Pb virus internet

Bonjour,

Depuis déjà plusieurs semaines j'ai des virus (cheval de troie, logiciels espions et malveillants...) sur mon ordinatuer ainsi que sans arrêt l'affichage de page intempestive "Drive cleaner" qui sont des virus. J'ai essayé de m'en débarasser avec Avast, Ccleaner, spyware doctor mais rien n'y fait mon pc est de plus en plus lent et jen ai assez. Ne sacahant plus trop quoi faire je m'adresse a vous en vous demandant votre aide svp. Je suis loin d'être un expert en informatique.

En attendant votre réponse je vous remercie encore

Jeremich56@wanadoo.fr
Configuration: Windows XP
Internet Explorer 7.0

28 réponses

Résumé de la discussion

Le fil porte sur une infection informatique sous Windows XP associant cheval de Troie, logiciels espions et affichages intempestifs de Drive Cleaner qui ralentissent significativement l’ordinateur. Plusieurs conseils visent à identifier et supprimer les composants malveillants grâce à des outils spécialisés et à des nettoyages manuels, notamment HiJackThis, ComboFix et des rapports d’analyse. Des propositions couvrent la suppression de processus et fichiers douteux, la vérification des entrées de démarrage et des éléments de registre, ainsi que des scans en mode sans échec. En cas de persistance, certains participants recommandent d’établir un plan de nettoyage progressif et de surveiller les restes potentiels dans l’historique des cookies et des fichiers temporaires.

Bobot (l’IA à votre service)
  1. Bien,
    sur MSN, tu n'as pas encore vu de poulet rotis ? (euhh, ma question est sérieuse !)
    il sagit de ceci:
    http://vil.nai.com/vil/content/v_131539.htm
    regarde l'article ici:
    http://www.microsoft.com/france/securite/bulletins/2005/200502_msnmessenger.mspx
    --------------------------
    MSN est tellement cibler et vulnérable que je déconseille son usage...il y a des alternatives !
    https://www.luanagames.com/index.fr.html
    ----------------------------
    ensuite:
    fais ceci:
    Téléchargez MSNFix.zip (de !aur3n7) sur votre bureau:
    http://sosvirus.changelog.fr/MSNFix.zip

    Décompressez-le (clic droit >> Extraire ici) et double cliquer sur le fichier MSNFix.bat.
    - Exécutez l'option R.
    -- Si l'infection est détectée, exécutez l'option N.
    --- Sauvegardez ce rapport puis faites un copier/coller de ce rapport sur le forum, ainsi qu'un nouveau scan HijackThis fait en mode normal.

    Note :
    Suivant la variante détectée il est possible qu'un message vous demande d'exécuter le nettoyage en mode sans échec. dans ce cas :

    ---Redémarrer votre ordinateur
    - Au démarrage de l'ordinateur "tapotez" la touche F8 de ton clavier jusqu'à ce que les options de démarrage apparaissent.
    * A l'aide des touches de ton clavier descend jusque Mode sans échec puis valide par la touche [entrée]
    -- Si le choix est proposé choisis le même nom d'utilisateur qu'en mode normal.

    puis relancez le Fix comme décrit plus haut. (n'oubliez pas de sauvegardez le rapport)
    1. Je n'ai plus de fenêtres intempestives qui s'ouvre sans arrêt m'annonçant des virus mais mon pc a toujours une certaine lenteur sinon j'ai également 2 autres problèmes de nature différente :

      - Sur MSN Messenger, les emoticones ne s'affiche plus
      - Mon lecteur CD / DVD sur mon pc ne lis plus les CD et DVD

      Merci
      1. Modérateur
        Salut

        si tu parles de ceci :

        Impossible de supprimer C:\WINDOWS\ALCXMNTR.EXE


        c'est pas méchant du tout ... :)

        ++
        1. salut à tous,
          Je referais l'option 2 de clean en mode sans échec.
          A examiner le log en <22> il n'a pas su faire son travail correctement...
          1. 27/05/2007 a 15:54:53,40

            *** Recherche des fichiers dans C:

            *** Recherche des fichiers dans C:\WINDOWS\
            C:\WINDOWS\ALCXMNTR.EXE FOUND

            *** Recherche des fichiers dans C:\WINDOWS\system32
            C:\WINDOWS\system32\mcrh.tmp FOUND

            *** Recherche des fichiers dans C:\Program Files
            "C:\Program Files\Viewpoint\" FOUND
            *** Fin du rapport !

            Rapport clean par Malekal_morte - http://www.malekal.com
            Script execute en mode sans echec 27/05/2007 a 15:57:24,06

            Microsoft Windows XP [version 5.1.2600]

            *** Suppression des fichiers dans C:

            *** Suppression des fichiers dans C:\WINDOWS\
            tentative de suppression de C:\WINDOWS\ALCXMNTR.EXE
            Impossible de supprimer C:\WINDOWS\ALCXMNTR.EXE

            *** Suppression des fichiers dans C:\WINDOWS\system32
            tentative de suppression de C:\WINDOWS\system32\mcrh.tmp

            *** Suppression des fichiers dans C:\Program Files
            tentative de suppression de "C:\Program Files\Viewpoint\"

            *** Suppression des clefs du registre effectuee..
            *** Fin du rapport !
            1. Modérateur
              Salut

              Pour supprimer ces fichiers, il suffit de passer à l'option 2 du fix :-)

              ++
              1. recherches ceci dans ton PC:
                --------------------------------------------
                mqmddtcm.ini
                qukjjpri.ini
                auiqtyfd.ini
                supprimes-les
                si ça ne vas pas, fais le en mode sans échec
                https://leblogdeclaude.blogspot.com/2007/04/informatique-rebooter-xp-en-mode-sans.html

                ---------------------------------------
                download ceci:
                http://www.malekal.com/download/clean.zip
                Décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier dénommé "clean ".
                Redémarre en mode sans échec. ( note bien ce que tu as à faire ).
                Ouvre le dossier « clean » qui se trouve sur ton bureau.
                Double-clic sur « clean.cmd ».
                Une fenêtre noire va apparaître, suis les consignes
                fais l'option1 et 2
                poste le log
                Où est le rapport clean ? : « Poste de travail » / double clic sur disque « C / » double-clic sur « rapport_clean.txt » et « copier/coller le contenu » sur le forum.

                1. L2MFIX find log 051206
                  These are the registry keys present
                  **********************************************************************************
                  Winlogon/notify:
                  Windows Registry Editor Version 5.00

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
                  "DLLName"="Ati2evxx.dll"
                  "Asynchronous"=dword:00000000
                  "Impersonate"=dword:00000001
                  "Lock"="AtiLockEvent"
                  "Logoff"="AtiLogoffEvent"
                  "Logon"="AtiLogonEvent"
                  "Disconnect"="AtiDisConnectEvent"
                  "Reconnect"="AtiReConnectEvent"
                  "Safe"=dword:00000000
                  "Shutdown"="AtiShutdownEvent"
                  "StartScreenSaver"="AtiStartScreenSaverEvent"
                  "StartShell"="AtiStartShellEvent"
                  "Startup"="AtiStartupEvent"
                  "StopScreenSaver"="AtiStopScreenSaverEvent"
                  "Unlock"="AtiUnLockEvent"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
                  "Asynchronous"=dword:00000000
                  "Impersonate"=dword:00000000
                  "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
                  6c,00,00,00
                  "Logoff"="ChainWlxLogoffEvent"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
                  "Asynchronous"=dword:00000000
                  "Impersonate"=dword:00000000
                  "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
                  6c,00,6c,00,00,00
                  "Logoff"="CryptnetWlxLogoffEvent"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
                  "DLLName"="cscdll.dll"
                  "Logon"="WinlogonLogonEvent"
                  "Logoff"="WinlogonLogoffEvent"
                  "ScreenSaver"="WinlogonScreenSaverEvent"
                  "Startup"="WinlogonStartupEvent"
                  "Shutdown"="WinlogonShutdownEvent"
                  "StartShell"="WinlogonStartShellEvent"
                  "Impersonate"=dword:00000000
                  "Asynchronous"=dword:00000001

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
                  "DLLName"="wlnotify.dll"
                  "Logon"="SCardStartCertProp"
                  "Logoff"="SCardStopCertProp"
                  "Lock"="SCardSuspendCertProp"
                  "Unlock"="SCardResumeCertProp"
                  "Enabled"=dword:00000001
                  "Impersonate"=dword:00000001
                  "Asynchronous"=dword:00000001

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
                  "Asynchronous"=dword:00000000
                  "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                  6c,00,6c,00,00,00
                  "Impersonate"=dword:00000000
                  "StartShell"="SchedStartShell"
                  "Logoff"="SchedEventLogOff"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
                  "Logoff"="WLEventLogoff"
                  "Impersonate"=dword:00000000
                  "Asynchronous"=dword:00000001
                  "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
                  6c,00,6c,00,00,00

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
                  "DLLName"="WlNotify.dll"
                  "Lock"="SensLockEvent"
                  "Logon"="SensLogonEvent"
                  "Logoff"="SensLogoffEvent"
                  "Safe"=dword:00000001
                  "MaxWait"=dword:00000258
                  "StartScreenSaver"="SensStartScreenSaverEvent"
                  "StopScreenSaver"="SensStopScreenSaverEvent"
                  "Startup"="SensStartupEvent"
                  "Shutdown"="SensShutdownEvent"
                  "StartShell"="SensStartShellEvent"
                  "PostShell"="SensPostShellEvent"
                  "Disconnect"="SensDisconnectEvent"
                  "Reconnect"="SensReconnectEvent"
                  "Unlock"="SensUnlockEvent"
                  "Impersonate"=dword:00000001
                  "Asynchronous"=dword:00000001

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
                  "Asynchronous"=dword:00000000
                  "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                  6c,00,6c,00,00,00
                  "Impersonate"=dword:00000000
                  "Logoff"="TSEventLogoff"
                  "Logon"="TSEventLogon"
                  "PostShell"="TSEventPostShell"
                  "Shutdown"="TSEventShutdown"
                  "StartShell"="TSEventStartShell"
                  "Startup"="TSEventStartup"
                  "MaxWait"=dword:00000258
                  "Reconnect"="TSEventReconnect"
                  "Disconnect"="TSEventDisconnect"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
                  "Logon"="WLEventLogon"
                  "Logoff"="WLEventLogoff"
                  "Startup"="WLEventStartup"
                  "Shutdown"="WLEventShutdown"
                  "StartScreenSaver"="WLEventStartScreenSaver"
                  "StopScreenSaver"="WLEventStopScreenSaver"
                  "Lock"="WLEventLock"
                  "Unlock"="WLEventUnlock"
                  "StartShell"="WLEventStartShell"
                  "PostShell"="WLEventPostShell"
                  "Disconnect"="WLEventDisconnect"
                  "Reconnect"="WLEventReconnect"
                  "Impersonate"=dword:00000001
                  "Asynchronous"=dword:00000000
                  "SafeMode"=dword:00000001
                  "MaxWait"=dword:ffffffff
                  "DllName"=hex(2):57,00,67,00,61,00,4c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,\
                  6c,00,6c,00,00,00
                  "Event"=dword:00000002
                  "EulaAccepted"=dword:00000000

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings]
                  "Data"=hex:01,00,00,00,d0,8c,9d,df,01,15,d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,\
                  00,00,fc,7d,35,12,1a,d0,ae,4e,bd,9a,7b,21,c3,27,79,46,04,00,00,00,04,00,00,\
                  00,53,00,00,00,03,66,00,00,a8,00,00,00,10,00,00,00,ab,a3,c0,77,84,9a,a2,c9,\
                  c1,9d,12,dc,30,a8,76,0c,00,00,00,00,04,80,00,00,a0,00,00,00,10,00,00,00,a1,\
                  cb,7c,f5,49,3d,59,22,4b,8c,e3,b2,30,5a,6a,64,b0,01,00,00,e3,81,6d,55,c1,0e,\
                  ed,77,3f,8c,83,ca,51,e3,17,9c,2b,b1,f3,ab,a0,db,cb,d2,d0,26,74,8b,e8,2d,6f,\
                  7f,1d,73,aa,d9,16,1d,e4,3f,9a,e9,83,3b,40,13,4b,50,83,39,c7,64,00,71,e0,d4,\
                  b9,3d,c2,f2,f7,4a,b3,3f,95,12,80,8c,3a,7d,0d,db,26,b7,01,d0,94,00,91,ae,b7,\
                  29,32,c1,d2,cd,0b,c7,c6,09,4d,d2,55,46,66,64,6d,a0,fe,0d,0a,19,90,ae,85,0c,\
                  7a,76,26,d7,5d,b3,05,65,77,2e,5c,c1,c0,9f,5d,67,0b,0c,3e,3f,4c,35,cc,e0,8c,\
                  8b,fc,e5,a9,f3,51,c1,60,17,28,5b,6d,eb,4a,7f,2b,7e,f6,e9,37,77,b1,02,76,0e,\
                  88,d5,ab,4f,d7,a3,5a,41,99,e0,41,43,69,f1,67,13,46,c6,96,11,28,0a,30,ef,3b,\
                  fb,a4,9c,2c,06,0a,c1,1f,fd,f5,39,14,03,15,c1,06,d2,b3,c7,1c,b6,0b,18,75,71,\
                  e7,16,2e,18,39,42,78,62,54,43,4a,7d,ec,54,18,4c,41,c7,36,05,81,4d,70,c3,3a,\
                  f6,70,ff,91,c6,9b,1e,10,aa,e3,5f,0f,26,77,3c,33,e2,1e,6c,18,8f,b1,c1,9b,6e,\
                  a2,a0,fa,21,2d,ae,2c,72,86,6e,d8,3b,70,e7,b2,14,cd,75,cb,88,ef,eb,76,2d,54,\
                  49,23,78,5f,14,ae,5b,b3,6d,0c,f5,d9,7d,64,1d,49,f1,2b,f9,cf,56,c5,49,6b,cb,\
                  b2,ce,d8,43,f2,44,47,c7,ce,f1,1c,be,17,20,ac,64,cf,b2,b8,50,51,dc,18,cd,96,\
                  94,53,56,e3,76,80,90,39,62,b3,03,a1,63,4a,74,1b,73,74,35,ab,75,2c,ed,0f,79,\
                  01,de,09,43,9e,44,79,1d,f3,44,ea,09,02,1c,fc,a3,75,f9,f7,51,0c,70,64,df,8a,\
                  f4,8c,cf,87,2d,32,95,79,f2,77,1c,c9,16,7f,a8,db,92,3c,42,69,57,06,88,c3,ca,\
                  c3,bf,15,fc,86,00,f2,1a,04,e1,df,dd,33,73,c6,e8,b0,58,0a,36,06,55,ae,4d,47,\
                  8f,14,00,00,00,f7,21,dc,ec,9b,09,b8,cf,2c,3b,c7,49,fe,6d,ad,e1,fd,36,38,6b

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
                  "DLLName"="wlnotify.dll"
                  "Logon"="RegisterTicketExpiredNotificationEvent"
                  "Logoff"="UnregisterTicketExpiredNotificationEvent"
                  "Impersonate"=dword:00000001
                  "Asynchronous"=dword:00000001

                  **********************************************************************************
                  useragent:
                  Windows Registry Editor Version 5.00

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                  "Wanadoo 7.1 ; NaviWoo1.1"="IEAKFT"

                  **********************************************************************************
                  Shell Extension key:
                  Windows Registry Editor Version 5.00

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
                  "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
                  "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
                  "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
                  "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
                  "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                  "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
                  "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
                  "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
                  "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
                  "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
                  "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Page de compatibilit‚"
                  "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'environnement"
                  "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
                  "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'environnement pour les objets r‚seau de Microsoft Windows"
                  "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
                  "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
                  "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensions de l'environnement de compression de fichiers"
                  "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension de l'environnement d'imprimante Web"
                  "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
                  "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu contextuel de cryptage"
                  "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
                  "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extension ic“ne HyperTerminal"
                  "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
                  "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
                  "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
                  "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                  "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
                  "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
                  "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
                  "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau"
                  "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Connexions r‚seau"
                  "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Scanneurs et appareils photo"
                  "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Scanneurs et appareils photo"
                  "{905667aa-acd6-11d2-8080-00805f6596d2}"="&Scanneurs et appareils photo"
                  "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Scanneurs et appareils photo"
                  "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Scanneurs et appareils photo"
                  "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
                  "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensions de l'interpr‚teur de commandes pour l'environnement d'ex‚cution de scripts Windows"
                  "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Liaison de donn‚es Microsoft"
                  "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
                  "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
                  "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
                  "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
                  "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
                  "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barre des tƒches et menu D‚marrer"
                  "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Rechercher"
                  "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                  "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                  "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ex‚cuter..."
                  "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
                  "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Courrier ‚lectronique"
                  "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Polices"
                  "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Outils d'administration"
                  "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Page de propri‚t‚s des versions pr‚c‚dentes"
                  "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Versions pr‚c‚dentes"
                  "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
                  "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
                  "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
                  "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
                  "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
                  "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
                  "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
                  "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
                  "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
                  "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
                  "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
                  "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
                  "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="IE Search Band"
                  "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
                  "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
                  "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
                  "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
                  "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
                  "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
                  "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
                  "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
                  "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
                  "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
                  "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
                  "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
                  "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
                  "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
                  "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
                  "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
                  "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
                  "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
                  "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
                  "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
                  "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
                  "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
                  "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
                  "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
                  "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
                  "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
                  "{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
                  "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                  "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                  "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
                  "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
                  "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
                  "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
                  "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
                  "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
                  "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
                  "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
                  "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                  "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                  "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
                  "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
                  "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
                  "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
                  "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
                  "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
                  "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
                  "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
                  "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
                  "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
                  "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
                  "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'applications d'environnement"
                  "{0B124F8F-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
                  "{CFCCC7A0-A282-11D1-9082-006008059382}"="Publication d'application Darwin"
                  "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
                  "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
                  "{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow"
                  "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extracteur de miniatures de fichier + GDI"
                  "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Gestionnaire de miniatures - Informations de r‚sum‚ (DOCFILES)"
                  "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
                  "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
                  "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Assistant Publication de sites Web"
                  "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Commande d'impressions via le Web"
                  "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objet Assistant de publication Shell"
                  "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Assistant Obtenir une identit‚ Passport"
                  "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Comptes d'utilisateurs"
                  "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
                  "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
                  "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
                  "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
                  "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
                  "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
                  "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
                  "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
                  "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
                  "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
                  "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
                  "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
                  "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
                  "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
                  "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
                  "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
                  "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
                  "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
                  "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
                  "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
                  "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
                  "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
                  "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
                  "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
                  "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
                  "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
                  "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
                  "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
                  "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Burn Audio CD Context Menu Handler"
                  "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Play as Playlist Context Menu Handler"
                  "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
                  "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
                  "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
                  "{7F67036B-66F1-411A-AD85-759FB9C5B0DB}"="SampleView"
                  "{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"
                  "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Dossiers Web"
                  "{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
                  "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
                  "{472083B0-C522-11CF-8763-00608CC02F24}"="avast"
                  "{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
                  "{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
                  "{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
                  "{E0D79307-84BE-11CE-9641-444553540000}"="WinZip"
                  "{acb4a560-3606-11d3-aef4-00104bd0f92d}"="KodakShellExtension"
                  "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
                  "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}"="Messenger Sharing Folders"
                  "{07C45BB1-4A8C-4642-A1F5-237E7215FF66}"="IE Microsoft BrowserBand"
                  "{1C1EDB47-CE22-4bbb-B608-77B48F83C823}"="IE Fade Task"
                  "{205D7A97-F16D-4691-86EF-F3075DCCA57D}"="IE Menu Desk Bar"
                  "{3028902F-6374-48b2-8DC6-9725E775B926}"="IE AutoComplete"
                  "{43886CD5-6529-41c4-A707-7B3C92C05E68}"="IE Navigation Bar"
                  "{44C76ECD-F7FA-411c-9929-1B77BA77F524}"="IE Menu Site"
                  "{4B78D326-D922-44f9-AF2A-07805C2A3560}"="IE Menu Band"
                  "{6038EF75-ABFC-4e59-AB6F-12D397F6568D}"="IE Microsoft History AutoComplete List"
                  "{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}"="IE Tracking Shell Menu"
                  "{6CF48EF8-44CD-45d2-8832-A16EA016311B}"="IE IShellFolderBand"
                  "{73CFD649-CD48-4fd8-A272-2070EA56526B}"="IE BandProxy"
                  "{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}"="IE MRU AutoComplete List"
                  "{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}"="IE RSS Feeder Folder"
                  "{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}"="IE Microsoft Shell Folder AutoComplete List"
                  "{B31C5FAE-961F-415b-BAF0-E697A5178B94}"="IE Microsoft Multiple AutoComplete List Container"
                  "{BC476F4C-D9D7-4100-8D4E-E043F6DEC409}"="Microsoft Browser Architecture"
                  "{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}"="IE Shell Rebar BandSite"
                  "{E6EE9AAC-F76B-4947-8260-A9F136138E11}"="IE Shell Band Site Menu"
                  "{F2CF5485-4E02-4f68-819C-B92DE9277049}"="&Links"
                  "{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}"="IE Registry Tree Options Utility"
                  "{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}"="IE User Assist"
                  "{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}"="IE Custom MRU AutoCompleted List"
                  "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
                  "{35786D3C-B075-49b9-88DD-029876E11C01}"="Portable Devices"
                  "{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8}"="Portable Devices Menu"
                  "{e82a2d71-5b2f-43a0-97b8-81be15854de8}"="ShellLink for Application References"
                  "{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}"="Shell Icon Handler for Application References"
                  "{45670FA8-ED97-4F44-BC93-305082590BFB}"="Microsoft.XPS.Shell.Metadata.1"
                  "{44121072-A222-48f2-A58A-6D9AD51EBBE9}"="Microsoft.XPS.Shell.Thumbnail.1"
                  "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"

                  **********************************************************************************
                  HKEY ROOT CLASSIDS:
                  **********************************************************************************
                  Files Found are not all bad files:

                  C:\WINDOWS\SYSTEM32\
                  advpack.dll Tue 27 Feb 2007 15:25:02 A.... 124 928 122,00 K
                  extmgr.dll Tue 27 Feb 2007 15:25:02 A.... 132 608 129,50 K
                  gdi32.dll Thu 8 Mar 2007 17:37:50 A.... 281 600 275,00 K
                  ieakeng.dll Tue 27 Feb 2007 15:25:02 A.... 153 088 149,50 K
                  ieaksie.dll Tue 27 Feb 2007 15:25:04 A.... 230 400 225,00 K
                  ieakui.dll Wed 21 Feb 2007 10:00:54 A.... 161 792 158,00 K
                  ieapfltr.dll Tue 3 Apr 2007 16:29:24 A.... 383 488 374,50 K
                  iedkcs32.dll Tue 27 Feb 2007 15:25:10 A.... 384 000 375,00 K
                  ieframe.dll Tue 27 Feb 2007 15:25:32 A.... 6 054 400 5,77 M
                  iernonce.dll Tue 27 Feb 2007 15:25:32 A.... 44 544 43,50 K
                  iertutil.dll Tue 27 Feb 2007 15:25:34 A.... 266 752 260,50 K
                  jsproxy.dll Tue 27 Feb 2007 15:25:44 A.... 27 136 26,50 K
                  legitc~1.dll Thu 15 Mar 2007 18:19:28 ..... 1 476 992 1,41 M
                  mf3216.dll Thu 8 Mar 2007 17:37:50 A.... 40 960 40,00 K
                  msfeeds.dll Tue 27 Feb 2007 15:25:46 A.... 458 752 448,00 K
                  msfeed~1.dll Tue 27 Feb 2007 15:25:46 A.... 51 712 50,50 K
                  mshtml.dll Tue 27 Feb 2007 15:25:58 A.... 3 581 952 3,41 M
                  mshtmled.dll Tue 27 Feb 2007 15:25:58 A.... 477 696 466,50 K
                  msrating.dll Tue 27 Feb 2007 15:25:58 A.... 193 024 188,50 K
                  mstime.dll Tue 27 Feb 2007 15:26:04 A.... 670 720 655,00 K
                  occache.dll Tue 27 Feb 2007 15:26:06 A.... 102 400 100,00 K
                  url.dll Tue 27 Feb 2007 15:26:06 A.... 105 984 103,50 K
                  urlmon.dll Tue 27 Feb 2007 15:26:14 A.... 1 150 464 1,09 M
                  user32.dll Thu 8 Mar 2007 17:37:50 A.... 578 560 565,00 K
                  webcheck.dll Tue 27 Feb 2007 15:26:16 A.... 232 960 227,50 K
                  wgalogon.dll Thu 15 Mar 2007 18:16:48 A.... 236 928 231,38 K
                  wininet.dll Tue 27 Feb 2007 15:26:24 A.... 822 784 803,50 K
                  winsrv.dll Sat 17 Mar 2007 15:44:48 A.... 293 376 286,50 K
                  xpsp3res.dll Fri 9 Mar 2007 13:51:20 A.... 265 216 259,00 K

                  29 items found: 29 files, 0 directories.
                  Total of file sizes: 18 985 216 bytes 18,11 M
                  Locate .tmp files:

                  C:\WINDOWS\SYSTEM32\
                  mcrh.tmp Sun 8 Apr 2007 22:27:30 A.... 97 0,09 K

                  1 item found: 1 file, 0 directories.
                  Total of file sizes: 97 bytes 0,09 K
                  **********************************************************************************
                  Directory Listing of system files:
                  Le volume dans le lecteur C s'appelle HP_PAVILION
                  Le num‚ro de s‚rie du volume est 947E-5624

                  R‚pertoire de C:\WINDOWS\System32

                  11/05/2007 16:06 1ÿ488ÿ819 mqmddtcm.ini
                  03/05/2007 19:39 1ÿ184 qukjjpri.ini
                  27/04/2007 16:36 534 auiqtyfd.ini
                  3 fichier(s) 1ÿ490ÿ537 octets
                  0 R‚p(s) 63ÿ093ÿ006ÿ336 octets libres

                  A quoi servent tous ces rapports ? et Maintenant ? merci
                  1. Modérateur
                    Salut :)

                    télécharge l2mfix ici:
                    http://www.downloads.subratam.org/l2mfix.exe
                    Double-cliquer sur l2mfix.exe pour lancer l'extraction
                    Dans le dossier l2mfix, double clic sur l2mfix.bat, appuyer sur n'importe quelle touche puis choisir l'option #1 (et pas autre chose) et valider avec la touche entre.
                    Le bloc note va s'ouvrir avec le résultat du scan.copie/colles le rapport ici

                    ++
                    1. "HP_Propri‚taire" - 2007-05-17 15:17:26 Service Pack 2
                      ComboFix 07-05.17.6.V - Running from: "C:\Documents and Settings\HP_Propri‚taire\Mes documents\"

                      (((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))

                      C:\WINDOWS\system32\nmgyfpse.dll
                      C:\WINDOWS\system32\otujcdkt.dll
                      C:\WINDOWS\system32\ynsjyrro.dll
                      C:\WINDOWS\system32\hgjlm.bak1
                      C:\WINDOWS\system32\hgjlm.bak2
                      C:\WINDOWS\system32\hgjlm.ini
                      C:\WINDOWS\system32\hgjlm.ini2
                      C:\WINDOWS\system32\hgjlm.tmp
                      C:\WINDOWS\system32\tkdcjuto.ini
                      C:\WINDOWS\system32\tkdcjuto.ini2
                      C:\WINDOWS\system32\tkdcjuto.tmp
                      C:\WINDOWS\system32\mljgh.dll

                      * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

                      ((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-17 ))))))))))))))))))))))))))))))))))

                      2007-05-12 09:49 65,536 --a------ C:\WINDOWS\IFinst27.exe
                      2007-05-09 21:02 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
                      2007-05-06 15:58 <REP> d-------- C:\DOCUME~1\HP_PRO~1\APPLIC~1\Hamachi
                      2007-05-06 15:56 26,056 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
                      2007-05-06 15:56 <REP> d-------- C:\Program Files\Hamachi
                      2007-05-02 16:40 <REP> d-------- C:\WINDOWS\BDOSCAN8
                      2007-05-01 12:58 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
                      2007-04-22 15:52 <REP> d-------- C:\VundoFix Backups
                      2007-04-19 14:56 83,536 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
                      2007-04-19 14:56 59,984 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
                      2007-04-19 14:56 52,304 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
                      2007-04-19 14:56 39,248 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys
                      2007-04-19 14:56 26,064 --a------ C:\WINDOWS\system32\drivers\kcom.sys
                      2007-04-19 14:56 <REP> d-------- C:\Program Files\Spyware Doctor
                      2007-04-19 14:56 <REP> d-------- C:\DOCUME~1\HP_PRO~1\APPLIC~1\PC Tools
                      2007-04-19 14:55 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll

                      (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

                      2007-05-17 13:27:53 -------- d-----w C:\Program Files\Wanadoo
                      2007-05-16 16:52:04 -------- d-----w C:\Program Files\Gravity
                      2007-05-12 09:02:10 -------- d-----w C:\Program Files\Windows Live Safety Center
                      2007-05-06 14:15:33 -------- d-----w C:\Program Files\Warcraft III
                      2007-05-01 14:44:32 -------- d-----w C:\Program Files\Brochette Online V2
                      2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
                      2007-04-30 15:41:55 85,952 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
                      2007-04-30 15:41:42 94,552 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
                      2007-04-30 15:39:41 23,416 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
                      2007-04-30 15:38:51 43,176 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
                      2007-04-30 15:37:23 26,888 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
                      2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr
                      2007-04-08 17:36:49 -------- d-----w C:\DOCUME~1\HP_PRO~1\APPLIC~1\Screenshot Sender
                      2007-04-02 07:42:34 -------- d-----w C:\Program Files\MyProduct
                      2007-03-31 08:54:20 -------- d-----w C:\Program Files\FRose
                      2007-03-25 13:18:44 84,156 ----a-w C:\WINDOWS\system32\perfc00C.dat
                      2007-03-25 13:18:44 506,460 ----a-w C:\WINDOWS\system32\perfh00C.dat
                      2007-03-24 21:01:00 64,776 ----a-w C:\DOCUME~1\HP_PRO~1\APPLIC~1\GDIPFONTCACHEV1.DAT
                      2007-03-20 17:11:04 -------- d-----w C:\Program Files\Fichiers communs\LogiShrd
                      2007-03-18 13:46:42 -------- d-----w C:\Program Files\Logitech
                      2007-03-17 13:44:47 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
                      2007-03-14 16:15:12 -------- d-----w C:\Program Files\Messenger Plus! Live
                      2007-03-08 15:37:50 578,560 ----a-w C:\WINDOWS\system32\user32.dll
                      2007-03-08 15:37:50 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
                      2007-03-08 15:37:50 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
                      2007-03-08 15:33:58 1,843,712 ----a-w C:\WINDOWS\system32\win32k.sys
                      2007-02-23 13:23:32 28 ----a-w C:\WINDOWS\mscpt.dat
                      2007-02-12 09:56:55 111,992 ----a-w C:\WINDOWS\War3Unin.dat
                      2007-02-07 23:24:46 323,624 ----a-w C:\WINDOWS\system32\wiaaut.dll
                      2007-02-05 20:19:06 185,344 ----a-w C:\WINDOWS\system32\upnphost.dll

                      (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

                      *Note* empty entries & legit default entries are not shown

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
                      {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 09:56]
                      {733FD72F-103E-4B9E-BCB9-A76064AF3C72}=C:\WINDOWS\system32\gebyabb.dll []
                      {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll [2006-10-12 03:25]
                      {9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-04-17 13:32]
                      {AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar3.dll [2007-01-20 00:56]
                      {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=C:\Program Files\Windows Live Toolbar\msntb.dll [2006-09-27 18:45]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2006-10-07 14:20]
                      "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04]
                      "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-08 05:05]
                      "HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 08:35]
                      "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-05-05 01:21]
                      "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 22:43]
                      "AlcxMonitor"="ALCXMNTR.EXE" []
                      "HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 07:12]
                      "WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49]
                      "WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55]
                      "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 17:42]
                      "KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44]
                      "LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 02:12]
                      "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2007-02-08 02:13]
                      "SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-04-27 16:26]

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "WOOKIT"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55]
                      "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 20:00]
                      "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-01-31 18:39]
                      "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:55]

                      [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
                      "^SetupICWDesktop"=""

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                      "{733FD72F-103E-4B9E-BCB9-A76064AF3C72}"="C:\WINDOWS\system32\gebyabb.dll" []
                      "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 16:13]

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                      Authentication Packages msv1_0
                      Security Packages kerberos msv1_0 schannel wdigest
                      Notification Packages scecli

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice]

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice]

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                      HTTPFilter HTTPFilter
                      LocalService Alerter WebClient LmHosts RemoteRegistry upnphost SSDPSRV
                      NetworkService DnsCache
                      DcomLaunch DcomLaunch TermService
                      rpcss RpcSs
                      imgsvc StiSvc
                      termsvcs TermService
                      WudfServiceGroup WUDFSvc

                      HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

                      Contents of the 'Scheduled Tasks' folder
                      C:\WINDOWS\tasks\Symantec NetDetect.job
                      C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job

                      ********************************************************************

                      catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
                      Rootkit scan 2007-05-17 15:27:19
                      Windows 5.1.2600 Service Pack 2 NTFS

                      scanning hidden processes ...

                      scanning hidden autostart entries ...

                      scanning hidden files ...

                      scan completed successfully
                      hidden files: 0

                      ********************************************************************

                      Completion time: 2007-05-17 15:33:02 - machine was rebooted
                      C:\ComboFix-quarantined-files.txt ... 2007-05-17 15:33

                      --- E O F ---

                      Et Maintenant ? rien est arrangé.
                      1. Modérateur
                        Bonjour :)

                        c'est pas encore fini :)

                        Télécharge ComboFix (par sUBs) d'un de ces liens sur ton bureau:

                        http://www.techsupportforum.com/sectools/combofix.exe

                        http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                        Double clique combofix.exe et suis les invites

                        Poste le rapport stp

                        ++
                        1. ---------------------------------------------------------
                          AVG Anti-Spyware - Rapport d'analyse
                          ---------------------------------------------------------

                          + Créé à: 11:45:23 07/05/2007

                          + Résultat de l'analyse:

                          C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180228.dll -> Adware.ErrorSafe : Nettoyé.
                          C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180229.dll -> Adware.ErrorSafe : Nettoyé.
                          C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180230.exe -> Adware.ErrorSafe : Nettoyé.
                          C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180231.dll -> Adware.ErrorSafe : Nettoyé.
                          C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180232.exe -> Adware.ErrorSafe : Nettoyé.
                          C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180233.exe -> Adware.WinFixer : Nettoyé.
                          C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP371\A0180467.dll -> Dropper.Agent.bhc : Nettoyé.
                          C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@ad.adocean[1].txt -> TrackingCookie.Adocean : Nettoyé.
                          C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@searchportal.information[1].txt -> TrackingCookie.Information : Nettoyé.
                          C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@www.paypal[1].txt -> TrackingCookie.Paypal : Nettoyé.
                          C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@revsci[2].txt -> TrackingCookie.Revsci : Nettoyé.
                          C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@specificclick[2].txt -> TrackingCookie.Specificclick : Nettoyé.
                          C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.

                          Fin du rapport

                          Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                          Scan saved at 12:23:35, on 07/05/2007
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          C:\WINDOWS\System32\FTRTSVC.exe
                          C:\Program Files\Spyware Doctor\svcntaux.exe
                          C:\Program Files\Spyware Doctor\swdsvc.exe
                          C:\WINDOWS\system32\svchost.exe
                          c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Spyware Doctor\SDTrayApp.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\windows\system\hpsysdrv.exe
                          C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\WINDOWS\ALCXMNTR.EXE
                          C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                          C:\Program Files\iPod\bin\iPodService.exe
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                          C:\HP\KBD\KBD.EXE
                          C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                          C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                          C:\PROGRA~1\Wanadoo\ComComp.exe
                          C:\Program Files\MSN Messenger\msnmsgr.exe
                          C:\PROGRA~1\Wanadoo\Toaster.exe
                          C:\PROGRA~1\Wanadoo\Inactivity.exe
                          C:\PROGRA~1\Wanadoo\PollingModule.exe
                          C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                          C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
                          C:\PROGRA~1\Wanadoo\Watch.exe
                          C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                          C:\Documents and Settings\HP_Propriétaire\Bureau\HiJackThis_v2.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://store.hp.com/us/en?jumpid=re_r11662_redirect_ETR
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                          O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\xjrnhngp.dll
                          O2 - BHO: (no name) - {733FD72F-103E-4B9E-BCB9-A76064AF3C72} - C:\WINDOWS\system32\gebyabb.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                          O2 - BHO: (no name) - {7E022C3D-B859-42F0-8AF4-23B986CC26F0} - C:\WINDOWS\system32\mljgh.dll
                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                          O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\nmgyfpse.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                          O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                          O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                          O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                          O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                          O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
                          O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                          O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
                          O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
                          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                          O4 - HKLM\..\Run: [WindowsService] rundll32.exe "C:\WINDOWS\system32\mctddmqm.dll",realset
                          O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                          O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
                          O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                          O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                          O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                          O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                          O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                          O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                          O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                          O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                          O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
                          O20 - Winlogon Notify: mljgh - C:\WINDOWS\system32\mljgh.dll
                          O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                          O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
                          O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
                          O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
                          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                          O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
                          O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
                          O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                          O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                          O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
                          O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
                          O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
                          O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
                          O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files\Spyware Doctor\svcntaux.exe
                          O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
                          O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                          O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
                          O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
                          O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
                          O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
                          1. Modérateur
                            Salut

                            supprime ces deux logiciels :

                            WinAntiSpyware 2006 Scanner
                            Error Safe Free


                            ensuite refais un scan avec avg et poste le ainsi qu'un nouveau hijack

                            ++
                            1. ---------------------------------------------------------
                              AVG Anti-Spyware - Rapport d'analyse
                              ---------------------------------------------------------

                              + Créé à: 14:51:34 01/05/2007

                              + Résultat de l'analyse:

                              HKU\S-1-5-21-1558018719-2868653155-1144433344-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{56F1D444-11BF-4879-A12B-79CF0177F038} -> Adware.180Solutions : Ignoré.
                              C:\Program Files\Error Safe Free\FWraper.dll -> Adware.ErrorSafe : Ignoré.
                              C:\Program Files\Error Safe Free\FxCore.dll -> Adware.ErrorSafe : Ignoré.
                              C:\Program Files\Error Safe Free\InstHelp.exe -> Adware.ErrorSafe : Ignoré.
                              C:\Program Files\Error Safe Free\MMFx.dll -> Adware.ErrorSafe : Ignoré.
                              C:\Program Files\Error Safe Free\emptyERSF.exe -> Adware.ErrorSafe : Ignoré.
                              HKLM\SOFTWARE\WinAntiSpyware 2006 Scanner -> Adware.WinAntiSpyware : Ignoré.
                              C:\Program Files\Error Safe Free\Updater.exe -> Adware.WinFixer : Ignoré.
                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP343\A0163829.exe -> Logger.Winflyer : Ignoré.
                              C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@www.paypal[1].txt -> TrackingCookie.Paypal : Ignoré.
                              C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@weborama[1].txt -> TrackingCookie.Weborama : Ignoré.

                              Fin du rapport

                              BitDefender Online Scanner

                              Rapport d'analyse généré à: Wed, May 02, 2007 - 20:35:27

                              Voie d'analyse: C:\;D:\;E:\;F:\;G:\;H:\;I:\;

                              Statistiques

                              Temps
                              03:51:12

                              Fichiers
                              529605

                              Directoires
                              6977

                              Secteurs de boot
                              3

                              Archives
                              17584

                              Paquets programmes
                              56758

                              Résultats

                              Virus identifiés
                              8

                              Fichiers infectés
                              33

                              Fichiers suspects
                              0

                              Avertissements
                              0

                              Désinfectés
                              0

                              Fichiers effacés
                              29

                              Info sur les moteurs

                              Définition virus
                              503616

                              Version des moteurs
                              AVCORE v1.0 (build 2397) (i386) (Feb 8 2007 14:24:08)

                              Analyse des plugins
                              14

                              Archive des plugins
                              38

                              Unpack des plugins
                              6

                              E-mail plugins
                              6

                              Système plugins
                              1

                              Paramètres d'analyse

                              Première action
                              Désinfecté

                              Seconde Action
                              Supprimé

                              Heuristique
                              Oui

                              Acceptez les avertissements
                              Oui

                              Extensions analysées
                              *;

                              Excludez les extensions

                              Analyse d'emails
                              Oui

                              Analyse des Archives
                              Oui

                              Analyser paquets programmes
                              Oui

                              Analyse des fichiers
                              Oui

                              Analyse de boot
                              Oui

                              Fichier analysé
                              Statut

                              C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WR34TBW5\lo1[1]
                              Infecté par: MemScan:Trojan.Vundo.AP

                              C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WR34TBW5\lo1[1]
                              Echec de la désinfection

                              C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WR34TBW5\lo1[1]
                              Supprimé

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178718.dll
                              Infecté par: Trojan.Vundo.AN

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178718.dll
                              Echec de la désinfection

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178718.dll
                              Supprimé

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178721.dll
                              Infecté par: Trojan.Virtumod.KE

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178721.dll
                              Echec de la désinfection

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178721.dll
                              Supprimé

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178722.dll
                              Infecté par: Trojan.Vundo.AN

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178722.dll
                              Echec de la désinfection

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178722.dll
                              Supprimé

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178723.dll
                              Infecté par: Trojan.Vundo.AN

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178723.dll
                              Echec de la désinfection

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178723.dll
                              Supprimé

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178724.dll
                              Infecté par: Trojan.Vundo.AN

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178724.dll
                              Echec de la désinfection

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178724.dll
                              Supprimé

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178725.dll
                              Infecté par: Trojan.Virtumod.JB

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178725.dll
                              Echec de la désinfection

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178725.dll
                              Supprimé

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178726.dll
                              Infecté par: Trojan.Vundo.AN

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178726.dll
                              Echec de la désinfection

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178726.dll
                              Supprimé

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178727.dll
                              Infecté par: Trojan.Vundo.AN

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178727.dll
                              Echec de la désinfection

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178727.dll
                              Supprimé

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178728.dll
                              Infecté par: Trojan.Vundo.AN

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178728.dll
                              Echec de la désinfection

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178728.dll
                              Supprimé

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178729.dll
                              Infecté par: Trojan.BHO.AU

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178729.dll
                              Echec de la désinfection

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178729.dll
                              Supprimé

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178730.dll
                              Infecté par: Trojan.Vundo.AN

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178730.dll
                              Echec de la désinfection

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178730.dll
                              Supprimé

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP366\A0179110.dll
                              Infecté par: Trojan.Vundo.AN

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP366\A0179110.dll
                              Echec de la désinfection

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP366\A0179110.dll
                              Supprimé

                              C:\VundoFix Backups\bkboxlgw.dll.bad
                              Infecté par: Trojan.Vundo.AN

                              C:\VundoFix Backups\bkboxlgw.dll.bad
                              Echec de la désinfection

                              C:\VundoFix Backups\bkboxlgw.dll.bad
                              Supprimé

                              C:\VundoFix Backups\gebyabb.dll.bad
                              Infecté par: MemScan:Trojan.Vundo.AJ

                              C:\VundoFix Backups\gebyabb.dll.bad
                              Echec de la désinfection

                              C:\VundoFix Backups\gebyabb.dll.bad
                              Supprimé

                              C:\VundoFix Backups\iajsddpu.dll.bad
                              Infecté par: Trojan.Virtumod.KE

                              C:\VundoFix Backups\iajsddpu.dll.bad
                              Echec de la désinfection

                              C:\VundoFix Backups\iajsddpu.dll.bad
                              Supprimé

                              C:\VundoFix Backups\idpqbycb.dll.bad
                              Infecté par: Trojan.Vundo.AN

                              C:\VundoFix Backups\idpqbycb.dll.bad
                              Echec de la désinfection

                              C:\VundoFix Backups\idpqbycb.dll.bad
                              Supprimé

                              C:\VundoFix Backups\imrnotsv.dll.bad
                              Infecté par: Trojan.Vundo.AN

                              C:\VundoFix Backups\imrnotsv.dll.bad
                              Echec de la désinfection

                              C:\VundoFix Backups\imrnotsv.dll.bad
                              Supprimé

                              C:\VundoFix Backups\inrushjs.dll.bad
                              Infecté par: Trojan.Vundo.AN

                              C:\VundoFix Backups\inrushjs.dll.bad
                              Echec de la désinfection

                              C:\VundoFix Backups\inrushjs.dll.bad
                              Supprimé

                              C:\VundoFix Backups\itdyidub.dll.bad
                              Infecté par: Trojan.Virtumod.JB

                              C:\VundoFix Backups\itdyidub.dll.bad
                              Echec de la désinfection

                              C:\VundoFix Backups\itdyidub.dll.bad
                              Supprimé

                              C:\VundoFix Backups\kccpgfkd.dll.bad
                              Infecté par: Trojan.Vundo.AN

                              C:\VundoFix Backups\kccpgfkd.dll.bad
                              Echec de la désinfection

                              C:\VundoFix Backups\kccpgfkd.dll.bad
                              Supprimé

                              C:\VundoFix Backups\mcsphway.dll.bad
                              Infecté par: Trojan.Vundo.AN

                              C:\VundoFix Backups\mcsphway.dll.bad
                              Echec de la désinfection

                              C:\VundoFix Backups\mcsphway.dll.bad
                              Supprimé

                              C:\VundoFix Backups\mjopwubb.dll.bad
                              Infecté par: Trojan.Vundo.AN

                              C:\VundoFix Backups\mjopwubb.dll.bad
                              Echec de la désinfection

                              C:\VundoFix Backups\mjopwubb.dll.bad
                              Supprimé

                              C:\VundoFix Backups\nivagsyb.dll.bad
                              Infecté par: Trojan.BHO.AU

                              C:\VundoFix Backups\nivagsyb.dll.bad
                              Echec de la désinfection

                              C:\VundoFix Backups\nivagsyb.dll.bad
                              Supprimé

                              C:\VundoFix Backups\ptfvarem.dll.bad
                              Infecté par: Trojan.Vundo.AN

                              C:\VundoFix Backups\ptfvarem.dll.bad
                              Echec de la désinfection

                              C:\VundoFix Backups\ptfvarem.dll.bad
                              Supprimé

                              C:\VundoFix Backups\thrkujyq.dll.bad
                              Infecté par: Trojan.Vundo.AN

                              C:\VundoFix Backups\thrkujyq.dll.bad
                              Echec de la désinfection

                              C:\VundoFix Backups\thrkujyq.dll.bad
                              Supprimé

                              C:\WINDOWS\system32\gebyabb.dll
                              Infecté par: MemScan:Trojan.Vundo.AJ

                              C:\WINDOWS\system32\gebyabb.dll
                              Echec de la désinfection

                              C:\WINDOWS\system32\gebyabb.dll
                              Echec de la suppression

                              C:\WINDOWS\system32\lfwwgggh.dll
                              Infecté par: Trojan.Vundo.AN

                              C:\WINDOWS\system32\lfwwgggh.dll
                              Echec de la désinfection

                              C:\WINDOWS\system32\lfwwgggh.dll
                              Supprimé

                              C:\WINDOWS\system32\mljgh.dll
                              Infecté par: MemScan:Trojan.Vundo.AP

                              C:\WINDOWS\system32\mljgh.dll
                              Echec de la désinfection

                              C:\WINDOWS\system32\mljgh.dll
                              Echec de la suppression

                              C:\WINDOWS\system32\nmgyfpse.dll
                              Infecté par: Trojan.Vundo.DLP

                              C:\WINDOWS\system32\nmgyfpse.dll
                              Echec de la désinfection

                              C:\WINDOWS\system32\nmgyfpse.dll
                              Echec de la suppression

                              C:\WINDOWS\system32\pkawxcdt.dll
                              Infecté par: Trojan.Vundo.AN

                              C:\WINDOWS\system32\pkawxcdt.dll
                              Echec de la désinfection

                              C:\WINDOWS\system32\pkawxcdt.dll
                              Supprimé

                              C:\WINDOWS\system32\qlluclsp.dll
                              Infecté par: Trojan.Vundo.AO

                              C:\WINDOWS\system32\qlluclsp.dll
                              Echec de la désinfection

                              C:\WINDOWS\system32\qlluclsp.dll
                              Supprimé

                              C:\WINDOWS\system32\xjrnhngp.dll
                              Infecté par: Trojan.Vundo.AO

                              C:\WINDOWS\system32\xjrnhngp.dll
                              Echec de la désinfection

                              C:\WINDOWS\system32\xjrnhngp.dll
                              Echec de la suppression

                              Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                              Scan saved at 20:51:18, on 02/05/2007
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\csrss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              C:\WINDOWS\System32\FTRTSVC.exe
                              C:\Program Files\Spyware Doctor\svcntaux.exe
                              C:\windows\system\hpsysdrv.exe
                              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\WINDOWS\ALCXMNTR.EXE
                              C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              C:\HP\KBD\KBD.EXE
                              C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                              C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                              C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
                              C:\WINDOWS\system32\rundll32.exe
                              C:\Program Files\Spyware Doctor\SDTrayApp.exe
                              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                              C:\PROGRA~1\Wanadoo\ComComp.exe
                              C:\Program Files\MSN Messenger\msnmsgr.exe
                              C:\PROGRA~1\Wanadoo\Toaster.exe
                              C:\PROGRA~1\Wanadoo\Inactivity.exe
                              C:\PROGRA~1\Wanadoo\PollingModule.exe
                              C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
                              c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                              C:\PROGRA~1\Wanadoo\Watch.exe
                              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\WINDOWS\System32\alg.exe
                              C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                              C:\Program Files\Outlook Express\msimn.exe
                              C:\Program Files\Spyware Doctor\swdsvc.exe
                              C:\Program Files\Internet Explorer\IEXPLORE.EXE
                              C:\Documents and Settings\HP_Propriétaire\Bureau\HiJackThis_v2.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://store.hp.com/us/en?jumpid=re_r11662_redirect_ETR
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                              O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\xjrnhngp.dll
                              O2 - BHO: (no name) - {733FD72F-103E-4B9E-BCB9-A76064AF3C72} - C:\WINDOWS\system32\gebyabb.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                              O2 - BHO: (no name) - {76F94FCB-1281-494D-BC0C-0756C7F7FA47} - C:\WINDOWS\system32\mljgh.dll
                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                              O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\nmgyfpse.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                              O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                              O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                              O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                              O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                              O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
                              O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                              O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
                              O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\itdyidub.dll",setvm
                              O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
                              O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\irpjjkuq.dll",realset
                              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                              O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
                              O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                              O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                              O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                              O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                              O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                              O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                              O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                              O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                              O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
                              O17 - HKLM\System\CCS\Services\Tcpip\..\{34CB4B96-6783-4D74-AC33-1375619936AA}: NameServer = 80.10.246.1 80.10.246.132
                              O17 - HKLM\System\CS1\Services\Tcpip\..\{34CB4B96-6783-4D74-AC33-1375619936AA}: NameServer = 80.10.246.1 80.10.246.132
                              O20 - Winlogon Notify: mljgh - C:\WINDOWS\system32\mljgh.dll
                              O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                              O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
                              O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
                              O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
                              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                              O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
                              O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
                              O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                              O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                              O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
                              O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
                              O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
                              O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
                              O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files\Spyware Doctor\svcntaux.exe
                              O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
                              O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                              O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
                              O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
                              O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
                              O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
                              1. Modérateur
                                Salut

                                fais les manips de ce lien stp :

                                virus methode preliminaire de desinfection version fr

                                ++
                                • 1
                                • 2