Spyware encombrant

Bonjour,

J'ai depuis hier des spywares très encombrants du nom de "webdialer", "dso exploit", "coolwebsearch" et "allcybersearch".
Spybot et ad-aware SE ne réussisse pas à les éliminer.
J'ai lancé Hijack this mais je ne sais pas ce qu'il faut fixer.

voici le log affiché :

Logfile of HijackThis v1.99.1
Scan saved at 14:44:05, on 10/04/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\rundll32.exe
C:\Documents and Settings\Daniel\Mes documents\Vincent\internet\HijackThis.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\System32\ctfmon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {CBC5014C-CC96-4316-9A04-EA3A6D5108D9} - C:\WINDOWS\System32\clfl.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gknhmurpb] c:\windows\system32\gknhmurpb.exe -start
O4 - HKLM\..\Run: [Anti Spyware] "C:\Program Files\SinEspias\No-Spy.exe" /autorun
O4 - HKLM\..\Run: [Sans Espions] "C:\Program Files\SinEspias\No-Spy.exe" /autorun
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll,DllInstall
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {DDF44FD9-749F-4761-89BB-E8A59339E459} - http://akamai.downloadv3.com/binaries/LiveService/LiveService_9_FR_XP.cab
O18 - Filter: text/html - {CC2DAD45-523A-4F12-9D78-8055E365C561} - C:\WINDOWS\System32\clfl.dll
O18 - Filter: text/plain - {CC2DAD45-523A-4F12-9D78-8055E365C561} - C:\WINDOWS\System32\clfl.dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Quelqu'un peut il m'aider s'il vous plait.

merci d'avance
Configuration: PC Packard Bell
avec windows XP

18 réponses

  1. salut vincent

    Commence par mettre à jours ad-aware et spybot (ne pas oublier de revacciner apres).
    ensuite telecharge:
    - CWShredder:
    http://cwshredder.net/bin/CWShredder.exe
    et met le à jour immediatement (update).
    ne l'utilise pas pour l'instant.

    -------------

    -> Rend visible les fichiers cachés et systeme
    panneau de configuration > options des dossiers > onglet affichage
    cocher " afficher les fichiers et dossiers cachés "
    décocher " masquer les extentions des fichiers dont le type est connu
    décocher " masquer les fichiers protégés du système"

    -> désactive la restauration systéme
    Clic droit sur poste de travail > propriétés > onglet restauration système
    puis cocher "désactiver la restauration système".

    Lance hijackthis et Fixe:
    (cocher au début de chaques lignes valider avec fix checked)

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

    O2 - BHO: (no name) - {008DB894-99ED-445D-8547-0E7C9808898D} - (no file)
    O2 - BHO: (no name) - {CBC5014C-CC96-4316-9A04-EA3A6D5108D9} - C:\WINDOWS\System32\clfl.dll

    O4 - HKLM\..\Run: [gknhmurpb] c:\windows\system32\gknhmurpb.exe -start
    O4 - HKLM\..\Run: [Anti Spyware] "C:\Program Files\SinEspias\No-Spy.exe" /autorun
    O4 - HKLM\..\Run: [Sans Espions] "C:\Program Files\SinEspias\No-Spy.exe" /autorun
    O4 - HKLM\..\Run: [sp] rundll32 C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll,DllInstall

    O16 - DPF: {DDF44FD9-749F-4761-89BB-E8A59339E459} - http://akamai.downloadv3.com/binaries/LiveService/LiveService_9_FR_XP.cab

    O18 - Filter: text/html - {CC2DAD45-523A-4F12-9D78-8055E365C561} - C:\WINDOWS\System32\clfl.dll
    O18 - Filter: text/plain - {CC2DAD45-523A-4F12-9D78-8055E365C561} - C:\WINDOWS\System32\clfl.dll

    Puis:
    - Redémarre en mode sans échec en appuyant sur la touche F8 au démarrage de ton PC (apres l'ecran du bios)

    Rechercher et supprimer si présent:

    C:\WINDOWS\System32\clfl.dll
    C:\Program Files\SinEspias<= tout le dossier
    c:\windows\system32\gknhmurpb.exe
    C:\Documents and Settings\administrateur\Local Settings\Temp<= vide tout le contenu du dossier

    Supprimer tout les fichiers à l'intérieur des dossiers suivants:

    * C:\Temp
    * C:\Windows\Temp
    * C:\WINDOWS\Prefetch <= sauf le fichier layout.ini
    * C:\Documents and Settings\pour chaques utilisateurs\Local Settings\Temp
    * C:\Documents and Settings\pour chaques utilisateurs \Local Settings\Temporary Internet Files
    * C:\Documents and Settings\pour chaques utilisateurs \Cookies

    * Vider la corbeille !

    lance cwshredder (clic sur FIX)

    Profite d'être en mode sans echecs pour lancer le scan de ad-aware, spybot... et supprime tout ce qu'ils trouvent.

    Redemarre normalement et reposte un log hijack pour vérifier l'évolution

    tu peux telecharger cet utilitaire pour nettoyer ton registre:
    regseeker
    http://www.hoverdesk.net/freeware.htm
    lance le, puis clic sur nettoyage registre et ne supprime que les entrées en vert (attention !)

    Ne pas oublier après les manips de recocher " masquer les fichiers protégés du système" dans les options des dossiers

    a+
    0
    1. voici le nouveau log Hijack, j'espère que c'est mieux :

      par contre, je n'ai pas réussi à supprimer un fichier :

      C:\WINDOWS\System32\clfl.dll

      Logfile of HijackThis v1.99.1
      Scan saved at 16:51:25, on 10/04/2005
      Platform: Windows XP SP1 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\System32\drivers\CDAC11BA.EXE
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\cisvc.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
      C:\WINDOWS\system32\slserv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
      C:\WINDOWS\wanmpsvc.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Winamp\winampa.exe
      C:\PROGRA~1\Wanadoo\CnxMon.exe
      C:\PROGRA~1\MESSAG~1\StartMessager.exe
      C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\MSN Messenger\MsnMsgr.Exe
      C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
      C:\VSTASCAN\vsaccess.exe
      C:\Documents and Settings\Daniel\Mes documents\Vincent\internet\HijackThis.exe
      C:\WINDOWS\System32\wuauclt.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Daniel\LOCALS~1\Temp\se.dll/spage.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.wanadoo.fr/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
      O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
      O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [gknhmurpb] c:\windows\system32\gknhmurpb.exe -start
      O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - Startup: UMAX VistaAccess.lnk = C:\VSTASCAN\vsaccess.exe
      O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
      O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
      O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
      O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

      merci

      A+
      0
  2. Contributeur sécurité
    salut
    imprime ceci pour ne rien oublier et tous faire
    tous faire dans l ordre imperativement
    -------------------------
    tous da bord telecharge ces programmes si tu ne les a pas et met les a jour mais ne les utilise pas encore
    adaware (1)
    spyboot (2)
    (ici) http://www.florensac-chasse-trap.com/ section virus
    et aussi ceci
    CleanUp312.exe (3)

    ----------------

    demarre en mode sans echec
    mode sans echec pour cela tu tapote la touche f8
    des le debut de l allumage du pc sans t arreter
    une fenetre vas souvrir tute deplace avec les fleches du clavier sur demarreren mode sans echec
    une fois sur le bureau il ni auras pas toutes les couleurs et autres c est normal.si f8 ne marche pas utilise la touche f5
    -------------------------
    desactive ta restauration systeme
    pour ça tu fais clic droit sur poste de travail
    propriété tu clique sur onglet restauration système
    tu coche la case désactiver la restauration et applique
    ------------

    assure toi de ceci
    Affiche tous les fichiers et dossiers :
    cliquer sur démarrer/panneau de configuration/option des dossiers/affichage
    Cocher afficher les dossiers cacher

    Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

    Décocher masquer les extensions dont le type est connu
    Puis fais «Ok» pour valider les changements.

    Et appliquer
    ----------------------
    vide tes fichiers temps et tempory internet file sur tous les utilisateur
    utilise ceci pour le faire
    http://pageperso.aol.fr/Balltrap34/CleanUp312.exe

    --------------------
    relance hijack coche ces lignes et ensuite clik sur fix

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Daniel\LOCALS~1\Temp\se.dll/spage.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O4 - HKLM\..\Run: [gknhmurpb] c:\windows\system32\gknhmurpb.exe -start
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab

    la ligne si dessous c est toi qui la mis en zone de confiance
    O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm

    ----------------------
    recherche et suppr ceci
    attention seulement les fichiers
    C:\DOCUME~1\Daniel\LOCALS~1\Temp\se.dll/spage.html
    c:\windows\system32\gknhmurpb.exe

    ---------------
    passe adaware et vire tous se qu il trouve
    ----------
    passe spy boot et vire tous se qu il trouvent
    -------------

    -------------
    tu vide ta poubelle et tu redemarre en mode normal et refait un hijack

    --
    0
    1. Salut vincent

      toujours les memes...

      -> Rend visible les fichiers cachés et systeme
      panneau de configuration > options des dossiers > onglet affichage
      cocher " afficher les fichiers et dossiers cachés "
      décocher " masquer les extentions des fichiers dont le type est connu
      décocher " masquer les fichiers protégés du système"

      -> désactive la restauration systéme
      Clic droit sur poste de travail > propriétés > onglet restauration système
      puis cocher "désactiver la restauration système".

      Puis important:
      - Redémarre en mode sans échec en appuyant sur la touche F8 au démarrage de ton PC (apres l'ecran du bios)

      ---------------------------------------------

      Lance hijackthis et Fixe:
      (cocher au début de chaques lignes valider avec fix checked)

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Daniel\LOCALS~1\Temp\se.dll/spage.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/spage.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

      O4 - HKLM\..\Run: [gknhmurpb] c:\windows\system32\gknhmurpb.exe -start

      Rechercher et supprimer si présent:

      c:\windows\system32\gknhmurpb.exe

      C:\Documents and Settings\administrateur\Local Settings\Temp\se.dll

      C:\Documents and Settings\Daniel\Local Settings\Temp\se.dll

      Ensuite:

      Supprimer tout les fichiers à l'intérieur des dossiers suivants:

      * C:\Temp
      * C:\Windows\Temp
      * C:\WINDOWS\Prefetch <= sauf le fichier layout.ini
      * C:\Documents and Settings\tous les utilisateurs\Local Settings\Temp
      * C:\Documents and Settings\tous les utilisateurs \Local Settings\Temporary Internet Files
      * C:\Documents and Settings\tous les utilisateurs \Cookies
      * Vider la corbeille !

      Nettoyage du disque:
      Démarrer > Tous les programmes > accessoires > outils système > nettoyage du disque
      cocher:
      - fichiers et programmes téléchargés
      - fichiers internet temporaires
      - corbeille
      - fichier temporaires
      valider ok

      relance hijackthis et clic sur "open the misc tool section"
      clic sur "delete file on reboot"
      deplace toi jusqu' a C:\WINDOWS\System32\
      clic sur clfl.dll
      et valide "ouvrir"
      accepte le redemarrage

      une fois redemarré , fais un scan AV ici:
      http://www.ravantivirus.com/scan/
      Clic sur "To continue without subscribing click here"
      Lorsque "Ready" est affiché dans "status", clic sur "Scan my PC".
      A la fin de l'analyse, copier/coller le rapport ici + un nouveau rapport hijackthis

      Ne pas oublier après les manips de recocher " masquer les fichiers protégés du système" dans les options des dossiers

      a+
      0
      1. Contributeur sécurité
        oups j avais sauter l administrateur
        je rajoute lance deux fois de suite about buster
        0
        1. salut balltrap

          j'avais pas vu ton post, dsl
          0
          1. Contributeur sécurité
            pas grave la preuve j en avait sauter un
            0
            1. Merci les gars,

              mais je quelle manip, car les deux semble assez diférente ????
              0
              1. Contributeur sécurité
                fait celle de moe pas grave

                pour moe
                tu la sort d ou celle ci
                clic sur clfl.dll
                0
                1. elle apparait dans le premier log en 018, et vincent n'a pas reussi à la supprimer.
                  elle n'est plus là dans le dernier log, mais bon.... toujours dans system32.
                  0
                  1. Contributeur sécurité
                    oki j avais pas repris le debut du post
                    peut etre si elle exixte toujour clik droit dessus et decocher lecture seul
                    0
                    1. merci beaucoup les gars

                      j'ai effectué la manip de Moe mais certaines lignes à fixer n'étaient plus présentes et je n'ai pas retrouvé le fichier clfl.dll lorsque je devais le supprimer en rebootant.
                      j'ai alors redémarrer simplement.

                      voici le rapport de Hijackthis, scan AV est lancé depuis plus d'une heure, y'en a pour combien de temps ????

                      Logfile of HijackThis v1.99.1
                      Scan saved at 19:45:28, on 10/04/2005
                      Platform: Windows XP SP1 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\cisvc.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                      C:\WINDOWS\system32\slserv.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                      C:\WINDOWS\wanmpsvc.exe
                      C:\WINDOWS\SOUNDMAN.EXE
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\Program Files\Winamp\winampa.exe
                      C:\Program Files\Fichiers communs\Real\Update_OB\rnathchk.exe
                      C:\PROGRA~1\Wanadoo\CnxMon.exe
                      C:\PROGRA~1\MESSAG~1\StartMessager.exe
                      C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                      C:\VSTASCAN\vsaccess.exe
                      C:\Program Files\Wanadoo\EspaceWanadoo.exe
                      C:\Program Files\Wanadoo\ComComp.exe
                      C:\Program Files\Wanadoo\Watch.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\WINDOWS\system32\cidaemon.exe
                      C:\Documents and Settings\Daniel\Mes documents\Vincent\internet\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.wanadoo.fr/
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                      O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                      O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                      O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
                      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                      O4 - Startup: UMAX VistaAccess.lnk = C:\VSTASCAN\vsaccess.exe
                      O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
                      O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                      O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
                      O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
                      O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{482B124D-CC2C-442B-B760-0D6A0F508EA4}: NameServer = 80.10.246.1 80.10.246.132
                      O17 - HKLM\System\CS1\Services\Tcpip\..\{482B124D-CC2C-442B-B760-0D6A0F508EA4}: NameServer = 80.10.246.1 80.10.246.132
                      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                      O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                      O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
                      0
                      1. salut

                        tu peux fixer celles ci (pas besoin de redemarrer en sans echec):
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

                        sinon pour moi c'est ok.

                        Pour le scan av, ca bloque?
                        sinon essaye ici:
                        http://www.bitdefender.com/scan/licence.php

                        a+
                        0
                        1. Salut,

                          ça y est, scan AV a terminé. voici le rapport ainsi que celui de hijackthis après avoir fixé les dernières lignes.

                          Scan started at 10/04/2005 18:32:47

                          Scanning memory...
                          Scanning boot sectors...
                          Scanning files...
                          C:\Documents and Settings\Daniel\Local Settings\Application Data\Identities\{050CEDE1-32C5-41E7-BE5C-3FDF69A8197D}\Microsoft\Outlook Express\Éléments supprimés.dbx->Message.0: (MAILER-DAEMON@wanadoo.fr (Mail Delivery System) [Undelivered Mail Returned to S... - Win32/Netsky.C@mm -> Suspicious
                          C:\WINDOWS\system32\msklive.dll - TrojanSpy:Win32/Mslagent -> Infected

                          Scanned
                          ============================
                          Objects: 43884
                          Directories: 4433
                          Archives: 6936
                          Size(Kb): -1993131
                          Infected files: 2

                          Found
                          ============================
                          Viruses found: 1
                          Suspicious files: 1
                          Disinfected files: 0
                          Mail files: 129

                          Logfile of HijackThis v1.99.1
                          Scan saved at 20:08:30, on 10/04/2005
                          Platform: Windows XP SP1 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\cisvc.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                          C:\WINDOWS\system32\slserv.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                          C:\WINDOWS\wanmpsvc.exe
                          C:\WINDOWS\SOUNDMAN.EXE
                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                          C:\Program Files\Winamp\winampa.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\rnathchk.exe
                          C:\PROGRA~1\Wanadoo\CnxMon.exe
                          C:\PROGRA~1\MESSAG~1\StartMessager.exe
                          C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                          C:\Program Files\QuickTime\qttask.exe
                          C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                          C:\VSTASCAN\vsaccess.exe
                          C:\Program Files\Wanadoo\EspaceWanadoo.exe
                          C:\Program Files\Wanadoo\ComComp.exe
                          C:\Program Files\Wanadoo\Watch.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\WINDOWS\system32\cidaemon.exe
                          C:\WINDOWS\bdonlinescan\avxLive.exe
                          C:\Documents and Settings\Daniel\Mes documents\Vincent\internet\HijackThis.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
                          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.wanadoo.fr/
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                          O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                          O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
                          O4 - HKLM\..\Run: [MessagerStarter Wanadoo] C:\PROGRA~1\MESSAG~1\StartMessager.exe Messager Wanadoo
                          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                          O4 - Startup: UMAX VistaAccess.lnk = C:\VSTASCAN\vsaccess.exe
                          O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                          O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
                          O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                          O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst0401.cab
                          O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
                          O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
                          O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
                          O17 - HKLM\System\CCS\Services\Tcpip\..\{482B124D-CC2C-442B-B760-0D6A0F508EA4}: NameServer = 80.10.246.1 80.10.246.132
                          O17 - HKLM\System\CS1\Services\Tcpip\..\{482B124D-CC2C-442B-B760-0D6A0F508EA4}: NameServer = 80.10.246.1 80.10.246.132
                          O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                          O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                          O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                          O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

                          merci encore
                          A+
                          0
                      2. Contributeur sécurité
                        celui la tu recherche et tu suppr
                        C:\WINDOWS\system32\msklive.dll
                        por l autre tu vas dans ta messageries sur message suppr et tu vire tous
                        0
                        1. le hijack est ok
                          pour le rapport de rav:

                          le 1er est dans les elements supprimés d'outlook
                          vide le contenu des elements supprimés

                          pour celui là, supprime le C:\WINDOWS\system32\msklive.dll
                          si tu n'y arrives pas en mode normal, supprime le en mode sans echecs.

                          a+
                          0
                          1. argghh!! grillé !
                            0
                            1. Contributeur sécurité
                              ca brule moe
                              0
                          2. ça y est, logiquement c'est terminé, je vous remercie beaucoup !!!!

                            Par contre, comment faire pour que ce genre de truc n'arrive plus ?????

                            Encore merci

                            A+
                            0
                            1. en espérant que ca reponde à ta question:

                              pour éviter pas mal de problemes.

                              - Windows Update parfaitement à jour (catégorie critique, Services Pack)
                              http://v5.windowsupdate.microsoft.com

                              - Un firewall bien paramétré.
                              http://www.firewall-net.com/
                              http://www.commentcamarche.net/protect/firewall.php3

                              - Un antivirus bien paramétré et mis à jour regulièrement et un scan complet régulier.
                              + de temps en temps un scan en ligne.
                              Liste scans AV en ligne ici:
                              http://assiste.free.fr/p/antivirus_gratuits_en_ligne/antivirus_en_ligne.php

                              - scan régulier avec antispywares à jours.

                              - une attitude prudente en surfant (téléchargements) et vis à vis de la messagerie (les fichiers joints aux messages doivent etre scannés avant d'etre ouvert).

                              - Pour Internet explorer, un bon réglage de la gestion des controles activex.
                              http://gerard.melone.free.fr/IT/IT-AM0.html
                              ou envisager de passer à un autre navigateur comme mozilla, firefox...
                              http://frenchmozilla.sourceforge.net/

                              - Être vigilant aux fonctionnements inhabituels de ton système.

                              - nettoyage régulier du système (suppression des fichiers inutiles, nettoyage de la base de registre, defragmentation).

                              _______________________

                              Antispywares:

                              * Spybot S&D:
                              http://spybot.safer-networking.de/fr/download/index.html
                              l'aide:
                              http://www.zebulon.fr/articles/spybot_1.php
                              http://assiste.free.fr/p/internet_utilitaires/spybot_search_destroy.php#ssd_02

                              * Ad-aware:
                              http://www.lavasoftusa.com/french/support/download/
                              l'aide:
                              http://www.ordi-netfr.org/tutorialadaware.php

                              * A² free
                              http://www.emsisoft.net/fr/software/free/

                              * Spysweeper (gratuit 30 jours):
                              http://www.webroot.com/fr/products/spysweeper/

                              Pour la prévention:
                              * SpywareBlaster :
                              http://www.javacoolsoftware.com/downloads.html

                              Bien lire l'aide, et mettre à jours avant de les utiliser.

                              Pour sécuriser un peu plus son pc:
                              Safe XP:
                              http://theorica.click-now.net/download.htm

                              Nettoyage du registre:

                              * Regseeker(gratuit)
                              lire l'aide avant d'utiliser:
                              http://www.ordi-netfr.com/regseeker.html

                              Nettoyage fichiers internet, temps, cookies...

                              * CCleaner (gratuit)
                              http://www.ccleaner.com/ccdownload.asp

                              * Cleanup:
                              http://pageperso.aol.fr/Balltrap34/CleanUp312.exe

                              A lire de toute urgence:
                              http://sebsauvage.net/safehex.html
                              http://assiste.free.fr

                              a+
                              0
                              1. Salut,

                                merci beaucoup pour toutes ces infos et encore merci pour l'après-midi passée à soigner mon PC.

                                A+
                                0