Trojan (aidez- moi svp)

Bonjour Je me suis aperçu que j'avais un Trojan : Trojan.Win32.Agent.bck

Sa ouvre des page internet me montrant Winantivirus, Drive cleaner, ...

Voila avez vous une solution pour supprimé ou remédier à l'affichage de ces pages

J'utilise F-Secure comme anti-virus

Merci, aurevoir
Configuration: Windows XP
Firefox 2.0.0.6

29 réponses

Résumé de la discussion

Le souci décrit est une infection Trojan.Win32.Agent.bck affichant l'affichage intempestif de pages promotionnelles, telles que Winantivirus et Drive Cleaner, sous Windows XP et Firefox 2.0.0.6. Des procédures de détection et de suppression centrées sur F-Secure et des outils dédiés ont été proposées, notamment l'utilisation de BlackLight (fsbl.exe) pour générer un rapport et cibler les fichiers suspects. Il est préconisé de sauvegarder le rapport, ne pas renommer les fichiers pendant l'analyse, puis d'installer HijackThis pour obtenir un rapport complémentaire et faciliter le nettoyage. D'autres réponses évoquent aussi VundoFix et des options en ligne comme secuser.com, et l'intérêt de partager les rapports pour que les experts vérifient les éléments risqués et évitent la suppression de fichiers légitimes.

Bobot (l’IA à votre service)
  1. le mieux pour enlever se trojan , se serait de lancer un scan avec ton anti virus f-secure
    si le trojan revien tu peux toujours tester l'antivirus en ligne sur secuser.com
    +
    0
    1. Une fois sur le site je fais quoi ?
      0
  2. salut

    Télécharge Blacklight
    https://europe.f-secure.com/exclude/blacklight/index.shtml
    (de F-Secure)
    (le premier de la page)

    Enregistre le sur ton Bureau.
    Double-clique fsbl.exe
    Clique sur "I ACCEPT" .
    clique Scan puis Next<*gras>

    Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport,
    sur ton Bureau, nommé <gras>fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).

    Copie et colle le contenu de ce rapport dans ta prochaine réponse.
    NE PAS choisir l'option "Rename" de suite : nous devons analyser le rapport,
    car des fichiers légitimes peuvent être présents, tel wbemtest.exe

    et

    * Télécharge HijackThis et poste le rapport stp

    http://pchelpbordeaux.free.fr/logiciels.html
    Tutorial
    http://pchelpbordeaux.free.fr/tuto.html
    Démo en image
    http://pageperso.aol.fr/balltrap34/demohijack.htm

    bizoux
    0
    1. F-secure blacklight me met une commande Ms-dos :s
      0
    2. @ArnaudLa commande c'est couper et j'ai une un fichier texte :

      09/11/07 21:14:43 [Info]: BlackLight Engine 1.0.64 initialized
      09/11/07 21:14:43 [Info]: OS: 5.1 build 2600 (Service Pack 2)
      09/11/07 21:14:43 [Note]: 7019 4
      09/11/07 21:14:43 [Note]: 7005 0
      09/11/07 21:14:44 [Note]: 7006 0
      09/11/07 21:14:44 [Note]: 7011 1736
      09/11/07 21:14:44 [Note]: 7026 0
      09/11/07 21:14:45 [Note]: 7026 0
      09/11/07 21:14:47 [Note]: FSRAW library version 1.7.1022
      09/11/07 21:16:45 [Error]: 6023 3
      09/11/07 21:16:45 [Note]: 7007 0
      0
    3. @ArnaudJ'ai fais avec Hijackthis :

      Logfile of HijackThis v1.99.1
      Scan saved at 21:29:37, on 11/09/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16512)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
      C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
      C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
      C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
      C:\Program Files\F-Secure\Common\FSMA32.EXE
      C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
      C:\Program Files\F-Secure\Common\FSMB32.EXE
      C:\Program Files\F-Secure\Common\FCH32.EXE
      C:\Program Files\F-Secure\BackWeb\7681197\Program\F-Secure Automatic Update.exe
      C:\Program Files\F-Secure\Common\FAMEH32.EXE
      C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
      C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
      C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
      C:\Program Files\F-Secure\Common\FNRB32.EXE
      C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
      C:\Program Files\F-Secure\Common\FIH32.EXE
      C:\WINDOWS\system32\igfxtray.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\system32\igfxpers.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\sm56hlpr.exe
      C:\Program Files\F-Secure\Common\FSM32.EXE
      C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
      C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
      C:\Program Files\F-Secure\FSGUI\fsguidll.exe
      C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
      C:\Program Files\MSN Messenger\MsnMsgr.Exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
      C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
      C:\Program Files\MSN Messenger\usnsvc.exe
      C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
      C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/webhp?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O2 - BHO: (no name) - {78AD4868-21BF-4315-85A4-337D3EC584C1} - C:\WINDOWS\system32\mljgg.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: (no name) - {890CFBF0-10D5-43D3-ABFD-206F7C4A2699} - C:\WINDOWS\system32\opnkkih.dll
      O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\simvyesc.dll (file missing)
      O2 - BHO: (no name) - {D3EEE7A6-94AB-4F4B-A623-39FB6EBDA716} - C:\WINDOWS\system32\vtsqr.dll (file missing)
      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
      O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
      O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
      O4 - HKLM\..\Run: [\\DOMINIQUE\EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P38 "\\DOMINIQUE\EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
      O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\dbpuptga.dll",forkonce
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
      O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
      O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
      O20 - Winlogon Notify: mljgg - C:\WINDOWS\system32\mljgg.dll
      O20 - Winlogon Notify: opnkkih - C:\WINDOWS\SYSTEM32\opnkkih.dll
      O20 - Winlogon Notify: vtsqr - C:\WINDOWS\system32\vtsqr.dll (file missing)
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
      O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\yywxfqju.exe (file missing)
      O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
      O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
      O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
      O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
      O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      0
  3. va sur www.secuser.com et va sur desinfection (coté gauche) tu va trouver ton bonheurs a+
    0
    1. Bon ben là je vais me couché demain cours héhé, et donc je ferais ca en début d'après midi pour vous le donner au plus vite

      Cordialement, Arnaud et encore merci !
      0
      1. re

        op op op va au lit je compte jusqu'à 3 apres tu sera privé de .........euh Naruto!!!! ou autre !!!nan je rigole je dis de la ***** !!! bonne nuit et bon courrage pour demain Arnaud

        Bizoux

        ohhhhhhhhhhhhhhh t'es encore là!!!!!!!!!!!!!!!!!!!!! zouuuuuuuuuuuuuuuu ^^

        babaye
        0
        1. http://img136.imageshack.us/img136/4397/kasperskymp9.jpg

          Voila une image de l'analyse donc ... Quesque je dois faire maintenant ?
          0
          1. salut

            Qui avait il en infection ? des cookies ou tu as vu pire?

            bizoux
            0
            1. C'est bizarre j'ai refais l'analyse et j'ai 6 virus trouvé et 8 infécté

              -un trojan dans c:/windows/system32/VSTQR.dll
              -Un trojan dans d:/fichier internet temporaire/content ...
              -Un trojan dans d:/fichier internet temporaire/content ...
              -Un trojan dans d:/fichier internet temporaire/content ...
              -un "backdoor" dans d:/recyclers/ ...
              -un fichier ZIP dans d:/recyclers/...

              Que dois faire ? Y a pas un logiciel pour tous suprimé
              0
              1. re

                ok t'as des amis trojens ^^

                lance ceci déjà stp:

                Sdfix:

                Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
                http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
                Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
                • Redémarre ton ordinateur
                • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
                • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
                • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
                • Choisis ton compte.
                Déroule la liste des instructions ci-dessous :
                • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le scrïpt.
                • Appuie sur Y pour commencer le processus de nettoyage.
                • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                • Appuie sur une touche pour redémarrer le PC.
                • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                • Appuie sur une touche pour finir l'exécution du scrïpt et charger les icônes de ton Bureau.
                • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !

                bizz
                0
                1. Purrée j'ause pas chipoter dasn le bios ou le truc au démarrage moi ... euh et t'entends quoi par tapoter la touche F8 ?
                  0
                  1. ce n'est pas dans le bios t'en fais pas
                    tu redemarre ton pc et des l'allumage tu tape sans cesse la touche F8 ou F5 là tu aura 1 écran noir qui te demandera ton choix ! en haut tu as le mode sans échec ( pas d'acces interenet donc copie ce que je t'ai dis sur 1 page bloc note )que tu pourra consulter

                    biz
                    0
                    1. Voila avec SDFix :

                      SDFix: Version 1.104

                      Run by Arnaud on mer. 12/09/2007 at 21:26

                      Microsoft Windows XP [version 5.1.2600]

                      Running From: C:\SDFix

                      Safe Mode:
                      Checking Services:

                      Name:
                      DomainService

                      ImagePath:
                      C:\WINDOWS\system32\yywxfqju.exe /service

                      DomainService - Deleted

                      Restoring Windows Registry Values
                      Restoring Windows Default Hosts File

                      Rebooting...

                      Normal Mode:
                      Checking Files:

                      No Trojan Files Found

                      Removing Temp Files...

                      ADS Check:

                      C:\WINDOWS
                      No streams found.

                      C:\WINDOWS\system32
                      No streams found.

                      C:\WINDOWS\system32\svchost.exe
                      No streams found.

                      C:\WINDOWS\system32\ntoskrnl.exe
                      No streams found.

                      Final Check:

                      Remaining Services:
                      ------------------

                      Authorized Application Key Export:

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                      "C:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\F-Secure Automatic Update.exe"="C:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\F-Secure Automatic Update.exe:*:Enabled:F-Secure Automatic Update"
                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                      "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
                      "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
                      "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
                      "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
                      "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
                      "C:\\Program Files\\Shareaza\\Shareaza.exe"="C:\\Program Files\\Shareaza\\Shareaza.exe:*:Enabled:Shareaza"
                      "C:\\WINDOWS\\system32\\yywxfqju.exe"="C:\\WINDOWS\\system32\\yyw"

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                      "C:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\F-Secure Automatic Update.exe"="C:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\F-Secure Automatic Update.exe:*:Enabled:F-Secure Automatic Update"
                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                      "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
                      "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

                      Remaining Files:
                      ---------------

                      Files with Hidden Attributes:

                      C:\Documents and Settings\Arnaud\Local Settings\Application Data\Microsoft\Messenger\blizz_la_glizz@msn.com\Sharing Folders\j0uly@hotmail.com\Thumbs.db
                      C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp

                      Finished!

                      ---------------------------------------------

                      Et voila avec hijackthis :

                      Logfile of HijackThis v1.99.1
                      Scan saved at 21:45:12, on 12/09/2007
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16512)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
                      C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
                      C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
                      C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
                      C:\Program Files\F-Secure\Common\FSMA32.EXE
                      C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
                      C:\Program Files\F-Secure\Common\FSMB32.EXE
                      C:\Program Files\F-Secure\BackWeb\7681197\Program\F-Secure Automatic Update.exe
                      C:\Program Files\F-Secure\Common\FCH32.EXE
                      C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
                      C:\Program Files\F-Secure\Common\FAMEH32.EXE
                      C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
                      C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
                      C:\Program Files\F-Secure\Common\FNRB32.EXE
                      C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
                      C:\Program Files\F-Secure\Common\FIH32.EXE
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\WINDOWS\system32\notepad.exe
                      C:\WINDOWS\system32\igfxtray.exe
                      C:\WINDOWS\system32\hkcmd.exe
                      C:\WINDOWS\system32\igfxpers.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\WINDOWS\SOUNDMAN.EXE
                      C:\WINDOWS\sm56hlpr.exe
                      C:\Program Files\F-Secure\Common\FSM32.EXE
                      C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
                      C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
                      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
                      C:\Program Files\MSN Messenger\MsnMsgr.Exe
                      C:\Program Files\F-Secure\FSGUI\fsguidll.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
                      C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
                      C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
                      C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                      C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/webhp?gws_rd=ssl
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: (no name) - {69792542-6BA3-41CC-B5F3-D53712A2F1B3} - C:\WINDOWS\system32\mljgg.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: (no name) - {890CFBF0-10D5-43D3-ABFD-206F7C4A2699} - C:\WINDOWS\system32\opnkkih.dll
                      O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\simvyesc.dll (file missing)
                      O2 - BHO: (no name) - {D3EEE7A6-94AB-4F4B-A623-39FB6EBDA716} - C:\WINDOWS\system32\vtsqr.dll (file missing)
                      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                      O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                      O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                      O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
                      O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
                      O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                      O4 - HKLM\..\Run: [\\DOMINIQUE\EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P38 "\\DOMINIQUE\EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
                      O4 - HKLM\..\Run: [SystemOptimizer] rundll32.exe "C:\WINDOWS\system32\gcqwnmfi.dll",forkonce
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
                      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                      O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
                      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                      O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
                      O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                      O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                      O11 - Options group: [INTERNATIONAL] International*
                      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
                      O20 - Winlogon Notify: mljgg - C:\WINDOWS\system32\mljgg.dll
                      O20 - Winlogon Notify: opnkkih - C:\WINDOWS\SYSTEM32\opnkkih.dll
                      O20 - Winlogon Notify: vtsqr - C:\WINDOWS\system32\vtsqr.dll (file missing)
                      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                      O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                      O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
                      O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
                      O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
                      O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
                      O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
                      O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
                      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

                      -------------------------------------------
                      0
                  2. Contributeur sécurité
                    bonsoir,

                    juste de passage
                    je pense que c'est vundo son infection

                    * Télécharge VundoFix.exe (par Atribune) sur ton Bureau

                    http://www.atribune.org/ccount/click.php?id=4

                    * Double-clique VundoFix.exe afin de le lancer

                    * Clique sur le bouton Scan for Vundo

                    * Lorsque le scan est complété, clique sur le bouton Remove Vundo

                    * Une invite te demandera si tu veux supprimer les fichiers, clique YES

                    * Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers

                    * Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK

                    * Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse

                    Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".

                    0
                    1. re!!

                      désolée me suis absentée !!!! fais ce que te recommande Philae , lance vundofix! arrete de t'en faire ^^ tu ne risque rien là et celà nous aideras a te faire avancer !! ok ^^

                      bizoux et merci a toi Philae !!!!!!!!
                      0
                      1. Okay je ferais ca demain bien merci beaucoup je veux mettre fin à ca avant vendredi 15h ^^

                        Bonne nuit et merci a vous !!
                        Faites de beaus rêve ^^
                        0
                    2. merci !!! a toi aussi mister 15h00 lol

                      biz
                      0
                      1. et re re

                        fais ce que t'as dis Phlilae des que possible stp c'est important !!!!

                        ouala maintenant tu peu ronfler ^^

                        bizoux
                        0
                        1. Vundo fix :

                          VundoFix V6.5.8

                          Checking Java version...

                          Scan started at 19:22:37 13/09/2007

                          Listing files found while scanning....

                          C:\windows\system32\aauinxgj.ini
                          C:\windows\system32\bhbvfrvi.ini
                          C:\WINDOWS\system32\ceqbnqwx.dll
                          C:\windows\system32\dqrmpgkh.dll
                          C:\windows\system32\erecriqi.ini
                          C:\WINDOWS\system32\gcqwnmfi.dll
                          C:\windows\system32\hilfguui.dll
                          C:\windows\system32\hkgpmrqd.ini
                          C:\WINDOWS\system32\ifmnwqcg.ini
                          C:\windows\system32\iqircere.dll
                          C:\windows\system32\iuugflih.ini
                          C:\windows\system32\ivrfvbhb.dll
                          C:\windows\system32\jgxniuaa.dll
                          C:\windows\system32\knfgdluu.ini
                          C:\WINDOWS\system32\mljgg.dll
                          C:\WINDOWS\system32\opnkkih.dll
                          C:\WINDOWS\system32\simvyesc.dll
                          C:\WINDOWS\system32\upbikptq.dll
                          C:\windows\system32\uuldgfnk.dll
                          C:\WINDOWS\system32\vtsqr.dll

                          Beginning removal...

                          Attempting to delete C:\windows\system32\aauinxgj.ini
                          C:\windows\system32\aauinxgj.ini Has been deleted!

                          Attempting to delete C:\windows\system32\bhbvfrvi.ini
                          C:\windows\system32\bhbvfrvi.ini Has been deleted!

                          Attempting to delete C:\windows\system32\dqrmpgkh.dll
                          C:\windows\system32\dqrmpgkh.dll Has been deleted!

                          Attempting to delete C:\windows\system32\erecriqi.ini
                          C:\windows\system32\erecriqi.ini Has been deleted!

                          Attempting to delete C:\WINDOWS\system32\gcqwnmfi.dll
                          C:\WINDOWS\system32\gcqwnmfi.dll Could not be deleted.

                          Attempting to delete C:\windows\system32\hilfguui.dll
                          C:\windows\system32\hilfguui.dll Has been deleted!

                          Attempting to delete C:\windows\system32\hkgpmrqd.ini
                          C:\windows\system32\hkgpmrqd.ini Has been deleted!

                          Attempting to delete C:\WINDOWS\system32\ifmnwqcg.ini
                          C:\WINDOWS\system32\ifmnwqcg.ini Has been deleted!

                          Attempting to delete C:\windows\system32\iqircere.dll
                          C:\windows\system32\iqircere.dll Has been deleted!

                          Attempting to delete C:\windows\system32\iuugflih.ini
                          C:\windows\system32\iuugflih.ini Has been deleted!

                          Attempting to delete C:\windows\system32\ivrfvbhb.dll
                          C:\windows\system32\ivrfvbhb.dll Has been deleted!

                          Attempting to delete C:\windows\system32\jgxniuaa.dll
                          C:\windows\system32\jgxniuaa.dll Has been deleted!

                          Attempting to delete C:\windows\system32\knfgdluu.ini
                          C:\windows\system32\knfgdluu.ini Has been deleted!

                          Attempting to delete C:\WINDOWS\system32\mljgg.dll
                          C:\WINDOWS\system32\mljgg.dll Could not be deleted.

                          Attempting to delete C:\WINDOWS\system32\opnkkih.dll
                          C:\WINDOWS\system32\opnkkih.dll Could not be deleted.

                          Attempting to delete C:\WINDOWS\system32\upbikptq.dll
                          C:\WINDOWS\system32\upbikptq.dll Has been deleted!

                          Attempting to delete C:\windows\system32\uuldgfnk.dll
                          C:\windows\system32\uuldgfnk.dll Has been deleted!

                          Performing Repairs to the registry.
                          Done!

                          Beginning removal...

                          Attempting to delete C:\WINDOWS\system32\gcqwnmfi.dll
                          C:\WINDOWS\system32\gcqwnmfi.dll Has been deleted!

                          Attempting to delete C:\WINDOWS\system32\mljgg.dll
                          C:\WINDOWS\system32\mljgg.dll Could not be deleted.

                          Attempting to delete C:\WINDOWS\system32\opnkkih.dll
                          C:\WINDOWS\system32\opnkkih.dll Could not be deleted.

                          Performing Repairs to the registry.
                          Done!

                          Beginning removal...

                          ET HiJackThis :

                          Logfile of HijackThis v1.99.1
                          Scan saved at 19:57:31, on 13/09/2007
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16512)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
                          C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
                          C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
                          C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
                          C:\Program Files\F-Secure\Common\FSMA32.EXE
                          C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
                          C:\Program Files\F-Secure\Common\FSMB32.EXE
                          C:\Program Files\F-Secure\BackWeb\7681197\Program\F-Secure Automatic Update.exe
                          C:\Program Files\F-Secure\Common\FCH32.EXE
                          C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
                          C:\Program Files\F-Secure\Common\FAMEH32.EXE
                          C:\Program Files\F-Secure\Common\FNRB32.EXE
                          C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
                          C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
                          C:\Program Files\F-Secure\Common\FIH32.EXE
                          C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
                          C:\WINDOWS\system32\igfxtray.exe
                          C:\WINDOWS\system32\hkcmd.exe
                          C:\WINDOWS\system32\igfxpers.exe
                          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          C:\WINDOWS\SOUNDMAN.EXE
                          C:\WINDOWS\sm56hlpr.exe
                          C:\Program Files\F-Secure\Common\FSM32.EXE
                          C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\Program Files\QuickTime\qttask.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
                          C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
                          C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
                          C:\Program Files\MSN Messenger\MsnMsgr.Exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
                          C:\Program Files\iPod\bin\iPodService.exe
                          C:\Program Files\F-Secure\FSGUI\fsguidll.exe
                          C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
                          C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                          C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
                          C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\WINDOWS\system32\NOTEPAD.EXE
                          C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/webhp?gws_rd=ssl
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: (no name) - {80733F3D-BA19-4F93-887A-3AD791E73ACC} - C:\WINDOWS\system32\mljgg.dll
                          O2 - BHO: (no name) - {890CFBF0-10D5-43D3-ABFD-206F7C4A2699} - C:\WINDOWS\system32\opnkkih.dll
                          O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\beikpkyg.dll
                          O2 - BHO: (no name) - {D3EEE7A6-94AB-4F4B-A623-39FB6EBDA716} - C:\WINDOWS\system32\vtsqr.dll (file missing)
                          O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                          O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                          O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                          O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
                          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                          O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                          O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
                          O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
                          O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                          O4 - HKLM\..\Run: [\\DOMINIQUE\EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P38 "\\DOMINIQUE\EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
                          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                          O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
                          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                          O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                          O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
                          O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
                          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                          O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                          O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                          O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                          O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                          O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                          O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                          O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                          O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                          O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                          O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                          O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                          O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                          O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                          O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                          O11 - Options group: [INTERNATIONAL] International*
                          O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                          O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                          O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
                          O20 - Winlogon Notify: mljgg - C:\WINDOWS\system32\mljgg.dll
                          O20 - Winlogon Notify: opnkkih - C:\WINDOWS\SYSTEM32\opnkkih.dll
                          O20 - Winlogon Notify: vtsqr - C:\WINDOWS\system32\vtsqr.dll (file missing)
                          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                          O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                          O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                          O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
                          O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
                          O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
                          O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
                          O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
                          O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
                          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

                          Voila et maintenant ?
                          0
                          1. Il faust que je vire le fichier

                            O20 - Winlogon Notify: vtsqr - C:\WINDOWS\system32\vtsqr.dll (file missing)

                            Mais comment faire parce que j'en suis sur c'est celui là et j'ai tout fais et je viens de ravoir une alerte et une nouvelle page Internet drive cleaner ...

                            rhoo lala
                            0
                          2. @Arnaud... S'il vous plait
                            0
                          3. @ArnaudIl faut vraiment finir sa aujourd'hui s'il vous plait ...
                            0
                        2. Contributeur sécurité
                          bonsoir,

                          pour avancer un peu,
                          ca valait la peine de lancer vundofix visiblement :)

                          * Relance Vundofix
                          * Ne clique pas sur "Scan for a vundo"
                          * Clique droit au milieu de la fenêtre
                          * Clique sur Add more files ?
                          * Copie/colle les fichiers ci-dessous ( un par case) :

                          C:\WINDOWS\system32\mljgg.dll
                          C:\WINDOWS\system32\opnkkih.dll
                          C:\WINDOWS\system32\beikpkyg.dll


                          * Clique sur Add files
                          * Ensuite clique sur Close Windows
                          * Enfin, clique sur Remove Vundo ( les fichiers précédents doivent apparaitre dans la fenêtre principale)
                          * Si l'outils demande un redémarrage, accepte
                          * Poste le rapport Vundofix

                          puis

                          * lance hijackthis puis coche ces lignes :

                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: (no name) - {80733F3D-BA19-4F93-887A-3AD791E73ACC} - C:\WINDOWS\system32\mljgg.dll
                          O2 - BHO: (no name) - {890CFBF0-10D5-43D3-ABFD-206F7C4A2699} - C:\WINDOWS\system32\opnkkih.dll
                          O2 - BHO: (no name) - {C6039E6C-BDE9-4de5-BB40-768CAA584FDC} - C:\WINDOWS\system32\beikpkyg.dll
                          O2 - BHO: (no name) - {D3EEE7A6-94AB-4F4B-A623-39FB6EBDA716} - C:\WINDOWS\system32\vtsqr.dll (file missing)
                          O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                          O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                          O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
                          O20 - Winlogon Notify: mljgg - C:\WINDOWS\system32\mljgg.dll
                          O20 - Winlogon Notify: opnkkih - C:\WINDOWS\SYSTEM32\opnkkih.dll
                          O20 - Winlogon Notify: vtsqr - C:\WINDOWS\system32\vtsqr.dll (file missing)

                          * ferme toutes les applications ouvertes y compris IE et clique sur "fixer objet"

                          puis reposte un nouveau rapport hijackthis stp
                          0
                          1. VundoFix V6.5.8

                            Checking Java version...

                            Scan started at 19:22:37 13/09/2007

                            Listing files found while scanning....

                            C:\windows\system32\aauinxgj.ini
                            C:\windows\system32\bhbvfrvi.ini
                            C:\WINDOWS\system32\ceqbnqwx.dll
                            C:\windows\system32\dqrmpgkh.dll
                            C:\windows\system32\erecriqi.ini
                            C:\WINDOWS\system32\gcqwnmfi.dll
                            C:\windows\system32\hilfguui.dll
                            C:\windows\system32\hkgpmrqd.ini
                            C:\WINDOWS\system32\ifmnwqcg.ini
                            C:\windows\system32\iqircere.dll
                            C:\windows\system32\iuugflih.ini
                            C:\windows\system32\ivrfvbhb.dll
                            C:\windows\system32\jgxniuaa.dll
                            C:\windows\system32\knfgdluu.ini
                            C:\WINDOWS\system32\mljgg.dll
                            C:\WINDOWS\system32\opnkkih.dll
                            C:\WINDOWS\system32\simvyesc.dll
                            C:\WINDOWS\system32\upbikptq.dll
                            C:\windows\system32\uuldgfnk.dll
                            C:\WINDOWS\system32\vtsqr.dll

                            Beginning removal...

                            Attempting to delete C:\windows\system32\aauinxgj.ini
                            C:\windows\system32\aauinxgj.ini Has been deleted!

                            Attempting to delete C:\windows\system32\bhbvfrvi.ini
                            C:\windows\system32\bhbvfrvi.ini Has been deleted!

                            Attempting to delete C:\windows\system32\dqrmpgkh.dll
                            C:\windows\system32\dqrmpgkh.dll Has been deleted!

                            Attempting to delete C:\windows\system32\erecriqi.ini
                            C:\windows\system32\erecriqi.ini Has been deleted!

                            Attempting to delete C:\WINDOWS\system32\gcqwnmfi.dll
                            C:\WINDOWS\system32\gcqwnmfi.dll Could not be deleted.

                            Attempting to delete C:\windows\system32\hilfguui.dll
                            C:\windows\system32\hilfguui.dll Has been deleted!

                            Attempting to delete C:\windows\system32\hkgpmrqd.ini
                            C:\windows\system32\hkgpmrqd.ini Has been deleted!

                            Attempting to delete C:\WINDOWS\system32\ifmnwqcg.ini
                            C:\WINDOWS\system32\ifmnwqcg.ini Has been deleted!

                            Attempting to delete C:\windows\system32\iqircere.dll
                            C:\windows\system32\iqircere.dll Has been deleted!

                            Attempting to delete C:\windows\system32\iuugflih.ini
                            C:\windows\system32\iuugflih.ini Has been deleted!

                            Attempting to delete C:\windows\system32\ivrfvbhb.dll
                            C:\windows\system32\ivrfvbhb.dll Has been deleted!

                            Attempting to delete C:\windows\system32\jgxniuaa.dll
                            C:\windows\system32\jgxniuaa.dll Has been deleted!

                            Attempting to delete C:\windows\system32\knfgdluu.ini
                            C:\windows\system32\knfgdluu.ini Has been deleted!

                            Attempting to delete C:\WINDOWS\system32\mljgg.dll
                            C:\WINDOWS\system32\mljgg.dll Could not be deleted.

                            Attempting to delete C:\WINDOWS\system32\opnkkih.dll
                            C:\WINDOWS\system32\opnkkih.dll Could not be deleted.

                            Attempting to delete C:\WINDOWS\system32\upbikptq.dll
                            C:\WINDOWS\system32\upbikptq.dll Has been deleted!

                            Attempting to delete C:\windows\system32\uuldgfnk.dll
                            C:\windows\system32\uuldgfnk.dll Has been deleted!

                            Performing Repairs to the registry.
                            Done!

                            Beginning removal...

                            Attempting to delete C:\WINDOWS\system32\gcqwnmfi.dll
                            C:\WINDOWS\system32\gcqwnmfi.dll Has been deleted!

                            Attempting to delete C:\WINDOWS\system32\mljgg.dll
                            C:\WINDOWS\system32\mljgg.dll Could not be deleted.

                            Attempting to delete C:\WINDOWS\system32\opnkkih.dll
                            C:\WINDOWS\system32\opnkkih.dll Could not be deleted.

                            Performing Repairs to the registry.
                            Done!

                            Beginning removal...

                            Beginning removal...

                            Attempting to delete C:\WINDOWS\system32\beikpkyg.dll
                            C:\WINDOWS\system32\beikpkyg.dll Could not be deleted.

                            Attempting to delete C:\WINDOWS\system32\beikpkyg.dll
                            C:\WINDOWS\system32\beikpkyg.dll Could not be deleted.

                            Attempting to delete C:\WINDOWS\system32\mljgg.dll
                            C:\WINDOWS\system32\mljgg.dll Could not be deleted.

                            Attempting to delete C:\WINDOWS\system32\mljgg.dll
                            C:\WINDOWS\system32\mljgg.dll Could not be deleted.

                            Attempting to delete C:\WINDOWS\system32\opnkkih.dll
                            C:\WINDOWS\system32\opnkkih.dll Could not be deleted.

                            Attempting to delete C:\WINDOWS\system32\opnkkih.dll
                            C:\WINDOWS\system32\opnkkih.dll Could not be deleted.

                            Performing Repairs to the registry.
                            Done!

                            Beginning removal...

                            Sa les a pas supprimé :( je sais j'ai cliké deux fois ... ^^

                            et hijack this

                            Logfile of HijackThis v1.99.1
                            Scan saved at 22:49:59, on 13/09/2007
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16512)

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
                            C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
                            C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
                            C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
                            C:\Program Files\F-Secure\Common\FSMA32.EXE
                            C:\Program Files\F-Secure\Anti-Virus\fssm32.exe
                            C:\Program Files\F-Secure\Common\FSMB32.EXE
                            C:\Program Files\F-Secure\BackWeb\7681197\Program\F-Secure Automatic Update.exe
                            C:\Program Files\F-Secure\Common\FCH32.EXE
                            C:\Program Files\F-Secure\Common\FAMEH32.EXE
                            C:\Program Files\F-Secure\Anti-Virus\fsqh.exe
                            C:\Program Files\F-Secure\Anti-Virus\fsrw.exe
                            C:\Program Files\F-Secure\Common\FNRB32.EXE
                            C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
                            C:\Program Files\F-Secure\Common\FIH32.EXE
                            C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
                            C:\WINDOWS\system32\hkcmd.exe
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            C:\WINDOWS\SOUNDMAN.EXE
                            C:\WINDOWS\sm56hlpr.exe
                            C:\Program Files\F-Secure\Common\FSM32.EXE
                            C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
                            C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
                            C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe
                            C:\Program Files\MSN Messenger\MsnMsgr.Exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
                            C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
                            C:\Program Files\F-Secure\FSGUI\fsguidll.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
                            C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                            C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/webhp?gws_rd=ssl
                            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                            O2 - BHO: (no name) - {890CFBF0-10D5-43D3-ABFD-206F7C4A2699} - C:\WINDOWS\system32\opnkkih.dll
                            O2 - BHO: (no name) - {D664D716-202B-4A32-B864-C6D1D1F095EA} - C:\WINDOWS\system32\mljgg.dll
                            O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                            O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
                            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                            O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                            O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
                            O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
                            O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                            O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                            O4 - HKLM\..\Run: [\\DOMINIQUE\EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P38 "\\DOMINIQUE\EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
                            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
                            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                            O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
                            O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                            O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
                            O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
                            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                            O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                            O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                            O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                            O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                            O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                            O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                            O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                            O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                            O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                            O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                            O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                            O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                            O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                            O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
                            O11 - Options group: [INTERNATIONAL] International*
                            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                            O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                            O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                            O20 - Winlogon Notify: mljgg - C:\WINDOWS\system32\mljgg.dll
                            O20 - Winlogon Notify: opnkkih - C:\WINDOWS\SYSTEM32\opnkkih.dll
                            O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                            O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                            O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                            O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
                            O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
                            O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
                            O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
                            O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
                            O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
                            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            0
                        • 1
                        • 2