[Virus] TROJ_CONHOOK.CT

Bonjour ,

j'ai lu plusieurs messages sur les trojans, je voudrais me débarrasser de celui ci : TROJ_CONHOOK.CT

PC Cillin me dit qu'il se trouve ici : C:\WINDOWS\system32\adsdep.dll

Je ne peux pas le supprimer manuellement et le problème est que je n'arrive pas à trouver process xp... Le lien donné sur les précédents messages et invalide...
Configuration: Windows XP
Internet Explorer 6.0

13 réponses

  1. Contributeur sécurité
    Salut

    Ok, un indice apparait.

    Vas sur le site https://virusscan.jotti.org/
    - Clic en haut à droite sur "Parcourir", navigue dans les dossiers et sélectionne ce fichier :C:\WINDOWS\System32\tmp_0.dll
    - Clic sur submit toujours en haut à droite
    - Le scan va se lancer, ça va prendre un petit instant
    - En bas, tu as le résultat du scan, copie/colle le résultat complet du scan ici.
    Aide : https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId662799
    0
    1. Le rapport Silent runner :

      "Silent Runners.vbs", revision R50, https://www.silentrunners.org/
      Operating System: Windows XP
      Output limited to non-default values, except where indicated by "{++}"

      Startup items buried in registry:
      ---------------------------------

      HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
      "CTFMON.EXE" = "C:\WINDOWS\System32\ctfmon.exe" [MS]
      "WOOKIT" = "C:\Program Files\Wanadoo\GestMaj.exe EspaceWanadoo.exe" ["France Télécom R&D"]
      "MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]
      "msnmsgr" = ""C:\Program Files\MSN Messenger\msnmsgr.exe" /background" [MS]
      "swg" = "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" ["Google Inc."]

      HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
      "ATIPTA" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" ["ATI Technologies, Inc."]
      "CnxDslTaskBar" = ""C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"" ["Conexant Systems, Inc."]
      "WOOWATCH" = "C:\PROGRA~1\Wanadoo\Watch.exe" ["France Télécom R&D"]
      "WOOTASKBARICON" = "C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe" ["France Télécom R&D"]
      "HP Software Update" = ""C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"" ["Hewlett-Packard Company"]
      "pccguide.exe" = ""C:\Program Files\Trend Micro\PC-cillin 9\pccguide.exe"" ["Trend Micro Inc."]
      "PCCClient.exe" = ""C:\Program Files\Trend Micro\PC-cillin 9\PCCClient.exe"" ["Trend Micro Inc."]
      "Pop3trap.exe" = ""C:\Program Files\Trend Micro\PC-cillin 9\Pop3trap.exe"" ["Trend Micro Inc."]
      "SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."]
      "NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
      "DAEMON Tools-1033" = ""C:\Program Files\D-Tools\daemon.exe" -lang 1033" ["DAEMON'S HOME"]
      "Adobe Photo Downloader" = ""C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"" ["Adobe Systems Incorporated"]
      "LVCOMSX" = "C:\WINDOWS\System32\LVCOMSX.EXE" ["Logitech Inc."]
      "LogitechCameraAssistant" = "C:\Program Files\Logitech\Video\CameraAssistant.exe" ["Logitech Inc."]
      "LogitechVideo[inspector]" = "C:\Program Files\Logitech\Video\InstallHelper.exe /inspect" ["Logitech Inc."]
      "LogitechCameraService(E)" = "C:\WINDOWS\System32\ElkCtrl.exe /automation" ["Logitech Inc."]
      "!AVG Anti-Spyware" = ""C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized" ["Anti-Malware Development a.s."]
      "a-squared" = ""C:\Program Files\a-squared Anti-Malware\a2guard.exe"" ["Emsi Software GmbH"]
      "SunJavaUpdateSched" = ""C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"" ["Sun Microsystems, Inc."]

      HKLM\Software\Microsoft\Active Setup\Installed Components\
      >{26923b43-4d38-484f-9b9e-de460746276c}\(Default) = "Internet Explorer"
      \StubPath = "C:\WINDOWS\system32\shmgrate.exe OCInstallUserConfigIE" [MS]
      {306D6C21-C1B6-4629-986C-E59E1875B8AF}\(Default) = (no title provided)
      \StubPath = ""C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\Messenger\msgsc.dll",ShowIconsUser" [MS]

      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
      {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
      -> {HKLM...CLSID} = "Adobe PDF Reader Link Helper"
      \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
      {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
      -> {HKLM...CLSID} = "SSVHelper Class"
      \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll" ["Sun Microsystems, Inc."]
      {9030D464-4C02-4ABF-8ECC-5164760863C6}\(Default) = (no title provided)
      -> {HKLM...CLSID} = "Windows Live Sign-in Helper"
      \InProcServer32\(Default) = "C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll" [MS]
      {a880d597-a2c2-4199-bfe9-e71eb14c24b1}\(Default) = (no title provided)
      -> {HKLM...CLSID} = (no title provided)
      \InProcServer32\(Default) = "C:\WINDOWS\system32\adsdep.dll" [null data]
      {AA58ED58-01DD-4d91-8333-CF10577473F7}\(Default) = (no title provided)
      -> {HKLM...CLSID} = "Google Toolbar Helper"
      \InProcServer32\(Default) = "c:\program files\google\googletoolbar3.dll" ["Google Inc."]

      HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
      "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
      -> {HKLM...CLSID} = "Extension Affichage Panorama du Panneau de configuration"
      \InProcServer32\(Default) = "deskpan.dll" [file not found]
      "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
      -> {HKLM...CLSID} = (no title provided)
      \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
      "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
      -> {HKLM...CLSID} = "WinRAR"
      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
      "{48F45200-91E6-11CE-8A4F-0080C81A28D4}" = "TMD Shell Extension"
      -> {HKLM...CLSID} = "TMD Shell Extension"
      \InProcServer32\(Default) = "C:\Program Files\Trend Micro\PC-cillin 9\Tmdshell.dll" ["Trend Micro Inc."]
      "{771A9DA0-731A-11CE-993C-00AA004ADB6C}" = "VBPropSheet"
      -> {HKLM...CLSID} = "VBPropSheet"
      \InProcServer32\(Default) = "C:\Program Files\Trend Micro\PC-cillin 9\VBProp.dll" ["Trend Micro Inc."]
      "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
      -> {HKLM...CLSID} = "Mes dossiers de partage"
      \InProcServer32\(Default) = "C:\Program Files\MSN Messenger\fsshext.8.1.0178.00.dll" [MS]
      "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
      -> {HKLM...CLSID} = "Portable Media Devices Menu"
      \InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
      "{AB77609F-2178-4E6F-9C4B-44AC179D937A}" = "a-squared Context Menu Shell Extension"
      -> {HKLM...CLSID} = "a-squared context menu"
      \InProcServer32\(Default) = "C:\PROGRA~1\A-SQUA~1\A2CONT~1.DLL" ["Emsi Software GmbH"]

      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
      <<!>> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware 7.5"
      -> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
      \InProcServer32\(Default) = "C:\Program Files\AVG Anti-Spyware 7.5\shellexecutehook.dll" ["Anti-Malware Development a.s."]

      HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\
      <<!>> "AppInit_DLLs" = "C:\WINDOWS\System32\tmp_0.dll" [file not found]

      HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
      <<!>> adsdep\DLLName = "adsdep.dll" [null data]
      <<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]
      <<!>> crypt\DLLName = "crypts.dll" [file not found]

      HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
      {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
      -> {HKLM...CLSID} = "PDF Shell Extension"
      \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]

      HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
      AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
      -> {HKLM...CLSID} = "CContextScan Object"
      \InProcServer32\(Default) = "C:\Program Files\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]
      WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
      -> {HKLM...CLSID} = "WinRAR"
      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

      HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
      AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
      -> {HKLM...CLSID} = "CContextScan Object"
      \InProcServer32\(Default) = "C:\Program Files\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]
      WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
      -> {HKLM...CLSID} = "WinRAR"
      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

      HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
      a2ContMenu\(Default) = "{AB77609F-2178-4E6F-9C4B-44AC179D937A}"
      -> {HKLM...CLSID} = "a-squared context menu"
      \InProcServer32\(Default) = "C:\PROGRA~1\A-SQUA~1\A2CONT~1.DLL" ["Emsi Software GmbH"]
      WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
      -> {HKLM...CLSID} = "WinRAR"
      \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

      HKLM\Software\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
      a2ContMenu\(Default) = "{AB77609F-2178-4E6F-9C4B-44AC179D937A}"
      -> {HKLM...CLSID} = "a-squared context menu"
      \InProcServer32\(Default) = "C:\PROGRA~1\A-SQUA~1\A2CONT~1.DLL" ["Emsi Software GmbH"]

      Group Policies {GPedit.msc branch and setting}:
      -----------------------------------------------

      Note: detected settings may not have any effect.

      HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\

      "DisableRegistryTools" = (REG_DWORD) hex:0x00000000
      {User Configuration|Administrative Templates|System|
      Prevent access to registry editing tools}

      HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

      "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
      {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
      Shutdown: Allow system to be shut down without having to log on}

      "undockwithoutlogon" = (REG_DWORD) hex:0x00000001
      {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
      Devices: Allow undock without having to log on}

      Active Desktop and Wallpaper:
      -----------------------------

      Active Desktop may be disabled at this entry:
      HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

      Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
      HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
      "Wallpaper" = "C:\Documents and Settings\Isabelle\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

      Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
      HKCU\Control Panel\Desktop\
      "Wallpaper" = "C:\Documents and Settings\Isabelle\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

      Enabled Screen Saver:
      ---------------------

      HKCU\Control Panel\Desktop\
      "SCRNSAVE.EXE" = "C:\WINDOWS\VALRYG~1.SCR" (Valéry Grancher.scr) ["MacSourcery"]

      Startup items in "Isabelle" & "All Users" startup folders:
      ----------------------------------------------------------

      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
      "Adobe Gamma Loader" -> shortcut to: "C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]
      "Démarrage rapide du logiciel HP Image Zone" -> shortcut to: "C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe -s" [null data]
      "HP Digital Imaging Monitor" -> shortcut to: "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" ["Hewlett-Packard Co."]
      "Lancement rapide d'Adobe Reader" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]
      "Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office10\OSA.EXE -b -l" [MS]

      Enabled Scheduled Tasks:
      ------------------------

      "HPpromotions journeysoftware" -> launches: "C:\Program Files\hp\digital imaging\bin\hp promotions\journeysoftware\HPpromo.exe /N "journeysoftware" -r" ["hp"]

      Winsock2 Service Provider DLLs:
      -------------------------------

      Namespace Service Providers

      HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
      000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
      000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
      000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

      Transport Service Providers

      HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
      0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
      %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 15
      %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

      Toolbars, Explorer Bars, Extensions:
      ------------------------------------

      Toolbars

      HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
      "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
      -> {HKLM...CLSID} = "&Google"
      \InProcServer32\(Default) = "c:\program files\google\googletoolbar3.dll" ["Google Inc."]

      HKLM\Software\Microsoft\Internet Explorer\Toolbar\
      "{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
      -> {HKLM...CLSID} = "&Google"
      \InProcServer32\(Default) = "c:\program files\google\googletoolbar3.dll" ["Google Inc."]

      Explorer Bars

      HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\

      HKLM\Software\Classes\CLSID\{01002DB2-8170-4D9B-A8B1-DDC9DD114E03}\(Default) = "Volet Wanadoo"
      Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
      InProcServer32\(Default) = "C:\PROGRA~1\Wanadoo\audience\audience.dll" [empty string]

      HKLM\Software\Classes\CLSID\{3BAF4A27-C764-4E1A-A6F4-62F7A7E5E51C}\(Default) = "ToolBand Class"
      Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
      InProcServer32\(Default) = "C:\PROGRA~1\Wanadoo\audience\audience.dll" [empty string]

      HKLM\Software\Classes\CLSID\{5BF498C0-931E-4A4F-B33F-456D07137EAA}\(Default) = "Volet Wanadoo"
      Implemented Categories\{00021494-0000-0000-C000-000000000046}\ [horizontal bar]
      InProcServer32\(Default) = "C:\PROGRA~1\Wanadoo\audience\audience.dll" [empty string]

      Extensions (Tools menu items, main toolbar menu buttons)

      HKLM\Software\Microsoft\Internet Explorer\Extensions\
      {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
      "MenuText" = "Console Java (Sun)"
      "CLSIDExtension" = "{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}"
      -> {HKCU...CLSID} = "Java Plug-in 1.5.0_11"
      \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll" ["Sun Microsystems, Inc."]
      -> {HKLM...CLSID} = "Java Plug-in 1.5.0_11"
      \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll" ["Sun Microsystems, Inc."]

      {85D1F590-48F4-11D9-9669-0800200C9A66}\
      "MenuText" = "Uninstall BitDefender Online Scanner v8"
      "Exec" = "%windir%\bdoscandel.exe" [null data]

      Miscellaneous IE Hijack Points
      ------------------------------

      C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

      Added lines (compared with English-language version):
      [Strings]: SAFESITE_VALUE="https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fhome.microsoft.com%2fintl%2ffr%2f%3f"

      Missing lines (compared with English-language version):
      [Strings]: 1 line

      HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\
      <<H>> "{08C06D61-F1F3-4799-86F8-BE1A89362C85}" = (no title provided)
      -> {HKLM...CLSID} = "Search Class"
      \InProcServer32\(Default) = "C:\PROGRA~1\Wanadoo\SEARCH~1.DLL" [empty string]

      Running Services (Display Name, Service Name, Path {Service DLL}):
      ------------------------------------------------------------------

      Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\System32\Ati2evxx.exe" ["ATI Technologies Inc."]
      AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, "C:\Program Files\AVG Anti-Spyware 7.5\guard.exe" ["Anti-Malware Development a.s."]
      France Telecom Routing Table Service, FTRTSVC, "C:\WINDOWS\System32\FTRTSVC.exe" ["France Telecom"]
      Logitech Process Monitor, LVPrcSrv, "c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe" ["Logitech Inc."]
      PC-cillin PersonalFirewall, PCCPFW, "C:\Program Files\Trend Micro\PC-cillin 9\PCCPFW.exe" ["Trend Micro Inc."]
      Service Messenger Sharing Folders USN Journal Reader, usnjsvc, "C:\Program Files\MSN Messenger\usnsvc.exe" [MS]
      Trend NT Realtime Service, Tmntsrv, ""C:\Program Files\Trend Micro\PC-cillin 9\Tmntsrv.exe"" ["Trend Micro Inc."]
      Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\System32\wdfmgr.exe" [MS]

      Print Monitors:
      ---------------

      HKLM\System\CurrentControlSet\Control\Print\Monitors\
      hpzlnt12\Driver = "hpzlnt12.dll" ["HP"]

      ----------
      <<!>>: Suspicious data at a malware launch point.
      <<H>>: Suspicious data at a browser hijack point.

      + This report excludes default entries except where indicated.
      + To see *everywhere* the script checks and *everything* it finds,
      launch it from a command prompt or a shortcut with the -all parameter.
      + To search all directories of local fixed drives for DESKTOP.INI
      DLL launch points, use the -supp parameter or answer "No" at the
      first message box and "Yes" at the second message box.
      ---------- (total run time: 1099 seconds, including 18 seconds for message boxes)


      Et le rapport Hijack :


      Logfile of HijackThis v1.99.1
      Scan saved at 18:55:22, on 22/03/2007
      Platform: Windows XP SP1 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\System32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Trend Micro\PC-cillin 9\Tmntsrv.exe
      C:\WINDOWS\System32\wdfmgr.exe
      C:\Program Files\Trend Micro\PC-cillin 9\PCCPFW.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Trend Micro\PC-cillin 9\PCCGUIDE.EXE
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
      C:\Program Files\Trend Micro\PC-cillin 9\WebTrap.EXE
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Trend Micro\PC-cillin 9\PCCClient.exe
      C:\Program Files\Trend Micro\PC-cillin 9\Pop3trap.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\D-Tools\daemon.exe
      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
      C:\WINDOWS\System32\LVCOMSX.EXE
      C:\Program Files\Logitech\Video\CameraAssistant.exe
      C:\WINDOWS\System32\ElkCtrl.exe
      C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
      C:\Program Files\a-squared Anti-Malware\a2guard.exe
      C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
      C:\WINDOWS\System32\ctfmon.exe
      C:\Program Files\Wanadoo\EspaceWanadoo.exe
      C:\Program Files\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\Program Files\Wanadoo\Watch.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\WINDOWS\System32\wuauclt.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
      C:\Program Files\MSN Messenger\usnsvc.exe
      C:\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: (no name) - {a880d597-a2c2-4199-bfe9-e71eb14c24b1} - C:\WINDOWS\system32\adsdep.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
      O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 9\pccguide.exe"
      O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 9\PCCClient.exe"
      O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 9\Pop3trap.exe"
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
      O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
      O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
      O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\System32\ElkCtrl.exe /automation
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\GestMaj.exe EspaceWanadoo.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - https://www.afternic.com/domains/drivecleaner.com
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{AC9F156C-F2AC-4C17-B76E-82E708DFBCB2}: NameServer = 80.10.246.130 80.10.246.3
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - AppInit_DLLs: C:\WINDOWS\System32\tmp_0.dll
      O20 - Winlogon Notify: adsdep - C:\WINDOWS\SYSTEM32\adsdep.dll
      O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
      O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 9\PCCPFW.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 9\Tmntsrv.exe

      Vundo Fix n'a absolument rien trouvé et pourtant il est bien toujours là d'aprés PC-Cillin...
      Je désespère... Saleté de trojan :-/
      @+
      0
      1. Contributeur sécurité
        Salut,

        1-

        Telecharge ceci
        https://www.silentrunners.org/Silent%20Runners.vbs
        Execute le,atends quelques minutes, il va creer ensuite un dossier juste a coté de silent runner sous format texte, copie/colle ce qu il te donnera

        2-

        Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
        http://www.atribune.org/ccount/click.php?id=4

        Double-clique VundoFix.exe afin de le lancer.
        Coche Run VundoFix as a task.
        Un message t'avertira que l'outil va se fermer et s'ouvrir à nouveau : clique Ok
        Clique sur le bouton Scan for Vundo.
        Lorsque le scan est complété, clique sur le bouton Remove Vundo.
        Une invite te demandera si tu veux supprimer les fichiers, clique YES
        Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
        Tu verras une invite qui t'annonce que ton PC va s'éteindre ("shutdown") ; clique OK
        Démarre ton PC à nouveau.
        Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis! dans ta prochaine réponse.

        A+
        0
        1. ---------------------------------------------------------
          AVG Anti-Spyware - Rapport d'analyse
          ---------------------------------------------------------

          Rien à signaler.

          :-/ Mais toujours le même message de PC- Cillin... Ne me dit pas qu'un virus est plus fort que toi Regis quand même :D
          0
          1. Contributeur sécurité
            Salut

            AVG AS est clean?

            A+
            0
            1. BitDefender Online Scanner

              Scan report generated at: Mon, Mar 19, 2007 - 22:53:37

              Scan path: A:\;C:\;D:\;E:\;F:\;G:\;L:\;M:\;N:\;

              Statistics

              Time
              02:35:08

              Files
              261828

              Folders
              4340

              Boot Sectors
              3

              Archives
              2372

              Packed Files
              18143

              Results

              Identified Viruses
              0

              Infected Files
              0

              Suspect Files
              0

              Warnings
              0

              Disinfected
              0

              Deleted Files
              0

              Engines Info

              Virus Definitions
              405790

              Engine build
              AVCORE v1.0 (build 2397) (i386) (Feb 8 2007 14:24:08)

              Scan plugins
              14

              Archive plugins
              38

              Unpack plugins
              6

              E-mail plugins
              6

              System plugins
              1

              Scan Settings

              First Action
              Disinfect

              Second Action
              Delete

              Heuristics
              Yes

              Enable Warnings
              Yes

              Scanned Extensions
              *;

              Exclude Extensions

              Scan Emails
              Yes

              Scan Archives
              Yes

              Scan Packed
              Yes

              Scan Files
              Yes

              Scan Boot
              Yes

              Scanned File
              Status

              No virus found.

              Rien trouvé mais toujours le même message de PC Cillin :s

              Théophile.
              0
              1. Contributeur sécurité
                Salut

                Ok.

                Lance ce scan en ligne:
                http://www.bitdefender.fr/scan8/ie.html
                Copie/colle le rapport
                Aide en image : http://pageperso.aol.fr/rginformatique/mapage/defender.htm

                A+
                0
                1. File : adsdep.dll

                  Status : INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)

                  MD5 : da2ba3564f51b339ee30ad2c6b60fcb2

                  Scan taken on 18 Mar 2007 22:10:18 (GMT)

                  AntiVir Found TR/Dldr.ConHook.Gen
                  ArcaVir Found Trojan.Downloader.Conhook.An

                  Avast Found nothing
                  AVG Antivirus Found nothing
                  BitDefender Found Trojan.Downloader.Conhook.O
                  ClamAV Found nothing
                  Dr.Web Found nothing
                  F-Prot Antivirus Found nothing
                  F-Secure Anti-Virus Found Trojan-Downloader.Win32.ConHook.an
                  Fortinet Found W32/ConHook.AN!tr.dldr
                  Kaspersky Anti-Virus Found Trojan-Downloader.Win32.ConHook.an

                  NOD32 Found nothing
                  Norman Virus Control Found nothing
                  Panda Antivirus Found nothing
                  VirusBuster Found Packed/Upack
                  VBA32 Found Trojan-Downloader.Win32.ConHook.an


                  Voilà ce que ça donne.
                  0
                  1. Contributeur sécurité
                    Salut,

                    ok !

                    Vas sur le site https://virusscan.jotti.org/
                    - Clic en haut à droite sur "Parcourir", navigue dans les dossiers et sélectionne ce fichier : C:\WINDOWS\system32\adsdep.dll
                    - Clic sur submit toujours en haut à droite
                    - Le scan va se lancer, ça va prendre un petit instant
                    - En bas, tu as le résultat du scan, copie/colle le résultat complet du scan ici.
                    Aide : https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId662799
                    0
                    1. VundoFix V6.3.16

                      Checking Java version...

                      Scan started at 22:55:44 18/03/2007

                      Listing files found while scanning....

                      No infected files were found.

                      Beginning removal...

                      Beginning removal...

                      Vundo n'as rien trouvé... PC Cillin détecte toujours TROJ_CONHOOK.CT

                      dans C:\WINDOWS\system32\adsdep.dll

                      :-/
                      0
                      1. Contributeur sécurité
                        Salut

                        Essaie ceci...

                        Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
                        http://www.atribune.org/ccount/click.php?id=4

                        Double-clique VundoFix.exe afin de le lancer.
                        Coche Run VundoFix as a task.
                        Un message t'avertira que l'outil va se fermer et s'ouvrir à nouveau : clique Ok
                        Clique sur le bouton Scan for Vundo.
                        Lorsque le scan est complété, clique sur le bouton Remove Vundo.
                        Une invite te demandera si tu veux supprimer les fichiers, clique YES
                        Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
                        Tu verras une invite qui t'annonce que ton PC va s'éteindre ("shutdown") ; clique OK
                        Démarre ton PC à nouveau.
                        Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis! dans ta prochaine réponse.

                        0
                        1. Logfile of HijackThis v1.99.1
                          Scan saved at 22:34:43, on 18/03/2007
                          Platform: Windows XP SP1 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\System32\Ati2evxx.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
                          C:\WINDOWS\System32\FTRTSVC.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Trend Micro\PC-cillin 9\Tmntsrv.exe
                          C:\WINDOWS\System32\wdfmgr.exe
                          C:\Program Files\Trend Micro\PC-cillin 9\PCCPFW.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\Trend Micro\PC-cillin 9\PCCGUIDE.EXE
                          C:\Program Files\Trend Micro\PC-cillin 9\WebTrap.EXE
                          C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                          C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
                          C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          C:\Program Files\Trend Micro\PC-cillin 9\PCCClient.exe
                          C:\Program Files\Trend Micro\PC-cillin 9\Pop3trap.exe
                          C:\WINDOWS\SOUNDMAN.EXE
                          C:\Program Files\D-Tools\daemon.exe
                          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                          C:\WINDOWS\System32\wuauclt.exe
                          C:\WINDOWS\System32\LVCOMSX.EXE
                          C:\Program Files\Logitech\Video\CameraAssistant.exe
                          C:\WINDOWS\System32\ElkCtrl.exe
                          C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
                          C:\Program Files\a-squared Anti-Malware\a2guard.exe
                          C:\WINDOWS\System32\ctfmon.exe
                          C:\Program Files\MSN Messenger\msnmsgr.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
                          C:\Program Files\Wanadoo\EspaceWanadoo.exe
                          C:\Program Files\Wanadoo\ComComp.exe
                          C:\PROGRA~1\Wanadoo\Toaster.exe
                          C:\PROGRA~1\Wanadoo\Inactivity.exe
                          C:\PROGRA~1\Wanadoo\PollingModule.exe
                          C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                          C:\Program Files\Wanadoo\Watch.exe
                          C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
                          C:\Program Files\MSN Messenger\usnsvc.exe
                          C:\WINDOWS\System32\rasautou.exe
                          C:\HijackThis\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: (no name) - {a880d597-a2c2-4199-bfe9-e71eb14c24b1} - C:\WINDOWS\system32\adsdep.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                          O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                          O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
                          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                          O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
                          O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\PC-cillin 9\pccguide.exe"
                          O4 - HKLM\..\Run: [PCCClient.exe] "C:\Program Files\Trend Micro\PC-cillin 9\PCCClient.exe"
                          O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 9\Pop3trap.exe"
                          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                          O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
                          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
                          O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
                          O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
                          O4 - HKLM\..\Run: [LogitechCameraService(E)] C:\WINDOWS\System32\ElkCtrl.exe /automation
                          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                          O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                          O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\GestMaj.exe EspaceWanadoo.exe
                          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                          O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                          O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - https://www.afternic.com/domains/drivecleaner.com
                          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                          O20 - AppInit_DLLs: C:\WINDOWS\System32\tmp_0.dll
                          O20 - Winlogon Notify: adsdep - C:\WINDOWS\SYSTEM32\adsdep.dll
                          O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
                          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                          O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
                          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                          O23 - Service: PC-cillin PersonalFirewall (PCCPFW) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 9\PCCPFW.exe
                          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                          O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Inc. - C:\Program Files\Trend Micro\PC-cillin 9\Tmntsrv.exe

                          J'attends tes indications car je ne comprends pas grand chose à tout ça ;)

                          Théophile.
                          0
                          1. Contributeur sécurité
                            Salut,

                            télécharge HijackThis ici:
                            http://telechargement.zebulon.fr/138-hijackthis-1991.html

                            Dézippe le dans un dossier prévu à cet effet.
                            Par exemple C:\hijackthis < Enregistre le bien dans c : !
                            Démo : (Merci a Balltrap34 pour cette réalisation)
                            http://pageperso.aol.fr/balltrap34/Hijenr.gif

                            Lance le puis:
                            clique sur "do a system scan and save logfile" (cf démo)
                            faire un copier coller du log entier sur le forum

                            Démo : (Merci a Balltrap34 pour cette réalisation)
                            http://pageperso.aol.fr/balltrap34/demohijack.htm

                            Bon courage

                            A+
                            0