:00000001
                  "MaxWait"=dword:00000258
                  "StartScreenSaver"="SensStartScreenSaverEvent"
                  "StopScreenSaver"="SensStopScreenSaverEvent"
                  "Startup"="SensStartupEvent"
                  "Shutdown"="SensShutdownEvent"
                  "StartShell"="SensStartShellEvent"
                  "PostShell"="SensPostShellEvent"
                  "Disconnect"="SensDisconnectEvent"
                  "Reconnect"="SensReconnectEvent"
                  "Unlock"="SensUnlockEvent"
                  "Impersonate"=dword:00000001
                  "Asynchronous"=dword:00000001

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
                  "Asynchronous"=dword:00000000
                  "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                  6c,00,6c,00,00,00
                  "Impersonate"=dword:00000000
                  "Logoff"="TSEventLogoff"
                  "Logon"="TSEventLogon"
                  "PostShell"="TSEventPostShell"
                  "Shutdown"="TSEventShutdown"
                  "StartShell"="TSEventStartShell"
                  "Startup"="TSEventStartup"
                  "MaxWait"=dword:00000258
                  "Reconnect"="TSEventReconnect"
                  "Disconnect"="TSEventDisconnect"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
                  "DLLName"="wlnotify.dll"
                  "Logon"="RegisterTicketExpiredNotificationEvent"
                  "Logoff"="UnregisterTicketExpiredNotificationEvent"
                  "Impersonate"=dword:00000001
                  "Asynchronous"=dword:00000001

                  **********************************************************************************
                  useragent:
                  Windows Registry Editor Version 5.00

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                  "{BD328C94-4ADC-CE39-002D-4E96CD28213B}"=""

                  **********************************************************************************
                  Shell Extension key:
                  Windows Registry Editor Version 5.00

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
                  "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
                  "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
                  "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
                  "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
                  "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                  "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
                  "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
                  "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
                  "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
                  "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
                  "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Page de compatibilit‚"
                  "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'environnement"
                  "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
                  "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'environnement pour les objets r‚seau de Microsoft Windows"
                  "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
                  "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
                  "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensions de l'environnement de compression de fichiers"
                  "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension de l'environnement d'imprimante Web"
                  "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
                  "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu contextuel de cryptage"
                  "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
                  "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extension ic“ne HyperTerminal"
                  "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
                  "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
                  "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
                  "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                  "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
                  "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
                  "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
                  "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau"
                  "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Connexions r‚seau"
                  "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Scanneurs et appareils photo"
                  "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Scanneurs et appareils photo"
                  "{905667aa-acd6-11d2-8080-00805f6596d2}"="&Scanneurs et appareils photo"
                  "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Scanneurs et appareils photo"
                  "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Scanneurs et appareils photo"
                  "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
                  "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
                  "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensions de l'interpr‚teur de commandes pour l'environnement d'ex‚cution de scripts Windows"
                  "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Liaison de donn‚es Microsoft"
                  "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
                  "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
                  "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
                  "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barre des tƒches et menu D‚marrer"
                  "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Rechercher"
                  "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                  "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                  "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ex‚cuter..."
                  "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
                  "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Courrier ‚lectronique"
                  "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Polices"
                  "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Outils d'administration"
                  "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
                  "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
                  "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
                  "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
                  "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
                  "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
                  "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
                  "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
                  "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
                  "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
                  "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
                  "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
                  "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Bande de recherche"
                  "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
                  "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
                  "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
                  "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
                  "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
                  "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
                  "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
                  "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
                  "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
                  "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
                  "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
                  "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
                  "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Analyseur de la barre d'adresses"
                  "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
                  "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
                  "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
                  "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
                  "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
                  "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
                  "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
                  "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
                  "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
                  "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
                  "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
                  "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
                  "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
                  "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
                  "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
                  "{FF393560-C2A7-11CF-BFF4-444553540000}"="Historique"
                  "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                  "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                  "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
                  "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
                  "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
                  "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
                  "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
                  "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
                  "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
                  "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
                  "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                  "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                  "{88C6C381-2E85-11D0-94DE-444553540000}"="Dossier ActiveX Cache"
                  "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
                  "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
                  "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Dossier Inscription"
                  "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
                  "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
                  "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
                  "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
                  "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
                  "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
                  "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
                  "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'applications d'environnement"
                  "{0B124F8F-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
                  "{CFCCC7A0-A282-11D1-9082-006008059382}"="Publication d'application Darwin"
                  "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
                  "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
                  "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extracteur de miniatures de fichier + GDI"
                  "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Gestionnaire de miniatures - Informations de r‚sum‚ (DOCFILES)"
                  "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
                  "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
                  "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Assistant Publication de sites Web"
                  "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Commande d'impressions via le Web"
                  "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objet Assistant de publication Shell"
                  "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Assistant Obtenir une identit‚ Passport"
                  "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Comptes d'utilisateurs"
                  "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
                  "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
                  "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Fichier de chaŒne"
                  "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Raccourci de chaŒne"
                  "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
                  "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
                  "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
                  "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
                  "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
                  "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
                  "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
                  "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
                  "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
                  "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
                  "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
                  "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
                  "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
                  "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
                  "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
                  "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
                  "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
                  "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
                  "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
                  "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
                  "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
                  "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
                  "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
                  "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
                  "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
                  "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
                  "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
                  "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
                  "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
                  "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
                  "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
                  "{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3}"="My Logitech Pictures"
                  "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
                  "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
                  "{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
                  "{9CDC0E91-4654-4B6F-ACC6-6B1B8E924E17}"=""
                  "{9C4C2352-1444-41E3-96DD-8B4F2A1CDECF}"=""
                  "{99449184-83CE-4E0D-A0B2-79B04030F0EE}"=""
                  "{3B3FC515-0484-46F0-9F6A-C0418D99A6C7}"=""
                  "{DDCE8458-4C58-4D00-B3E5-5A402D0F34CE}"=""
                  "{9C076A38-4A13-45E2-8308-0030A9A03B86}"=""
                  "{4A441DCA-BF77-4D23-9E95-98637BA928A3}"=""
                  "{F1301EC8-9CAA-40B9-BB30-1DA6914A65BD}"=""
                  "{160DA0C3-1926-4A97-9E3E-C99E0F14E5D3}"=""
                  "{AA933FF8-41DE-4F9E-AFF7-7048EC3DE25A}"=""

                  **********************************************************************************
                  HKEY ROOT CLASSIDS:
                  Windows Registry Editor Version 5.00

                  [HKEY_CLASSES_ROOT\CLSID\{9CDC0E91-4654-4B6F-ACC6-6B1B8E924E17}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{9CDC0E91-4654-4B6F-ACC6-6B1B8E924E17}\Implemented Categories]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{9CDC0E91-4654-4B6F-ACC6-6B1B8E924E17}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{9CDC0E91-4654-4B6F-ACC6-6B1B8E924E17}\InprocServer32]
                  @="C:\\WINDOWS\\system32\\guard.tmp"
                  "ThreadingModel"="Apartment"

                  Windows Registry Editor Version 5.00

                  [HKEY_CLASSES_ROOT\CLSID\{9C4C2352-1444-41E3-96DD-8B4F2A1CDECF}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{9C4C2352-1444-41E3-96DD-8B4F2A1CDECF}\Implemented Categories]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{9C4C2352-1444-41E3-96DD-8B4F2A1CDECF}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{9C4C2352-1444-41E3-96DD-8B4F2A1CDECF}\InprocServer32]
                  @="C:\\WINDOWS\\system32\\doskcopy.dll"
                  "ThreadingModel"="Apartment"

                  Windows Registry Editor Version 5.00

                  [HKEY_CLASSES_ROOT\CLSID\{99449184-83CE-4E0D-A0B2-79B04030F0EE}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{99449184-83CE-4E0D-A0B2-79B04030F0EE}\Implemented Categories]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{99449184-83CE-4E0D-A0B2-79B04030F0EE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{99449184-83CE-4E0D-A0B2-79B04030F0EE}\InprocServer32]
                  @="C:\\WINDOWS\\system32\\tzntsvrp.dll"
                  "ThreadingModel"="Apartment"

                  Windows Registry Editor Version 5.00

                  [HKEY_CLASSES_ROOT\CLSID\{3B3FC515-0484-46F0-9F6A-C0418D99A6C7}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{3B3FC515-0484-46F0-9F6A-C0418D99A6C7}\Implemented Categories]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{3B3FC515-0484-46F0-9F6A-C0418D99A6C7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{3B3FC515-0484-46F0-9F6A-C0418D99A6C7}\InprocServer32]
                  @="C:\\WINDOWS\\system32\\wthtcpip.dll"
                  "ThreadingModel"="Apartment"

                  Windows Registry Editor Version 5.00

                  [HKEY_CLASSES_ROOT\CLSID\{DDCE8458-4C58-4D00-B3E5-5A402D0F34CE}]
                  @=""
                  "IDEx"="AD"

                  [HKEY_CLASSES_ROOT\CLSID\{DDCE8458-4C58-4D00-B3E5-5A402D0F34CE}\Implemented Categories]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{DDCE8458-4C58-4D00-B3E5-5A402D0F34CE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{DDCE8458-4C58-4D00-B3E5-5A402D0F34CE}\InprocServer32]
                  @="C:\\WINDOWS\\system32\\sigina.dll"
                  "ThreadingModel"="Apartment"

                  Windows Registry Editor Version 5.00

                  [HKEY_CLASSES_ROOT\CLSID\{9C076A38-4A13-45E2-8308-0030A9A03B86}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{9C076A38-4A13-45E2-8308-0030A9A03B86}\Implemented Categories]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{9C076A38-4A13-45E2-8308-0030A9A03B86}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{9C076A38-4A13-45E2-8308-0030A9A03B86}\InprocServer32]
                  @="C:\\WINDOWS\\system32\\maricons.dll"
                  "ThreadingModel"="Apartment"

                  Windows Registry Editor Version 5.00

                  [HKEY_CLASSES_ROOT\CLSID\{4A441DCA-BF77-4D23-9E95-98637BA928A3}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{4A441DCA-BF77-4D23-9E95-98637BA928A3}\Implemented Categories]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{4A441DCA-BF77-4D23-9E95-98637BA928A3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{4A441DCA-BF77-4D23-9E95-98637BA928A3}\InprocServer32]
                  @="C:\\WINDOWS\\system32\\mhvidc32.dll"
                  "ThreadingModel"="Apartment"

                  Windows Registry Editor Version 5.00

                  [HKEY_CLASSES_ROOT\CLSID\{F1301EC8-9CAA-40B9-BB30-1DA6914A65BD}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{F1301EC8-9CAA-40B9-BB30-1DA6914A65BD}\Implemented Categories]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{F1301EC8-9CAA-40B9-BB30-1DA6914A65BD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{F1301EC8-9CAA-40B9-BB30-1DA6914A65BD}\InprocServer32]
                  @="C:\\WINDOWS\\system32\\pWnmap.dll"
                  "ThreadingModel"="Apartment"

                  Windows Registry Editor Version 5.00

                  [HKEY_CLASSES_ROOT\CLSID\{160DA0C3-1926-4A97-9E3E-C99E0F14E5D3}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{160DA0C3-1926-4A97-9E3E-C99E0F14E5D3}\Implemented Categories]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{160DA0C3-1926-4A97-9E3E-C99E0F14E5D3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{160DA0C3-1926-4A97-9E3E-C99E0F14E5D3}\InprocServer32]
                  @="C:\\WINDOWS\\system32\\MJSwitch.dll"
                  "ThreadingModel"="Apartment"

                  Windows Registry Editor Version 5.00

                  [HKEY_CLASSES_ROOT\CLSID\{AA933FF8-41DE-4F9E-AFF7-7048EC3DE25A}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{AA933FF8-41DE-4F9E-AFF7-7048EC3DE25A}\Implemented Categories]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{AA933FF8-41DE-4F9E-AFF7-7048EC3DE25A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                  @=""

                  [HKEY_CLASSES_ROOT\CLSID\{AA933FF8-41DE-4F9E-AFF7-7048EC3DE25A}\InprocServer32]
                  @="C:\\WINDOWS\\system32\\iSssvcs.dll"
                  "ThreadingModel"="Apartment"

                  **********************************************************************************
                  Files Found are not all bad files:

                  C:\WINDOWS\SYSTEM32\
                  msxml3a.dll Sat 2006-05-27 12:49:18 A.... 24 576 24,00 K
                  isssvcs.dll Tue 2006-05-30 9:06:30 ..S.R 233 973 228,49 K
                  irsmzenz.dll Mon 2006-05-29 15:03:16 A.... 405 504 396,00 K
                  irsmarlq.dll Sun 2006-05-28 18:15:48 A.... 405 504 396,00 K
                  m646lg~1.dll Mon 2006-05-29 18:08:24 ..S.R 235 038 229,53 K
                  pwnmap.dll Mon 2006-05-29 15:02:24 ..S.. 235 038 229,53 K
                  nsnbc.dll Fri 2006-04-07 13:16:56 A.... 78 848 77,00 K
                  en6sl1~1.dll Mon 2006-05-29 18:09:20 ..S.R 237 148 231,59 K
                  c2002c~1.dll Mon 2006-05-29 18:44:16 ..S.R 234 249 228,76 K
                  mjswitch.dll Mon 2006-05-29 19:01:42 ..S.R 236 043 230,51 K
                  j4p00e~1.dll Mon 2006-05-29 19:02:42 ..S.R 236 043 230,51 K

                  11 items found: 11 files (7 H/S), 0 directories.
                  Total of file sizes: 2 561 964 bytes 2,44 M
                  Locate .tmp files:

                  C:\WINDOWS\SYSTEM32\
                  guard.tmp Tue 2006-05-30 9:06:34 A.... 235 574 230,05 K

                  1 item found: 1 file, 0 directories.
                  Total of file sizes: 235 574 bytes 230,05 K
                  **********************************************************************************
                  Directory Listing of system files:
                  Le volume dans le lecteur C s'appelle DAVID
                  Le num‚ro de s‚rie du volume est C0D6-430A

                  R‚pertoire de C:\WINDOWS\System32

                  2006-05-30 09:06 233ÿ973 iSssvcs.dll
                  2006-05-29 19:02 236ÿ043 j4p00e7meh.dll
                  2006-05-29 19:01 236ÿ043 MJSwitch.dll
                  2006-05-29 18:44 234ÿ249 c2002cdmgf0a2.dll
                  2006-05-29 18:09 237ÿ148 en6sl1j71.dll
                  2006-05-29 18:08 235ÿ038 m646lghs1646.dll
                  2006-05-29 15:02 235ÿ038 pWnmap.dll
                  2005-10-16 20:11 <REP> Microsoft
                  2001-12-31 23:07 <REP> dllcache
                  7 fichier(s) 1ÿ647ÿ532 octets
                  2 R‚p(s) 5ÿ807ÿ996ÿ928 octets libres

                  ----------------------------------------------------------------------

                  Merci!

                  dayvee
                  0
                  1. Contributeur
                    Bonsoir,

                    Télécharge l2mfix ici:

                    http://www.downloads.subratam.org/l2mfix.exe

                    Double clic sur l2mfix.exe pour lancer l'extraction.
                    Dans le dossier l2mfix, double clic sur l2mfix.bat et choisis l'option #1 (et pas autre chose) et valide avec la touche entrée.
                    Le bloc note va s'ouvrir avec le résultat du scan.
                    Fais un copier coller du résultat sur le forum.

                    Bon courage.

                    A+
                    0
                    1. Bonjour! Voici le rapport que j'ai obtenu en exécutant l'option 1:

                      SmitFraudFix v2.51

                      Rapport fait à 13:26:08,80, 2006-05-30
                      Executé à partir de C:\SmitfraudFix
                      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                      Fix executé en mode normal

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\

                      C:\defender??.exe PRESENT !
                      C:\keyboard??.exe PRESENT !
                      C:\newname??.exe PRESENT !

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\DAVIDS\Application Data

                      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\DAVIDS\Favoris

                      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                      "Source"="About:Home"
                      "SubscribedURL"="About:Home"
                      "FriendlyName"="Ma page d'accueil"

                      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Fin

                      ----------------------------------------------------------------------------

                      Ça c'est le rapport que j'ai eu en sélectionnant l'option 2:

                      SmitFraudFix v2.51

                      Rapport fait à 13:34:52,90, 2006-05-30
                      Executé à partir de C:\SmitfraudFix
                      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                      Fix executé en mode sans echec

                      »»»»»»»»»»»»»»»»»»»»»»»» Avant SmitFraudFix
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                      »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                      C:\defender??.exe supprimé
                      C:\keyboard??.exe supprimé
                      C:\newname??.exe supprimé

                      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                      GenericRenosFix by S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                      »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                      Nettoyage terminé.

                      »»»»»»»»»»»»»»»»»»»»»»»» Après SmitFraudFix
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Fin

                      ----------------------------------------------------------------------------

                      Ça c'est le log que j'ai eu ensuite avec hijackthis:

                      Logfile of HijackThis v1.99.1
                      Scan saved at 13:39:01, on 2006-05-30
                      Platform: Windows XP (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 (6.00.2600.0000)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\System32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\System32\LVCOMSX.EXE
                      C:\Program Files\Logitech\Video\LogiTray.exe
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
                      C:\PROGRA~1\mcafee.com\agent\mcagent.exe
                      C:\WINDOWS\System32\ctfmon.exe
                      C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                      c:\progra~1\mcafee.com\vso\mcvsescn.exe
                      C:\Program Files\Logitech\Video\FxSvr2.exe
                      C:\Program Files\ewido anti-malware\ewidoctrl.exe
                      c:\program files\mcafee.com\agent\mcdetect.exe
                      c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                      c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
                      C:\WINDOWS\System32\svchost.exe
                      c:\PROGRA~1\mcafee.com\vso\mcshield.exe
                      C:\WINDOWS\System32\wuauclt.exe
                      C:\WINDOWS\System32\wuauclt.exe
                      C:\hijackthis\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - Default URLSearchHook is missing
                      O2 - BHO: RieMon Class - {70F6A776-579A-4C95-BA88-134253907752} - C:\WINDOWS\System32\irsmzenz.dll
                      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                      O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
                      O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
                      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
                      O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\Video\ISStart.exe
                      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
                      O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
                      O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
                      O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                      O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                      O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                      O4 - HKCU\..\Run: [irssyncd] C:\WINDOWS\System32\irssyncd.exe
                      O4 - Startup: Morpheus.lnk = C:\Program Files\Morpheus\Morpheus.exe
                      O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                      O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                      O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                      O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                      O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                      O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                      O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
                      O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
                      O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
                      O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                      O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
                      O15 - Trusted Zone: *.adgate.info
                      O15 - Trusted Zone: *.dollarrevenue.com
                      O15 - Trusted Zone: *.imagesrvr.com
                      O15 - Trusted Zone: *.media-motor.com
                      O15 - Trusted Zone: *.mediatickets.net
                      O15 - Trusted Zone: *.snipernet.biz
                      O15 - Trusted Zone: *.snipernet.us
                      O15 - Trusted Zone: *.systemdoctor.com
                      O15 - Trusted Zone: *.winantivirus.com
                      O15 - Trusted Zone: *.yazzle.net
                      O15 - Trusted Zone: *.adgate.info (HKLM)
                      O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
                      O15 - Trusted Zone: http://click.getmirar.com (HKLM)
                      O15 - Trusted Zone: *.imagesrvr.com (HKLM)
                      O15 - Trusted Zone: *.media-motor.com (HKLM)
                      O15 - Trusted Zone: *.mediatickets.net (HKLM)
                      O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
                      O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
                      O15 - Trusted Zone: *.snipernet.biz (HKLM)
                      O15 - Trusted Zone: *.snipernet.us (HKLM)
                      O15 - Trusted Zone: *.systemdoctor.com (HKLM)
                      O15 - Trusted Zone: *.winantivirus.com (HKLM)
                      O15 - Trusted Zone: *.yazzle.net (HKLM)
                      O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
                      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                      O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} (mm06ocx.mm06ocxf) - mk:@MSITStore:C:\DOCUME~1\DAVIDS\LOCALS~1\Temp\mma.chm::/alien.cab
                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                      O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20060104/qtinstall.info.apple.com/snape/us/wi...
                      O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} (Progetto1.int_ver34) - http://advnt01.com/dialer/int_ver34.CAB
                      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                      O20 - Winlogon Notify: Dynamic Directory - C:\WINDOWS\system32\d2j02c1mgf.dll (file missing)
                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
                      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
                      O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
                      O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                      O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
                      O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

                      --------------------------------------------------------------------------

                      J'attend ton diagnostic, merci encore pour tout!

                      dayvee
                      0
                      1. Contributeur
                        Bonjour,

                        telecharge SmitfraudFix

                        http://siri.urz.free.fr/Fix/SmitfraudFix.zip
                        Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1, il va générer un rapport
                        Copie/colle le sur le poste stp.

                        voila a quoi cela ressemble : http://siri.urz.free.fr/Fix/SmitfraudFix.php

                        Démarre en mode sans échec :
                        Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                        Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                        Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                        (Si F8 ne marche pas utilise la touche F5).
                        ----------------------------------------------------------------------------
                        Relance le programme Smitfraud,
                        Cette fois choisit l’option 2, répond oui a toutes les questions.
                        Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

                        Relance hijackthis et colle un nouveau log ici.

                        Bon courage.

                        A+
                        0
                        1. Ça y est! j'ai fait toutes les étapes et je dois dire que mon pc avait grandement besoin d'un ménage... pour le barre MIRAR c'est réglé elle n'est plus là mais il y a toujours ces foutus pop-up qui apparaissent aux 2 minutes sans qu'internet explorer soit ouvert et... oui j'avais déjà un pop-up blocker donc j'ignore qu'est-ce qui m'envoi toutes ces fenêtres.

                          Voici mon nouveau log par hijackthis:

                          Logfile of HijackThis v1.99.1
                          Scan saved at 18:12:30, on 2006-05-29
                          Platform: Windows XP (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 (6.00.2600.0000)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\System32\Ati2evxx.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\system32\rundll32.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\System32\LVCOMSX.EXE
                          C:\Program Files\Logitech\Video\LogiTray.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                          C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
                          C:\PROGRA~1\mcafee.com\agent\mcagent.exe
                          C:\defender24.exe
                          c:\progra~1\mcafee.com\vso\mcvsescn.exe
                          C:\WINDOWS\System32\ctfmon.exe
                          C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                          C:\Program Files\Morpheus\Morpheus.exe
                          C:\Program Files\ewido anti-malware\ewidoctrl.exe
                          c:\program files\mcafee.com\agent\mcdetect.exe
                          c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                          C:\Program Files\Logitech\Video\FxSvr2.exe
                          c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
                          C:\WINDOWS\System32\svchost.exe
                          c:\PROGRA~1\mcafee.com\vso\mcshield.exe
                          C:\Program Files\Internet Explorer\IEXPLORE.EXE
                          C:\WINDOWS\System32\wuauclt.exe
                          C:\WINDOWS\System32\wuauclt.exe
                          C:\WINDOWS\System32\tdopw.exe
                          C:\hijackthis\HijackThis.exe

                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hugedomains.com/domain_profile.cfm?d=meloco&e=com
                          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - Default URLSearchHook is missing
                          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                          O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr-ca\msntb.dll
                          O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
                          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
                          O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\Video\ISStart.exe
                          O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                          O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
                          O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
                          O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
                          O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKLM\..\Run: [defender] C:\\defender24.exe
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                          O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                          O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                          O4 - HKCU\..\Run: [irssyncd] C:\WINDOWS\System32\irssyncd.exe
                          O4 - Startup: Morpheus.lnk = C:\Program Files\Morpheus\Morpheus.exe
                          O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                          O8 - Extra context menu item: &Traduire à partir de l'anglais - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
                          O8 - Extra context menu item: Pages liées - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
                          O8 - Extra context menu item: Pages similaires - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
                          O8 - Extra context menu item: Recherche &Google - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
                          O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                          O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
                          O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
                          O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
                          O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                          O12 - Plugin for .PDF: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
                          O15 - Trusted Zone: *.adgate.info
                          O15 - Trusted Zone: *.dollarrevenue.com
                          O15 - Trusted Zone: *.imagesrvr.com
                          O15 - Trusted Zone: *.media-motor.com
                          O15 - Trusted Zone: *.mediatickets.net
                          O15 - Trusted Zone: *.snipernet.biz
                          O15 - Trusted Zone: *.snipernet.us
                          O15 - Trusted Zone: *.systemdoctor.com
                          O15 - Trusted Zone: *.winantivirus.com
                          O15 - Trusted Zone: *.yazzle.net
                          O15 - Trusted Zone: *.adgate.info (HKLM)
                          O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
                          O15 - Trusted Zone: http://click.getmirar.com (HKLM)
                          O15 - Trusted Zone: *.imagesrvr.com (HKLM)
                          O15 - Trusted Zone: *.media-motor.com (HKLM)
                          O15 - Trusted Zone: *.mediatickets.net (HKLM)
                          O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
                          O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
                          O15 - Trusted Zone: *.snipernet.biz (HKLM)
                          O15 - Trusted Zone: *.snipernet.us (HKLM)
                          O15 - Trusted Zone: *.systemdoctor.com (HKLM)
                          O15 - Trusted Zone: *.winantivirus.com (HKLM)
                          O15 - Trusted Zone: *.yazzle.net (HKLM)
                          O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
                          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                          O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} (mm06ocx.mm06ocxf) - mk:@MSITStore:C:\DOCUME~1\DAVIDS\LOCALS~1\Temp\mma.chm::/alien.cab
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                          O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20060104/qtinstall.info.apple.com/snape/us/wi...
                          O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} (Progetto1.int_ver34) - http://advnt01.com/dialer/int_ver34.CAB
                          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                          O20 - Winlogon Notify: Telephony - C:\WINDOWS\system32\ir00l5dm1.dll
                          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
                          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                          O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\RGF2aWQ\command.exe (file missing)
                          O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
                          O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
                          O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
                          O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
                          O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe

                          J'attend ton diagnostic, merci beaucoup de ton aide!

                          dayvee
                          0
                          1. Contributeur
                            Bonsoir David,

                            Belles infections sur ton ordi !

                            Dans un premier temps, fait déja tout cela :

                            telecharge et execute ces antispywares ( pense a les mettre a jour avant de les lancer)

                            (1) ad-aware version 1.06

                            (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
                            voir demo
                            http://pageperso.aol.fr/balltrap34/adwseflash.zip

                            ***

                            (2) spybot version 1.4

                            (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
                            voir demo d utilisation
                            http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm
                            ***

                            et aussi ceci

                            (3) Ccleaner :
                            Télécharge Ccleaner ici :
                            https://www.ccleaner.com/ccleaner/download

                            Tutorial ici:
                            https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

                            (4) Ewido
                            http://download.ewido.net/ewido-setup.exe
                            Pendant l'installation, sur la page "Additional Options", décoche les deux options "Install background guard" et "Install scan via context menu Ewido Security Suite. Clique sur mise à jour.

                            Clique sur scanner puis sur scan complet du système.

                            (5) Pour vérifier, scanne ton PC avec cet antivirus en ligne :
                            https://www.bitdefender.com/toolbox/

                            (6) Relance hijackthis et colle le log ici stp.

                            Bon courage

                            A+
                            0