TROJAN TENACES

Résolu
Bonjour,

Avant tout ce post est une 1ere pour moi... qui manque de compétences en informatique !

Mon PC semble infecté par des virus que je n'arrive pas à enlever avec Norton 2002 ou Ad-aware :
A chaque connexions IE un message apparait m'indiquant un virus dans C:windows\system32\cisvvc.exe ou rdsndin.exe

J'ai aussi une fenetre qui s'affiche régulièrement au centre de l'écran " Windows Security Center"...

Enfin, apparait en bas à droite une autre fenetre "Your computer might be at risk"...

J'avoue que je suis perdu et qu'un scan en mode sans echec ne sert à rien.

P.S. : après chaque utilisation, Ad Aware detecte des virus que je supprime, mais qui ré-apparaisse la fois suivante.

J'utilise Windows XP edition familiale SP1 (le SP2 me plante le Wifi ?!) avec Norton 2002 et connexion freebox.

Par avance merci pour votre aide, un formatage n'est pas super envisageable pour moi

Merci

66 réponses

Résumé de la discussion

Le problème décrit est une infection virale sous Windows XP, avec des messages d'alerte au démarrage et des fenêtres centralisées qui réapparaissent malgré Norton 2002 et Ad-Aware. Des propositions de réparation évoquent HijackThis et SmitFraudFix comme mesures initiales, en privilégiant l'analyse des entrées de démarrage et la suppression des éléments malveillants à partir de rapports effectués. Plusieurs réponses recommandent d'exécuter les outils et de partager les rapports, notamment un rapport HijackThis et un rapport SmitFraudFix, puis de vérifier les restes d'entrées suspectes et les éléments de démarrage. Le dernier échange note l'installation de Mozilla comme navigateur par défaut et cite le rapport SmitFraudFix v1.81, avec des éléments Ad-Aware trouvant des cookies non menaçants, ouvrant des pistes pour la suite.

Bobot (l’IA à votre service)
  1. salut

    telecharge hijackthis:
    http://www.merijn.org/files/hijackthis.zip
    Dezippe le dans un dossier prévu a cet effet.
    Par exemple C:\hijack
    et surtout pas dans un dossier temporaire (temp)
    lance le puis:
    clic sur "do a system scan and save logfile" et pas autre chose
    Le bloc note va s'ouvrir, copie tout le contenu et colle le ici a la suite de ton message.
    Si tu as du mal, regarde ceci:
    http://pageperso.aol.fr/balltrap34/demohijack.htm

    et telecharge Silentrunners
    http://www.silentrunners.org/Silent%20Runners.vbs

    lance le, (si norton te demande si tu veux autoriser l'execution du script, autorise le) et poste le rapport qu'il va generer

    a+
    1. Voila le rapport de HijackThis :

      Logfile of HijackThis v1.99.1
      Scan saved at 20:56:27, on 23/08/2005
      Platform: Windows XP (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 (6.00.2600.0000)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\System32\alg.exe
      c:\Program Files\Norton AntiVirus\navapsvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\wdfmgr.exe
      C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
      C:\windows\system\hpsysdrv.exe
      C:\HP\KBD\KBD.EXE
      C:\WINDOWS\system32\dla\tfswctrl.exe
      C:\PROGRA~1\NORTON~1\navapw32.exe
      C:\Program Files\ATI Technologies\Panneau de contrôle ATI\atiptaxx.exe
      C:\Program Files\Softwin\BitDefender8\bdoesrv.exe
      D:\Program files\System\mnyexpr.exe
      C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
      C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.21 V1.10\WlanCU.exe
      C:\Program Files\Sony Handheld\HOTSYNC.EXE
      C:\Program Files\Sony Handheld\USBSwt.exe
      C:\WINDOWS\System32\wuauclt.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      D:\Nico\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.fr/
      O1 - Hosts: localhost 127.0.0.1
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
      O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
      O4 - HKLM\..\Run: [NAV Agent] c:\PROGRA~1\NORTON~1\navapw32.exe
      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
      O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
      O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
      O4 - HKLM\..\Run: [BDOESRV] C:\Program Files\Softwin\BitDefender8\bdoesrv.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [MoneyAgent] "D:\Program files\System\mnyexpr.exe"
      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
      O4 - HKCU\..\Run: [WareOut] "C:\Program Files\WareOut\WareOut.exe"
      O4 - Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
      O4 - Startup: PowerReg Scheduler.exe
      O4 - Startup: SonyPDA USB Switcher.lnk = C:\Program Files\Sony Handheld\USBSwt.exe
      O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O4 - Global Startup: Wireless Configuration Utility.lnk = C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.21 V1.10\WlanCU.exe
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1112646766326
      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
      O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photoways.com/clients/ImageUploader3.cab
      O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f001.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{41C99A1D-9E68-456C-ABB8-AA75BF304688}: NameServer = 69.50.176.157,85.255.112.6
      O17 - HKLM\System\CCS\Services\Tcpip\..\{D101339D-4EC9-4454-BAEA-55AEE95630E1}: NameServer = 69.50.176.157,85.255.112.6
      O17 - HKLM\System\CCS\Services\Tcpip\..\{DB2F4DF2-C383-414D-BF85-D9329DF5A3FA}: NameServer = 69.50.176.157,85.255.112.6
      O17 - HKLM\System\CCS\Services\Tcpip\..\{EB0BD396-91DC-422B-B3D2-B4BE32C00727}: NameServer = 69.50.176.157,85.255.112.6
      O17 - HKLM\System\CS1\Services\Tcpip\..\{41C99A1D-9E68-456C-ABB8-AA75BF304688}: NameServer = 69.50.176.157,85.255.112.6
      O17 - HKLM\System\CS2\Services\Tcpip\..\{41C99A1D-9E68-456C-ABB8-AA75BF304688}: NameServer = 69.50.176.157,85.255.112.6
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
      O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
      O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender8\vsserv.exe
      O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe

      je telecharge pdt ce temps l'autre programme
      1. Voici le 2eme rapport :

        "Silent Runners.vbs", revision 40, http://www.silentrunners.org/
        Operating System: Windows XP
        Output limited to non-default values, except where indicated by "{++}"

        Startup items buried in registry:
        ---------------------------------

        HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
        "MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]
        "MoneyAgent" = ""D:\Program files\System\mnyexpr.exe"" [MS]
        "H/PC Connection Agent" = ""C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"" [MS]
        "WareOut" = ""C:\Program Files\WareOut\WareOut.exe"" [file not found]

        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
        "hpsysdrv" = "c:\windows\system\hpsysdrv.exe" ["Hewlett-Packard Company"]
        "IgfxTray" = "C:\WINDOWS\System32\igfxtray.exe" ["Intel Corporation"]
        "HotKeysCmds" = "C:\WINDOWS\System32\hkcmd.exe" ["Intel Corporation"]
        "KBD" = "C:\HP\KBD\KBD.EXE" ["Hewlett-Packard Company"]
        "StorageGuard" = ""C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r" ["VERITAS Software, Inc."]
        "dla" = "C:\WINDOWS\system32\dla\tfswctrl.exe" ["VERITAS Software, Inc."]
        "Recguard" = "C:\WINDOWS\SMINST\RECGUARD.EXE" [empty string]
        "NvCplDaemon" = "RUNDLL32.EXE NvQTwk,NvCplDaemon initialize" [MS]
        "nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
        "PS2" = "C:\WINDOWS\system32\ps2.exe" ["Hewlett-Packard Company"]
        "NAV Agent" = "c:\PROGRA~1\NORTON~1\navapw32.exe" ["Symantec Corporation"]
        "ATIModeChange" = "Ati2mdxx.exe" ["ATI Technologies, Inc."]
        "ATIPTA" = "atiptaxx.exe" [file not found]
        "Symantec NetDriver Monitor" = "C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer" ["Symantec Corporation"]
        "Microsoft Works Update Detection" = "C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [file not found]
        "hclean32.exe" = "C:\WINDOWS\System32\hclean32.exe" [null data]
        "BDOESRV" = "C:\Program Files\Softwin\BitDefender8\bdoesrv.exe" ["SOFTWIN SRL"]

        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
        {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
        -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx" [empty string]
        {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
        -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
        {BDF3E430-B101-42AD-A544-FADC6B084872}\(Default) = "NAV Helper"
        -> {CLSID}\InProcServer32\(Default) = "c:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

        HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
        "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
        -> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
        "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
        -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
        "{5CA3D70E-1895-11CF-8E15-001234567890}" = "DriveLetterAccess"
        -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\dla\tfswshx.dll" ["VERITAS Software, Inc."]
        "{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Explorateur de Bureau"
        -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
        "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
        -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
        "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
        -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
        "{596AB062-B4D2-4215-9F74-E9109B0A8153}" = "Previous Versions Property Page"
        -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\twext.dll" [file not found]
        "{9DB7A13C-F208-4981-8353-73CC61AE2783}" = "Previous Versions"
        -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\twext.dll" [file not found]
        "{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
        -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
        "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
        -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
        "{D653647D-D607-4DF6-A5B8-48D2BA195F7B}" = "BitDefender Antivirus v8"
        -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Softwin\BitDefender8\bdshelxt.dll" ["SOFTWIN S.R.L."]

        HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\
        INFECTION WARNING! "System" = "csoqe.exe" [null data]

        HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
        INFECTION WARNING! igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"]

        HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
        BitDefender Antivirus v8\(Default) = "{D653647D-D607-4DF6-A5B8-48D2BA195F7B}"
        -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Softwin\BitDefender8\bdshelxt.dll" ["SOFTWIN S.R.L."]
        Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"
        -> {CLSID}\InProcServer32\(Default) = "c:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

        HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
        BitDefender Antivirus v8\(Default) = "{D653647D-D607-4DF6-A5B8-48D2BA195F7B}"
        -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Softwin\BitDefender8\bdshelxt.dll" ["SOFTWIN S.R.L."]
        Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"
        -> {CLSID}\InProcServer32\(Default) = "c:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

        Active Desktop and Wallpaper:
        -----------------------------

        Active Desktop is disabled at this entry:
        HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

        HKCU\Control Panel\Desktop\
        "Wallpaper" = "C:\WINDOWS\Web\Wallpaper\HPi1-1024.bmp"

        Enabled Screen Saver:
        ---------------------

        HKCU\Control Panel\Desktop\
        "SCRNSAVE.EXE" = "C:\WINDOWS\System32\PORSCH~1.SCR" [file not found]

        Startup items in "Propriétaire" & "All Users" startup folders:
        --------------------------------------------------------------

        C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\Démarrage
        "HotSync Manager" -> shortcut to: "C:\Program Files\Sony Handheld\HOTSYNC.EXE" ["Palm, Inc."]
        INFECTION WARNING! "PowerReg Scheduler.exe" [empty string]
        "SonyPDA USB Switcher" -> shortcut to: "C:\Program Files\Sony Handheld\USBSwt.exe" ["Sony Corporation"]

        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
        "Adobe Gamma Loader.exe" -> shortcut to: "C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]
        "Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l" [MS]
        "Wireless Configuration Utility" -> shortcut to: "C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.21 V1.10\WlanCU.exe" [empty string]

        Enabled Scheduled Tasks:
        ------------------------

        "Norton AntiVirus - Analyser mon ordinateur" -> launches: "c:\PROGRA~1\NORTON~1\NAVW32.exe /task:C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\NORTON~1\Tasks\mycomp.sca" ["Symantec Corporation"]
        "Symantec NetDetect" -> launches: "C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE" ["Symantec Corporation"]
        "XoftSpy" -> launches: "C:\Program Files\XoftSpy\XoftSpy.exe -t" [file not found]

        Winsock2 Service Provider DLLs:
        -------------------------------

        Namespace Service Providers

        HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
        000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
        000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
        000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

        Transport Service Providers

        HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
        0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
        %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17
        %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

        Toolbars, Explorer Bars, Extensions:
        ------------------------------------

        Toolbars

        HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
        "{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus" [from CLSID]
        -> {CLSID}\InProcServer32\(Default) = "c:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
        "{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus" [from CLSID]
        -> {CLSID}\InProcServer32\(Default) = "c:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

        HKLM\Software\Microsoft\Internet Explorer\Toolbar\
        "{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus"
        -> {CLSID}\InProcServer32\(Default) = "c:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

        Miscellaneous IE Hijack Points
        ------------------------------

        C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

        Added lines (compared with English-language version):
        [Strings]: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
        [Strings]: SAFESITE_VALUE="http://home.microsoft.com/intl/fr/"

        Missing lines (compared with English-language version):
        [Strings]: 2 lines

        HOSTS file
        ----------

        C:\WINDOWS\System32\drivers\etc\HOSTS

        maps: 1 domain name to an IP address,
        1 of the IP addresses is *not* localhost!

        Running Services (Display Name, Service Name, Path {Service DLL}):
        ------------------------------------------------------------------

        BitDefender Communicator, XCOMM, "C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe /service" ["Softwin"]
        Service Norton AntiVirus Auto-Protect, navapsvc, "c:\Program Files\Norton AntiVirus\navapsvc.exe" ["Symantec Corporation"]
        Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\System32\wdfmgr.exe" [MS]

        ----------
        + This report excludes default entries except where indicated.
        + To see *everywhere* the script checks and *everything* it finds,
        launch it from a command prompt or a shortcut with the -all parameter.
        + To search all directories of local fixed drives for DESKTOP.INI
        DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
        use the -supp parameter or answer "Yes" at the first message box.
        ---------- (total run time: 85 seconds, including 2 seconds for message boxes)

        y vois tu + clair ? merci
        1. ok, laisse moi quelque minutes le temps de verifier tout ca, si tu peux ne redemarre pas ton pc, avant ma reponse

          +
          1. merci, pas de problème je laisse tout comme ca.
            prends ton temps une urgence m'appelle (femme enceinte).
            dès que je suis dispo je reprend le poste

            toutes mes excuses pour cette interruption!

            a tout à l'heure
            1. salut

              Telecharge: Pocket Killbox ici
              http://www.downloads.subratam.org/KillBox.exe
              l'aide détaillé de la manip est téléchargeable ici:
              http://get.yourfile.net/qn53063.zip
              ou en video ici:
              http://pageperso.aol.fr/balltrap34/killbox.htm

              Imprime, ou fais un copier coller du post et enregistre dans le bloc note pour ne rien oublier

              Deconnecte toi d'internet c'est important

              Vide le cache de tous tes navigateurs et supprime les cookies:

              Pour Internet Explorer:
              * Panneau de configuration >> Options internet >> Onglet "Général"
              - Clic sur [supprimer les cookies]
              - Clic sur [Supprimer les fichiers] et coche la case "Supprimer tout le contenu hors connexion"
              Valide avec ok

              Pour Firefox:
              menu 'Outils' > Options
              icône 'Vie privée'
              rubrique Cache, appuyer sur le bouton "Vider le cache"
              rubrique Cookies appuyer sur le bouton "Effacer"
              valide ok

              Pour Mozilla
              Edition > Préférences > Avancé > Cache
              clic sur "Vider le cache"
              et pour les cookies:
              Outils > Gestionnaire de cookies > Gérer les cookies stockés
              clic sur "Supprimer les cookies"
              valider ok

              -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

              Lance hijackthis et clic sur [do a system scan only]
              cocher la case au début des lignes suivantes:

              O1 - Hosts: localhost 127.0.0.1
              O4 - HKCU\..\Run: [WareOut] "C:\Program Files\WareOut\WareOut.exe"

              valider en cliquant sur [fix checked]

              -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

              ouvre le bloc note et fais un copier coller de ce qui est en gras ci-dessous:

              REGEDIT4

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
              "System"=-
              "System"=""

              [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins]

              [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WareOut]

              [-HKEY_LOCAL_MACHINE\SOFTWARE\WareOut]

              [-HKEY_CURRENT_USER\Software\WareOut]

              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
              "NoBandCustomize"=-

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion]
              "Disabled"=-

              [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls]

              [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "hclean32.exe"=-


              Puis enregistrer sous et dans:
              Nom du fichier, met fix.reg
              Type de fichier: selectionne "tous les fichiers"
              clic sur enregistrer

              ensuite double clic sur fix.reg et accepte de fusionner

              -_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_-_

              - Double-clic sur KillBox.exe (sert toi de l'aide que tu as telechargé si tu as du mal avec cette manip)
              - ouvre le bloc notes et copie la liste en gras ci-dessous
              - Selectionne "Delete on Reboot"
              - reviens sur le bloc-notes et surligne toute la liste, puis clic droit dessus et clic sur copier
              - reviens sur killbox, et dans le menu du haut clic sur File, puis sur paste from clipboard
              - clic sur le rond rouge
              - une fenetre va apparaitre pour confirmation clic sur OUI
              - une seconde fenetre te demande si tu veux redemarrer clic sur OUI

              liste:

              C:\WINDOWS\SYSTEM32\ntfsnlpa.exe
              C:\WINDOWS\System32\CISVVC.EXE
              C:\WINDOWS\SYSTEM32\CSVMC.EXE
              C:\WINDOWS\SYSTEM32\rdsndin.exe
              C:\WINDOWS\SYSTEM32\gpsresl32.exe
              C:\WINDOWS\SYSTEM32\LOADCTR.EXE
              C:\WINDOWS\SYSTEM32\loadctr32.exe
              C:\WINDOWS\SYSTEM32\DRV2CLTR.DLL
              C:\WINDOWS\SYSTEM32\csoqe.exe
              C:\WINDOWS\system32\gpsresl32.exe
              C:\WINDOWS\system32\hclean32.exe
              C:\WINDOWS\SYSTEM32\GPSRESL.EXE


              le pc devrait redemarrer, si tu as un message de killbox à ce moment là et que le pc ne redemarre pas tout seul, redemarre le manuellement.
              une fois redemarré, fais ceci:

              demarrer > connection > clic droit sur ta connection > propriétés
              gestion de reseau
              assure toi que protocole internet tcp/ip est en surbrillance (attention, ne décoche pas la case)> clic sur propriétés > selectionne "obtenir les adresses des serveurs automatiquement"
              valide avec ok

              reposte un hijackthis + un silentrunners

              a+
              1. Encore désolé (une fausse alerte !) :
                Voila après 3 essais j'ai réalisé la procédure et voici le rapport de Hijackthis :

                Logfile of HijackThis v1.99.1
                Scan saved at 22:39:27, on 23/08/2005
                Platform: Windows XP (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 (6.00.2600.0000)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\spoolsv.exe
                c:\Program Files\Norton AntiVirus\navapsvc.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                C:\Program Files\Softwin\BitDefender8\vsserv.exe
                C:\windows\system\hpsysdrv.exe
                C:\HP\KBD\KBD.EXE
                C:\Program Files\VERITAS Software\Update Manager\sgtray.exe
                C:\WINDOWS\system32\dla\tfswctrl.exe
                C:\PROGRA~1\NORTON~1\navapw32.exe
                C:\Program Files\ATI Technologies\Panneau de contrôle ATI\atiptaxx.exe
                C:\Program Files\Softwin\BitDefender8\bdoesrv.exe
                D:\Program files\System\mnyexpr.exe
                C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
                C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.21 V1.10\WlanCU.exe
                C:\Program Files\Sony Handheld\HOTSYNC.EXE
                C:\Program Files\Sony Handheld\USBSwt.exe
                C:\WINDOWS\System32\wuauclt.exe
                C:\WINDOWS\System32\wuauclt.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                D:\Nico\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.fr/
                O1 - Hosts: localhost 127.0.0.1
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
                O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
                O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
                O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
                O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                O4 - HKLM\..\Run: [NAV Agent] c:\PROGRA~1\NORTON~1\navapw32.exe
                O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
                O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                O4 - HKLM\..\Run: [BDOESRV] C:\Program Files\Softwin\BitDefender8\bdoesrv.exe
                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                O4 - HKCU\..\Run: [MoneyAgent] "D:\Program files\System\mnyexpr.exe"
                O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
                O4 - Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
                O4 - Startup: PowerReg Scheduler.exe
                O4 - Startup: SonyPDA USB Switcher.lnk = C:\Program Files\Sony Handheld\USBSwt.exe
                O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                O4 - Global Startup: Wireless Configuration Utility.lnk = C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.21 V1.10\WlanCU.exe
                O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1112646766326
                O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
                O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photoways.com/clients/ImageUploader3.cab
                O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f001.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
                O17 - HKLM\System\CCS\Services\Tcpip\..\{41C99A1D-9E68-456C-ABB8-AA75BF304688}: NameServer = 69.50.176.157,85.255.112.6
                O17 - HKLM\System\CCS\Services\Tcpip\..\{DB2F4DF2-C383-414D-BF85-D9329DF5A3FA}: NameServer = 69.50.176.157,85.255.112.6
                O17 - HKLM\System\CCS\Services\Tcpip\..\{EB0BD396-91DC-422B-B3D2-B4BE32C00727}: NameServer = 69.50.176.157,85.255.112.6
                O17 - HKLM\System\CS1\Services\Tcpip\..\{41C99A1D-9E68-456C-ABB8-AA75BF304688}: NameServer = 69.50.176.157,85.255.112.6
                O17 - HKLM\System\CS2\Services\Tcpip\..\{41C99A1D-9E68-456C-ABB8-AA75BF304688}: NameServer = 69.50.176.157,85.255.112.6
                O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
                O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender8\vsserv.exe
                O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe

                je te poste dans la foulée le 2nd
                merci
                1. et voici silentrunners :

                  "Silent Runners.vbs", revision 40, http://www.silentrunners.org/
                  Operating System: Windows XP
                  Output limited to non-default values, except where indicated by "{++}"

                  Startup items buried in registry:
                  ---------------------------------

                  HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                  "MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]
                  "MoneyAgent" = ""D:\Program files\System\mnyexpr.exe"" [MS]
                  "H/PC Connection Agent" = ""C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"" [MS]

                  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                  "hpsysdrv" = "c:\windows\system\hpsysdrv.exe" ["Hewlett-Packard Company"]
                  "IgfxTray" = "C:\WINDOWS\System32\igfxtray.exe" ["Intel Corporation"]
                  "HotKeysCmds" = "C:\WINDOWS\System32\hkcmd.exe" ["Intel Corporation"]
                  "KBD" = "C:\HP\KBD\KBD.EXE" ["Hewlett-Packard Company"]
                  "StorageGuard" = ""C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r" ["VERITAS Software, Inc."]
                  "dla" = "C:\WINDOWS\system32\dla\tfswctrl.exe" ["VERITAS Software, Inc."]
                  "Recguard" = "C:\WINDOWS\SMINST\RECGUARD.EXE" [empty string]
                  "NvCplDaemon" = "RUNDLL32.EXE NvQTwk,NvCplDaemon initialize" [MS]
                  "nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
                  "PS2" = "C:\WINDOWS\system32\ps2.exe" ["Hewlett-Packard Company"]
                  "NAV Agent" = "c:\PROGRA~1\NORTON~1\navapw32.exe" ["Symantec Corporation"]
                  "ATIModeChange" = "Ati2mdxx.exe" ["ATI Technologies, Inc."]
                  "ATIPTA" = "atiptaxx.exe" [file not found]
                  "Symantec NetDriver Monitor" = "C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer" ["Symantec Corporation"]
                  "Microsoft Works Update Detection" = "C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [file not found]
                  "BDOESRV" = "C:\Program Files\Softwin\BitDefender8\bdoesrv.exe" ["SOFTWIN SRL"]

                  en esperant que cela t'aide...
                  1. stop, voici le bon rapport (je n'ai pas attendu assez lgtps et le précédent post doit etre incomplet
                    Quand on est nul... on est nul !

                    voici :

                    "Silent Runners.vbs", revision 40, http://www.silentrunners.org/
                    Operating System: Windows XP
                    Output limited to non-default values, except where indicated by "{++}"

                    Startup items buried in registry:
                    ---------------------------------

                    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                    "MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]
                    "MoneyAgent" = ""D:\Program files\System\mnyexpr.exe"" [MS]
                    "H/PC Connection Agent" = ""C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"" [MS]

                    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
                    "hpsysdrv" = "c:\windows\system\hpsysdrv.exe" ["Hewlett-Packard Company"]
                    "IgfxTray" = "C:\WINDOWS\System32\igfxtray.exe" ["Intel Corporation"]
                    "HotKeysCmds" = "C:\WINDOWS\System32\hkcmd.exe" ["Intel Corporation"]
                    "KBD" = "C:\HP\KBD\KBD.EXE" ["Hewlett-Packard Company"]
                    "StorageGuard" = ""C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r" ["VERITAS Software, Inc."]
                    "dla" = "C:\WINDOWS\system32\dla\tfswctrl.exe" ["VERITAS Software, Inc."]
                    "Recguard" = "C:\WINDOWS\SMINST\RECGUARD.EXE" [empty string]
                    "NvCplDaemon" = "RUNDLL32.EXE NvQTwk,NvCplDaemon initialize" [MS]
                    "nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
                    "PS2" = "C:\WINDOWS\system32\ps2.exe" ["Hewlett-Packard Company"]
                    "NAV Agent" = "c:\PROGRA~1\NORTON~1\navapw32.exe" ["Symantec Corporation"]
                    "ATIModeChange" = "Ati2mdxx.exe" ["ATI Technologies, Inc."]
                    "ATIPTA" = "atiptaxx.exe" [file not found]
                    "Symantec NetDriver Monitor" = "C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer" ["Symantec Corporation"]
                    "Microsoft Works Update Detection" = "C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [file not found]
                    "BDOESRV" = "C:\Program Files\Softwin\BitDefender8\bdoesrv.exe" ["SOFTWIN SRL"]

                    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
                    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
                    -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx" [empty string]
                    {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
                    -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" ["Safer Networking Limited"]
                    {BDF3E430-B101-42AD-A544-FADC6B084872}\(Default) = "NAV Helper"
                    -> {CLSID}\InProcServer32\(Default) = "c:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

                    HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
                    "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Extension Affichage Panorama du Panneau de configuration"
                    -> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
                    "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Extension icône HyperTerminal"
                    -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
                    "{5CA3D70E-1895-11CF-8E15-001234567890}" = "DriveLetterAccess"
                    -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\dla\tfswshx.dll" ["VERITAS Software, Inc."]
                    "{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Explorateur de Bureau"
                    -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
                    "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
                    -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
                    "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
                    -> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
                    "{596AB062-B4D2-4215-9F74-E9109B0A8153}" = "Previous Versions Property Page"
                    -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\twext.dll" [file not found]
                    "{9DB7A13C-F208-4981-8353-73CC61AE2783}" = "Previous Versions"
                    -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\twext.dll" [file not found]
                    "{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
                    -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
                    "{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
                    -> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Audiodev.dll" [MS]
                    "{D653647D-D607-4DF6-A5B8-48D2BA195F7B}" = "BitDefender Antivirus v8"
                    -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Softwin\BitDefender8\bdshelxt.dll" ["SOFTWIN S.R.L."]

                    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\
                    INFECTION WARNING! "AppInit_DLLs" = "sockspy.dll" [null data]

                    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
                    INFECTION WARNING! igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"]

                    HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
                    BitDefender Antivirus v8\(Default) = "{D653647D-D607-4DF6-A5B8-48D2BA195F7B}"
                    -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Softwin\BitDefender8\bdshelxt.dll" ["SOFTWIN S.R.L."]
                    Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"
                    -> {CLSID}\InProcServer32\(Default) = "c:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

                    HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
                    BitDefender Antivirus v8\(Default) = "{D653647D-D607-4DF6-A5B8-48D2BA195F7B}"
                    -> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Softwin\BitDefender8\bdshelxt.dll" ["SOFTWIN S.R.L."]
                    Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2}"
                    -> {CLSID}\InProcServer32\(Default) = "c:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

                    Active Desktop and Wallpaper:
                    -----------------------------

                    Active Desktop is disabled at this entry:
                    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

                    HKCU\Control Panel\Desktop\
                    "Wallpaper" = "C:\WINDOWS\Web\Wallpaper\HPi1-1024.bmp"

                    Enabled Screen Saver:
                    ---------------------

                    HKCU\Control Panel\Desktop\
                    "SCRNSAVE.EXE" = "C:\WINDOWS\System32\PORSCH~1.SCR" [file not found]

                    Startup items in "Propriétaire" & "All Users" startup folders:
                    --------------------------------------------------------------

                    C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\Démarrage
                    "HotSync Manager" -> shortcut to: "C:\Program Files\Sony Handheld\HOTSYNC.EXE" ["Palm, Inc."]
                    INFECTION WARNING! "PowerReg Scheduler.exe" [empty string]
                    "SonyPDA USB Switcher" -> shortcut to: "C:\Program Files\Sony Handheld\USBSwt.exe" ["Sony Corporation"]

                    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
                    "Adobe Gamma Loader.exe" -> shortcut to: "C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe" ["Adobe Systems, Inc."]
                    "Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l" [MS]
                    "Wireless Configuration Utility" -> shortcut to: "C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.21 V1.10\WlanCU.exe" [empty string]

                    Enabled Scheduled Tasks:
                    ------------------------

                    "Norton AntiVirus - Analyser mon ordinateur" -> launches: "c:\PROGRA~1\NORTON~1\NAVW32.exe /task:C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\NORTON~1\Tasks\mycomp.sca" ["Symantec Corporation"]
                    "Symantec NetDetect" -> launches: "C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE" ["Symantec Corporation"]
                    "XoftSpy" -> launches: "C:\Program Files\XoftSpy\XoftSpy.exe -t" [file not found]

                    Winsock2 Service Provider DLLs:
                    -------------------------------

                    Namespace Service Providers

                    HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
                    000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
                    000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
                    000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

                    Transport Service Providers

                    HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
                    0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
                    %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 17
                    %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

                    Toolbars, Explorer Bars, Extensions:
                    ------------------------------------

                    Toolbars

                    HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
                    "{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus" [from CLSID]
                    -> {CLSID}\InProcServer32\(Default) = "c:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

                    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
                    "{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus" [from CLSID]
                    -> {CLSID}\InProcServer32\(Default) = "c:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

                    HKLM\Software\Microsoft\Internet Explorer\Toolbar\
                    "{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" = "Norton AntiVirus"
                    -> {CLSID}\InProcServer32\(Default) = "c:\Program Files\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

                    Miscellaneous IE Hijack Points
                    ------------------------------

                    C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

                    Added lines (compared with English-language version):
                    [Strings]: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    [Strings]: SAFESITE_VALUE="http://home.microsoft.com/intl/fr/"

                    Missing lines (compared with English-language version):
                    [Strings]: 2 lines

                    HOSTS file
                    ----------

                    C:\WINDOWS\System32\drivers\etc\HOSTS

                    maps: 1 domain name to an IP address,
                    1 of the IP addresses is *not* localhost!

                    Running Services (Display Name, Service Name, Path {Service DLL}):
                    ------------------------------------------------------------------

                    BitDefender Communicator, XCOMM, "C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe /service" ["Softwin"]
                    BitDefender Virus Shield, VSSERV, "C:\Program Files\Softwin\BitDefender8\vsserv.exe /service" ["SOFTWIN S.R.L."]
                    Service Norton AntiVirus Auto-Protect, navapsvc, "c:\Program Files\Norton AntiVirus\navapsvc.exe" ["Symantec Corporation"]
                    Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\System32\wdfmgr.exe" [MS]

                    ----------
                    + This report excludes default entries except where indicated.
                    + To see *everywhere* the script checks and *everything* it finds,
                    launch it from a command prompt or a shortcut with the -all parameter.
                    + To search all directories of local fixed drives for DESKTOP.INI
                    DLL launch points and all Registry CLSIDs for dormant Explorer Bars,
                    use the -supp parameter or answer "Yes" at the first message box.
                    ---------- (total run time: 105 seconds, including 4 seconds for message boxes)
                    1. il reste celles ci à supprimer avec hijackthis :
                      (pour les 017 il faut etre connecté, sinon elles n'apparaissent pas)

                      O1 - Hosts: localhost 127.0.0.1

                      O17 - HKLM\System\CCS\Services\Tcpip\..\{41C99A1D-9E68-456C-ABB8-AA75BF304688}: NameServer = 69.50.176.157,85.255.112.6
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{DB2F4DF2-C383-414D-BF85-D9329DF5A3FA}: NameServer = 69.50.176.157,85.255.112.6
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{EB0BD396-91DC-422B-B3D2-B4BE32C00727}: NameServer = 69.50.176.157,85.255.112.6
                      O17 - HKLM\System\CS1\Services\Tcpip\..\{41C99A1D-9E68-456C-ABB8-AA75BF304688}: NameServer = 69.50.176.157,85.255.112.6
                      O17 - HKLM\System\CS2\Services\Tcpip\..\{41C99A1D-9E68-456C-ABB8-AA75BF304688}: NameServer = 69.50.176.157,85.255.112.6

                      une fois fais, redemarre ton pc et reposte un hijack et dis moi ou en sont tes soucis

                      a+
                      1. Après redemarrage du PC voici le hijack :

                        Logfile of HijackThis v1.99.1
                        Scan saved at 23:06:30, on 23/08/2005
                        Platform: Windows XP (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 (6.00.2600.0000)

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        c:\Program Files\Norton AntiVirus\navapsvc.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                        C:\Program Files\Softwin\BitDefender8\vsserv.exe
                        C:\windows\system\hpsysdrv.exe
                        C:\HP\KBD\KBD.EXE
                        C:\Program Files\VERITAS Software\Update Manager\sgtray.exe
                        C:\WINDOWS\system32\dla\tfswctrl.exe
                        C:\PROGRA~1\NORTON~1\navapw32.exe
                        C:\Program Files\ATI Technologies\Panneau de contrôle ATI\atiptaxx.exe
                        C:\Program Files\Softwin\BitDefender8\bdoesrv.exe
                        D:\Program files\System\mnyexpr.exe
                        C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
                        C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.21 V1.10\WlanCU.exe
                        C:\Program Files\Sony Handheld\HOTSYNC.EXE
                        C:\Program Files\Sony Handheld\USBSwt.exe
                        C:\WINDOWS\System32\wuauclt.exe
                        C:\WINDOWS\System32\wuauclt.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        D:\Nico\Depannage PC forum\HijackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.fr/
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
                        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
                        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
                        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                        O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
                        O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                        O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                        O4 - HKLM\..\Run: [NAV Agent] c:\PROGRA~1\NORTON~1\navapw32.exe
                        O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                        O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
                        O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                        O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                        O4 - HKLM\..\Run: [BDOESRV] C:\Program Files\Softwin\BitDefender8\bdoesrv.exe
                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                        O4 - HKCU\..\Run: [MoneyAgent] "D:\Program files\System\mnyexpr.exe"
                        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
                        O4 - Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
                        O4 - Startup: PowerReg Scheduler.exe
                        O4 - Startup: SonyPDA USB Switcher.lnk = C:\Program Files\Sony Handheld\USBSwt.exe
                        O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                        O4 - Global Startup: Wireless Configuration Utility.lnk = C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.21 V1.10\WlanCU.exe
                        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                        O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1112646766326
                        O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
                        O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photoways.com/clients/ImageUploader3.cab
                        O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f001.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
                        O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                        O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                        O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
                        O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                        O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender8\vsserv.exe
                        O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe

                        il semble que je n'ai plus ces messages de virusou trojan qui apparaissent.
                        je vais rester connecté encore un peu pour voir et te tiens au courant
                        en tout cas merci pour ta précieuse aide ! a priori tu viens de me sauver des heures d'enervement sur le WE !
                        1000 merci
                        a+
                        1. reposte un log fait en etant connecté pour voir si les 017 ont changées
                          1. bonsoir moe31...
                            il me semble Uque tu avais aidé quelqu'un à se debasser d'un trojan..avec un fichier msdirects...peux tu m aider
                            g le meme pb
                        2. voici le log avec une connection :

                          Logfile of HijackThis v1.99.1
                          Scan saved at 23:13:01, on 23/08/2005
                          Platform: Windows XP (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 (6.00.2600.0000)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\spoolsv.exe
                          c:\Program Files\Norton AntiVirus\navapsvc.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                          C:\Program Files\Softwin\BitDefender8\vsserv.exe
                          C:\windows\system\hpsysdrv.exe
                          C:\HP\KBD\KBD.EXE
                          C:\Program Files\VERITAS Software\Update Manager\sgtray.exe
                          C:\WINDOWS\system32\dla\tfswctrl.exe
                          C:\PROGRA~1\NORTON~1\navapw32.exe
                          C:\Program Files\ATI Technologies\Panneau de contrôle ATI\atiptaxx.exe
                          C:\Program Files\Softwin\BitDefender8\bdoesrv.exe
                          D:\Program files\System\mnyexpr.exe
                          C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
                          C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.21 V1.10\WlanCU.exe
                          C:\Program Files\Sony Handheld\HOTSYNC.EXE
                          C:\Program Files\Sony Handheld\USBSwt.exe
                          C:\WINDOWS\System32\wuauclt.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          D:\Nico\Depannage PC forum\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.fr/
                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
                          O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
                          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                          O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                          O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
                          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                          O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
                          O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
                          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                          O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                          O4 - HKLM\..\Run: [NAV Agent] c:\PROGRA~1\NORTON~1\navapw32.exe
                          O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                          O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
                          O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                          O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                          O4 - HKLM\..\Run: [BDOESRV] C:\Program Files\Softwin\BitDefender8\bdoesrv.exe
                          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                          O4 - HKCU\..\Run: [MoneyAgent] "D:\Program files\System\mnyexpr.exe"
                          O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
                          O4 - Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
                          O4 - Startup: PowerReg Scheduler.exe
                          O4 - Startup: SonyPDA USB Switcher.lnk = C:\Program Files\Sony Handheld\USBSwt.exe
                          O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                          O4 - Global Startup: Wireless Configuration Utility.lnk = C:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.21 V1.10\WlanCU.exe
                          O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                          O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1112646766326
                          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                          O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
                          O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photoways.com/clients/ImageUploader3.cab
                          O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f001.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
                          O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                          O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                          O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
                          O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                          O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                          O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                          O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender8\vsserv.exe
                          O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe

                          tu vois des choses à enlever ?
                          1. ben normallement en étant connecté, il devrait y avoir une ligne 017 qui apparait dans hijackthis, sinon rien de suspect.

                            tu peux faire un scan de verif ici, quand tu auras un peu de temps devant toi:
                            http://www.bitdefender.fr

                            a++
                            1. un super grand merci pour tes competences.
                              juste 2 questions : faut il systematiquement supp les lignes 017 ?
                              d'ou venaient ces m..... ? (comment prévenir ?)

                              sinon je vais de ce pas faire un scan en ligne

                              Merci et re-merci !!!

                              A+
                              1. non surtout pas, elle corresponde à ta connection et ton adresse ip
                                par exemple ton adresse ip avait était detournée au profit de celle là: 69.50.176.157,85.255.112.6
                                ce qui correspond apres verif à Atrivotechnologie, alias coolwebsearch, qui est responsable actuellement des pires spywares et trojans.
                                http://www.dnsstuff.com/tools/whois.ch?ip=69.50.176.157

                                poste le resultat du scan et on dicutera du reste demain
                                j'arrete pour ce soir demain lever tres tot :-(

                                à demain
                                1. pas de problème, d'ailleurs vu le tps que me demande le scan, je le stop et file aussi au lit.
                                  je le relancerai demain soir après le boulot et te posterai le resultat.

                                  Merci pour ta patience et ton savoir

                                  A+
                                  1. bonjour cnb et moe.

                                    je m'excuse d'intervenir comme ça dans votre discussion, mais après de nombreuses recherches, j'ai l'impression que c'est ici que je trouverais la solution à mon problème.
                                    je ne voulais pas ouvrir un nouveau topic, vu que cela me semble assez similaire.
                                    Donc, le problème est un trojandownloader, que norton 2004 détecte dans winsocks5.exe, et que adaware détecte dans les H-KEYS comme un coolwebsearch, au nombre de 6, à chaque fois.
                                    Adaware dit qu'il supprime le fichier ( ce qui n'est pas le cas puisqu'à chaque nouveau scan il redétecte les mêmes virus ) et Norton dit qu'il n'y arrive pas.

                                    Donc ma question c'est dois-je suivre la même procédure que celle que tu indiques pour cnb? à savoir dwld de hijackthis et silentrunners.
                                    et surtout à tu le temps et l'envie de te pencher encore sur ce problème ( qui peut être réglé après celui de cnb évidemment ) sinon, peux tu m'indiquer une autre personne du forum ou un autre forum où on saura m'aider aussi bien qu'ici?

                                    dans tous les cas, merci d'avance!

                                    ps: le pc infecté n'est pas celui à partir duquel je poste le msg. le pc infecté n'arrive plus à se connecter à internet, il n'y a que msn qui marche. et norton fait une boucle infernale disant qu'il a repéré le virus puis qu'il n'a pas réussi à s'en débarasser, je clique sur "ok", et il recommence...indéfiniment.
                                    ps2: le pc infecté est en réseau avec celui à partir duquel je poste le msg, y a t'il un risque de contamination?

                                    merci
                                    1. salut stephane

                                      crée ton propre message, ce sera plus clair pour tout le monde.

                                      dans ton nouveau message, poste un rapport hijackthis + un silentrunners et je regarderais volontier de quoi il en retourne

                                      a+
                                      1. Bonsoir moe31,

                                        je reviens vers toi car ce soir, car après un scan complet Norton m'a trouvé 4 virus :
                                        - cisvvc.exe (trojan adclicker)
                                        - hclean32.exe (trojan horse)
                                        - cstob.exe (trojan Dropper)
                                        - mssosxrt.exe (trojan dropper)

                                        Par ailleurs j'ai effectué le scan en ligne bitdefender qui m'a aussi trouvé des "trucs pas terribles". As-tu besoin du rapport qui est super long ? comment t'aider ?

                                        par avance merci pour cette affaire qui devient un peu galère
                                        • 1
                                        • 2
                                        • 3
                                        • 4