Trojan !!

Résolu
Bonjour,
après avoir réussi a supprimer un cheval de troie
malwarebytes me trouve maintenant d'autres éléments infectés ( voir ci-dessous ) que je ne parviens pas
a mettre en quarantaine ou a supprimer malgré plusieurs essais
est -il nécessaire de les supprimer ou peut-on les laisser ainsi ?

Malwarebytes' Anti-Malware 1.36
Version de la base de données: 2035
Windows 5.1.2600 Service Pack 3

29/04/2009 20:15:34
mbam-log-2009-04-29 (20-15-18).txt

Type de recherche: Examen rapide
Eléments examinés: 72145
Temps écoulé: 4 minute(s), 57 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 3
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7463d08d-98f5-4217-997d-da19c71023b9} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\kzjrvqgi (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{7463d08d-98f5-4217-997d-da19c71023b9} (Trojan.Vundo.H) -> No action taken.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\windows\system32\vwsbdmh.dll (Trojan.Vundo.H) -> No action taken.
Configuration: Windows XP
Firefox 3.0.3

16 réponses

  1. Télécharge Spyware Terminator,

    Il détecte facilement les fichiers dans le registres infectés.
    0
    1. j'ai télécharger et fait une analyse avec spyware terminator
      il m'a trouvé 3 objets infectés et je les ai supprimés
      cependant après avoir relancé une analyse avec malwarebytes
      celui-ci me retrouve toujours les 4 mêmes objets infectés qu'auparavant ....
      0
      1. B'soir,

        No action taken. cela veut aucune action prise....

        Regarde ce tutoriel pour t'aider a supprimer ce qu'il ta trouver:

        Tutoriel pour MalwareByte's

        Poste le rapport de suppression

        Ensuite fait ce qui suit:

        ▶ Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.

        ▶ Double clique sur RSIT.exe pour lancer l'outil.

        ▶ Clique sur ' continue ' à l'écran Disclaimer.

        ▶ Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

        ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports séparément.
        ( log.txt & info.txt )

        (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
        0
        1. rapport malwarebytes :

          Malwarebytes' Anti-Malware 1.36
          Version de la base de données: 2035
          Windows 5.1.2600 Service Pack 3

          29/04/2009 21:20:32
          mbam-log-2009-04-29 (21-20-32).txt

          Type de recherche: Examen rapide
          Eléments examinés: 72109
          Temps écoulé: 4 minute(s), 9 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 3
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 1

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7463d08d-98f5-4217-997d-da19c71023b9} (Trojan.Vundo.H) -> Delete on reboot.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\kzjrvqgi (Trojan.Vundo.H) -> Delete on reboot.
          HKEY_CLASSES_ROOT\CLSID\{7463d08d-98f5-4217-997d-da19c71023b9} (Trojan.Vundo.H) -> Delete on reboot.

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          c:\windows\system32\vwsbdmh.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
          0
          1. Re,

            Redémarre ton pc et fait un rapport RSIT.
            0
            1. Logfile of random's system information tool 1.06 (written by random/random)
              Run by Romuald at 2009-04-29 21:29:42
              Microsoft Windows XP Édition familiale Service Pack 3
              System drive C: has 68 GB (72%) free of 93 GB
              Total RAM: 991 MB (42% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 21:30:11, on 29/04/2009
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16827)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\RTHDCPL.EXE
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
              C:\Program Files\LaCie\Backup Software\LaCieBackup.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\Program Files\Wallpaper\Wallpaper.exe
              C:\Program Files\Spybot - Search & Destroy 1.6.2\TeaTimer.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
              C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
              C:\WINDOWS\system32\HPZipm12.exe
              C:\WINDOWS\VPro530.exe
              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
              C:\Program Files\Spyware Terminator\sp_rsser.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
              C:\WINDOWS\system32\wbem\wmiapsrv.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\rsit\RSIT.exe
              C:\Program Files\Romuald.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2.2\SDHelper.dll
              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
              O2 - BHO: (no name) - {7463D08D-98F5-4217-997D-DA19C71023B9} - c:\windows\system32\vwsbdmh.dll (file missing)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
              O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [LaCie Backup] C:\Program Files\LaCie\Backup Software\\LaCieBackup.exe /background
              O4 - HKCU\..\Run: [Wallpaper] "C:\Program Files\Wallpaper\Wallpaper.exe" Starter
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy 1.6.2\TeaTimer.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p (User 'Default user')
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
              O4 - Global Startup: VPro530.lnk = ?
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~2.2\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~2.2\SDHelper.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
              O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O20 - Winlogon Notify: kzjrvqgi - vwsbdmh.dll (file missing)
              O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
              O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
              0
              1. info.txt logfile of random's system information tool 1.06 2009-04-29 21:30:13

                ======Uninstall list======

                -->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
                -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
                -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                ACDSee 8-->MsiExec.exe /I{DD54C6DE-B787-406D-A5A7-A49E0471E45B}
                Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
                Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
                Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
                CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
                Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                DVD Suite-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" -uninstall
                Galerie de photos Windows Live-->MsiExec.exe /X{44E54A81-9D91-4AA1-9417-80AFF134F5FF}
                Haali Media Splitter-->"C:\Program Files\Matroska Pack\haali\uninstall.exe"
                High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
                HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                HP Image Zone 4.7-->C:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
                HP PSC & OfficeJet 4.7-->"C:\Program Files\HP\Digital Imaging\{5469D537-9B44-4c78-BF2D-5F9807564F74}\setup\hpzscr01.exe" -datfile hposcr05.dat
                Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                iWizz-->C:\Program Files\wizzgo\uninstall.exe
                Java(TM) 6 Update 13-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
                Java(TM) 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
                Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
                Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
                Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
                Kaspersky Online Scanner-->C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
                LaCie Backup Software v1.5.2378-->MsiExec.exe /I{5967A03E-3B74-4DF1-B591-2D89CA26BDC9}
                Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                LimeWire 5.1.2-->"C:\Program Files\LimeWire\uninstall.exe"
                Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                Matroska Pack-->C:\Program Files\Matroska Pack\uninstall.exe
                Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
                Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
                Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
                Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
                Microsoft Money Shared Libraries-->MsiExec.exe /X{5F00DF7E-418B-4CD9-8EC5-781156BCC49E}
                Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
                Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
                Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
                Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
                Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
                Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
                Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                Mise à jour critique pour Lecteur Windows Media 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
                Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB961503)-->"C:\WINDOWS\$NtUninstallKB961503$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
                Mozilla Firefox (3.0.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
                MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                Nero 7 Essentials-->MsiExec.exe /X{AAB93551-3FFE-42B2-8315-96252BBC1036}
                Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                Philips SPC530NC Webcam-->"C:\Program Files\InstallShield Installation Information\{69D598A7-A9C5-4396-8C92-39465FF2C874}\Setup.exe" -runfromtemp -l0x040c -removeonly
                Philips VLounge-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EA57A1B9-0DD2-44DD-9B70-64E8DA553F6F}\Setup.exe" -l0x40c
                QuickTime-->MsiExec.exe /I{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}
                Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
                Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
                Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy 1.6.2\unins000.exe"
                Spyware Terminator-->"C:\Program Files\Spyware Terminator\unins000.exe"
                VideoLAN VLC media player 0.8.6d-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                Wallpaper-->C:\Program Files\Wallpaper\uninst.exe
                Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                Windows Live Contrôle parental-->MsiExec.exe /X{D6A2DDE3-9D7C-412C-932A-756580D29919}
                Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
                Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                Windows Live Sync-->MsiExec.exe /X{9C5EB781-0D37-44B8-9A58-77B3E4BF5F5E}
                Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
                Windows Live Writer-->MsiExec.exe /X{2231CE39-B963-4B9D-823A-F412ECA637B1}
                Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
                Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

                =====HijackThis Backups=====

                O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file) [2009-04-27]
                O2 - BHO: (no name) - {7463D08D-98F5-4217-997D-DA19C71023B9} - c:\windows\system32\vwsbdmh.dll (file missing) [2009-04-27]
                O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file) [2009-04-27]
                O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) [2009-04-27]
                O2 - BHO: (no name) - {8246F4B7-292F-468E-AC61-934A14C69414} - (no file) [2009-04-27]
                O20 - Winlogon Notify: kzjrvqgi - vwsbdmh.dll (file missing) [2009-04-27]
                O20 - Winlogon Notify: kzjrvqgi - vwsbdmh.dll (file missing) [2009-04-27]
                O2 - BHO: (no name) - {7463D08D-98F5-4217-997D-DA19C71023B9} - c:\windows\system32\vwsbdmh.dll (file missing) [2009-04-27]

                ======Hosts File======

                127.0.0.1 www.007guard.com
                127.0.0.1 007guard.com
                127.0.0.1 008i.com
                127.0.0.1 www.008k.com
                127.0.0.1 008k.com
                127.0.0.1 www.00hq.com
                127.0.0.1 00hq.com
                127.0.0.1 010402.com
                127.0.0.1 www.032439.com
                127.0.0.1 032439.com

                ======Security center information======

                AV: Avira AntiVir PersonalEdition Classic

                ======System event log======

                Computer Name: DETAIN-CE76E662
                Event Code: 7035
                Message: Un contrôle Démarrer a correctement été envoyé au service Compatibilité avec le Changement rapide d'utilisateur.

                Record Number: 31207
                Source Name: Service Control Manager
                Time Written: 20090415094110.000000+120
                Event Type: Informations
                User: AUTORITE NT\SYSTEM

                Computer Name: DETAIN-CE76E662
                Event Code: 7036
                Message: Le service Services Terminal Server est entré dans l'état : en cours d'exécution.

                Record Number: 31206
                Source Name: Service Control Manager
                Time Written: 20090415094110.000000+120
                Event Type: Informations
                User:

                Computer Name: DETAIN-CE76E662
                Event Code: 7000
                Message: Le service mickey32 n'a pas pu démarrer en raison de l'erreur :
                Le fichier spécifié est introuvable.

                Record Number: 31205
                Source Name: Service Control Manager
                Time Written: 20090415094109.000000+120
                Event Type: erreur
                User:

                Computer Name: DETAIN-CE76E662
                Event Code: 2003
                Message:
                Record Number: 31204
                Source Name: SRTSP
                Time Written: 20090415094028.000000+120
                Event Type: Informations
                User:

                Computer Name: DETAIN-CE76E662
                Event Code: 121
                Message: Port A is up with 100 Mbps

                Record Number: 31203
                Source Name: yukonwxp
                Time Written: 20090415094028.000000+120
                Event Type: Informations
                User:

                =====Application event log=====

                Computer Name: DETAIN-CE76E662
                Event Code: 101
                Message:
                Record Number: 10538
                Source Name: Automatic LiveUpdate Scheduler
                Time Written: 20090127122524.000000+060
                Event Type: Informations
                User: AUTORITE NT\SYSTEM

                Computer Name: DETAIN-CE76E662
                Event Code: 101
                Message:
                Record Number: 10537
                Source Name: Automatic LiveUpdate Scheduler
                Time Written: 20090127122524.000000+060
                Event Type: Informations
                User: AUTORITE NT\SYSTEM

                Computer Name: DETAIN-CE76E662
                Event Code: 101
                Message:
                Record Number: 10536
                Source Name: Automatic LiveUpdate Scheduler
                Time Written: 20090127122436.000000+060
                Event Type: Informations
                User: AUTORITE NT\SYSTEM

                Computer Name: DETAIN-CE76E662
                Event Code: 101
                Message:
                Record Number: 10535
                Source Name: Automatic LiveUpdate Scheduler
                Time Written: 20090127085430.000000+060
                Event Type: Informations
                User: AUTORITE NT\SYSTEM

                Computer Name: DETAIN-CE76E662
                Event Code: 101
                Message:
                Record Number: 10534
                Source Name: Automatic LiveUpdate Scheduler
                Time Written: 20090127081802.000000+060
                Event Type: Informations
                User: AUTORITE NT\SYSTEM

                ======Environment variables======

                "ComSpec"=%SystemRoot%\system32\cmd.exe
                "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
                "windir"=%SystemRoot%
                "FP_NO_HOST_CHECK"=NO
                "OS"=Windows_NT
                "PROCESSOR_ARCHITECTURE"=x86
                "PROCESSOR_LEVEL"=15
                "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
                "PROCESSOR_REVISION"=2f02
                "NUMBER_OF_PROCESSORS"=1
                "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                "TEMP"=%SystemRoot%\TEMP
                "TMP"=%SystemRoot%\TEMP
                "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
                "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

                -----------------EOF-----------------
                0
                1. Re,

                  Si tu n'as pas hijackthis:

                  ▶ Télécharge hijackthis

                  ▶ Enregistre la cible sous .... "le bureau"

                  ▶ Fais un double-clic sur "HJTInstall.exe" afin de lancer l'installation

                  ▶ Clique sur Install ensuite sur "I Accept"

                  ▶ Clique sur" Do a scan system and save log file"
                  xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
                  ▶ Relance hijack et clique sur "Do a system scan only"

                  ▶ Ensuite recherche ces lignes et coches les cases

                  O2 - BHO: (no name) - {7463D08D-98F5-4217-997D-DA19C71023B9} - c:\windows\system32\vwsbdmh.dll (file missing)
                  O20 - Winlogon Notify: kzjrvqgi - vwsbdmh.dll (file missing)

                  ▶ Ensuite clique sur "Fix checked"
                  xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
                  ▶ Télécharge CCleaner (N'installe pas la Yahoo Toolbar) :
                  CCLEANER

                  ▶ Lance-le. Va dans "Options" puis "Avancé",

                  ▶ Tu décoches la case "Effacer uniquement les fichiers etc...".

                  ▶ Tu vas dans "Nettoyeur", tu fais "Analyse". Une fois terminé, tu lances le nettoyage.

                  ▶ Tu vas dans "Registre", tu fais "Chercher des erreurs".

                  Une fois terminé, tu répares toutes les erreurs sans sauvegarder la base de registre.

                  ▶ Un tuto ( aide )

                  Redémarre ton pc et refait un log avec RSIT.
                  0
                  1. Logfile of random's system information tool 1.06 (written by random/random)
                    Run by Romuald at 2009-04-29 21:51:19
                    Microsoft Windows XP Édition familiale Service Pack 3
                    System drive C: has 68 GB (72%) free of 93 GB
                    Total RAM: 991 MB (46% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 21:51:52, on 29/04/2009
                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16827)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    C:\WINDOWS\RTHDCPL.EXE
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                    C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
                    C:\Program Files\Java\jre6\bin\jqs.exe
                    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                    C:\Program Files\LaCie\Backup Software\LaCieBackup.exe
                    C:\Program Files\Wallpaper\Wallpaper.exe
                    C:\Program Files\Spybot - Search & Destroy 1.6.2\TeaTimer.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                    C:\WINDOWS\system32\HPZipm12.exe
                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                    C:\WINDOWS\VPro530.exe
                    C:\Program Files\Spyware Terminator\sp_rsser.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                    C:\WINDOWS\system32\wbem\wmiapsrv.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\Program Files\rsit\RSIT.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Program Files\Romuald.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2.2\SDHelper.dll
                    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                    O2 - BHO: (no name) - {7463D08D-98F5-4217-997D-DA19C71023B9} - c:\windows\system32\vwsbdmh.dll (file missing)
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                    O4 - HKCU\..\Run: [LaCie Backup] C:\Program Files\LaCie\Backup Software\\LaCieBackup.exe /background
                    O4 - HKCU\..\Run: [Wallpaper] "C:\Program Files\Wallpaper\Wallpaper.exe" Starter
                    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy 1.6.2\TeaTimer.exe
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p (User 'Default user')
                    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                    O4 - Global Startup: VPro530.lnk = ?
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~2.2\SDHelper.dll
                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~2.2\SDHelper.dll
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
                    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
                    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                    O20 - Winlogon Notify: kzjrvqgi - vwsbdmh.dll (file missing)
                    O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
                    0
                    1. Re,

                      ▶ Télécharge hijackthis

                      ▶ Enregistre la cible sous .... "le bureau"

                      ▶ Fais un double-clic sur "HJTInstall.exe" afin de lancer l'installation

                      ▶ Clique sur Install ensuite sur "I Accept"

                      ▶ Clique sur" Do a scan system and save log file"

                      ▶ Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse

                      ▶ Tuto hijackthis(Merci à Balltrap34)

                      xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
                      ▶ Relance hijack et clique sur "Do a system scan only"

                      ▶ Ensuite recherche ces lignes et coches les cases

                      O2 - BHO: (no name) - {7463D08D-98F5-4217-997D-DA19C71023B9} - c:\windows\system32\vwsbdmh.dll (file missing)
                      O20 - Winlogon Notify: kzjrvqgi - vwsbdmh.dll (file missing)

                      ▶ Ensuite clique sur "Fix checked"

                      Fait ccleaner aussi et refait un log après tout sa.......
                      0
                      1. Logfile of random's system information tool 1.06 (written by random/random)
                        Run by Romuald at 2009-04-29 22:02:12
                        Microsoft Windows XP Édition familiale Service Pack 3
                        System drive C: has 68 GB (72%) free of 93 GB
                        Total RAM: 991 MB (51% free)

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 22:02:37, on 29/04/2009
                        Platform: Windows XP SP3 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16827)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        C:\WINDOWS\RTHDCPL.EXE
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
                        C:\Program Files\Java\jre6\bin\jqs.exe
                        C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                        C:\Program Files\LaCie\Backup Software\LaCieBackup.exe
                        C:\Program Files\Wallpaper\Wallpaper.exe
                        C:\Program Files\Spybot - Search & Destroy 1.6.2\TeaTimer.exe
                        C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                        C:\WINDOWS\system32\HPZipm12.exe
                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                        C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                        C:\WINDOWS\VPro530.exe
                        C:\Program Files\Spyware Terminator\sp_rsser.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                        C:\WINDOWS\system32\wbem\wmiapsrv.exe
                        C:\Program Files\rsit\RSIT.exe
                        C:\Program Files\Romuald.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2.2\SDHelper.dll
                        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                        O2 - BHO: (no name) - {7463D08D-98F5-4217-997D-DA19C71023B9} - c:\windows\system32\vwsbdmh.dll (file missing)
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                        O4 - HKCU\..\Run: [LaCie Backup] C:\Program Files\LaCie\Backup Software\\LaCieBackup.exe /background
                        O4 - HKCU\..\Run: [Wallpaper] "C:\Program Files\Wallpaper\Wallpaper.exe" Starter
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy 1.6.2\TeaTimer.exe
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -p (User 'Default user')
                        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                        O4 - Global Startup: VPro530.lnk = ?
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~2.2\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~2.2\SDHelper.dll
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
                        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
                        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                        O20 - Winlogon Notify: kzjrvqgi - vwsbdmh.dll (file missing)
                        O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                        O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                        O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
                        0
                        1. Re,

                          Je t'ai demander de faire hijackthis et de fixer les lignes et elles sont toujours là ou je les voit partout !!!!!!!!!!

                          Alors installe hijackthis et ensuite tu vire le rapport d'hijackthis et tu le relance et tu fixe les lignes que je t'ai donner.

                          Une fois fait tu me le dit et refait un log avec rsit.
                          0
                          1. j'ai déja refait hijackthis 2 fois et moi aussi j'ai bien vu qu'il n'a pas résolu les problèmes !!!!
                            j'ai également refait c cleaner
                            mais y'a rien de changer
                            0
                            1. Re,

                              Télécharge ComboFix (de sUBs) sur ton Bureau.

                              /!\Désactive temporairement toute protection résidente /!\ (Antivirus, antispywares..)
                              Double clique sur ComboFix.exe.
                              Accepte la licence en cliquant sur Oui.
                              Le programme va te demander si tu souhaites installer la Console de Récupération. C'est une précaution, au cas où l'ordinateur tomberait en panne. Je te conseille donc de l'installer, ça ne coûte rien, et ça pourrait potentiellement servir !
                              Lorsque l'opération sera terminée, un rapport apparaîtra. Poste ce rapport dans ta prochaine réponse.

                              Le rapport se trouve ici : %SystemDrive%\ComboFix.txt (%systemdrive% étant la partition où est installée Windows; C:\ en général)

                              Aide :Comment utiliser ComboFix.

                              Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
                              0
                              1. ComboFix 09-04-29.01 - Romuald 29/04/2009 22:13.1 - NTFSx86
                                Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.991.529 [GMT 2:00]
                                Lancé depuis: c:\program files\ComboFix.exe
                                AV: Avira AntiVir PersonalEdition Classic *On-access scanning disabled* (Updated)
                                * Un nouveau point de restauration a été créé
                                .

                                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                .

                                .
                                ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                                .

                                -------\Legacy_MICKEY32

                                ((((((((((((((((((((((((((((( Fichiers créés du 2009-05-28 au 2009-4-29 ))))))))))))))))))))))))))))))))))))
                                .

                                2009-04-29 20:11 . 2009-04-29 20:11 3010965 ----a-r c:\program files\ComboFix.exe
                                2009-04-29 19:29 . 2009-04-29 19:30 -------- d-----w C:\rsit
                                2009-04-29 18:44 . 2009-04-29 18:44 142592 ----a-w c:\windows\system32\drivers\sp_rsdrv2.sys
                                2009-04-29 18:44 . 2009-04-29 19:03 -------- d-----w c:\documents and settings\Romuald\Application Data\Spyware Terminator
                                2009-04-29 18:44 . 2009-04-29 19:00 -------- d-----w c:\documents and settings\All Users\Application Data\Spyware Terminator
                                2009-04-29 18:44 . 2009-04-29 19:51 -------- d-----w c:\program files\Spyware Terminator
                                2009-04-29 17:20 . 2009-04-29 19:02 -------- d-----w c:\documents and settings\All Users\Application Data\NOS
                                2009-04-29 17:20 . 2009-04-29 19:02 -------- d-----w c:\program files\NOS
                                2009-04-27 19:26 . 2009-04-27 19:26 -------- d-----w c:\windows\system32\Kaspersky Lab
                                2009-04-27 19:12 . 2009-04-29 17:47 -------- d-----w c:\program files\CCleaner
                                2009-04-27 18:48 . 2009-04-27 17:55 401720 ----a-w c:\program files\Romuald.exe
                                2009-04-27 18:02 . 2009-04-27 18:13 -------- d-----w c:\program files\_OTMoveIt
                                2009-04-27 18:00 . 2009-04-29 20:10 -------- d-----w c:\program files\backups
                                2009-04-27 17:55 . 2009-04-27 17:55 401720 ----a-w c:\program files\HiJackThis.exe
                                2009-04-24 08:01 . 2009-04-24 08:01 -------- d-----w c:\documents and settings\Romuald\Application Data\Malwarebytes
                                2009-04-24 08:01 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
                                2009-04-24 08:01 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
                                2009-04-24 08:01 . 2009-04-24 08:01 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
                                2009-04-24 08:01 . 2009-04-24 10:14 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
                                2009-04-24 06:29 . 2009-04-27 18:49 -------- d-----w c:\program files\rsit
                                2009-04-24 06:17 . 2009-04-24 06:17 -------- d-----w c:\documents and settings\Romuald\Application Data\lahkcqpp
                                2009-04-24 06:17 . 2009-04-24 06:17 -------- d-----w c:\documents and settings\Romuald\Local Settings\Application Data\lahkcqpp
                                2009-04-23 16:04 . 2009-04-27 17:54 -------- d-----w c:\program files\Trend Micro
                                2009-04-22 23:30 . 2009-04-22 23:30 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
                                2009-04-22 23:30 . 2009-04-22 23:31 -------- d-----w c:\program files\Avira
                                2009-04-22 09:10 . 2009-04-22 19:03 -------- d-----w c:\program files\Spybot - Search & Destroy 1.6.2
                                2009-04-21 20:24 . 2009-04-21 20:24 -------- d-----w c:\documents and settings\NetworkService\Application Data\lahkcqpp
                                2009-04-21 20:24 . 2009-04-21 20:24 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\lahkcqpp
                                2009-04-18 19:24 . 2009-04-18 20:47 -------- d-----w c:\documents and settings\Romuald\Application Data\Wallpaper
                                2009-04-18 19:24 . 2009-04-18 19:25 -------- d-----w c:\program files\Wallpaper
                                2009-04-18 14:01 . 2009-04-18 19:25 -------- d-----w c:\program files\LimeWire
                                2009-04-16 21:33 . 2008-12-16 12:31 354304 -c----w c:\windows\system32\dllcache\winhttp.dll
                                2009-04-16 21:33 . 2008-04-21 21:15 219136 -c----w c:\windows\system32\dllcache\wordpad.exe
                                2009-04-16 21:32 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
                                2009-04-16 21:32 . 2009-03-06 14:20 286720 -c----w c:\windows\system32\dllcache\pdh.dll
                                2009-04-16 21:32 . 2009-02-09 11:23 111104 -c----w c:\windows\system32\dllcache\services.exe
                                2009-04-16 21:32 . 2009-02-09 10:53 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
                                2009-04-16 21:32 . 2009-02-09 10:53 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
                                2009-04-16 21:32 . 2009-02-09 10:53 685568 -c----w c:\windows\system32\dllcache\advapi32.dll
                                2009-04-16 21:32 . 2009-02-09 10:53 735744 -c----w c:\windows\system32\dllcache\lsasrv.dll
                                2009-04-16 21:32 . 2009-02-09 10:53 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
                                2009-04-16 21:32 . 2009-02-09 10:53 739840 -c----w c:\windows\system32\dllcache\ntdll.dll

                                .
                                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                2009-04-29 20:02 . 2009-04-27 18:49 8276 ----a-w c:\program files\hijackthis.log
                                2009-04-29 17:33 . 2008-02-06 22:32 -------- d-----w c:\program files\Fichiers communs\Adobe
                                2009-04-27 18:08 . 2008-02-05 15:12 20536 -c--a-w c:\documents and settings\Romuald\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                                2009-04-23 21:02 . 2008-07-30 16:20 -------- d-----w c:\program files\Fichiers communs\Symantec Shared
                                2009-04-21 22:48 . 2004-08-05 12:00 75614 ----a-w c:\windows\system32\perfc00C.dat
                                2009-04-21 22:48 . 2004-08-05 12:00 468404 ----a-w c:\windows\system32\perfh00C.dat
                                2009-04-04 07:46 . 2008-02-07 22:17 -------- d-----w c:\program files\Java
                                2009-03-09 03:19 . 2008-12-13 15:41 410984 ----a-w c:\windows\system32\deploytk.dll
                                2009-03-06 14:20 . 2004-08-05 12:00 286720 ----a-w c:\windows\system32\pdh.dll
                                2009-03-03 00:13 . 2004-08-05 12:00 826368 ----a-w c:\windows\system32\wininet.dll
                                2009-02-20 17:10 . 2004-08-05 12:00 78336 ----a-w c:\windows\system32\ieencode.dll
                                2009-02-10 17:06 . 2004-08-04 00:48 2068096 ----a-w c:\windows\system32\ntkrnlpa.exe
                                2009-02-09 14:05 . 2004-08-05 12:00 1846912 ----a-w c:\windows\system32\win32k.sys
                                2009-02-09 11:24 . 2004-08-05 12:00 2191104 ----a-w c:\windows\system32\ntoskrnl.exe
                                2009-02-09 11:23 . 2004-08-05 12:00 111104 ----a-w c:\windows\system32\services.exe
                                2009-02-09 10:53 . 2004-08-05 12:00 735744 ----a-w c:\windows\system32\lsasrv.dll
                                2009-02-09 10:53 . 2004-08-05 12:00 739840 ----a-w c:\windows\system32\ntdll.dll
                                2009-02-09 10:53 . 2004-08-05 12:00 685568 ----a-w c:\windows\system32\advapi32.dll
                                2009-02-09 10:53 . 2004-08-05 12:00 401408 ----a-w c:\windows\system32\rpcss.dll
                                2009-02-06 18:39 . 2009-02-06 18:39 308600 -c--a-w c:\windows\WLXPGSS.SCR
                                2009-02-06 17:52 . 2009-02-06 17:52 49504 ----a-w c:\windows\system32\sirenacm.dll
                                2009-02-06 17:08 . 2009-02-24 15:13 55152 ----a-w c:\windows\system32\drivers\fssfltr_tdi.sys
                                2009-02-06 10:39 . 2004-08-05 12:00 35328 ----a-w c:\windows\system32\sc.exe
                                2009-02-03 19:58 . 2004-08-05 12:00 56832 ----a-w c:\windows\system32\secur32.dll
                                2008-06-25 09:14 . 2008-06-25 09:14 62910 ----a-w c:\program files\Uninstall.exe
                                2008-06-25 09:14 . 2008-06-25 09:14 0 -c--a-w c:\program files\uninstall.dat
                                .

                                ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                REGEDIT4

                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
                                "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]
                                "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
                                "LaCie Backup"="c:\program files\LaCie\Backup Software\\LaCieBackup.exe" [2006-07-06 2596864]
                                "Wallpaper"="c:\program files\Wallpaper\Wallpaper.exe" [2007-08-20 233472]
                                "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy 1.6.2\TeaTimer.exe" [2009-03-05 2260480]

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
                                "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 282624]
                                "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
                                "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
                                "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
                                "High Definition Audio Property Page Shortcut"="HDAShCut.exe" - c:\windows\system32\HdAShCut.exe [2005-01-07 61952]
                                "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2005-06-08 14565376]

                                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
                                "FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe" [2009-02-03 240544]

                                c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                                Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2002-8-20 83360]
                                VPro530.lnk - c:\windows\VPro530.exe [2009-1-19 155648]

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                                "DisableMonitoring"=dword:00000001

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                                "DisableMonitoring"=dword:00000001

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                                "DisableMonitoring"=dword:00000001

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                "%windir%\\system32\\sessmgr.exe"=
                                "c:\\Program Files\\LimeWire\\LimeWire.exe"=
                                "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                "c:\\Program Files\\Messenger\\msmsgs.exe"=
                                "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                                "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

                                R0 Winah28;Winah28; [x]
                                R3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
                                S0 m5287;m5287;c:\windows\system32\drivers\m5287.sys [2005-02-05 85888]
                                S0 seuhbdge;seuhbdge;c:\windows\system32\drivers\seuhbdge.sys [2004-08-05 23424]
                                S2 fssfltr;fssfltr;c:\windows\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
                                S2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
                                S3 phaudlwr;Philips Audio Filter;c:\windows\system32\DRIVERS\phaudlwr.sys [2008-05-07 88704]
                                S3 SPC530;Philips SPC530NC PC Camera;c:\windows\system32\drivers\SPC530.sys [2008-05-21 486912]
                                S3 SPC530m;Philips SPC530NC PC Cameram;c:\windows\system32\drivers\SPC530m.sys [2008-05-21 7680]

                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
                                phtnkjec
                                .
                                - - - - ORPHELINS SUPPRIMES - - - -

                                BHO-{7463D08D-98F5-4217-997D-DA19C71023B9} - c:\windows\system32\vwsbdmh.dll
                                Notify-kzjrvqgi - vwsbdmh.dll

                                .
                                ------- Examen supplémentaire -------
                                .
                                uStart Page = hxxp://www.google.fr/
                                IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
                                FF - ProfilePath - c:\documents and settings\Romuald\Application Data\Mozilla\Firefox\Profiles\39v4jwx6.default\
                                FF - prefs.js: browser.search.selectedEngine - Yahoo
                                FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
                                FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll

                                ---- PARAMETRES FIREFOX ----
                                FF - user.js: yahoo.homepage.dontask - true.

                                **************************************************************************

                                catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2009-04-29 22:17
                                Windows 5.1.2600 Service Pack 3 NTFS

                                Recherche de processus cachés ...

                                Recherche d'éléments en démarrage automatique cachés ...

                                Recherche de fichiers cachés ...

                                Scan terminé avec succès
                                Fichiers cachés: 0

                                **************************************************************************
                                .
                                --------------------- DLLs chargées dans les processus actifs ---------------------

                                - - - - - - - > 'winlogon.exe'(696)
                                c:\windows\system32\Ati2evxx.dll

                                - - - - - - - > 'explorer.exe'(3720)
                                c:\windows\system32\eappprxy.dll
                                c:\windows\system32\WPDShServiceObj.dll
                                c:\windows\system32\PortableDeviceTypes.dll
                                c:\windows\system32\PortableDeviceApi.dll
                                .
                                ------------------------ Autres processus actifs ------------------------
                                .
                                c:\windows\system32\ati2evxx.exe
                                c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                c:\windows\system32\ati2evxx.exe
                                c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                c:\program files\Java\jre6\bin\jqs.exe
                                c:\program files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                                c:\windows\system32\HPZipm12.exe
                                c:\program files\Spyware Terminator\sp_rsser.exe
                                c:\program files\LaCie\Backup Software\LacieBackup.exe
                                c:\program files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                                c:\program files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                                c:\windows\system32\wbem\wmiapsrv.exe
                                .
                                **************************************************************************
                                .
                                Heure de fin: 2009-04-29 22:20 - La machine a redémarré
                                ComboFix-quarantined-files.txt 2009-04-29 20:20

                                Avant-CF: 70 881 923 072 octets libres
                                Après-CF: 70 796 894 208 octets libres

                                WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
                                [boot loader]
                                timeout=2
                                default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
                                [operating systems]
                                c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                                multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

                                200 --- E O F --- 2009-04-29 11:46
                                0
                                1. Re,

                                  Télécharge OTCleanIt de OldTimer sur ton Bureau

                                  Lance OTCleanIt avec un double-clic (sous Vista, lance-le en cliquant droit sur OTCleanIt.exe et en sélectionnant "exécuter en tant qu'administrateur")

                                  Appuie sur le bouton "CleanUp!"

                                  A la question "begin cleanup process?", réponds "YES"

                                  A la fin de l'opération, si OTCleanIt demande de redémarrer ("Do you want to reboot now?"), ferme ce que tu es en train de faire (internet, documents divers...) et clique sur "YES":

                                  Au redémarrage, OTCleanIt aura supprimé les outils de désinfection, et se sera même auto-détruit!
                                  xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
                                  > Fais un scan en ligne avec Kaspersky : Kaspersky

                                  N.B. : Le scan ne marche que sous Internet Explorer.

                                  - Commence par connecter tout ton matériel de stockage à ton PC (clés USB, DD amovible...). Allume les si necessaire.

                                  - Sous Démonstration en ligne, on t'explique la marche à suivre, et pour lancer le scan il faut sélectionner < Exécuter l'analyse en ligne >.

                                  - On va te demander de télécharger un contrôle active x, accepte .

                                  - Dans le menu < Choisissez la cible de l'analyse >, sélectionne < Poste de travail >. Le scan va commencer.

                                  - Poste le rapport qui sera généré stp. (clique sur <enregistrer le rapport> puis sauvegarde-le sur ton bureau en choisissant "fichier texte (*.txt)" pour l'extension).
                                  S'il y a un problème, assure toi que les contrôles active x sont bien configurés dans les options internet comme décrit sur ce lien : clic ici

                                  Rappel : le scan est à faire sous Internet Explorer
                                  Tuto ici si problème

                                  NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte toi sur le site de Kaspersky pour retenter le scan en ligne.
                                  Pour le rapport Kaspersky il faut que tu choisisses "Afficher le rapport" puis que tu l'enregistres sur ton bureau sous forme de fichier texte (type de fichier "tous les fichiers").
                                  0