Besoin d'une analyse Svp

Bonjour à tous,

j'aurai besoin que quelqu'un puisse m'aider à éradiquer un virus. J'ai déjà supprimer les spywares et tout et tout...il me reste à fixer certaines lignes: voici mon log:

Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\GEARSec.exe
d:\Norton Ghost\Agent\PQV2iSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
C:\WINDOWS\Explorer.EXE
D:\Norton Ghost\Agent\GhostTray.exe
D:\bitdef~1\bdmcon.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\inet20010\services.exe
c:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\SAGEM\SAGEM F@st 800-908\dslmon.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\inet20010\mm4.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\inet20010\mm4.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\ServicePackFiles\i386\IExplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
F:\Logiciels\Virus de merde\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F3 - REG:win.ini: run=C:\WINDOWS\inet20010\services.exe
O2 - BHO: HBO Class - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - C:\WINDOWS\inet20010\3.00.13.dll
O4 - HKLM\..\Run: [Norton Ghost 9.0] d:\Norton Ghost\Agent\GhostTray.exe
O4 - HKLM\..\Run: [BDMCon] D:\bitdef~1\bdmcon.exe
O4 - HKLM\..\Run: [BDNewsAgent] D:\bitdef~1\bdnagent.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20010\services.exe
O4 - HKLM\..\Run: [SystemLoader] C:\WINDOWS\sysldr32.exe
O4 - HKLM\..\Run: [Microsoft Office] C:\WINDOWS\system32\msvcp.exe
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [WinMedia] C:\WINDOWS\system32\wwwloader.exe
O4 - HKCU\..\Run: [xp_system] C:\WINDOWS\inet20010\services.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-908\dslmon.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128282998868
O16 - DPF: {826287F8-454E-11D9-ADFE-00062919A34C} (ActiveXUploadFotoCom.UserCtrlFotoCom) - http://express.foto.com/activeX/newUploadFotoCom.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: msupdate - C:\WINDOWS\SYSTEM32\msupdate32.dll
O20 - Winlogon Notify: Reliability - C:\WINDOWS\system32\j0j6la1s1d.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton Ghost - Symantec Corporation - d:\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

Merci de votre aide
Charly

14 réponses

  1. Contributeur
    Salut Charly

    Hormis BitDefender c'est quoi ta protection ?

    - Télécharge et scanne ton PC avec Ewido Security Suite : http://www.01net.com/telecharger/windows/Utilitaire/antivirus/fiches/31851.html
    Copie/colle le rapport sur le forum.

    ++
    0
    1. En fait, je n'ai que Bit Defender. J'ai fait cependant une analyse avec Panda Active Scan entre temps.

      Je mets le résultat du scan avec Ewido dans quelques minutes ;)
      0
  2. Re- !

    Donc voici le rapport avec Ediwo

    ---------------------------------------------------------
    ewido anti-malware - Rapport de scan
    ---------------------------------------------------------

    + Créé le: 22:12:52, 28/01/2006
    + Somme de contrôle: 44C36682

    + Résultats du scan:

    HKLM\SOFTWARE\Classes\CLSID\{5321E378-FFAD-4999-8C62-03CA8155F0B3} -> Spyware.CoolWebSearch : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\CLSID\{724510C3-F3C8-4FB7-879A-D99F29008A2F} -> Hijacker.SpyAxe : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\Replace.HBO -> Spyware.CoolWebSearch : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\Replace.HBO\CLSID -> Spyware.CoolWebSearch : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\Replace.HBO\CurVer -> Spyware.CoolWebSearch : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Classes\Replace.HBO.1 -> Spyware.CoolWebSearch : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objecta\{724510c3-f3c8-4fb7-879a-d99f29008a2f} -> Hijacker.SpyAxe : Nettoyer et sauvegarder
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5321E378-FFAD-4999-8C62-03CA8155F0B3} -> Spyware.CoolWebSearch : Nettoyer et sauvegarder
    HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{724510C3-F3C8-4FB7-879A-D99F29008A2F} -> Hijacker.SpyAxe : Nettoyer et sauvegarder
    HKU\S-1-5-21-1715567821-1060284298-854245398-1005\Software\Microsoft\Internet Explorer\Keywords -> Spyware.CoolWebSearch : Nettoyer et sauvegarder
    HKU\S-1-5-21-1715567821-1060284298-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{44BE0690-5429-47F0-85BB-3FFD8020233E} -> Spyware.UCmore : Nettoyer et sauvegarder
    HKU\S-1-5-21-1715567821-1060284298-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5321E378-FFAD-4999-8C62-03CA8155F0B3} -> Spyware.CoolWebSearch : Nettoyer et sauvegarder
    HKU\S-1-5-21-1715567821-1060284298-854245398-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{724510C3-F3C8-4FB7-879A-D99F29008A2F} -> Hijacker.SpyAxe : Nettoyer et sauvegarder
    HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{724510C3-F3C8-4FB7-879A-D99F29008A2F} -> Hijacker.SpyAxe : Nettoyer et sauvegarder
    [1696] C:\WINDOWS\system32\mujtes40.dll -> Spyware.Look2Me : Erreur durant le nettoyage
    [796] C:\WINDOWS\system32\mujtes40.dll -> Spyware.Look2Me : Erreur durant le nettoyage
    [200] C:\WINDOWS\inet20010\3.00.13.dll -> Spyware.Ihbo : Nettoyer et sauvegarder
    [6200] C:\WINDOWS\inet20010\3.00.13.dll -> Spyware.Ihbo : Erreur durant le nettoyage
    [9448] C:\WINDOWS\inet20010\mm4.exe -> Proxy.Delf.an : Nettoyer et sauvegarder
    [12440] C:\WINDOWS\inet20010\3.00.13.dll -> Spyware.Ihbo : Erreur durant le nettoyage
    C:\Documents and Settings\Charly\Cookies\charly@247realmedia[1].txt -> Spyware.Cookie.247realmedia : Nettoyer et sauvegarder
    C:\Documents and Settings\Charly\Cookies\charly@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Nettoyer et sauvegarder
    C:\Documents and Settings\Charly\Cookies\charly@adtech[2].txt -> Spyware.Cookie.Adtech : Nettoyer et sauvegarder
    C:\Documents and Settings\Charly\Cookies\charly@atdmt[2].txt -> Spyware.Cookie.Atdmt : Nettoyer et sauvegarder
    C:\Documents and Settings\Charly\Cookies\charly@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Nettoyer et sauvegarder
    C:\Documents and Settings\Charly\Cookies\charly@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Nettoyer et sauvegarder
    C:\Documents and Settings\Charly\Cookies\charly@estat[1].txt -> Spyware.Cookie.Estat : Nettoyer et sauvegarder
    C:\Documents and Settings\Charly\Cookies\charly@paypopup[2].txt -> Spyware.Cookie.Paypopup : Nettoyer et sauvegarder
    C:\Documents and Settings\Charly\Cookies\charly@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Nettoyer et sauvegarder
    C:\Documents and Settings\Charly\Cookies\charly@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Nettoyer et sauvegarder
    C:\Documents and Settings\Charly\Cookies\charly@valueclick[1].txt -> Spyware.Cookie.Valueclick : Nettoyer et sauvegarder
    C:\Documents and Settings\Charly\Cookies\charly@weborama[1].txt -> Spyware.Cookie.Weborama : Nettoyer et sauvegarder
    C:\Documents and Settings\Charly\Cookies\charly@wreport.weborama[1].txt -> Spyware.Cookie.Weborama : Nettoyer et sauvegarder
    C:\Documents and Settings\Charly\Cookies\charly@www.smartadserver[1].txt -> Spyware.Cookie.Smartadserver : Nettoyer et sauvegarder
    C:\WINDOWS\inet20010\alg.exe -> Worm.Delf.i : Nettoyer et sauvegarder
    C:\WINDOWS\inet20010\__delete_on_reboot__3.00.13.dll -> Spyware.Ihbo : Nettoyer et sauvegarder
    C:\WINDOWS\system32\__delete_on_reboot__msupdate32.dll -> Proxy.Agent.ij : Nettoyer et sauvegarder
    D:\BitDefender Free Edition\Infected\mspostsp.exe -> Trojan.Inject.i : Nettoyer et sauvegarder

    ::Fin du rapport

    Que faire alors? J'ai toujours des pop up qui s'ouvrent sans cesse :@
    0
    1. Contributeur
      bsr
      vraiment crados ton log
      --------
      continue de nettoyer avec ceci
      Télécharge ceci: (merci a S!RI pour ce petit programme).
      http://siri.urz.free.fr/Fix/SmitfraudFix.zip
      Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1, il va générer un rapport
      Copie/colle le sur le poste stp.
      ----------------------------------------------------------------------------
      Démarre en mode sans échec :
      Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
      Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
      Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
      (Si F8 ne marche pas utilise la touche F5).
      ----------------------------------------------------------------------------
      Relance le programme Smitfraud,
      Cette fois choisit l’option 2, répond oui a tous ;
      Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

      0
      1. Contributeur
        Hé aran c du gros kk son log lol

        Mais heureusement qu'on est là ^^

        Bonne nuit ;)
        0
      2. Salut Aranjuez, voici le rapport !!

        SmitFraudFix v2.15

        Rapport fait à 22:29:16,54 le 28/01/2006
        Executé à partir de F:\Logiciels\Virus de merde
        OS: Microsoft Windows XP [version 5.1.2600]

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

        C:\secure32.html PRESENT !

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS

        C:\WINDOWS\tool2.exe PRESENT !
        C:\WINDOWS\tool4.exe PRESENT !
        C:\WINDOWS\toolbar.exe PRESENT !
        C:\WINDOWS\inet20066\ PRESENT!

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\Web

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINDOWS\system32

        C:\WINDOWS\system32\AdService.dll PRESENT !

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Charly\Application Data

        C:\Documents and Settings\Charly\Application Data\Install.dat PRESENT !

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
        "Source"="About:Home"
        "SubscribedURL"="About:Home"
        "FriendlyName"="Ma page d'accueil"

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
        "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pr‚-chargeur Browseui"
        "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="D‚mon de cache des cat‚gories de composant"
        "{A2D9D3F0-8C2A-2A1D-A376-1BECFB10AB72}"="Reload Browse"

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

        »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
        0
      3. Contributeur
        @CharlySalut Charly

        Fais cette manipulation :

        - Redémarre le PC en mode sans échec : tu tapotes sur la touche F8 de ton clavier (ou bien F5 selon la version de Windows) et tu choisis le mode sans échec)

        - Tu relances SmitfraudFix cette fois-ci en choisissant l'option 2 et tu réponds oui à tout.

        Colle le nouveau rapport ensuite.

        ++
        0
      4. @KristopherRe-Salut Kristopher

        voici le rapport du mode sans échec:

        SmitFraudFix v2.15

        Rapport fait à 22:35:31,84 le 28/01/2006
        Executé à partir de F:\Logiciels\Virus de merde
        OS: Microsoft Windows XP [version 5.1.2600]

        »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

        »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

        C:\secure32.html supprimé
        C:\WINDOWS\tool2.exe supprimé
        C:\WINDOWS\tool4.exe supprimé
        C:\WINDOWS\toolbar.exe supprimé
        C:\WINDOWS\inet20010\ supprimé
        C:\WINDOWS\system32\AdService.dll supprimé
        C:\Documents and Settings\Charly\Application Data\Install.dat supprimé

        »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage Fichiers Temporaires

        »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

        Nettoyage terminé.

        »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport
        0
    2. Contributeur
      bsr
      remets un nouvel hijack
      0
      1. OK,

        voici le rapport Hijack

        Logfile of HijackThis v1.99.1
        Scan saved at 22:52:10, on 28/01/2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\rundll32.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\ewido anti-malware\ewidoctrl.exe
        C:\Program Files\ewido anti-malware\ewidoguard.exe
        C:\WINDOWS\System32\GEARSec.exe
        d:\Norton Ghost\Agent\PQV2iSvc.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
        C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
        D:\Norton Ghost\Agent\GhostTray.exe
        D:\bitdef~1\bdmcon.exe
        C:\WINDOWS\system32\LVCOMSX.EXE
        C:\Program Files\Logitech\Video\LogiTray.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Logitech\Video\FxSvr2.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        d:\WinRAR\WinRAR.exe
        F:\Logiciels\Virus de merde\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O4 - HKLM\..\Run: [Norton Ghost 9.0] d:\Norton Ghost\Agent\GhostTray.exe
        O4 - HKLM\..\Run: [BDMCon] D:\bitdef~1\bdmcon.exe
        O4 - HKLM\..\Run: [BDNewsAgent] D:\bitdef~1\bdnagent.exe
        O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
        O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
        O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
        O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
        O4 - HKCU\..\Run: [WinMedia] C:\WINDOWS\system32\wwwloader.exe
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-908\dslmon.exe
        O4 - Global Startup: Microsoft Office.lnk = D:\Microsoft Office\Office10\OSA.EXE
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\MICROS~1\Office10\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128282998868
        O16 - DPF: {826287F8-454E-11D9-ADFE-00062919A34C} (ActiveXUploadFotoCom.UserCtrlFotoCom) - http://express.foto.com/activeX/newUploadFotoCom.CAB
        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
        O20 - Winlogon Notify: Control Panel - C:\WINDOWS\system32\j4l40e3qeh.dll
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
        O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
        O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
        O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: Norton Ghost - Symantec Corporation - d:\Norton Ghost\Agent\PQV2iSvc.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
        0
        1. Contributeur
          re charly
          ------
          éclaire ma lanterne
          nom de ton p-feu ?
          nom de ton antivirus?
          --------
          fixe ces lignes
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128282998868
          O16 - DPF: {826287F8-454E-11D9-ADFE-00062919A34C} (ActiveXUploadFotoCom.UserCtrlFotoCom) - http://express.foto.com/activeX/newUploadFotoCom.CAB
          O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
          O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
          -------
          ce n est pas fini

          0
          1. Merci pour l'aide que tu m'apportes Aranjuez.
            Pour ce qui est de mon antivirus, j'utilise Bit Defender Free Edition v7.2, quant au pare feu, c'est celui de XP mais il est désactivé.
            0
        2. Donc voici le log que j'ai actuellement:

          Logfile of HijackThis v1.99.1
          Scan saved at 23:12:55, on 28/01/2006
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\ewido anti-malware\ewidoctrl.exe
          C:\Program Files\ewido anti-malware\ewidoguard.exe
          C:\WINDOWS\System32\GEARSec.exe
          d:\Norton Ghost\Agent\PQV2iSvc.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
          C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
          D:\Norton Ghost\Agent\GhostTray.exe
          D:\bitdef~1\bdmcon.exe
          C:\WINDOWS\system32\LVCOMSX.EXE
          C:\Program Files\Logitech\Video\LogiTray.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Logitech\Video\FxSvr2.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          F:\Logiciels\Virus de merde\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O4 - HKLM\..\Run: [Norton Ghost 9.0] d:\Norton Ghost\Agent\GhostTray.exe
          O4 - HKLM\..\Run: [BDMCon] D:\bitdef~1\bdmcon.exe
          O4 - HKLM\..\Run: [BDNewsAgent] D:\bitdef~1\bdnagent.exe
          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
          O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
          O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
          O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
          O4 - HKCU\..\Run: [WinMedia] C:\WINDOWS\system32\wwwloader.exe
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-908\dslmon.exe
          O4 - Global Startup: Microsoft Office.lnk = D:\Microsoft Office\Office10\OSA.EXE
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\MICROS~1\Office10\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
          O20 - Winlogon Notify: Control Panel - C:\WINDOWS\system32\j4l40e3qeh.dll
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
          O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
          O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
          O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Norton Ghost - Symantec Corporation - d:\Norton Ghost\Agent\PQV2iSvc.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
          0
          1. oki, merci aranjuez en tout cas...dis moi, ca a l'air d'être clean mais j'ai toujours un problème au niveau des fenêtres intempestives....tu saurais pas d'où ca vient et comment je peux faire pour m'en débarasser??
            0
            1. Contributeur
              bsr

              Installer L2mfix là (nettoie ligne O20 de Hijackthis)

              http://www.downloads.subratam.org/l2mfix.exe
              http://users.skynet.be/BernieClub/tools.html
              1. extraire le fichier sur le bureau
              2. désactiver l'antivirus (car process est détecté faussement comme virus malware par certains antivirus)
              3. lancer l2mfix.bat et sélectionner l'option #1 et faire Enter pour faire apparaître le log (cela prend qqs minutes)
              4. Copie le log et colle sur un FORUM approprié pour une aide (par ex CMC sécurité/virus)
              5. Fermes toutes tes fenêtres windows

              6. Relances l2mfix.bat et sélectionne l'option #2
              7. l'ordi va redémarrer automatiquement sinon le faire manuellement
              8. Recopie le log et colle-le à nouveau sur un FORUM approprié pour une aide
              9. Lances un Hijackthis http://www.merijn.org/files/hijackthis.zip ou là http://users.skynet.be/BernieClub/tools.html
              tu le lances " Do a system scan and save log " et tu copie/colle le rapport sur un FORUM approprié pour une aide (avec cliq droit de la souris).
              0
              1. Bonsoir

                Alors voici mon 1er log avec l2mfix:

                L2MFIX find log 010406
                These are the registry keys present
                **********************************************************************************
                Winlogon/notify:
                Windows Registry Editor Version 5.00

                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MS-DOS Emulation]
                "Asynchronous"=dword:00000000
                "DllName"="C:\\WINDOWS\\system32\\en8ul1l91.dll"
                "Impersonate"=dword:00000000
                "Logon"="WinLogon"
                "Logoff"="WinLogoff"
                "Shutdown"="WinShutdown"

                **********************************************************************************
                useragent:
                Windows Registry Editor Version 5.00

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                "{B412360E-933D-687D-CBBC-785C3547C040}"=""

                **********************************************************************************
                Shell Extension key:
                Windows Registry Editor Version 5.00

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
                "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
                "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
                "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
                "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
                "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
                "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
                "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
                "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
                "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
                "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Page de compatibilit‚"
                "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'environnement"
                "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
                "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'environnement pour les objets r‚seau de Microsoft Windows"
                "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
                "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
                "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensions de l'environnement de compression de fichiers"
                "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension de l'environnement d'imprimante Web"
                "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
                "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu contextuel de cryptage"
                "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
                "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extension ic“ne HyperTerminal"
                "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
                "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
                "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
                "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
                "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
                "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
                "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau"
                "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Connexions r‚seau"
                "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Scanneurs et appareils photo"
                "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Scanneurs et appareils photo"
                "{905667aa-acd6-11d2-8080-00805f6596d2}"="&Scanneurs et appareils photo"
                "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Scanneurs et appareils photo"
                "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Scanneurs et appareils photo"
                "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
                "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
                "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensions de l'interpr‚teur de commandes pour l'environnement d'ex‚cution de scripts Windows"
                "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Liaison de donn‚es Microsoft"
                "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
                "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
                "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
                "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barre des tƒches et menu D‚marrer"
                "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Rechercher"
                "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ex‚cuter..."
                "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
                "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Courrier ‚lectronique"
                "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Polices"
                "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Outils d'administration"
                "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
                "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
                "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
                "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
                "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
                "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
                "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
                "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
                "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
                "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
                "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
                "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
                "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Bande de recherche"
                "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
                "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
                "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
                "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
                "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
                "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
                "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
                "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
                "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
                "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
                "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
                "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
                "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Analyseur de la barre d'adresses"
                "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
                "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
                "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
                "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
                "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
                "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
                "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
                "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
                "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
                "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
                "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
                "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
                "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
                "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
                "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
                "{FF393560-C2A7-11CF-BFF4-444553540000}"="Historique"
                "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
                "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
                "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
                "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
                "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
                "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
                "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
                "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
                "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                "{88C6C381-2E85-11D0-94DE-444553540000}"="Dossier ActiveX Cache"
                "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
                "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
                "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Dossier Inscription"
                "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
                "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
                "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
                "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
                "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
                "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
                "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
                "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'applications d'environnement"
                "{0B124F8F-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
                "{CFCCC7A0-A282-11D1-9082-006008059382}"="Publication d'application Darwin"
                "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
                "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
                "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extracteur de miniatures de fichier + GDI"
                "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Gestionnaire de miniatures - Informations de r‚sum‚ (DOCFILES)"
                "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
                "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
                "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Assistant Publication de sites Web"
                "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Commande d'impressions via le Web"
                "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objet Assistant de publication Shell"
                "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Assistant Obtenir une identit‚ Passport"
                "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Comptes d'utilisateurs"
                "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
                "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
                "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Fichier de chaŒne"
                "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Raccourci de chaŒne"
                "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
                "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
                "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
                "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
                "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
                "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
                "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
                "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
                "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
                "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
                "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
                "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
                "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
                "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
                "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
                "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
                "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
                "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
                "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
                "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
                "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
                "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
                "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
                "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
                "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
                "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
                "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
                "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
                "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
                "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
                "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
                "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
                "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
                "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
                "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
                "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
                "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
                "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
                "{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Dossiers Web"
                "{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
                "{D653647D-D607-4DF6-A5B8-48D2BA195F7B}"="BitDefender Antivirus v7"
                "{E4000AC4-5E5F-4956-807A-C5854405D64F}"="VirtualExpanderFile.1"
                "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
                "{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3}"="My Logitech Pictures"
                "{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"
                "{EA09E0B5-49BF-4A6F-ABF8-0070F0B772E2}"=""

                **********************************************************************************
                HKEY ROOT CLASSIDS:
                Windows Registry Editor Version 5.00

                [HKEY_CLASSES_ROOT\CLSID\{EA09E0B5-49BF-4A6F-ABF8-0070F0B772E2}]
                @=""

                [HKEY_CLASSES_ROOT\CLSID\{EA09E0B5-49BF-4A6F-ABF8-0070F0B772E2}\Implemented Categories]
                @=""

                [HKEY_CLASSES_ROOT\CLSID\{EA09E0B5-49BF-4A6F-ABF8-0070F0B772E2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
                @=""

                [HKEY_CLASSES_ROOT\CLSID\{EA09E0B5-49BF-4A6F-ABF8-0070F0B772E2}\InprocServer32]
                @="C:\\WINDOWS\\system32\\mdvcp50.dll"
                "ThreadingModel"="Apartment"

                **********************************************************************************
                Files Found are not all bad files:

                C:\WINDOWS\SYSTEM32\
                ahtapi.dll Sat 28 Jan 2006 22:38:02 ..S.R 235 882 230,35 K
                browseui.dll Thu 24 Nov 2005 1:08:34 A.... 1 022 976 999,00 K
                danim.dll Sat 5 Nov 2005 4:17:22 A.... 1 056 768 1,01 M
                en24l1~1.dll Sat 28 Jan 2006 23:25:54 ..S.R 233 958 228,47 K
                en8ul1~1.dll Sat 28 Jan 2006 23:27:46 ..S.R 234 238 228,75 K
                gdi32.dll Thu 29 Dec 2005 3:56:04 A.... 280 064 273,50 K
                hr8605~1.dll Sat 28 Jan 2006 23:22:06 ..S.R 235 882 230,35 K
                ktr8l7~1.dll Sat 28 Jan 2006 23:30:26 ..S.R 236 135 230,60 K
                lqwnd12n.dll Sat 28 Jan 2006 23:23:06 ..S.R 236 607 231,06 K
                mdvcp50.dll Sat 28 Jan 2006 23:30:26 ..S.R 234 238 228,75 K
                mshtml.dll Thu 24 Nov 2005 1:08:36 A.... 3 013 632 2,87 M
                mujtes40.dll Sat 28 Jan 2006 20:01:28 ..S.R 235 882 230,35 K
                sarmdll.dll Sat 28 Jan 2006 23:25:54 ..S.R 236 607 231,06 K
                shdocvw.dll Thu 1 Dec 2005 5:01:16 A.... 1 492 992 1,42 M
                sirenacm.dll Wed 14 Dec 2005 9:24:42 A.... 118 784 116,00 K
                urlmon.dll Sat 5 Nov 2005 4:17:26 A.... 606 208 592,00 K
                winxpa32.dll Sat 28 Jan 2006 18:55:44 A.... 16 896 16,50 K

                17 items found: 17 files (9 H/S), 0 directories.
                Total of file sizes: 9 727 749 bytes 9,27 M
                Locate .tmp files:

                No matches found.
                **********************************************************************************
                Directory Listing of system files:
                Le volume dans le lecteur C s'appelle WINXP
                Le num‚ro de s‚rie du volume est 6C28-AA86

                R‚pertoire de C:\WINDOWS\System32

                28/01/2006 23:30 234ÿ238 mdvcp50.dll
                28/01/2006 23:30 236ÿ135 ktr8l79u1.dll
                28/01/2006 23:27 234ÿ238 en8ul1l91.dll
                28/01/2006 23:25 236ÿ607 sarmdll.dll
                28/01/2006 23:25 233ÿ958 en24l1fq1.dll
                28/01/2006 23:23 236ÿ607 LQWND12n.DLL
                28/01/2006 23:22 235ÿ882 hr8605lse.dll
                28/01/2006 23:12 <REP> dllcache
                28/01/2006 22:38 235ÿ882 ahtapi.dll
                28/01/2006 20:01 235ÿ882 mujtes40.dll
                02/10/2005 19:19 <REP> Microsoft
                9 fichier(s) 2ÿ119ÿ429 octets
                2 R‚p(s) 6ÿ506ÿ467ÿ328 octets libres
                0
            2. Bonsoir,

              Voici après redémarrage mon 2nd log L2mfix ainsi que mon log Hijack this à la suite

              L2mfix 010406
              Creating Account.
              La commande s'est termin‚e correctement.

              Adding Administrative privleges.
              Checking for L2MFix account(0=no 1=yes):
              1
              Granting SeDebugPrivilege to L2MFIX ... successful

              Running From:
              C:\WINDOWS\system32

              Killing Processes!

              Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
              Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
              Killing PID 572 'smss.exe'

              Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
              Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
              Killing PID 996 'winlogon.exe'
              Killing PID 996 'winlogon.exe'
              Killing PID 996 'winlogon.exe'

              Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
              Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
              Killing PID 524 'explorer.exe'
              Killing PID 524 'explorer.exe'
              Killing PID 524 'explorer.exe'
              Killing PID 524 'explorer.exe'

              Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
              Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
              Killing PID 1752 'rundll32.exe'
              Restoring Sedebugprivilege:
              Granting SeDebugPrivilege to Administrateurs ... successful

              Scanning First Pass. Please Wait!

              First Pass Completed

              Second Pass Scanning

              Second pass Completed!
              1 fichier(s) copi‚(s).
              1 fichier(s) copi‚(s).
              1 fichier(s) copi‚(s).
              1 fichier(s) copi‚(s).
              1 fichier(s) copi‚(s).
              1 fichier(s) copi‚(s).
              1 fichier(s) copi‚(s).
              1 fichier(s) copi‚(s).
              1 fichier(s) copi‚(s).
              Deleting: C:\WINDOWS\system32\ahtapi.dll
              Successfully Deleted: C:\WINDOWS\system32\ahtapi.dll
              Deleting: C:\WINDOWS\system32\en24l1fq1.dll
              Successfully Deleted: C:\WINDOWS\system32\en24l1fq1.dll
              Deleting: C:\WINDOWS\system32\en8ul1l91.dll
              Successfully Deleted: C:\WINDOWS\system32\en8ul1l91.dll
              Deleting: C:\WINDOWS\system32\hr8605lse.dll
              Successfully Deleted: C:\WINDOWS\system32\hr8605lse.dll
              Deleting: C:\WINDOWS\system32\ktr8l79u1.dll
              Successfully Deleted: C:\WINDOWS\system32\ktr8l79u1.dll
              Deleting: C:\WINDOWS\system32\LQWND12n.DLL
              Successfully Deleted: C:\WINDOWS\system32\LQWND12n.DLL
              Deleting: C:\WINDOWS\system32\mdvcp50.dll
              Successfully Deleted: C:\WINDOWS\system32\mdvcp50.dll
              Deleting: C:\WINDOWS\system32\mujtes40.dll
              Successfully Deleted: C:\WINDOWS\system32\mujtes40.dll
              Deleting: C:\WINDOWS\system32\sarmdll.dll
              Successfully Deleted: C:\WINDOWS\system32\sarmdll.dll

              msg11?.dll
              0 fichier(s) copi‚(s).

              Restoring Windows Update Certificates.:

              The following Is the Current Export of the Winlogon notify key:
              ****************************************************************************
              Windows Registry Editor Version 5.00

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
              "Asynchronous"=dword:00000000
              "Impersonate"=dword:00000000
              "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
              6c,00,00,00
              "Logoff"="ChainWlxLogoffEvent"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
              "Asynchronous"=dword:00000000
              "Impersonate"=dword:00000000
              "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
              6c,00,6c,00,00,00
              "Logoff"="CryptnetWlxLogoffEvent"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
              "DLLName"="cscdll.dll"
              "Logon"="WinlogonLogonEvent"
              "Logoff"="WinlogonLogoffEvent"
              "ScreenSaver"="WinlogonScreenSaverEvent"
              "Startup"="WinlogonStartupEvent"
              "Shutdown"="WinlogonShutdownEvent"
              "StartShell"="WinlogonStartShellEvent"
              "Impersonate"=dword:00000000
              "Asynchronous"=dword:00000001

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\MS-DOS Emulation]
              "Asynchronous"=dword:00000000
              "DllName"="C:\\WINDOWS\\system32\\en8ul1l91.dll"
              "Impersonate"=dword:00000000
              "Logon"="WinLogon"
              "Logoff"="WinLogoff"
              "Shutdown"="WinShutdown"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
              "DLLName"="wlnotify.dll"
              "Logon"="SCardStartCertProp"
              "Logoff"="SCardStopCertProp"
              "Lock"="SCardSuspendCertProp"
              "Unlock"="SCardResumeCertProp"
              "Enabled"=dword:00000001
              "Impersonate"=dword:00000001
              "Asynchronous"=dword:00000001

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
              "Asynchronous"=dword:00000000
              "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
              6c,00,6c,00,00,00
              "Impersonate"=dword:00000000
              "StartShell"="SchedStartShell"
              "Logoff"="SchedEventLogOff"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
              "Logoff"="WLEventLogoff"
              "Impersonate"=dword:00000000
              "Asynchronous"=dword:00000001
              "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
              6c,00,6c,00,00,00

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
              "DLLName"="WlNotify.dll"
              "Lock"="SensLockEvent"
              "Logon"="SensLogonEvent"
              "Logoff"="SensLogoffEvent"
              "Safe"=dword:00000001
              "MaxWait"=dword:00000258
              "StartScreenSaver"="SensStartScreenSaverEvent"
              "StopScreenSaver"="SensStopScreenSaverEvent"
              "Startup"="SensStartupEvent"
              "Shutdown"="SensShutdownEvent"
              "StartShell"="SensStartShellEvent"
              "PostShell"="SensPostShellEvent"
              "Disconnect"="SensDisconnectEvent"
              "Reconnect"="SensReconnectEvent"
              "Unlock"="SensUnlockEvent"
              "Impersonate"=dword:00000001
              "Asynchronous"=dword:00000001

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
              "Asynchronous"=dword:00000000
              "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
              6c,00,6c,00,00,00
              "Impersonate"=dword:00000000
              "Logoff"="TSEventLogoff"
              "Logon"="TSEventLogon"
              "PostShell"="TSEventPostShell"
              "Shutdown"="TSEventShutdown"
              "StartShell"="TSEventStartShell"
              "Startup"="TSEventStartup"
              "MaxWait"=dword:00000258
              "Reconnect"="TSEventReconnect"
              "Disconnect"="TSEventDisconnect"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
              "DLLName"="wlnotify.dll"
              "Logon"="RegisterTicketExpiredNotificationEvent"
              "Logoff"="UnregisterTicketExpiredNotificationEvent"
              "Impersonate"=dword:00000001
              "Asynchronous"=dword:00000001

              The following are the files found:
              ****************************************************************************
              C:\WINDOWS\system32\ahtapi.dll
              C:\WINDOWS\system32\en24l1fq1.dll
              C:\WINDOWS\system32\en8ul1l91.dll
              C:\WINDOWS\system32\hr8605lse.dll
              C:\WINDOWS\system32\ktr8l79u1.dll
              C:\WINDOWS\system32\LQWND12n.DLL
              C:\WINDOWS\system32\mdvcp50.dll
              C:\WINDOWS\system32\mujtes40.dll
              C:\WINDOWS\system32\sarmdll.dll

              Registry Entries that were Deleted:
              Please verify that the listing looks ok.
              If there was something deleted wrongly there are backups in the backreg folder.
              ****************************************************************************
              Windows Registry Editor Version 5.00

              [HKEY_CLASSES_ROOT\CLSID\{EA09E0B5-49BF-4A6F-ABF8-0070F0B772E2}]
              @=""

              [HKEY_CLASSES_ROOT\CLSID\{EA09E0B5-49BF-4A6F-ABF8-0070F0B772E2}\Implemented Categories]
              @=""

              [HKEY_CLASSES_ROOT\CLSID\{EA09E0B5-49BF-4A6F-ABF8-0070F0B772E2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
              @=""

              [HKEY_CLASSES_ROOT\CLSID\{EA09E0B5-49BF-4A6F-ABF8-0070F0B772E2}\InprocServer32]
              @="C:\\WINDOWS\\system32\\mdvcp50.dll"
              "ThreadingModel"="Apartment"

              REGEDIT4

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
              "{EA09E0B5-49BF-4A6F-ABF8-0070F0B772E2}"=-
              [-HKEY_CLASSES_ROOT\CLSID\{EA09E0B5-49BF-4A6F-ABF8-0070F0B772E2}]
              REGEDIT4

              [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
              "SV1"=""
              ****************************************************************************
              Desktop.ini Contents:
              ****************************************************************************

              ****************************************************************************
              Checking for L2MFix account(0=no 1=yes):
              0
              Zipping up files for submission:
              adding: dlls/ahtapi.dll (188 bytes security) (deflated 5%)
              adding: dlls/en24l1fq1.dll (188 bytes security) (deflated 4%)
              adding: dlls/en8ul1l91.dll (188 bytes security) (deflated 4%)
              adding: dlls/hr8605lse.dll (188 bytes security) (deflated 5%)
              adding: dlls/ktr8l79u1.dll (188 bytes security) (deflated 5%)
              adding: dlls/LQWND12n.DLL (188 bytes security) (deflated 5%)
              adding: dlls/mdvcp50.dll (188 bytes security) (deflated 4%)
              adding: dlls/mujtes40.dll (188 bytes security) (deflated 5%)
              adding: dlls/sarmdll.dll (188 bytes security) (deflated 5%)
              adding: backregs/EA09E0B5-49BF-4A6F-ABF8-0070F0B772E2.reg (188 bytes security) (deflated 70%)
              adding: backregs/notibac.reg (188 bytes security) (deflated 63%)
              adding: backregs/shell.reg (188 bytes security) (deflated 73%)

              ______________________________________________________

              Logfile of HijackThis v1.99.1
              Scan saved at 00:20:38, on 29/01/2006
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\ewido anti-malware\ewidoctrl.exe
              C:\Program Files\ewido anti-malware\ewidoguard.exe
              C:\WINDOWS\System32\GEARSec.exe
              d:\Norton Ghost\Agent\PQV2iSvc.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
              C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
              D:\Norton Ghost\Agent\GhostTray.exe
              D:\bitdef~1\bdmcon.exe
              C:\WINDOWS\system32\LVCOMSX.EXE
              C:\Program Files\Logitech\Video\LogiTray.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\SAGEM\SAGEM F@st 800-908\dslmon.exe
              C:\Program Files\Logitech\Video\FxSvr2.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\WINDOWS\system32\wuauclt.exe
              F:\Logiciels\Virus de merde\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O4 - HKLM\..\Run: [Norton Ghost 9.0] d:\Norton Ghost\Agent\GhostTray.exe
              O4 - HKLM\..\Run: [BDMCon] D:\bitdef~1\bdmcon.exe
              O4 - HKLM\..\Run: [BDNewsAgent] D:\bitdef~1\bdnagent.exe
              O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
              O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
              O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
              O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
              O4 - HKCU\..\Run: [WinMedia] C:\WINDOWS\system32\wwwloader.exe
              O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
              O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-908\dslmon.exe
              O4 - Global Startup: Microsoft Office.lnk = D:\Microsoft Office\Office10\OSA.EXE
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\MICROS~1\Office10\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
              O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\system32\en8ul1l91.dll (file missing)
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
              O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
              O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
              O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Norton Ghost - Symantec Corporation - d:\Norton Ghost\Agent\PQV2iSvc.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

              Quelqu'un y voit-il clair là dedans pour résoudre mon problème ?!
              0
              1. Contributeur
                ok
                fais option 2 - colle

                puis nouvel ewido collé

                et dis si ton blem demeure
                0
                1. Et bien, il me semble que mon problème est résolu...Merci encore à vous 2 Kristopher et Aranjuez

                  ;)

                  Merci et bonne nuitée maintenant
                  Charly
                  0
                  1. Contributeur
                    have a nice night

                    si blem , tu connais le chemin pour revenir
                    0