Fenetres de pub temps ??

bonjour
j'ai des pub tout le temps des que je navigue sur le net
pub pour antispyware ,mozzilla,navi shearch,et meme des fois pub pour sites pornographique
pouvez vous m'aider
salutations
Logfile of HijackThis v1.99.1
Scan saved at 18:06:51, on 10/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\USB Storage RW\DskWatch.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\FRANCOIS\LOCALS~1\Temp\Rar$EX00.079\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.free.fr:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [USB Storage RW] "C:\Program Files\USB Storage RW\DskWatch.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [kxmqhynis] c:\windows\system32\kxmqhynis.exe kxmqhynis
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - Startup: desktop(2)(2).ini
O4 - Startup: desktop(2).ini
O4 - Startup: desktop(3).ini
O4 - Global Startup: desktop(2)(2).ini
O4 - Global Startup: desktop(2).ini
O4 - Global Startup: desktop(3).ini
O4 - Global Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - https://www.f-secure.com/en/home/support
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe

28 réponses

Résumé de la discussion

Plusieurs publicités intempestives et des redirections apparaissent lors de la navigation, et l’analyse HijackThis révèle de multiples éléments malveillants et entrées de démarrage suspectes sous Windows XP et Internet Explorer. La meilleure réponse propose une procédure en deux étapes: d’abord Brute Force Uninstaller et BlackLight pour supprimer les éléments résiduels, puis la suppression manuelle de fichiers et la vérification des programmes indésirables comme mailskinner. Des échanges indiquent aussi qu’une barre Yahoo s’est infiltrée dans Internet Explorer et que certains répondants proposent des nettoyeurs de registre ou la suppression via Ajout/Suppression de programme. En cas de persistance, certains participants évoquent l’utilisation de jv16 PowerTools pour nettoyer le registre et d’autres pistes comme la vérification des éléments cachés dans le système.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour zzorglub,

    Content que tout soit resolu.

    Bonne continuation a toi et si tu as besoin, n hesites pas

    a+
    1. Contributeur sécurité
      Salut

      As tu regardé dans ajout/suppression de programmes pour la supprimer?

      a+
      1. bonjour

        tu avais raison , elle etait dans ajout et suppresion
        pourtant j'avais regarder (pas bien je pense)

        je n'ai plus de probleme
        je te remercie pour ta patience et ton aide
        c'est vraiment tres sympa et c'est rassurant de pouvoir compter sur quelqun pour aider les "nuls'en informatique
        bonne soirèe et merci encore
        salutations
    2. Contributeur sécurité
      Salut

      Les points rouges tu les laisses car leur suppression pourrait causer des soucis a ton pc; tout simplement.

      Ou en sont tes soucis?

      a+
      1. bonjour
        je crois que je n'ai plus de soucis, a par la barreYAHOO qui c'est installer sur internet explorer
        comment fait on pour la supprimer
        salutations
    3. Contributeur sécurité
      Bonsoir

      Ou habites tu pour dire que le temps n est pas bon?
      La pierre? Ah bon, que fais tu?

      jv16

      (ancienne version gratuite) https://puntocr.it/index.php?module=downloads_riz&func=display&pid=3&lid=26

      Dans les options, met le en francais
      là tu le lances tu cliques sur outil registre/outil/nettoyage de registre/continuer /démarrer
      là tu le laisses faire c’est un peu long
      quand il a fini
      tu sélectionnes les ronds verts par paquet de 20 ou 30
      une fois que tu les a sélectionnés tu cliques sur supprimer en bas à droite
      et tu continues jusqu’à ce qu’il ne reste plus de ronds verts

      A+
      1. coucou
        j'habite vers lyon et il à plu toute la journèe(sa continue)
        je suis tailleur de pierre
        bo ,je vais nettoyer mon registre
        à+
        salutations
    4. Contributeur sécurité
      Salut

      Ok !
      As tu un nettoyeur de registre stp?

      Dis moi également ou en sont tes soucis?

      a+
      1. bonjour
        quel temps de chien
        je n'est pas de nettoyeur de registre (du moins je pense)
        je ne sais meme pas ce que c'est
        ,et oui moi mon truc c'est la pierre
        salutations
    5. Contributeur sécurité
      Re,

      et celui ci?

      HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
      "System" = "csntv.exe"

      A+
      1. coucou
        non il n'y est pas non plus
        salutations
    6. Contributeur sécurité
      Salut

      Y'a du mieux ;-)

      Demarrer < executer < tape : Regedit
      Le registre s'ouvre !
      /!\ Soit prudent et n y fait pas n'importe quoi, c'est un lieu "sensible"/!\

      Rend toi a cette clé:

      HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\

      Dans la case de droite, y vois tu ceci?
      "notepad.exe"
      "winlogon.exe"

      Ferme le Registre.

      A+
      1. COUCOU
        ils n'y sont pas
        il y à
        CTFMON.EXE REG_SZ C:/WINDOWS/system32/ctfmon.EXE

        NBJ REG_SZ C/progam files/ahead/nero backitup/NBJ.exe
        salutations
    7. bonjour
      j'ai tout supprimer
      il reste des "backup"faut t'il les supprimer??
      voici les rapports

      "Silent Runners.vbs", revision 49, https://www.silentrunners.org/
      Operating System: Windows XP SP2
      Output limited to non-default values, except where indicated by "{++}"

      Startup items buried in registry:
      ---------------------------------

      HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
      "CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
      "NBJ" = ""C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"" ["Ahead Software AG"]

      HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ {++}
      "notepad.exe" = "(empty string)" [file not found]
      "winlogon.exe" = "(empty string)" [file not found]

      HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
      "VTTimer" = "VTTimer.exe" ["S3 Graphics, Inc."]
      "USB Storage RW" = ""C:\Program Files\USB Storage RW\DskWatch.exe"" [null data]
      "NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
      "PCMService" = ""C:\Program Files\CyberLink\PowerCinema\PCMService.exe"" ["CyberLink Corp."]
      "QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
      "OEM-Reset" = "(empty string)" [file not found]
      "KAVPersonal50" = ""C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize" ["Kaspersky Lab"]
      "VTTrayp" = "VTtrayp.exe" ["S3 Graphics Co., Ltd."]
      "SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."]
      "CARPService" = "carpserv.exe" ["Conexant Systems, Inc."]
      "DAEMON Tools-1033" = ""C:\Program Files\D-Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]
      "SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0\bin\jusched.exe" ["Sun Microsystems, Inc."]

      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
      {02478D38-C3F9-4EFB-9B51-7695ECA05670}\(Default) = (no title provided)
      -> {HKLM...CLSID} = "Yahoo! Toolbar Helper"
      \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]
      {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
      -> {HKLM...CLSID} = (no title provided)
      \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
      {9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)
      -> {HKLM...CLSID} = "Windows Live Sign-in Helper"
      \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]

      HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
      "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
      -> {HKLM...CLSID} = "Extension Affichage Panorama du Panneau de configuration"
      \InProcServer32\(Default) = "deskpan.dll" [file not found]
      "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
      -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
      \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
      "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
      -> {HKLM...CLSID} = "Portable Media Devices Menu"
      \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
      "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
      -> {HKLM...CLSID} = (no title provided)
      \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
      "{59850401-6664-101B-B21C-00AA004BA90B}" = "Séparateur du Classeur Microsoft Office"
      -> {HKLM...CLSID} = "Séparateur du Classeur Microsoft Office"
      \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office\UNBIND.DLL" [MS]
      "{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.04 Context Menu Shell Extension"
      -> {HKLM...CLSID} = "WinAceContext Menu Extension"
      \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
      "{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.04 DragDrop Shell Extension"
      -> {HKLM...CLSID} = "WinAceDrag-Drop Extension"
      \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
      "{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.04 Context Menu Shell Extension"
      -> {HKLM...CLSID} = "WinAceContext Menu (Add) Extension"
      \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
      "{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.04 Property Sheet Shell Extension"
      -> {HKLM...CLSID} = "WinAceProperty Sheet Extension"
      \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
      "{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
      -> {HKLM...CLSID} = "WinZip"
      \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
      "{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
      -> {HKLM...CLSID} = "WinZip"
      \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
      "{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
      -> {HKLM...CLSID} = "WinZip"
      \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
      "{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
      -> {HKLM...CLSID} = "WinZip"
      \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
      "{780BCB64-0CAF-473c-A9FC-E08C03D75515}" = "Matroska Shell Extension, Properties Page CLSID"
      -> {HKLM...CLSID} = "The Matroska Shell Extension, Prop Page CLSID"
      \InProcServer32\(Default) = "C:\Program Files\MatroskaProp\MatroskaProp.dll" [" "]
      "{78DC191E-EFC1-4532-9A71-224577A86A7D}" = "Matroska Shell Extension, Thumbnail Handler CLSID"
      -> {HKLM...CLSID} = "The Matroska Shell Extension, Thumbnail Handler CLSID"
      \InProcServer32\(Default) = "C:\Program Files\MatroskaProp\MatroskaProp.dll" [" "]
      "{794D04CA-70AC-4020-80EB-FFD59DEF8027}" = "Matroska Shell Extension, Tooltip Provider CLSID"
      -> {HKLM...CLSID} = "The Matroska Shell Extension, Tooltip Provider CLSID"
      \InProcServer32\(Default) = "C:\Program Files\MatroskaProp\MatroskaProp.dll" [" "]
      "{789111D8-68A3-46a3-9663-145A3FF4C9C9}" = "Matroska Shell Extension, ContextMenu CLSID"
      -> {HKLM...CLSID} = "The Matroska Shell Extension, Context Menu CLSID"
      \InProcServer32\(Default) = "C:\Program Files\MatroskaProp\MatroskaProp.dll" [" "]
      "{781395AF-A127-469f-A06F-59B482AF4F3F}" = "Matroska Shell Extension, Column Provider CLSID"
      -> {HKLM...CLSID} = "The Matroska Shell Extension, Column Provider CLSID"
      \InProcServer32\(Default) = "C:\Program Files\MatroskaProp\MatroskaProp.dll" [" "]
      "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
      -> {HKLM...CLSID} = "WinRAR"
      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
      "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
      -> {HKLM...CLSID} = "Mes dossiers de partage"
      \InProcServer32\(Default) = "C:\Program Files\MSN Messenger\fsshext.8.0.0792.00.dll" [MS]
      "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}" = "Webroot Spy Sweeper Context Menu Integration"
      -> {HKLM...CLSID} = "Webroot Spy Sweeper Context Menu Integration"
      \InProcServer32\(Default) = "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" [file not found]

      HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
      <<!>> "System" = "csntv.exe" [file not found]

      HKLM\System\CurrentControlSet\Control\Session Manager\
      <<!>> "BootExecute" = "autocheck autochk *"|"SsiEfr.e" [file not found]

      HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
      <<!>> WRNotifier\DLLName = "WRLogonNTF.dll" ["Webroot Software, Inc."]

      HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
      {781395AF-A127-469f-A06F-59B482AF4F3F}\(Default) = "The Matroska Shell Extension, Column Provider CLSID"
      -> {HKLM...CLSID} = "The Matroska Shell Extension, Column Provider CLSID"
      \InProcServer32\(Default) = "C:\Program Files\MatroskaProp\MatroskaProp.dll" [" "]

      HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
      Kaspersky Anti-Virus\(Default) = "{dd230880-495a-11d1-b064-008048ec2fc5}"
      -> {HKLM...CLSID} = (no title provided)
      \InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\shellex.dll" ["Kaspersky Lab"]
      MatroskaContextMenu\(Default) = "{789111D8-68A3-46a3-9663-145A3FF4C9C9}"
      -> {HKLM...CLSID} = "The Matroska Shell Extension, Context Menu CLSID"
      \InProcServer32\(Default) = "C:\Program Files\MatroskaProp\MatroskaProp.dll" [" "]
      WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
      -> {HKLM...CLSID} = "WinRAR"
      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
      WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
      -> {HKLM...CLSID} = "WinZip"
      \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
      ZFAdd\(Default) = "{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"
      -> {HKLM...CLSID} = "WinAceContext Menu (Add) Extension"
      \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]

      HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
      WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
      -> {HKLM...CLSID} = "WinRAR"
      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
      WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
      -> {HKLM...CLSID} = "WinZip"
      \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
      ZFAdd\(Default) = "{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"
      -> {HKLM...CLSID} = "WinAceContext Menu (Add) Extension"
      \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]

      HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
      Kaspersky Anti-Virus\(Default) = "{dd230880-495a-11d1-b064-008048ec2fc5}"
      -> {HKLM...CLSID} = (no title provided)
      \InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\shellex.dll" ["Kaspersky Lab"]
      SpySweeper\(Default) = "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"
      -> {HKLM...CLSID} = "Webroot Spy Sweeper Context Menu Integration"
      \InProcServer32\(Default) = "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" [file not found]
      WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
      -> {HKLM...CLSID} = "WinRAR"
      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
      WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
      -> {HKLM...CLSID} = "WinZip"
      \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

      HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
      SpySweeper\(Default) = "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"
      -> {HKLM...CLSID} = "Webroot Spy Sweeper Context Menu Integration"
      \InProcServer32\(Default) = "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" [file not found]

      Default executables:
      --------------------

      HKCU\Software\Classes\.bat\(Default) = (value not set)

      HKCU\Software\Classes\.cmd\(Default) = (value not set)

      HKCU\Software\Classes\.com\(Default) = (value not set)

      HKCU\Software\Classes\.exe\(Default) = (value not set)

      HKCU\Software\Classes\.hta\(Default) = (value not set)

      Group Policies {policy setting}:
      --------------------------------

      Note: detected settings may not have any effect.

      HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\

      "DisableRegistryTools" = (REG_DWORD) hex:0x00000000
      {Prevent access to registry editing tools}

      HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

      "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
      {Shutdown: Allow system to be shut down without having to log on}

      "undockwithoutlogon" = (REG_DWORD) hex:0x00000001
      {Devices: Allow undock without having to log on}

      Active Desktop and Wallpaper:
      -----------------------------

      Active Desktop may be enabled at this entry:
      HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

      Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
      HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
      "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

      Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
      HKCU\Control Panel\Desktop\
      "Wallpaper" = "C:\Documents and Settings\FRANCOIS\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

      Active Desktop web content (hidden if disabled):

      HKCU\Software\Microsoft\Internet Explorer\Desktop\Components\0\
      "FriendlyName" = ""
      "Source" = "http://www.toquentete.net/style/objet/lexique.gif"
      "SubscribedURL" = "http://www.toquentete.net/style/objet/lexique.gif"

      HKCU\Software\Microsoft\Internet Explorer\Desktop\Components\1\
      "FriendlyName" = ""
      "Source" = "http://www.creapoemes.com/Mon_Chien.gif"
      "SubscribedURL" = "http://www.creapoemes.com/Mon_Chien.gif"

      Startup items in "FRANCOIS" & "All Users" startup folders:
      ----------------------------------------------------------

      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
      "Démarrage d'Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office\OSA.EXE -b" [MS]

      Winsock2 Service Provider DLLs:
      -------------------------------

      Namespace Service Providers

      HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
      000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
      000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
      000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

      Transport Service Providers

      HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
      0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
      %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 34
      %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

      Toolbars, Explorer Bars, Extensions:
      ------------------------------------

      Toolbars

      HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
      "{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
      -> {HKLM...CLSID} = "Yahoo! Toolbar"
      \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]

      HKLM\Software\Microsoft\Internet Explorer\Toolbar\
      "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
      -> {HKLM...CLSID} = "Yahoo! Toolbar"
      \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]

      Extensions (Tools menu items, main toolbar menu buttons)

      HKLM\Software\Microsoft\Internet Explorer\Extensions\
      {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
      "MenuText" = "Console Java (Sun)"
      "CLSIDExtension" = "{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}"
      -> {HKLM...CLSID} = "Java Plug-in 1.5.0"
      \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll" ["Sun Microsystems, Inc."]

      {FB5F1910-F110-11D2-BB9E-00C04F795683}\
      "ButtonText" = "Messenger"
      "MenuText" = "Windows Messenger"
      "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]

      Miscellaneous IE Hijack Points
      ------------------------------

      C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

      Added lines (compared with English-language version):
      [Strings]: SAFESITE_VALUE="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2ffr%2f%3f"

      Missing lines (compared with English-language version):
      [Strings]: 1 line

      Running Services (Display Name, Service Name, Path {Service DLL}):
      ------------------------------------------------------------------

      CyberLink Background Capture Service (CBCS), CLCapSvc, ""C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe"" [empty string]
      CyberLink Media Library Service, CyberLink Media Library Service, ""C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe"" ["Cyberlink"]
      CyberLink Task Scheduler (CTS), CLSched, ""C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe"" [empty string]
      kavsvc, kavsvc, ""C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe"" ["Kaspersky Lab"]
      Service d'application d'assistance IPv6, 6to4, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\6to4svc.dll" [MS]}

      ----------
      <<!>>: Suspicious data at a malware launch point.

      + This report excludes default entries except where indicated.
      + To see *everywhere* the script checks and *everything* it finds,
      launch it from a command prompt or a shortcut with the -all parameter.
      + To search all directories of local fixed drives for DESKTOP.INI
      DLL launch points, use the -supp parameter or answer "No" at the
      first message box and "Yes" at the second message box.
      ---------- (total run time: 44 seconds, including 4 seconds for message boxes)

      Logfile of HijackThis v1.99.1
      Scan saved at 20:13:46, on 16/11/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
      C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
      C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
      C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\VTTimer.exe
      C:\Program Files\USB Storage RW\DskWatch.exe
      C:\Program Files\CyberLink\PowerCinema\PCMService.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\WINDOWS\system32\VTtrayp.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\system32\carpserv.exe
      C:\Program Files\D-Tools\daemon.exe
      C:\Program Files\Java\jre1.5.0\bin\jusched.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Microsoft Office\Office\OSA.EXE
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Documents and Settings\FRANCOIS\Bureau\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.free.fr:3128
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
      O4 - HKLM\..\Run: [USB Storage RW] "C:\Program Files\USB Storage RW\DskWatch.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
      O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [CARPService] carpserv.exe
      O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
      O4 - Global Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
      O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
      O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - https://www.f-secure.com/en/home/support
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
      O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe

      salutations
      1. Contributeur sécurité
        Salut

        ok a l endroit ou tu les a trouvé, clik droit et supprime les !
        Vide ensuite ta corbeille.

        Tu redemarres ton pc et tu mets un HijackThis + un silent runner stp

        a+
        1. Contributeur sécurité
          Salut,

          ¤Affiche tous les fichiers et dossiers :
          Clique sur démarrer/panneau de configuration/outil/option des dossiers/affichage

          Coche « afficher les fichiers et dossiers cachés »

          Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

          Décoche « masquer les extensions dont le type est connu »
          Puis fais «Ok» pour valider les changements.

          Et appliquer !

          Trouves tu ceci?

          C:\Documents and Settings\FRANCOIS\Menu Démarrer\Programmes\Démarrage

          desktop(2)(2).ini
          desktop(2).ini
          desktop(3).ini

          A+
          1. coucou
            ils y sont ,je les est trouver la ou tu la dit
            c'est grave docteur??
            salutations
          2. bonsoir
            je dois partir , merci pour tout et à demain
            salutations
        2. Contributeur sécurité
          Salut

          Essai ceci stp:

          Demarer < rechercher < tape: csntv.exe
          Dans tous les fichiers.

          Dis moi juste s'il trouve quelque chose.

          A+
          1. bonjour
            je n'ai rien trouver
            salutations
        3. Contributeur sécurité
          Salut,

          Telecharge ceci
          https://www.silentrunners.org/Silent%20Runners.vbs
          Execute le,atends quelques minutes, il va creer ensuite un dossier juste a coté de silent runner sous format texte, copie/colle ce qu il te donnera

          A+
          1. bonjour
            voici le rapport
            "Silent Runners.vbs", revision 49, https://www.silentrunners.org/
            Operating System: Windows XP SP2
            Output limited to non-default values, except where indicated by "{++}"

            Startup items buried in registry:
            ---------------------------------

            HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
            "CTFMON.EXE" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
            "NBJ" = ""C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"" ["Ahead Software AG"]

            HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ {++}
            "notepad.exe" = "(empty string)" [file not found]
            "winlogon.exe" = "(empty string)" [file not found]

            HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
            "VTTimer" = "VTTimer.exe" ["S3 Graphics, Inc."]
            "USB Storage RW" = ""C:\Program Files\USB Storage RW\DskWatch.exe"" [null data]
            "NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
            "PCMService" = ""C:\Program Files\CyberLink\PowerCinema\PCMService.exe"" ["CyberLink Corp."]
            "QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
            "OEM-Reset" = "(empty string)" [file not found]
            "KAVPersonal50" = ""C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize" ["Kaspersky Lab"]
            "VTTrayp" = "VTtrayp.exe" ["S3 Graphics Co., Ltd."]
            "SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."]
            "CARPService" = "carpserv.exe" ["Conexant Systems, Inc."]
            "DAEMON Tools-1033" = ""C:\Program Files\D-Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]
            "SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0\bin\jusched.exe" ["Sun Microsystems, Inc."]

            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
            {02478D38-C3F9-4EFB-9B51-7695ECA05670}\(Default) = (no title provided)
            -> {HKLM...CLSID} = "Yahoo! Toolbar Helper"
            \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]
            {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
            -> {HKLM...CLSID} = (no title provided)
            \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
            {9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)
            -> {HKLM...CLSID} = "Windows Live Sign-in Helper"
            \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]

            HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
            "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
            -> {HKLM...CLSID} = "Extension Affichage Panorama du Panneau de configuration"
            \InProcServer32\(Default) = "deskpan.dll" [file not found]
            "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
            -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
            \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
            "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
            -> {HKLM...CLSID} = "Portable Media Devices Menu"
            \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
            "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
            -> {HKLM...CLSID} = (no title provided)
            \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
            "{59850401-6664-101B-B21C-00AA004BA90B}" = "Séparateur du Classeur Microsoft Office"
            -> {HKLM...CLSID} = "Séparateur du Classeur Microsoft Office"
            \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office\UNBIND.DLL" [MS]
            "{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.04 Context Menu Shell Extension"
            -> {HKLM...CLSID} = "WinAceContext Menu Extension"
            \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
            "{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.04 DragDrop Shell Extension"
            -> {HKLM...CLSID} = "WinAceDrag-Drop Extension"
            \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
            "{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.04 Context Menu Shell Extension"
            -> {HKLM...CLSID} = "WinAceContext Menu (Add) Extension"
            \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
            "{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}" = "WinAce Archiver 2.04 Property Sheet Shell Extension"
            -> {HKLM...CLSID} = "WinAceProperty Sheet Extension"
            \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]
            "{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
            -> {HKLM...CLSID} = "WinZip"
            \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
            "{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
            -> {HKLM...CLSID} = "WinZip"
            \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
            "{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
            -> {HKLM...CLSID} = "WinZip"
            \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
            "{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
            -> {HKLM...CLSID} = "WinZip"
            \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
            "{780BCB64-0CAF-473c-A9FC-E08C03D75515}" = "Matroska Shell Extension, Properties Page CLSID"
            -> {HKLM...CLSID} = "The Matroska Shell Extension, Prop Page CLSID"
            \InProcServer32\(Default) = "C:\Program Files\MatroskaProp\MatroskaProp.dll" [" "]
            "{78DC191E-EFC1-4532-9A71-224577A86A7D}" = "Matroska Shell Extension, Thumbnail Handler CLSID"
            -> {HKLM...CLSID} = "The Matroska Shell Extension, Thumbnail Handler CLSID"
            \InProcServer32\(Default) = "C:\Program Files\MatroskaProp\MatroskaProp.dll" [" "]
            "{794D04CA-70AC-4020-80EB-FFD59DEF8027}" = "Matroska Shell Extension, Tooltip Provider CLSID"
            -> {HKLM...CLSID} = "The Matroska Shell Extension, Tooltip Provider CLSID"
            \InProcServer32\(Default) = "C:\Program Files\MatroskaProp\MatroskaProp.dll" [" "]
            "{789111D8-68A3-46a3-9663-145A3FF4C9C9}" = "Matroska Shell Extension, ContextMenu CLSID"
            -> {HKLM...CLSID} = "The Matroska Shell Extension, Context Menu CLSID"
            \InProcServer32\(Default) = "C:\Program Files\MatroskaProp\MatroskaProp.dll" [" "]
            "{781395AF-A127-469f-A06F-59B482AF4F3F}" = "Matroska Shell Extension, Column Provider CLSID"
            -> {HKLM...CLSID} = "The Matroska Shell Extension, Column Provider CLSID"
            \InProcServer32\(Default) = "C:\Program Files\MatroskaProp\MatroskaProp.dll" [" "]
            "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
            -> {HKLM...CLSID} = "WinRAR"
            \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
            "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
            -> {HKLM...CLSID} = "Mes dossiers de partage"
            \InProcServer32\(Default) = "C:\Program Files\MSN Messenger\fsshext.8.0.0792.00.dll" [MS]
            "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}" = "Webroot Spy Sweeper Context Menu Integration"
            -> {HKLM...CLSID} = "Webroot Spy Sweeper Context Menu Integration"
            \InProcServer32\(Default) = "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" [file not found]

            HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
            <<!>> "System" = "csntv.exe" [file not found]

            HKLM\System\CurrentControlSet\Control\Session Manager\
            <<!>> "BootExecute" = "autocheck autochk *"|"SsiEfr.e" [file not found]

            HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
            <<!>> WRNotifier\DLLName = "WRLogonNTF.dll" ["Webroot Software, Inc."]

            HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
            {781395AF-A127-469f-A06F-59B482AF4F3F}\(Default) = "The Matroska Shell Extension, Column Provider CLSID"
            -> {HKLM...CLSID} = "The Matroska Shell Extension, Column Provider CLSID"
            \InProcServer32\(Default) = "C:\Program Files\MatroskaProp\MatroskaProp.dll" [" "]

            HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
            Kaspersky Anti-Virus\(Default) = "{dd230880-495a-11d1-b064-008048ec2fc5}"
            -> {HKLM...CLSID} = (no title provided)
            \InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\shellex.dll" ["Kaspersky Lab"]
            MatroskaContextMenu\(Default) = "{789111D8-68A3-46a3-9663-145A3FF4C9C9}"
            -> {HKLM...CLSID} = "The Matroska Shell Extension, Context Menu CLSID"
            \InProcServer32\(Default) = "C:\Program Files\MatroskaProp\MatroskaProp.dll" [" "]
            WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
            -> {HKLM...CLSID} = "WinRAR"
            \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
            WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
            -> {HKLM...CLSID} = "WinZip"
            \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
            ZFAdd\(Default) = "{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"
            -> {HKLM...CLSID} = "WinAceContext Menu (Add) Extension"
            \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]

            HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
            WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
            -> {HKLM...CLSID} = "WinRAR"
            \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
            WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
            -> {HKLM...CLSID} = "WinZip"
            \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
            ZFAdd\(Default) = "{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"
            -> {HKLM...CLSID} = "WinAceContext Menu (Add) Extension"
            \InProcServer32\(Default) = "C:\Program Files\WinAce\arcext.dll" ["e-merge GmbH"]

            HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
            Kaspersky Anti-Virus\(Default) = "{dd230880-495a-11d1-b064-008048ec2fc5}"
            -> {HKLM...CLSID} = (no title provided)
            \InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\shellex.dll" ["Kaspersky Lab"]
            SpySweeper\(Default) = "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"
            -> {HKLM...CLSID} = "Webroot Spy Sweeper Context Menu Integration"
            \InProcServer32\(Default) = "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" [file not found]
            WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
            -> {HKLM...CLSID} = "WinRAR"
            \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
            WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
            -> {HKLM...CLSID} = "WinZip"
            \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

            HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
            SpySweeper\(Default) = "{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"
            -> {HKLM...CLSID} = "Webroot Spy Sweeper Context Menu Integration"
            \InProcServer32\(Default) = "C:\PROGRA~1\Webroot\SPYSWE~1\SSCtxMnu.dll" [file not found]

            Default executables:
            --------------------

            HKCU\Software\Classes\.bat\(Default) = (value not set)

            HKCU\Software\Classes\.cmd\(Default) = (value not set)

            HKCU\Software\Classes\.com\(Default) = (value not set)

            HKCU\Software\Classes\.exe\(Default) = (value not set)

            HKCU\Software\Classes\.hta\(Default) = (value not set)

            Group Policies {policy setting}:
            --------------------------------

            Note: detected settings may not have any effect.

            HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\

            "DisableRegistryTools" = (REG_DWORD) hex:0x00000000
            {Prevent access to registry editing tools}

            HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

            "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
            {Shutdown: Allow system to be shut down without having to log on}

            "undockwithoutlogon" = (REG_DWORD) hex:0x00000001
            {Devices: Allow undock without having to log on}

            Active Desktop and Wallpaper:
            -----------------------------

            Active Desktop may be enabled at this entry:
            HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

            Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
            HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
            "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

            Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
            HKCU\Control Panel\Desktop\
            "Wallpaper" = "C:\Documents and Settings\FRANCOIS\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

            Active Desktop web content (hidden if disabled):

            HKCU\Software\Microsoft\Internet Explorer\Desktop\Components\0\
            "FriendlyName" = ""
            "Source" = "http://www.toquentete.net/style/objet/lexique.gif"
            "SubscribedURL" = "http://www.toquentete.net/style/objet/lexique.gif"

            HKCU\Software\Microsoft\Internet Explorer\Desktop\Components\1\
            "FriendlyName" = ""
            "Source" = "http://www.creapoemes.com/Mon_Chien.gif"
            "SubscribedURL" = "http://www.creapoemes.com/Mon_Chien.gif"

            Startup items in "FRANCOIS" & "All Users" startup folders:
            ----------------------------------------------------------

            C:\Documents and Settings\FRANCOIS\Menu Démarrer\Programmes\Démarrage
            <<!>> "desktop(2)(2).ini" [null data]
            <<!>> "desktop(2).ini" [null data]
            <<!>> "desktop(3).ini" [null data]

            C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
            <<!>> "desktop(2)(2).ini" [null data]
            <<!>> "desktop(2).ini" [null data]
            <<!>> "desktop(3).ini" [null data]
            "Démarrage d'Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office\OSA.EXE -b" [MS]

            Winsock2 Service Provider DLLs:
            -------------------------------

            Namespace Service Providers

            HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
            000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
            000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
            000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

            Transport Service Providers

            HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
            0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
            %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 34
            %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

            Toolbars, Explorer Bars, Extensions:
            ------------------------------------

            Toolbars

            HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
            "{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
            -> {HKLM...CLSID} = "Yahoo! Toolbar"
            \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]

            HKLM\Software\Microsoft\Internet Explorer\Toolbar\
            "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
            -> {HKLM...CLSID} = "Yahoo! Toolbar"
            \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ["Yahoo! Inc."]

            Extensions (Tools menu items, main toolbar menu buttons)

            HKLM\Software\Microsoft\Internet Explorer\Extensions\
            {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
            "MenuText" = "Console Java (Sun)"
            "CLSIDExtension" = "{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}"
            -> {HKLM...CLSID} = "Java Plug-in 1.5.0"
            \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll" ["Sun Microsystems, Inc."]

            {FB5F1910-F110-11D2-BB9E-00C04F795683}\
            "ButtonText" = "Messenger"
            "MenuText" = "Windows Messenger"
            "Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]

            Miscellaneous IE Hijack Points
            ------------------------------

            C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

            Added lines (compared with English-language version):
            [Strings]: SAFESITE_VALUE="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2ffr%2f%3f"

            Missing lines (compared with English-language version):
            [Strings]: 1 line

            Running Services (Display Name, Service Name, Path {Service DLL}):
            ------------------------------------------------------------------

            CyberLink Background Capture Service (CBCS), CLCapSvc, ""C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe"" [empty string]
            CyberLink Media Library Service, CyberLink Media Library Service, ""C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe"" ["Cyberlink"]
            CyberLink Task Scheduler (CTS), CLSched, ""C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe"" [empty string]
            kavsvc, kavsvc, ""C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe"" ["Kaspersky Lab"]
            Service d'application d'assistance IPv6, 6to4, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\6to4svc.dll" [MS]}

            ----------
            <<!>>: Suspicious data at a malware launch point.

            + This report excludes default entries except where indicated.
            + To see *everywhere* the script checks and *everything* it finds,
            launch it from a command prompt or a shortcut with the -all parameter.
            + To search all directories of local fixed drives for DESKTOP.INI
            DLL launch points, use the -supp parameter or answer "No" at the
            first message box and "Yes" at the second message box.
            ---------- (total run time: 54 seconds, including 11 seconds for message boxes)

            salutations
        4. coucou
          les2 premiers sont parti, mais les 3startup,et les3 global startup ne sont pas parti
          un message s'affichait" oui ou non " j'ai essayer les 2 mais rien àfaire
          Logfile of HijackThis v1.99.1
          Scan saved at 20:51:45, on 13/11/2006
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
          C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
          C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
          C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\VTTimer.exe
          C:\Program Files\USB Storage RW\DskWatch.exe
          C:\Program Files\CyberLink\PowerCinema\PCMService.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\WINDOWS\system32\VTtrayp.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\WINDOWS\system32\carpserv.exe
          C:\Program Files\D-Tools\daemon.exe
          C:\Program Files\Java\jre1.5.0\bin\jusched.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Microsoft Office\Office\OSA.EXE
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Documents and Settings\FRANCOIS\Bureau\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.free.fr:3128
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
          O4 - HKLM\..\Run: [USB Storage RW] "C:\Program Files\USB Storage RW\DskWatch.exe"
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
          O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [CARPService] carpserv.exe
          O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
          O4 - Startup: desktop(2)(2).ini
          O4 - Startup: desktop(2).ini
          O4 - Startup: desktop(3).ini
          O4 - Global Startup: desktop(2)(2).ini
          O4 - Global Startup: desktop(2).ini
          O4 - Global Startup: desktop(3).ini
          O4 - Global Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
          O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
          O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
          O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
          O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - https://www.f-secure.com/en/home/support
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
          O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
          O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
          O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
          O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe

          salutations
          1. Contributeur sécurité
            Salut

            Fais ceci deja:

            ¤Relance HijackThis, coche les cases devant ces lignes et ensuite clique sur fix checked :

            O4 - HKLM\..\Run: [vmtjurokw] c:\windows\system32\vmtjurokw.exe vmtjurokw

            O4 - HKLM\..\Run: [kxmqhynis] c:\windows\system32

            O4 - Startup: desktop(2)(2).ini
            O4 - Startup: desktop(2).ini
            O4 - Startup: desktop(3).ini
            O4 - Global Startup: desktop(2)(2).ini
            O4 - Global Startup: desktop(2).ini
            O4 - Global Startup: desktop(3).ini

            Ferme HJT.Redemarre ton pc et remet un HJT

            A+
            1. Contributeur
              Tu n'as pas du faire la manip avec Killbox avant le rapport Hijack ...

              Remet un log Hijack STP et dis nous ou en sont tes probs.

              a+
              1. salut
                voici un log hijack
                Logfile of HijackThis v1.99.1
                Scan saved at 17:32:07, on 13/11/2006
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
                C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\VTTimer.exe
                C:\Program Files\USB Storage RW\DskWatch.exe
                C:\Program Files\CyberLink\PowerCinema\PCMService.exe
                C:\Program Files\QuickTime\qttask.exe
                C:\WINDOWS\system32\VTtrayp.exe
                C:\WINDOWS\SOUNDMAN.EXE
                C:\WINDOWS\system32\carpserv.exe
                C:\Program Files\D-Tools\daemon.exe
                C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Microsoft Office\Office\OSA.EXE
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\Documents and Settings\FRANCOIS\Bureau\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.free.fr:3128
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                O4 - HKLM\..\Run: [USB Storage RW] "C:\Program Files\USB Storage RW\DskWatch.exe"
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
                O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                O4 - HKLM\..\Run: [CARPService] carpserv.exe
                O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
                O4 - HKLM\..\Run: [vmtjurokw] c:\windows\system32\vmtjurokw.exe vmtjurokw
                O4 - HKLM\..\Run: [kxmqhynis] c:\windows\system32\kxmqhynis.exe kxmqhynis
                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
                O4 - Startup: desktop(2)(2).ini
                O4 - Startup: desktop(2).ini
                O4 - Startup: desktop(3).ini
                O4 - Global Startup: desktop(2)(2).ini
                O4 - Global Startup: desktop(2).ini
                O4 - Global Startup: desktop(3).ini
                O4 - Global Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
                O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - https://www.f-secure.com/en/home/support
                O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
                O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
                O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe

                les fenetres de pub n'apparaissent plus pour le moment ,quels conseils pour ne plus les revoir??
                salutations
            2. Contributeur sécurité
              Salut

              redemarre le manuellement et redonne nous les rapports stp

              a+
              1. coucou
                voici les rapports
                Logfile of HijackThis v1.99.1
                Scan saved at 21:49:56, on 12/11/2006
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
                C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\VTTimer.exe
                C:\Program Files\USB Storage RW\DskWatch.exe
                C:\Program Files\CyberLink\PowerCinema\PCMService.exe
                C:\Program Files\QuickTime\qttask.exe
                C:\WINDOWS\system32\VTtrayp.exe
                C:\WINDOWS\SOUNDMAN.EXE
                C:\WINDOWS\system32\carpserv.exe
                C:\Program Files\D-Tools\daemon.exe
                C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Microsoft Office\Office\OSA.EXE
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Documents and Settings\FRANCOIS\Bureau\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.free.fr/freebox/index.html
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.free.fr:3128
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                O4 - HKLM\..\Run: [USB Storage RW] "C:\Program Files\USB Storage RW\DskWatch.exe"
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
                O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                O4 - HKLM\..\Run: [CARPService] carpserv.exe
                O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
                O4 - HKLM\..\Run: [vmtjurokw] c:\windows\system32\vmtjurokw.exe vmtjurokw
                O4 - HKLM\..\Run: [kxmqhynis] c:\windows\system32\kxmqhynis.exe kxmqhynis
                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
                O4 - Startup: desktop(2)(2).ini
                O4 - Startup: desktop(2).ini
                O4 - Startup: desktop(3).ini
                O4 - Global Startup: desktop(2)(2).ini
                O4 - Global Startup: desktop(2).ini
                O4 - Global Startup: desktop(3).ini
                O4 - Global Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
                O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
                O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - https://www.f-secure.com/en/home/support
                O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
                O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
                O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe

                et le blacklight
                11/12/06 21:50:15 [Info]: BlackLight Engine 1.0.47 initialized
                11/12/06 21:50:15 [Info]: OS: 5.1 build 2600 (Service Pack 2)
                11/12/06 21:50:16 [Note]: 7019 4
                11/12/06 21:50:16 [Note]: 7005 0
                11/12/06 21:50:17 [Note]: 7006 0
                11/12/06 21:50:17 [Note]: 7011 632
                11/12/06 21:50:18 [Note]: 7026 0
                11/12/06 21:50:18 [Note]: 7026 0
                11/12/06 21:50:18 [Note]: 7015 1816
                11/12/06 21:50:18 [Note]: 7015 5
                11/12/06 21:50:18 [Note]: 7015 2184
                11/12/06 21:50:18 [Note]: 7015 5
                11/12/06 21:50:28 [Note]: FSRAW library version 1.7.1020
                11/12/06 21:58:36 [Note]: 2000 1012
                11/12/06 22:01:27 [Note]: 7007 0

                salutations
            3. Contributeur sécurité
              Salut

              Double clic sur killbox.exe (Pocket Killbox)

              - coche: delete on reboot
              - Dans "Full Path of File to Delete"
              -Sélectionne "single File"

              -copie et colle: C:\windows\system32\vmtjurokw.exe

              - clique sur la croix rouge
              - une fenêtre va apparaître pour confirmation clique sur YES
              - une seconde fenêtre te demande si tu veux redémarrer clique sur YES

              Si ce message s’affiche ignore le :
              http://tinypic.com/images/goodbye.jpg
              Laisse le pc redémarrer.
              Et après reposte un log HijackThis + un black light

              A+
              1. coucou
                une premiere fenetre me demande si je veut reboot, je dis OUI
                ET APRES UN COMPTE A REBOURS SE MET et le message qu'il faut ingnorer s'affiche , met le pc ne s'arette pas
                salutations
            4. Contributeur
              fais cette manip moins lourde mais peut être moins radicale :

              Télécharge: Pocket Killbox ici
              http://www.downloads.subratam.org/KillBox.exe

              Démo d utilisation (merci a Balltrap34 pour cette réalisation) ::
              http://pageperso.aol.fr/balltrap34/killbox.htm

              Regarde la méthode du bloc note et fais pareil avec cette liste:

              c:\WINDOWS\Prefetch\VMTJUROKW.EXE-10E15F06.pf
              c:\WINDOWS\system32\vmtjurokw.dat
              C:\windows\system32\vmtjurokw.exe
              c:\WINDOWS\system32\vmtjurokw_nav.dat
              c:\WINDOWS\system32\vmtjurokw_navps.dat

              Ensuite, redemarre ton PC et remet un rapport Blacklight.

              a+

              1. coucou
                je ferais sa demain , je dois partir
                je vous remecie pour votre patience et pour votre aide
                bonne soirèe
                salutations
              2. Contributeur
                ok pas de prob.

                bonne soirée.

                a+

              3. @Séb08bonjour
                j'ai fait ce que tu à dit
                voici le rapport blacknight
                11/12/06 11:05:45 [Info]: BlackLight Engine 1.0.47 initialized
                11/12/06 11:05:45 [Info]: OS: 5.1 build 2600 (Service Pack 2)
                11/12/06 11:05:45 [Note]: 7019 4
                11/12/06 11:05:45 [Note]: 7005 0
                11/12/06 11:05:47 [Note]: 7006 0
                11/12/06 11:05:47 [Note]: 7011 228
                11/12/06 11:05:48 [Note]: 7026 0
                11/12/06 11:05:48 [Note]: 7026 0
                11/12/06 11:05:48 [Note]: 7015 632
                11/12/06 11:05:48 [Note]: 7015 5
                11/12/06 11:05:48 [Note]: 7024 3
                11/12/06 11:05:48 [Info]: Hidden process: C:\windows\system32\vmtjurokw.exe
                11/12/06 11:05:48 [Note]: 7015 2024
                11/12/06 11:05:48 [Note]: 7015 5
                11/12/06 11:05:48 [Note]: FSRAW library version 1.7.1020
                11/12/06 11:05:49 [Info]: Hidden file: c:\!KillBox\vmtjurokw.dat
                11/12/06 11:05:49 [Note]: 10002 1
                11/12/06 11:05:49 [Info]: Hidden file: c:\!KillBox\vmtjurokw.exe
                11/12/06 11:05:49 [Note]: 10002 1
                11/12/06 11:05:49 [Info]: Hidden file: c:\!KillBox\VMTJUROKW.EXE-10E15F06.pf
                11/12/06 11:05:49 [Note]: 10002 1
                11/12/06 11:05:49 [Info]: Hidden file: c:\!KillBox\vmtjurokw_nav.dat
                11/12/06 11:05:49 [Note]: 10002 1
                11/12/06 11:05:49 [Info]: Hidden file: c:\!KillBox\vmtjurokw_navps.dat
                11/12/06 11:05:49 [Note]: 10002 1
                11/12/06 11:15:30 [Info]: Hidden file: c:\WINDOWS\Prefetch\VMTJUROKW.EXE-10E15F06.pf
                11/12/06 11:15:30 [Note]: 10002 1
                11/12/06 11:15:35 [Error]: 6019 0
                11/12/06 11:15:35 [Error]: 6017 0
                11/12/06 11:16:03 [Note]: 7007 0
                salutations
            • 1
            • 2