Pb virus internet

Bonjour,

Depuis déjà plusieurs semaines j'ai des virus (cheval de troie, logiciels espions et malveillants...) sur mon ordinatuer ainsi que sans arrêt l'affichage de page intempestive "Drive cleaner" qui sont des virus. J'ai essayé de m'en débarasser avec Avast, Ccleaner, spyware doctor mais rien n'y fait mon pc est de plus en plus lent et jen ai assez. Ne sacahant plus trop quoi faire je m'adresse a vous en vous demandant votre aide svp. Je suis loin d'être un expert en informatique.

En attendant votre réponse je vous remercie encore

Jeremich56@wanadoo.fr
Configuration: Windows XP
Internet Explorer 7.0

28 réponses

Résumé de la discussion

Le fil porte sur une infection informatique sous Windows XP associant cheval de Troie, logiciels espions et affichages intempestifs de Drive Cleaner qui ralentissent significativement l’ordinateur. Plusieurs conseils visent à identifier et supprimer les composants malveillants grâce à des outils spécialisés et à des nettoyages manuels, notamment HiJackThis, ComboFix et des rapports d’analyse. Des propositions couvrent la suppression de processus et fichiers douteux, la vérification des entrées de démarrage et des éléments de registre, ainsi que des scans en mode sans échec. En cas de persistance, certains participants recommandent d’établir un plan de nettoyage progressif et de surveiller les restes potentiels dans l’historique des cookies et des fichiers temporaires.

Bobot (l’IA à votre service)
  1. Bien,
    sur MSN, tu n'as pas encore vu de poulet rotis ? (euhh, ma question est sérieuse !)
    il sagit de ceci:
    http://vil.nai.com/vil/content/v_131539.htm
    regarde l'article ici:
    http://www.microsoft.com/france/securite/bulletins/2005/200502_msnmessenger.mspx
    --------------------------
    MSN est tellement cibler et vulnérable que je déconseille son usage...il y a des alternatives !
    https://www.luanagames.com/index.fr.html
    ----------------------------
    ensuite:
    fais ceci:
    Téléchargez MSNFix.zip (de !aur3n7) sur votre bureau:
    http://sosvirus.changelog.fr/MSNFix.zip

    Décompressez-le (clic droit >> Extraire ici) et double cliquer sur le fichier MSNFix.bat.
    - Exécutez l'option R.
    -- Si l'infection est détectée, exécutez l'option N.
    --- Sauvegardez ce rapport puis faites un copier/coller de ce rapport sur le forum, ainsi qu'un nouveau scan HijackThis fait en mode normal.

    Note :
    Suivant la variante détectée il est possible qu'un message vous demande d'exécuter le nettoyage en mode sans échec. dans ce cas :

    ---Redémarrer votre ordinateur
    - Au démarrage de l'ordinateur "tapotez" la touche F8 de ton clavier jusqu'à ce que les options de démarrage apparaissent.
    * A l'aide des touches de ton clavier descend jusque Mode sans échec puis valide par la touche [entrée]
    -- Si le choix est proposé choisis le même nom d'utilisateur qu'en mode normal.

    puis relancez le Fix comme décrit plus haut. (n'oubliez pas de sauvegardez le rapport)
    0
    1. Je n'ai plus de fenêtres intempestives qui s'ouvre sans arrêt m'annonçant des virus mais mon pc a toujours une certaine lenteur sinon j'ai également 2 autres problèmes de nature différente :

      - Sur MSN Messenger, les emoticones ne s'affiche plus
      - Mon lecteur CD / DVD sur mon pc ne lis plus les CD et DVD

      Merci
      0
      1. Tu as raison, les avis sont partagés sur ce "ALCXMNTR.exe"
        Personnellement, je pense que tu peux fixer cette ligne sans aucun soucis. Je l'ai déja fait fixer sur des PC, et aucune conséquence constatée.
        Si on se fie à : bleepingcomputer.com !
        https://www.bleepingcomputer.com/startups/Alcxmntr.exe-245.html
        Perso je fais fixer.
        Bonne journée à toi.

        0
        1. Modérateur
          Salut

          si tu parles de ceci :

          Impossible de supprimer C:\WINDOWS\ALCXMNTR.EXE


          c'est pas méchant du tout ... :)

          ++
          0
          1. salut à tous,
            Je referais l'option 2 de clean en mode sans échec.
            A examiner le log en <22> il n'a pas su faire son travail correctement...
            0
            1. Modérateur
              Salut

              où en sont tes soucis ???

              ++
              0
              1. 27/05/2007 a 15:54:53,40

                *** Recherche des fichiers dans C:

                *** Recherche des fichiers dans C:\WINDOWS\
                C:\WINDOWS\ALCXMNTR.EXE FOUND

                *** Recherche des fichiers dans C:\WINDOWS\system32
                C:\WINDOWS\system32\mcrh.tmp FOUND

                *** Recherche des fichiers dans C:\Program Files
                "C:\Program Files\Viewpoint\" FOUND
                *** Fin du rapport !

                Rapport clean par Malekal_morte - http://www.malekal.com
                Script execute en mode sans echec 27/05/2007 a 15:57:24,06

                Microsoft Windows XP [version 5.1.2600]

                *** Suppression des fichiers dans C:

                *** Suppression des fichiers dans C:\WINDOWS\
                tentative de suppression de C:\WINDOWS\ALCXMNTR.EXE
                Impossible de supprimer C:\WINDOWS\ALCXMNTR.EXE

                *** Suppression des fichiers dans C:\WINDOWS\system32
                tentative de suppression de C:\WINDOWS\system32\mcrh.tmp

                *** Suppression des fichiers dans C:\Program Files
                tentative de suppression de "C:\Program Files\Viewpoint\"

                *** Suppression des clefs du registre effectuee..
                *** Fin du rapport !
                0
                1. Modérateur
                  Salut

                  Pour supprimer ces fichiers, il suffit de passer à l'option 2 du fix :-)

                  ++
                  0
                  1. recherches ceci dans ton PC:
                    --------------------------------------------
                    mqmddtcm.ini
                    qukjjpri.ini
                    auiqtyfd.ini
                    supprimes-les
                    si ça ne vas pas, fais le en mode sans échec
                    https://leblogdeclaude.blogspot.com/2007/04/informatique-rebooter-xp-en-mode-sans.html

                    ---------------------------------------
                    download ceci:
                    http://www.malekal.com/download/clean.zip
                    Décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier dénommé "clean ".
                    Redémarre en mode sans échec. ( note bien ce que tu as à faire ).
                    Ouvre le dossier « clean » qui se trouve sur ton bureau.
                    Double-clic sur « clean.cmd ».
                    Une fenêtre noire va apparaître, suis les consignes
                    fais l'option1 et 2
                    poste le log
                    Où est le rapport clean ? : « Poste de travail » / double clic sur disque « C / » double-clic sur « rapport_clean.txt » et « copier/coller le contenu » sur le forum.

                    0
                    1. L2MFIX find log 051206
                      These are the registry keys present
                      **********************************************************************************
                      Winlogon/notify:
                      Windows Registry Editor Version 5.00

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
                      "DLLName"="Ati2evxx.dll"
                      "Asynchronous"=dword:00000000
                      "Impersonate"=dword:00000001
                      "Lock"="AtiLockEvent"
                      "Logoff"="AtiLogoffEvent"
                      "Logon"="AtiLogonEvent"
                      "Disconnect"="AtiDisConnectEvent"
                      "Reconnect"="AtiReConnectEvent"
                      "Safe"=dword:00000000
                      "Shutdown"="AtiShutdownEvent"
                      "StartScreenSaver"="AtiStartScreenSaverEvent"
                      "StartShell"="AtiStartShellEvent"
                      "Startup"="AtiStartupEvent"
                      "StopScreenSaver"="AtiStopScreenSaverEvent"
                      "Unlock"="AtiUnLockEvent"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
                      "Asynchronous"=dword:00000000
                      "Impersonate"=dword:00000000
                      "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
                      6c,00,00,00
                      "Logoff"="ChainWlxLogoffEvent"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
                      "Asynchronous"=dword:00000000
                      "Impersonate"=dword:00000000
                      "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
                      6c,00,6c,00,00,00
                      "Logoff"="CryptnetWlxLogoffEvent"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
                      "DLLName"="cscdll.dll"
                      "Logon"="WinlogonLogonEvent"
                      "Logoff"="WinlogonLogoffEvent"
                      "ScreenSaver"="WinlogonScreenSaverEvent"
                      "Startup"="WinlogonStartupEvent"
                      "Shutdown"="WinlogonShutdownEvent"
                      "StartShell"="WinlogonStartShellEvent"
                      "Impersonate"=dword:00000000
                      "Asynchronous"=dword:00000001

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
                      "DLLName"="wlnotify.dll"
                      "Logon"="SCardStartCertProp"
                      "Logoff"="SCardStopCertProp"
                      "Lock"="SCardSuspendCertProp"
                      "Unlock"="SCardResumeCertProp"
                      "Enabled"=dword:00000001
                      "Impersonate"=dword:00000001
                      "Asynchronous"=dword:00000001

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
                      "Asynchronous"=dword:00000000
                      "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                      6c,00,6c,00,00,00
                      "Impersonate"=dword:00000000
                      "StartShell"="SchedStartShell"
                      "Logoff"="SchedEventLogOff"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
                      "Logoff"="WLEventLogoff"
                      "Impersonate"=dword:00000000
                      "Asynchronous"=dword:00000001
                      "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
                      6c,00,6c,00,00,00

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
                      "DLLName"="WlNotify.dll"
                      "Lock"="SensLockEvent"
                      "Logon"="SensLogonEvent"
                      "Logoff"="SensLogoffEvent"
                      "Safe"=dword:00000001
                      "MaxWait"=dword:00000258
                      "StartScreenSaver"="SensStartScreenSaverEvent"
                      "StopScreenSaver"="SensStopScreenSaverEvent"
                      "Startup"="SensStartupEvent"
                      "Shutdown"="SensShutdownEvent"
                      "StartShell"="SensStartShellEvent"
                      "PostShell"="SensPostShellEvent"
                      "Disconnect"="SensDisconnectEvent"
                      "Reconnect"="SensReconnectEvent"
                      "Unlock"="SensUnlockEvent"
                      "Impersonate"=dword:00000001
                      "Asynchronous"=dword:00000001

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
                      "Asynchronous"=dword:00000000
                      "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                      6c,00,6c,00,00,00
                      "Impersonate"=dword:00000000
                      "Logoff"="TSEventLogoff"
                      "Logon"="TSEventLogon"
                      "PostShell"="TSEventPostShell"
                      "Shutdown"="TSEventShutdown"
                      "StartShell"="TSEventStartShell"
                      "Startup"="TSEventStartup"
                      "MaxWait"=dword:00000258
                      "Reconnect"="TSEventReconnect"
                      "Disconnect"="TSEventDisconnect"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
                      "Logon"="WLEventLogon"
                      "Logoff"="WLEventLogoff"
                      "Startup"="WLEventStartup"
                      "Shutdown"="WLEventShutdown"
                      "StartScreenSaver"="WLEventStartScreenSaver"
                      "StopScreenSaver"="WLEventStopScreenSaver"
                      "Lock"="WLEventLock"
                      "Unlock"="WLEventUnlock"
                      "StartShell"="WLEventStartShell"
                      "PostShell"="WLEventPostShell"
                      "Disconnect"="WLEventDisconnect"
                      "Reconnect"="WLEventReconnect"
                      "Impersonate"=dword:00000001
                      "Asynchronous"=dword:00000000
                      "SafeMode"=dword:00000001
                      "MaxWait"=dword:ffffffff
                      "DllName"=hex(2):57,00,67,00,61,00,4c,00,6f,00,67,00,6f,00,6e,00,2e,00,64,00,\
                      6c,00,6c,00,00,00
                      "Event"=dword:00000002
                      "EulaAccepted"=dword:00000000

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon\Settings]
                      "Data"=hex:01,00,00,00,d0,8c,9d,df,01,15,d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,\
                      00,00,fc,7d,35,12,1a,d0,ae,4e,bd,9a,7b,21,c3,27,79,46,04,00,00,00,04,00,00,\
                      00,53,00,00,00,03,66,00,00,a8,00,00,00,10,00,00,00,ab,a3,c0,77,84,9a,a2,c9,\
                      c1,9d,12,dc,30,a8,76,0c,00,00,00,00,04,80,00,00,a0,00,00,00,10,00,00,00,a1,\
                      cb,7c,f5,49,3d,59,22,4b,8c,e3,b2,30,5a,6a,64,b0,01,00,00,e3,81,6d,55,c1,0e,\
                      ed,77,3f,8c,83,ca,51,e3,17,9c,2b,b1,f3,ab,a0,db,cb,d2,d0,26,74,8b,e8,2d,6f,\
                      7f,1d,73,aa,d9,16,1d,e4,3f,9a,e9,83,3b,40,13,4b,50,83,39,c7,64,00,71,e0,d4,\
                      b9,3d,c2,f2,f7,4a,b3,3f,95,12,80,8c,3a,7d,0d,db,26,b7,01,d0,94,00,91,ae,b7,\
                      29,32,c1,d2,cd,0b,c7,c6,09,4d,d2,55,46,66,64,6d,a0,fe,0d,0a,19,90,ae,85,0c,\
                      7a,76,26,d7,5d,b3,05,65,77,2e,5c,c1,c0,9f,5d,67,0b,0c,3e,3f,4c,35,cc,e0,8c,\
                      8b,fc,e5,a9,f3,51,c1,60,17,28,5b,6d,eb,4a,7f,2b,7e,f6,e9,37,77,b1,02,76,0e,\
                      88,d5,ab,4f,d7,a3,5a,41,99,e0,41,43,69,f1,67,13,46,c6,96,11,28,0a,30,ef,3b,\
                      fb,a4,9c,2c,06,0a,c1,1f,fd,f5,39,14,03,15,c1,06,d2,b3,c7,1c,b6,0b,18,75,71,\
                      e7,16,2e,18,39,42,78,62,54,43,4a,7d,ec,54,18,4c,41,c7,36,05,81,4d,70,c3,3a,\
                      f6,70,ff,91,c6,9b,1e,10,aa,e3,5f,0f,26,77,3c,33,e2,1e,6c,18,8f,b1,c1,9b,6e,\
                      a2,a0,fa,21,2d,ae,2c,72,86,6e,d8,3b,70,e7,b2,14,cd,75,cb,88,ef,eb,76,2d,54,\
                      49,23,78,5f,14,ae,5b,b3,6d,0c,f5,d9,7d,64,1d,49,f1,2b,f9,cf,56,c5,49,6b,cb,\
                      b2,ce,d8,43,f2,44,47,c7,ce,f1,1c,be,17,20,ac,64,cf,b2,b8,50,51,dc,18,cd,96,\
                      94,53,56,e3,76,80,90,39,62,b3,03,a1,63,4a,74,1b,73,74,35,ab,75,2c,ed,0f,79,\
                      01,de,09,43,9e,44,79,1d,f3,44,ea,09,02,1c,fc,a3,75,f9,f7,51,0c,70,64,df,8a,\
                      f4,8c,cf,87,2d,32,95,79,f2,77,1c,c9,16,7f,a8,db,92,3c,42,69,57,06,88,c3,ca,\
                      c3,bf,15,fc,86,00,f2,1a,04,e1,df,dd,33,73,c6,e8,b0,58,0a,36,06,55,ae,4d,47,\
                      8f,14,00,00,00,f7,21,dc,ec,9b,09,b8,cf,2c,3b,c7,49,fe,6d,ad,e1,fd,36,38,6b

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
                      "DLLName"="wlnotify.dll"
                      "Logon"="RegisterTicketExpiredNotificationEvent"
                      "Logoff"="UnregisterTicketExpiredNotificationEvent"
                      "Impersonate"=dword:00000001
                      "Asynchronous"=dword:00000001

                      **********************************************************************************
                      useragent:
                      Windows Registry Editor Version 5.00

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                      "Wanadoo 7.1 ; NaviWoo1.1"="IEAKFT"

                      **********************************************************************************
                      Shell Extension key:
                      Windows Registry Editor Version 5.00

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
                      "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
                      "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
                      "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
                      "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
                      "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                      "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
                      "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
                      "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
                      "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
                      "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
                      "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Page de compatibilit‚"
                      "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'environnement"
                      "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
                      "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'environnement pour les objets r‚seau de Microsoft Windows"
                      "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
                      "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
                      "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensions de l'environnement de compression de fichiers"
                      "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension de l'environnement d'imprimante Web"
                      "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
                      "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu contextuel de cryptage"
                      "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
                      "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extension ic“ne HyperTerminal"
                      "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
                      "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
                      "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
                      "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                      "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
                      "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
                      "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
                      "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau"
                      "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Connexions r‚seau"
                      "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Scanneurs et appareils photo"
                      "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Scanneurs et appareils photo"
                      "{905667aa-acd6-11d2-8080-00805f6596d2}"="&Scanneurs et appareils photo"
                      "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Scanneurs et appareils photo"
                      "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Scanneurs et appareils photo"
                      "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
                      "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensions de l'interpr‚teur de commandes pour l'environnement d'ex‚cution de scripts Windows"
                      "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Liaison de donn‚es Microsoft"
                      "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
                      "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
                      "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
                      "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
                      "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
                      "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barre des tƒches et menu D‚marrer"
                      "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Rechercher"
                      "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                      "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                      "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ex‚cuter..."
                      "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
                      "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Courrier ‚lectronique"
                      "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Polices"
                      "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Outils d'administration"
                      "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Page de propri‚t‚s des versions pr‚c‚dentes"
                      "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Versions pr‚c‚dentes"
                      "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
                      "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
                      "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
                      "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
                      "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
                      "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
                      "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
                      "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
                      "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
                      "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
                      "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
                      "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
                      "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="IE Search Band"
                      "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
                      "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
                      "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
                      "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
                      "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
                      "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
                      "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
                      "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
                      "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
                      "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
                      "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
                      "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
                      "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
                      "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
                      "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
                      "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
                      "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
                      "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
                      "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
                      "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
                      "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
                      "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
                      "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
                      "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
                      "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
                      "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
                      "{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
                      "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                      "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                      "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
                      "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
                      "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
                      "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
                      "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
                      "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
                      "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
                      "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
                      "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                      "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                      "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
                      "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
                      "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
                      "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
                      "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
                      "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
                      "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
                      "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
                      "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
                      "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
                      "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
                      "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'applications d'environnement"
                      "{0B124F8F-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
                      "{CFCCC7A0-A282-11D1-9082-006008059382}"="Publication d'application Darwin"
                      "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
                      "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
                      "{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow"
                      "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extracteur de miniatures de fichier + GDI"
                      "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Gestionnaire de miniatures - Informations de r‚sum‚ (DOCFILES)"
                      "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
                      "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
                      "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Assistant Publication de sites Web"
                      "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Commande d'impressions via le Web"
                      "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objet Assistant de publication Shell"
                      "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Assistant Obtenir une identit‚ Passport"
                      "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Comptes d'utilisateurs"
                      "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
                      "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
                      "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
                      "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
                      "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
                      "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
                      "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
                      "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
                      "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
                      "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
                      "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
                      "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
                      "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
                      "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
                      "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
                      "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
                      "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
                      "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
                      "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
                      "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
                      "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
                      "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
                      "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
                      "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
                      "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
                      "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
                      "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
                      "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
                      "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Burn Audio CD Context Menu Handler"
                      "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Play as Playlist Context Menu Handler"
                      "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
                      "{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
                      "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
                      "{7F67036B-66F1-411A-AD85-759FB9C5B0DB}"="SampleView"
                      "{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"
                      "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Dossiers Web"
                      "{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
                      "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
                      "{472083B0-C522-11CF-8763-00608CC02F24}"="avast"
                      "{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
                      "{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
                      "{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
                      "{E0D79307-84BE-11CE-9641-444553540000}"="WinZip"
                      "{acb4a560-3606-11d3-aef4-00104bd0f92d}"="KodakShellExtension"
                      "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
                      "{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}"="Messenger Sharing Folders"
                      "{07C45BB1-4A8C-4642-A1F5-237E7215FF66}"="IE Microsoft BrowserBand"
                      "{1C1EDB47-CE22-4bbb-B608-77B48F83C823}"="IE Fade Task"
                      "{205D7A97-F16D-4691-86EF-F3075DCCA57D}"="IE Menu Desk Bar"
                      "{3028902F-6374-48b2-8DC6-9725E775B926}"="IE AutoComplete"
                      "{43886CD5-6529-41c4-A707-7B3C92C05E68}"="IE Navigation Bar"
                      "{44C76ECD-F7FA-411c-9929-1B77BA77F524}"="IE Menu Site"
                      "{4B78D326-D922-44f9-AF2A-07805C2A3560}"="IE Menu Band"
                      "{6038EF75-ABFC-4e59-AB6F-12D397F6568D}"="IE Microsoft History AutoComplete List"
                      "{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}"="IE Tracking Shell Menu"
                      "{6CF48EF8-44CD-45d2-8832-A16EA016311B}"="IE IShellFolderBand"
                      "{73CFD649-CD48-4fd8-A272-2070EA56526B}"="IE BandProxy"
                      "{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}"="IE MRU AutoComplete List"
                      "{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}"="IE RSS Feeder Folder"
                      "{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}"="IE Microsoft Shell Folder AutoComplete List"
                      "{B31C5FAE-961F-415b-BAF0-E697A5178B94}"="IE Microsoft Multiple AutoComplete List Container"
                      "{BC476F4C-D9D7-4100-8D4E-E043F6DEC409}"="Microsoft Browser Architecture"
                      "{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}"="IE Shell Rebar BandSite"
                      "{E6EE9AAC-F76B-4947-8260-A9F136138E11}"="IE Shell Band Site Menu"
                      "{F2CF5485-4E02-4f68-819C-B92DE9277049}"="&Links"
                      "{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}"="IE Registry Tree Options Utility"
                      "{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}"="IE User Assist"
                      "{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}"="IE Custom MRU AutoCompleted List"
                      "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
                      "{35786D3C-B075-49b9-88DD-029876E11C01}"="Portable Devices"
                      "{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8}"="Portable Devices Menu"
                      "{e82a2d71-5b2f-43a0-97b8-81be15854de8}"="ShellLink for Application References"
                      "{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}"="Shell Icon Handler for Application References"
                      "{45670FA8-ED97-4F44-BC93-305082590BFB}"="Microsoft.XPS.Shell.Metadata.1"
                      "{44121072-A222-48f2-A58A-6D9AD51EBBE9}"="Microsoft.XPS.Shell.Thumbnail.1"
                      "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"

                      **********************************************************************************
                      HKEY ROOT CLASSIDS:
                      **********************************************************************************
                      Files Found are not all bad files:

                      C:\WINDOWS\SYSTEM32\
                      advpack.dll Tue 27 Feb 2007 15:25:02 A.... 124 928 122,00 K
                      extmgr.dll Tue 27 Feb 2007 15:25:02 A.... 132 608 129,50 K
                      gdi32.dll Thu 8 Mar 2007 17:37:50 A.... 281 600 275,00 K
                      ieakeng.dll Tue 27 Feb 2007 15:25:02 A.... 153 088 149,50 K
                      ieaksie.dll Tue 27 Feb 2007 15:25:04 A.... 230 400 225,00 K
                      ieakui.dll Wed 21 Feb 2007 10:00:54 A.... 161 792 158,00 K
                      ieapfltr.dll Tue 3 Apr 2007 16:29:24 A.... 383 488 374,50 K
                      iedkcs32.dll Tue 27 Feb 2007 15:25:10 A.... 384 000 375,00 K
                      ieframe.dll Tue 27 Feb 2007 15:25:32 A.... 6 054 400 5,77 M
                      iernonce.dll Tue 27 Feb 2007 15:25:32 A.... 44 544 43,50 K
                      iertutil.dll Tue 27 Feb 2007 15:25:34 A.... 266 752 260,50 K
                      jsproxy.dll Tue 27 Feb 2007 15:25:44 A.... 27 136 26,50 K
                      legitc~1.dll Thu 15 Mar 2007 18:19:28 ..... 1 476 992 1,41 M
                      mf3216.dll Thu 8 Mar 2007 17:37:50 A.... 40 960 40,00 K
                      msfeeds.dll Tue 27 Feb 2007 15:25:46 A.... 458 752 448,00 K
                      msfeed~1.dll Tue 27 Feb 2007 15:25:46 A.... 51 712 50,50 K
                      mshtml.dll Tue 27 Feb 2007 15:25:58 A.... 3 581 952 3,41 M
                      mshtmled.dll Tue 27 Feb 2007 15:25:58 A.... 477 696 466,50 K
                      msrating.dll Tue 27 Feb 2007 15:25:58 A.... 193 024 188,50 K
                      mstime.dll Tue 27 Feb 2007 15:26:04 A.... 670 720 655,00 K
                      occache.dll Tue 27 Feb 2007 15:26:06 A.... 102 400 100,00 K
                      url.dll Tue 27 Feb 2007 15:26:06 A.... 105 984 103,50 K
                      urlmon.dll Tue 27 Feb 2007 15:26:14 A.... 1 150 464 1,09 M
                      user32.dll Thu 8 Mar 2007 17:37:50 A.... 578 560 565,00 K
                      webcheck.dll Tue 27 Feb 2007 15:26:16 A.... 232 960 227,50 K
                      wgalogon.dll Thu 15 Mar 2007 18:16:48 A.... 236 928 231,38 K
                      wininet.dll Tue 27 Feb 2007 15:26:24 A.... 822 784 803,50 K
                      winsrv.dll Sat 17 Mar 2007 15:44:48 A.... 293 376 286,50 K
                      xpsp3res.dll Fri 9 Mar 2007 13:51:20 A.... 265 216 259,00 K

                      29 items found: 29 files, 0 directories.
                      Total of file sizes: 18 985 216 bytes 18,11 M
                      Locate .tmp files:

                      C:\WINDOWS\SYSTEM32\
                      mcrh.tmp Sun 8 Apr 2007 22:27:30 A.... 97 0,09 K

                      1 item found: 1 file, 0 directories.
                      Total of file sizes: 97 bytes 0,09 K
                      **********************************************************************************
                      Directory Listing of system files:
                      Le volume dans le lecteur C s'appelle HP_PAVILION
                      Le num‚ro de s‚rie du volume est 947E-5624

                      R‚pertoire de C:\WINDOWS\System32

                      11/05/2007 16:06 1ÿ488ÿ819 mqmddtcm.ini
                      03/05/2007 19:39 1ÿ184 qukjjpri.ini
                      27/04/2007 16:36 534 auiqtyfd.ini
                      3 fichier(s) 1ÿ490ÿ537 octets
                      0 R‚p(s) 63ÿ093ÿ006ÿ336 octets libres

                      A quoi servent tous ces rapports ? et Maintenant ? merci
                      0
                      1. Modérateur
                        Salut :)

                        télécharge l2mfix ici:
                        http://www.downloads.subratam.org/l2mfix.exe
                        Double-cliquer sur l2mfix.exe pour lancer l'extraction
                        Dans le dossier l2mfix, double clic sur l2mfix.bat, appuyer sur n'importe quelle touche puis choisir l'option #1 (et pas autre chose) et valider avec la touche entre.
                        Le bloc note va s'ouvrir avec le résultat du scan.copie/colles le rapport ici

                        ++
                        0
                        1. "HP_Propri‚taire" - 2007-05-17 15:17:26 Service Pack 2
                          ComboFix 07-05.17.6.V - Running from: "C:\Documents and Settings\HP_Propri‚taire\Mes documents\"

                          (((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))

                          C:\WINDOWS\system32\nmgyfpse.dll
                          C:\WINDOWS\system32\otujcdkt.dll
                          C:\WINDOWS\system32\ynsjyrro.dll
                          C:\WINDOWS\system32\hgjlm.bak1
                          C:\WINDOWS\system32\hgjlm.bak2
                          C:\WINDOWS\system32\hgjlm.ini
                          C:\WINDOWS\system32\hgjlm.ini2
                          C:\WINDOWS\system32\hgjlm.tmp
                          C:\WINDOWS\system32\tkdcjuto.ini
                          C:\WINDOWS\system32\tkdcjuto.ini2
                          C:\WINDOWS\system32\tkdcjuto.tmp
                          C:\WINDOWS\system32\mljgh.dll

                          * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

                          ((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-17 ))))))))))))))))))))))))))))))))))

                          2007-05-12 09:49 65,536 --a------ C:\WINDOWS\IFinst27.exe
                          2007-05-09 21:02 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
                          2007-05-06 15:58 <REP> d-------- C:\DOCUME~1\HP_PRO~1\APPLIC~1\Hamachi
                          2007-05-06 15:56 26,056 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
                          2007-05-06 15:56 <REP> d-------- C:\Program Files\Hamachi
                          2007-05-02 16:40 <REP> d-------- C:\WINDOWS\BDOSCAN8
                          2007-05-01 12:58 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
                          2007-04-22 15:52 <REP> d-------- C:\VundoFix Backups
                          2007-04-19 14:56 83,536 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
                          2007-04-19 14:56 59,984 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
                          2007-04-19 14:56 52,304 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
                          2007-04-19 14:56 39,248 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys
                          2007-04-19 14:56 26,064 --a------ C:\WINDOWS\system32\drivers\kcom.sys
                          2007-04-19 14:56 <REP> d-------- C:\Program Files\Spyware Doctor
                          2007-04-19 14:56 <REP> d-------- C:\DOCUME~1\HP_PRO~1\APPLIC~1\PC Tools
                          2007-04-19 14:55 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll

                          (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

                          2007-05-17 13:27:53 -------- d-----w C:\Program Files\Wanadoo
                          2007-05-16 16:52:04 -------- d-----w C:\Program Files\Gravity
                          2007-05-12 09:02:10 -------- d-----w C:\Program Files\Windows Live Safety Center
                          2007-05-06 14:15:33 -------- d-----w C:\Program Files\Warcraft III
                          2007-05-01 14:44:32 -------- d-----w C:\Program Files\Brochette Online V2
                          2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
                          2007-04-30 15:41:55 85,952 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
                          2007-04-30 15:41:42 94,552 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
                          2007-04-30 15:39:41 23,416 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
                          2007-04-30 15:38:51 43,176 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
                          2007-04-30 15:37:23 26,888 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
                          2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr
                          2007-04-08 17:36:49 -------- d-----w C:\DOCUME~1\HP_PRO~1\APPLIC~1\Screenshot Sender
                          2007-04-02 07:42:34 -------- d-----w C:\Program Files\MyProduct
                          2007-03-31 08:54:20 -------- d-----w C:\Program Files\FRose
                          2007-03-25 13:18:44 84,156 ----a-w C:\WINDOWS\system32\perfc00C.dat
                          2007-03-25 13:18:44 506,460 ----a-w C:\WINDOWS\system32\perfh00C.dat
                          2007-03-24 21:01:00 64,776 ----a-w C:\DOCUME~1\HP_PRO~1\APPLIC~1\GDIPFONTCACHEV1.DAT
                          2007-03-20 17:11:04 -------- d-----w C:\Program Files\Fichiers communs\LogiShrd
                          2007-03-18 13:46:42 -------- d-----w C:\Program Files\Logitech
                          2007-03-17 13:44:47 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
                          2007-03-14 16:15:12 -------- d-----w C:\Program Files\Messenger Plus! Live
                          2007-03-08 15:37:50 578,560 ----a-w C:\WINDOWS\system32\user32.dll
                          2007-03-08 15:37:50 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
                          2007-03-08 15:37:50 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
                          2007-03-08 15:33:58 1,843,712 ----a-w C:\WINDOWS\system32\win32k.sys
                          2007-02-23 13:23:32 28 ----a-w C:\WINDOWS\mscpt.dat
                          2007-02-12 09:56:55 111,992 ----a-w C:\WINDOWS\War3Unin.dat
                          2007-02-07 23:24:46 323,624 ----a-w C:\WINDOWS\system32\wiaaut.dll
                          2007-02-05 20:19:06 185,344 ----a-w C:\WINDOWS\system32\upnphost.dll

                          (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

                          *Note* empty entries & legit default entries are not shown

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
                          {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 09:56]
                          {733FD72F-103E-4B9E-BCB9-A76064AF3C72}=C:\WINDOWS\system32\gebyabb.dll []
                          {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll [2006-10-12 03:25]
                          {9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-04-17 13:32]
                          {AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar3.dll [2007-01-20 00:56]
                          {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=C:\Program Files\Windows Live Toolbar\msntb.dll [2006-09-27 18:45]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2006-10-07 14:20]
                          "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04]
                          "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-08 05:05]
                          "HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 08:35]
                          "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-05-05 01:21]
                          "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 22:43]
                          "AlcxMonitor"="ALCXMNTR.EXE" []
                          "HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 07:12]
                          "WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49]
                          "WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55]
                          "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 17:42]
                          "KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44]
                          "LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 02:12]
                          "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2007-02-08 02:13]
                          "SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-04-27 16:26]

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "WOOKIT"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55]
                          "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 20:00]
                          "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-01-31 18:39]
                          "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:55]

                          [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
                          "^SetupICWDesktop"=""

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                          "{733FD72F-103E-4B9E-BCB9-A76064AF3C72}"="C:\WINDOWS\system32\gebyabb.dll" []
                          "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 16:13]

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                          Authentication Packages msv1_0
                          Security Packages kerberos msv1_0 schannel wdigest
                          Notification Packages scecli

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice]

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                          HTTPFilter HTTPFilter
                          LocalService Alerter WebClient LmHosts RemoteRegistry upnphost SSDPSRV
                          NetworkService DnsCache
                          DcomLaunch DcomLaunch TermService
                          rpcss RpcSs
                          imgsvc StiSvc
                          termsvcs TermService
                          WudfServiceGroup WUDFSvc

                          HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

                          Contents of the 'Scheduled Tasks' folder
                          C:\WINDOWS\tasks\Symantec NetDetect.job
                          C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job

                          ********************************************************************

                          catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
                          Rootkit scan 2007-05-17 15:27:19
                          Windows 5.1.2600 Service Pack 2 NTFS

                          scanning hidden processes ...

                          scanning hidden autostart entries ...

                          scanning hidden files ...

                          scan completed successfully
                          hidden files: 0

                          ********************************************************************

                          Completion time: 2007-05-17 15:33:02 - machine was rebooted
                          C:\ComboFix-quarantined-files.txt ... 2007-05-17 15:33

                          --- E O F ---

                          Et Maintenant ? rien est arrangé.
                          0
                          1. Modérateur
                            Bonjour :)

                            c'est pas encore fini :)

                            Télécharge ComboFix (par sUBs) d'un de ces liens sur ton bureau:

                            http://www.techsupportforum.com/sectools/combofix.exe

                            http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                            Double clique combofix.exe et suis les invites

                            Poste le rapport stp

                            ++
                            0
                            1. ---------------------------------------------------------
                              AVG Anti-Spyware - Rapport d'analyse
                              ---------------------------------------------------------

                              + Créé à: 11:45:23 07/05/2007

                              + Résultat de l'analyse:

                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180228.dll -> Adware.ErrorSafe : Nettoyé.
                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180229.dll -> Adware.ErrorSafe : Nettoyé.
                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180230.exe -> Adware.ErrorSafe : Nettoyé.
                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180231.dll -> Adware.ErrorSafe : Nettoyé.
                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180232.exe -> Adware.ErrorSafe : Nettoyé.
                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP369\A0180233.exe -> Adware.WinFixer : Nettoyé.
                              C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP371\A0180467.dll -> Dropper.Agent.bhc : Nettoyé.
                              C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@ad.adocean[1].txt -> TrackingCookie.Adocean : Nettoyé.
                              C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@searchportal.information[1].txt -> TrackingCookie.Information : Nettoyé.
                              C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@www.paypal[1].txt -> TrackingCookie.Paypal : Nettoyé.
                              C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@revsci[2].txt -> TrackingCookie.Revsci : Nettoyé.
                              C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@specificclick[2].txt -> TrackingCookie.Specificclick : Nettoyé.
                              C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.

                              Fin du rapport

                              Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                              Scan saved at 12:23:35, on 07/05/2007
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\csrss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              C:\WINDOWS\System32\FTRTSVC.exe
                              C:\Program Files\Spyware Doctor\svcntaux.exe
                              C:\Program Files\Spyware Doctor\swdsvc.exe
                              C:\WINDOWS\system32\svchost.exe
                              c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              C:\Program Files\Spyware Doctor\SDTrayApp.exe
                              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              C:\WINDOWS\System32\alg.exe
                              C:\windows\system\hpsysdrv.exe
                              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\WINDOWS\ALCXMNTR.EXE
                              C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                              C:\HP\KBD\KBD.EXE
                              C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                              C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
                              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                              C:\PROGRA~1\Wanadoo\ComComp.exe
                              C:\Program Files\MSN Messenger\msnmsgr.exe
                              C:\PROGRA~1\Wanadoo\Toaster.exe
                              C:\PROGRA~1\Wanadoo\Inactivity.exe
                              C:\PROGRA~1\Wanadoo\PollingModule.exe
                              C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                              C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
                              C:\PROGRA~1\Wanadoo\Watch.exe
                              C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                              C:\Documents and Settings\HP_Propriétaire\Bureau\HiJackThis_v2.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://store.hp.com/us/en?jumpid=re_r11662_redirect_ETR
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                              O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\xjrnhngp.dll
                              O2 - BHO: (no name) - {733FD72F-103E-4B9E-BCB9-A76064AF3C72} - C:\WINDOWS\system32\gebyabb.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                              O2 - BHO: (no name) - {7E022C3D-B859-42F0-8AF4-23B986CC26F0} - C:\WINDOWS\system32\mljgh.dll
                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                              O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\nmgyfpse.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                              O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                              O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                              O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                              O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                              O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
                              O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                              O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
                              O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
                              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                              O4 - HKLM\..\Run: [WindowsService] rundll32.exe "C:\WINDOWS\system32\mctddmqm.dll",realset
                              O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
                              O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                              O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                              O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                              O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                              O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                              O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                              O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                              O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                              O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
                              O20 - Winlogon Notify: mljgh - C:\WINDOWS\system32\mljgh.dll
                              O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                              O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
                              O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
                              O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
                              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                              O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
                              O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
                              O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                              O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                              O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
                              O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
                              O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
                              O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
                              O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files\Spyware Doctor\svcntaux.exe
                              O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
                              O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                              O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
                              O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
                              O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
                              O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
                              0
                              1. Modérateur
                                Salut

                                supprime ces deux logiciels :

                                WinAntiSpyware 2006 Scanner
                                Error Safe Free


                                ensuite refais un scan avec avg et poste le ainsi qu'un nouveau hijack

                                ++
                                0
                                1. ---------------------------------------------------------
                                  AVG Anti-Spyware - Rapport d'analyse
                                  ---------------------------------------------------------

                                  + Créé à: 14:51:34 01/05/2007

                                  + Résultat de l'analyse:

                                  HKU\S-1-5-21-1558018719-2868653155-1144433344-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{56F1D444-11BF-4879-A12B-79CF0177F038} -> Adware.180Solutions : Ignoré.
                                  C:\Program Files\Error Safe Free\FWraper.dll -> Adware.ErrorSafe : Ignoré.
                                  C:\Program Files\Error Safe Free\FxCore.dll -> Adware.ErrorSafe : Ignoré.
                                  C:\Program Files\Error Safe Free\InstHelp.exe -> Adware.ErrorSafe : Ignoré.
                                  C:\Program Files\Error Safe Free\MMFx.dll -> Adware.ErrorSafe : Ignoré.
                                  C:\Program Files\Error Safe Free\emptyERSF.exe -> Adware.ErrorSafe : Ignoré.
                                  HKLM\SOFTWARE\WinAntiSpyware 2006 Scanner -> Adware.WinAntiSpyware : Ignoré.
                                  C:\Program Files\Error Safe Free\Updater.exe -> Adware.WinFixer : Ignoré.
                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP343\A0163829.exe -> Logger.Winflyer : Ignoré.
                                  C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@www.paypal[1].txt -> TrackingCookie.Paypal : Ignoré.
                                  C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@weborama[1].txt -> TrackingCookie.Weborama : Ignoré.

                                  Fin du rapport

                                  BitDefender Online Scanner

                                  Rapport d'analyse généré à: Wed, May 02, 2007 - 20:35:27

                                  Voie d'analyse: C:\;D:\;E:\;F:\;G:\;H:\;I:\;

                                  Statistiques

                                  Temps
                                  03:51:12

                                  Fichiers
                                  529605

                                  Directoires
                                  6977

                                  Secteurs de boot
                                  3

                                  Archives
                                  17584

                                  Paquets programmes
                                  56758

                                  Résultats

                                  Virus identifiés
                                  8

                                  Fichiers infectés
                                  33

                                  Fichiers suspects
                                  0

                                  Avertissements
                                  0

                                  Désinfectés
                                  0

                                  Fichiers effacés
                                  29

                                  Info sur les moteurs

                                  Définition virus
                                  503616

                                  Version des moteurs
                                  AVCORE v1.0 (build 2397) (i386) (Feb 8 2007 14:24:08)

                                  Analyse des plugins
                                  14

                                  Archive des plugins
                                  38

                                  Unpack des plugins
                                  6

                                  E-mail plugins
                                  6

                                  Système plugins
                                  1

                                  Paramètres d'analyse

                                  Première action
                                  Désinfecté

                                  Seconde Action
                                  Supprimé

                                  Heuristique
                                  Oui

                                  Acceptez les avertissements
                                  Oui

                                  Extensions analysées
                                  *;

                                  Excludez les extensions

                                  Analyse d'emails
                                  Oui

                                  Analyse des Archives
                                  Oui

                                  Analyser paquets programmes
                                  Oui

                                  Analyse des fichiers
                                  Oui

                                  Analyse de boot
                                  Oui

                                  Fichier analysé
                                  Statut

                                  C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WR34TBW5\lo1[1]
                                  Infecté par: MemScan:Trojan.Vundo.AP

                                  C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WR34TBW5\lo1[1]
                                  Echec de la désinfection

                                  C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WR34TBW5\lo1[1]
                                  Supprimé

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178718.dll
                                  Infecté par: Trojan.Vundo.AN

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178718.dll
                                  Echec de la désinfection

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178718.dll
                                  Supprimé

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178721.dll
                                  Infecté par: Trojan.Virtumod.KE

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178721.dll
                                  Echec de la désinfection

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178721.dll
                                  Supprimé

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178722.dll
                                  Infecté par: Trojan.Vundo.AN

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178722.dll
                                  Echec de la désinfection

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178722.dll
                                  Supprimé

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178723.dll
                                  Infecté par: Trojan.Vundo.AN

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178723.dll
                                  Echec de la désinfection

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178723.dll
                                  Supprimé

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178724.dll
                                  Infecté par: Trojan.Vundo.AN

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178724.dll
                                  Echec de la désinfection

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178724.dll
                                  Supprimé

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178725.dll
                                  Infecté par: Trojan.Virtumod.JB

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178725.dll
                                  Echec de la désinfection

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178725.dll
                                  Supprimé

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178726.dll
                                  Infecté par: Trojan.Vundo.AN

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178726.dll
                                  Echec de la désinfection

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178726.dll
                                  Supprimé

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178727.dll
                                  Infecté par: Trojan.Vundo.AN

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178727.dll
                                  Echec de la désinfection

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178727.dll
                                  Supprimé

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178728.dll
                                  Infecté par: Trojan.Vundo.AN

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178728.dll
                                  Echec de la désinfection

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178728.dll
                                  Supprimé

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178729.dll
                                  Infecté par: Trojan.BHO.AU

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178729.dll
                                  Echec de la désinfection

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178729.dll
                                  Supprimé

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178730.dll
                                  Infecté par: Trojan.Vundo.AN

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178730.dll
                                  Echec de la désinfection

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP363\A0178730.dll
                                  Supprimé

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP366\A0179110.dll
                                  Infecté par: Trojan.Vundo.AN

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP366\A0179110.dll
                                  Echec de la désinfection

                                  C:\System Volume Information\_restore{F75EEC69-6E97-419B-93B4-6A3A275301C4}\RP366\A0179110.dll
                                  Supprimé

                                  C:\VundoFix Backups\bkboxlgw.dll.bad
                                  Infecté par: Trojan.Vundo.AN

                                  C:\VundoFix Backups\bkboxlgw.dll.bad
                                  Echec de la désinfection

                                  C:\VundoFix Backups\bkboxlgw.dll.bad
                                  Supprimé

                                  C:\VundoFix Backups\gebyabb.dll.bad
                                  Infecté par: MemScan:Trojan.Vundo.AJ

                                  C:\VundoFix Backups\gebyabb.dll.bad
                                  Echec de la désinfection

                                  C:\VundoFix Backups\gebyabb.dll.bad
                                  Supprimé

                                  C:\VundoFix Backups\iajsddpu.dll.bad
                                  Infecté par: Trojan.Virtumod.KE

                                  C:\VundoFix Backups\iajsddpu.dll.bad
                                  Echec de la désinfection

                                  C:\VundoFix Backups\iajsddpu.dll.bad
                                  Supprimé

                                  C:\VundoFix Backups\idpqbycb.dll.bad
                                  Infecté par: Trojan.Vundo.AN

                                  C:\VundoFix Backups\idpqbycb.dll.bad
                                  Echec de la désinfection

                                  C:\VundoFix Backups\idpqbycb.dll.bad
                                  Supprimé

                                  C:\VundoFix Backups\imrnotsv.dll.bad
                                  Infecté par: Trojan.Vundo.AN

                                  C:\VundoFix Backups\imrnotsv.dll.bad
                                  Echec de la désinfection

                                  C:\VundoFix Backups\imrnotsv.dll.bad
                                  Supprimé

                                  C:\VundoFix Backups\inrushjs.dll.bad
                                  Infecté par: Trojan.Vundo.AN

                                  C:\VundoFix Backups\inrushjs.dll.bad
                                  Echec de la désinfection

                                  C:\VundoFix Backups\inrushjs.dll.bad
                                  Supprimé

                                  C:\VundoFix Backups\itdyidub.dll.bad
                                  Infecté par: Trojan.Virtumod.JB

                                  C:\VundoFix Backups\itdyidub.dll.bad
                                  Echec de la désinfection

                                  C:\VundoFix Backups\itdyidub.dll.bad
                                  Supprimé

                                  C:\VundoFix Backups\kccpgfkd.dll.bad
                                  Infecté par: Trojan.Vundo.AN

                                  C:\VundoFix Backups\kccpgfkd.dll.bad
                                  Echec de la désinfection

                                  C:\VundoFix Backups\kccpgfkd.dll.bad
                                  Supprimé

                                  C:\VundoFix Backups\mcsphway.dll.bad
                                  Infecté par: Trojan.Vundo.AN

                                  C:\VundoFix Backups\mcsphway.dll.bad
                                  Echec de la désinfection

                                  C:\VundoFix Backups\mcsphway.dll.bad
                                  Supprimé

                                  C:\VundoFix Backups\mjopwubb.dll.bad
                                  Infecté par: Trojan.Vundo.AN

                                  C:\VundoFix Backups\mjopwubb.dll.bad
                                  Echec de la désinfection

                                  C:\VundoFix Backups\mjopwubb.dll.bad
                                  Supprimé

                                  C:\VundoFix Backups\nivagsyb.dll.bad
                                  Infecté par: Trojan.BHO.AU

                                  C:\VundoFix Backups\nivagsyb.dll.bad
                                  Echec de la désinfection

                                  C:\VundoFix Backups\nivagsyb.dll.bad
                                  Supprimé

                                  C:\VundoFix Backups\ptfvarem.dll.bad
                                  Infecté par: Trojan.Vundo.AN

                                  C:\VundoFix Backups\ptfvarem.dll.bad
                                  Echec de la désinfection

                                  C:\VundoFix Backups\ptfvarem.dll.bad
                                  Supprimé

                                  C:\VundoFix Backups\thrkujyq.dll.bad
                                  Infecté par: Trojan.Vundo.AN

                                  C:\VundoFix Backups\thrkujyq.dll.bad
                                  Echec de la désinfection

                                  C:\VundoFix Backups\thrkujyq.dll.bad
                                  Supprimé

                                  C:\WINDOWS\system32\gebyabb.dll
                                  Infecté par: MemScan:Trojan.Vundo.AJ

                                  C:\WINDOWS\system32\gebyabb.dll
                                  Echec de la désinfection

                                  C:\WINDOWS\system32\gebyabb.dll
                                  Echec de la suppression

                                  C:\WINDOWS\system32\lfwwgggh.dll
                                  Infecté par: Trojan.Vundo.AN

                                  C:\WINDOWS\system32\lfwwgggh.dll
                                  Echec de la désinfection

                                  C:\WINDOWS\system32\lfwwgggh.dll
                                  Supprimé

                                  C:\WINDOWS\system32\mljgh.dll
                                  Infecté par: MemScan:Trojan.Vundo.AP

                                  C:\WINDOWS\system32\mljgh.dll
                                  Echec de la désinfection

                                  C:\WINDOWS\system32\mljgh.dll
                                  Echec de la suppression

                                  C:\WINDOWS\system32\nmgyfpse.dll
                                  Infecté par: Trojan.Vundo.DLP

                                  C:\WINDOWS\system32\nmgyfpse.dll
                                  Echec de la désinfection

                                  C:\WINDOWS\system32\nmgyfpse.dll
                                  Echec de la suppression

                                  C:\WINDOWS\system32\pkawxcdt.dll
                                  Infecté par: Trojan.Vundo.AN

                                  C:\WINDOWS\system32\pkawxcdt.dll
                                  Echec de la désinfection

                                  C:\WINDOWS\system32\pkawxcdt.dll
                                  Supprimé

                                  C:\WINDOWS\system32\qlluclsp.dll
                                  Infecté par: Trojan.Vundo.AO

                                  C:\WINDOWS\system32\qlluclsp.dll
                                  Echec de la désinfection

                                  C:\WINDOWS\system32\qlluclsp.dll
                                  Supprimé

                                  C:\WINDOWS\system32\xjrnhngp.dll
                                  Infecté par: Trojan.Vundo.AO

                                  C:\WINDOWS\system32\xjrnhngp.dll
                                  Echec de la désinfection

                                  C:\WINDOWS\system32\xjrnhngp.dll
                                  Echec de la suppression

                                  Logfile of Trend Micro HijackThis v2.0.0 (BETA)
                                  Scan saved at 20:51:18, on 02/05/2007
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\csrss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\Ati2evxx.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\Ati2evxx.exe
                                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                  C:\WINDOWS\System32\FTRTSVC.exe
                                  C:\Program Files\Spyware Doctor\svcntaux.exe
                                  C:\windows\system\hpsysdrv.exe
                                  C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                  C:\Program Files\iTunes\iTunesHelper.exe
                                  C:\WINDOWS\ALCXMNTR.EXE
                                  C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  C:\HP\KBD\KBD.EXE
                                  C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                                  C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                                  C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
                                  C:\WINDOWS\system32\rundll32.exe
                                  C:\Program Files\Spyware Doctor\SDTrayApp.exe
                                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
                                  C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                  C:\PROGRA~1\Wanadoo\ComComp.exe
                                  C:\Program Files\MSN Messenger\msnmsgr.exe
                                  C:\PROGRA~1\Wanadoo\Toaster.exe
                                  C:\PROGRA~1\Wanadoo\Inactivity.exe
                                  C:\PROGRA~1\Wanadoo\PollingModule.exe
                                  C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                  C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
                                  c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                                  C:\PROGRA~1\Wanadoo\Watch.exe
                                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  C:\Program Files\iPod\bin\iPodService.exe
                                  C:\WINDOWS\System32\alg.exe
                                  C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                                  C:\Program Files\Outlook Express\msimn.exe
                                  C:\Program Files\Spyware Doctor\swdsvc.exe
                                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                  C:\Documents and Settings\HP_Propriétaire\Bureau\HiJackThis_v2.exe

                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://store.hp.com/us/en?jumpid=re_r11662_redirect_ETR
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\xjrnhngp.dll
                                  O2 - BHO: (no name) - {733FD72F-103E-4B9E-BCB9-A76064AF3C72} - C:\WINDOWS\system32\gebyabb.dll
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                                  O2 - BHO: (no name) - {76F94FCB-1281-494D-BC0C-0756C7F7FA47} - C:\WINDOWS\system32\mljgh.dll
                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                  O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                  O2 - BHO: (no name) - {D651AFF4-9590-424d-BD1E-8E33E090DFB3} - C:\WINDOWS\system32\nmgyfpse.dll
                                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                  O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                  O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                                  O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                  O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
                                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                  O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                                  O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                                  O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                                  O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                  O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
                                  O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                                  O4 - HKLM\..\Run: [WinFlyer32.dll] "rundll32.exe" C:\WINDOWS\system32\WinFlyer32.dll,Run
                                  O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\itdyidub.dll",setvm
                                  O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
                                  O4 - HKLM\..\Run: [InfoData] rundll32.exe "C:\WINDOWS\system32\irpjjkuq.dll",realset
                                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                  O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
                                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                  O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
                                  O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                  O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                  O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                  O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                                  O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                                  O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                                  O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                                  O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                                  O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                                  O16 - DPF: {1F83CD9E-505E-4F87-BECE-0832A763E36F} (Image Uploader 3.0 Control) - http://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
                                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                  O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
                                  O17 - HKLM\System\CCS\Services\Tcpip\..\{34CB4B96-6783-4D74-AC33-1375619936AA}: NameServer = 80.10.246.1 80.10.246.132
                                  O17 - HKLM\System\CS1\Services\Tcpip\..\{34CB4B96-6783-4D74-AC33-1375619936AA}: NameServer = 80.10.246.1 80.10.246.132
                                  O20 - Winlogon Notify: mljgh - C:\WINDOWS\system32\mljgh.dll
                                  O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
                                  O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
                                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                  O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
                                  O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
                                  O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
                                  O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                  O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
                                  O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                  O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
                                  O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                                  O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                                  O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
                                  O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
                                  O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
                                  O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
                                  O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - Unknown owner - C:\Program Files\Spyware Doctor\svcntaux.exe
                                  O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
                                  O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                                  O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
                                  O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
                                  O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                  O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
                                  0
                                  1. Modérateur
                                    Salut

                                    fais les manips de ce lien stp :

                                    virus methode preliminaire de desinfection version fr

                                    ++
                                    0
                                    • 1
                                    • 2