Problème ! Window System 32

Bonjour, voilà, depuis quelque temps pleins de messages d'affichent lorsque j'ouvre mon ordinateur. Il me dise qu'une image est incorrecte, celle du fichier suivant : (ce n'est pas le seul qu'il affiche)

c:\WINDOWS\SYSTEM32\wowfx.dll

Voilà, j'ai Spybot et Estet Nod32.

Merci de m'aider si quelqu'un connait la solution.
Configuration: Windows XP
Internet Explorer 7.0

128 réponses

Résumé de la discussion

Des avertissements d'ouverture très fréquents signalent qu'une image est incorrecte et pointent vers le fichier c:\WINDOWS\SYSTEM32\wowfx.dll, symptôme typique d'une infection résiduelle sur Windows XP et IE7. Plusieurs éléments montrent la nécessité d'analyses approfondies via HijackThis et des nettoyages manuels, les outils antivirus ne suffisant pas toujours à éliminer les malware actuels. La solution préconisée consiste à supprimer manuellement la clé de registre ACMru associée à pmkhh.dll et, le cas échéant, à supprimer pmkhh.dll du système pour réparer le démarrage. Complémentairement, les rapports contiennent d'autres entrées potentiellement malveillantes telles que des DLL en exécution automatique et des services suspects, utiles pour un nettoyage global et plus approfondi.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonjour,

    IMPORTANT :
    Ne pas désactiver la restauration système, tant que le pc n'est pas propre. merci


    * Télécharge HijackThis et poste le rapport stp
    http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

    * Lance un scan "do a system scan & save a logfile" puis copie colle le rapport généré ici

    ------

    Tutorial
    http://pchelpbordeaux.free.fr/tuto.html
    Démo en image (merci balltrap)
    demo hijackenregistrement http://perso.orange.fr/rginformatique/section%20virus/Hijenr.gif
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
    0
    1. Ok merci, mais je pense qu'il n'y a pas de réstauration du system. Comment savoir si elle est activé ?
      0
      1. Contributeur sécurité
        à l'inverse de :

        http://pageperso.aol.fr/loraline60/desactiver_restauration_systeme.htm
        0
        1. Voilà merci beaucoup de m'aider.

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 10:57:37, on 2007-12-29
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16574)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\WINDOWS\arservice.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\WINDOWS\eHome\ehRecvr.exe
          C:\WINDOWS\eHome\ehSched.exe
          C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\WINDOWS\system32\HPZipm12.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Viewpoint\Common\ViewpointService.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/?gws_rd=ssl
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
          F3 - REG:win.ini: load=C:\WINDOWS\system32\pmkhh.exe
          O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
          O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
          O4 - HKLM\..\Run: [Gestionnaire de sécurité Sympatico] C:\Program Files\Bell\Gestionnaire de securite\RPS.exe
          O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
          O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Bell\Gestionnaire de securite\ZkRunOnceR.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
          O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - c:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
          O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra button: Correcteur - {F7C8E5F6-B6D1-45db-8D91-2BCFA5DF11A9} - C:\PROGRA~1\Druide\Antidote\Internet Explorer\7\Antidote K - IE 7.htm (HKCU)
          O9 - Extra button: Dictionnaires - {F9B969E8-58D0-4dd9-AC8A-EE2336FF8F65} - C:\PROGRA~1\Druide\Antidote\Internet Explorer\7\Antidote D - IE 7.htm (HKCU)
          O9 - Extra button: Guides - {FA089E36-3F1B-4c51-9A1A-C4E7012483AF} - C:\PROGRA~1\Druide\Antidote\Internet Explorer\7\Antidote G - IE 7.htm (HKCU)
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
          O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-CA/a-UNO1/GAME_UNO1.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
          O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
          O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
          O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
          O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
          0
          1. Contributeur sécurité
            re

            * Télécharge VundoFix.exe (par Atribune) sur ton Bureau

            http://www.atribune.org/ccount/click.php?id=4

            * Double-clique VundoFix.exe afin de le lancer

            * Clique sur le bouton Scan for Vundo

            * Lorsque le scan est complété, clique sur le bouton Remove Vundo

            * Une invite te demandera si tu veux supprimer les fichiers, clique YES

            * Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers

            * Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK

            * Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse

            Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".
            0
            1. Voici les rapports :

              VundoFix V6.7.7

              Checking Java version...

              Java version is 1.5.0.6
              Old versions of java are exploitable and should be removed.

              Scan started at 11:03:28 2007-12-29

              Listing files found while scanning....

              C:\WINDOWS\pchealth\helpctr\binaries\MSConfig.exe
              C:\windows\system32\drvsupr.dll
              C:\WINDOWS\system32\hhkmp.ini
              C:\WINDOWS\system32\hhkmp.ini2
              C:\WINDOWS\system32\nnnlkjh.dll
              C:\WINDOWS\system32\pmkhh.dll
              C:\WINDOWS\system32\pmkhh.exe

              Beginning removal...

              Attempting to delete C:\WINDOWS\pchealth\helpctr\binaries\MSConfig.exe
              C:\WINDOWS\pchealth\helpctr\binaries\MSConfig.exe Has been deleted!

              Attempting to delete C:\windows\system32\drvsupr.dll
              C:\windows\system32\drvsupr.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\hhkmp.ini
              C:\WINDOWS\system32\hhkmp.ini Has been deleted!

              Attempting to delete C:\WINDOWS\system32\hhkmp.ini2
              C:\WINDOWS\system32\hhkmp.ini2 Has been deleted!

              Attempting to delete C:\WINDOWS\system32\nnnlkjh.dll
              C:\WINDOWS\system32\nnnlkjh.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\pmkhh.dll
              C:\WINDOWS\system32\pmkhh.dll Has been deleted!

              Attempting to delete C:\WINDOWS\system32\pmkhh.exe
              C:\WINDOWS\system32\pmkhh.exe Has been deleted!

              Performing Repairs to the registry.
              Done!

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 11:22:48, on 2007-12-29
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16574)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\WINDOWS\arservice.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\WINDOWS\eHome\ehRecvr.exe
              C:\WINDOWS\eHome\ehSched.exe
              C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\WINDOWS\system32\HPZipm12.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Viewpoint\Common\ViewpointService.exe
              C:\WINDOWS\system32\dllhost.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/?gws_rd=ssl
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
              F3 - REG:win.ini: load=C:\WINDOWS\system32\pmkhh.exe
              O2 - BHO: (no name) - {036C7917-26A1-48F9-AF95-7EAB7A139815} - (no file)
              O2 - BHO: (no name) - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - (no file)
              O2 - BHO: (no name) - {428B4950-16E5-4B66-A15A-BDFF47987B2F} - (no file)
              O2 - BHO: (no name) - {457CD76E-394E-4140-A8C6-DA071658C8A5} - (no file)
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: (no name) - {6F6E975E-A2D8-4ABB-BBED-D98082BBB5CB} - C:\WINDOWS\system32\pmkhh.dll (file missing)
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
              O2 - BHO: (no name) - {D0C3B9AB-6707-4A19-BCBA-04B148954E36} - (no file)
              O2 - BHO: (no name) - {DB0B918E-A0A8-482B-8D75-A682816B0C7B} - C:\WINDOWS\system32\nnnnolk.dll
              O2 - BHO: (no name) - {FD629340-DAC0-4BA0-83E2-5EA6121A4E0A} - (no file)
              O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
              O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
              O4 - HKLM\..\Run: [Gestionnaire de sécurité Sympatico] C:\Program Files\Bell\Gestionnaire de securite\RPS.exe
              O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
              O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Bell\Gestionnaire de securite\ZkRunOnceR.exe"
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
              O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
              O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - c:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
              O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra button: Correcteur - {F7C8E5F6-B6D1-45db-8D91-2BCFA5DF11A9} - C:\PROGRA~1\Druide\Antidote\Internet Explorer\7\Antidote K - IE 7.htm (HKCU)
              O9 - Extra button: Dictionnaires - {F9B969E8-58D0-4dd9-AC8A-EE2336FF8F65} - C:\PROGRA~1\Druide\Antidote\Internet Explorer\7\Antidote D - IE 7.htm (HKCU)
              O9 - Extra button: Guides - {FA089E36-3F1B-4c51-9A1A-C4E7012483AF} - C:\PROGRA~1\Druide\Antidote\Internet Explorer\7\Antidote G - IE 7.htm (HKCU)
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
              O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-CA/a-UNO1/GAME_UNO1.cab
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll
              O20 - Winlogon Notify: nnnnolk - C:\WINDOWS\SYSTEM32\nnnnolk.dll
              O20 - Winlogon Notify: winzzd32 - winzzd32.dll (file missing)
              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
              O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
              O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
              O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
              O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
              0
              1. Contributeur sécurité
                re
                ce n'est pas suffisant

                * Télécharge combofix.exe (par sUBs) sur ton Bureau
                http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                IMPORTANT

                *désactive ton antivirus, antispyware, et spybot (résident) durant l'utilisation de ComboFix . Merci. Tu réactives ensuite
                puis

                * Double clique combofix.exe.

                * Tape sur la touche Y (Yes) pour démarrer le scan.

                * Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse

                NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                ainsi qu'un nouveau rapport hijackthis stp
                0
                1. Merci, désoler j'ai encore une question, comment je fais pour désactivé spybot et mon antivirus ?
                  0
                  1. Contributeur sécurité
                    pour l'antivirus, je suppose un peu comme tous les programmes clic droit -------quitter ou désactiver

                    c'est pour éviter qu'il ne "râle"

                    quant à spybot, tu clic droit sur l'icone du résident (dans le systray à côté de l'horloge) et quitter le programme.

                    0
                    1. C'est bizarre parce que je ne voie plus les icones à côtés de l'horloge même si je clique sur la flèche, il n'Y a que le son et pour désactiver les phériphérique, pourtand je les ai fait afficher. Je vais faire le rapport, j'imagine qu'ils sont désactivés.
                      0
                      1. Contributeur sécurité
                        si tu ne vois pas les icones, cela revient à dire que ton antivirus n'est pas actif.....
                        0
                        1. J'ai lancé le logiciel sa fait environ une heure, et il n'avait toujours pas terminé, il y avait ce message et ensuite il était écrit :

                          http://img99.imageshack.us/img99/3535/screenvc3.jpg

                          Étape1_terminé
                          Étape 2_terminé

                          ... Jusqu'à 36..
                          0
                          1. Contributeur sécurité
                            bonsoir,

                            je croyais pourtant avoir mis un message tout à l'heure, il n'apparait pas. Je recommence donc ce que je t'avais dit, je n'ai jamais eu ce problème, je vais voir ce que je peux trouver.

                            je reviens dès que possible
                            0
                            1. Contributeur sécurité
                              me revoilà, on va procéder autrement

                              * lance hiajckthis "do a system scan only" puis coche :

                              F3 - REG:win.ini: load=C:\WINDOWS\system32\pmkhh.exe
                              O2 - BHO: (no name) - {036C7917-26A1-48F9-AF95-7EAB7A139815} - (no file)
                              O2 - BHO: (no name) - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - (no file)
                              O2 - BHO: (no name) - {428B4950-16E5-4B66-A15A-BDFF47987B2F} - (no file)
                              O2 - BHO: (no name) - {457CD76E-394E-4140-A8C6-DA071658C8A5} - (no file)
                              O2 - BHO: (no name) - {6F6E975E-A2D8-4ABB-BBED-D98082BBB5CB} - C:\WINDOWS\system32\pmkhh.dll (file missing)
                              O2 - BHO: (no name) - {D0C3B9AB-6707-4A19-BCBA-04B148954E36} - (no file)
                              O2 - BHO: (no name) - {DB0B918E-A0A8-482B-8D75-A682816B0C7B} - C:\WINDOWS\system32\nnnnolk.dll
                              O2 - BHO: (no name) - {FD629340-DAC0-4BA0-83E2-5EA6121A4E0A} - (no file)
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                              O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-CA/a-UNO1/GAME_UNO1.cab
                              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                              O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll
                              O20 - Winlogon Notify: nnnnolk - C:\WINDOWS\SYSTEM32\nnnnolk.dll
                              O20 - Winlogon Notify: winzzd32 - winzzd32.dll (file missing)

                              * toutes applications fermées et HORS CONNEXION, clique sur FIX CHECKED

                              Puis

                              * Copie les lignes de la citation suivante, d'un trait :

                              Registry values to replace with dummy:
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs
                              
                              Registry keys to delete:
                              HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\nnnnolk
                              HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winzzd32
                              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{036C7917-26A1-48F9-AF95-7EAB7A139815}
                              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3C060EA2-E6A9-4E49-A530-D4657B8C449A}
                              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{428B4950-16E5-4B66-A15A-BDFF47987B2F}
                              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{457CD76E-394E-4140-A8C6-DA071658C8A5}
                              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6F6E975E-A2D8-4ABB-BBED-D98082BBB5CB}
                              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0C3B9AB-6707-4A19-BCBA-04B148954E36}
                              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DB0B918E-A0A8-482B-8D75-A682816B0C7B}
                              HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD629340-DAC0-4BA0-83E2-5EA6121A4E0A}
                              
                              Files to delete:
                              C:\WINDOWS\system32\wowfx.dll
                              C:\WINDOWS\SYSTEM32\nnnnolk.dll
                              C:\WINDOWS\system32\pmkhh.exe


                              --> Clic droit / "copier"

                              Maintenant crée un nouveau document texte : clic droit de souris sur le bureau, "Nouveau" > "Document Texte".

                              * Ouvre-le et colle dedans ce que tu viens de copier précédemment
                              * Enregistre ce fichier sur ton bureau (nom : mad.txt)

                              * Télécharge à présent The Avenger
                              http://www.geekstogo.com/forum/files/file/393-the-avenger-by-swandog46/
                              * Dézippe-le sur ton bureau et double-clique sur le fichier "avenger.exe"
                              * Clique sur "Ok"
                              * Sélectionne "Load Script from File" et clique sur l'icône en forme de dossier.
                              * Sélectionne le fichier mad.txt qui est sur ton bureau
                              * Clique sur le feu vert pour lancer le script
                              * Clique sur "Oui"
                              * Accepte de redémarrer ton pc

                              après le redémarrage :

                              * Ouvre le fichier C:\avenger.txt et copie/colle son contenu ici.
                              ainsi qu'un nouveau Log HijackThis
                              0
                              1. Re, désoler du retard, voilà maitenant, in n'y a pas de 02..., voici le scan :

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 17:33, on 2007-12-29
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                C:\WINDOWS\arservice.exe
                                C:\Program Files\Bonjour\mDNSResponder.exe
                                C:\WINDOWS\eHome\ehRecvr.exe
                                C:\WINDOWS\eHome\ehSched.exe
                                C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                C:\WINDOWS\system32\nvsvc32.exe
                                C:\WINDOWS\system32\HPZipm12.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Viewpoint\Common\ViewpointService.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\WINDOWS\system32\rundll32.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\WINDOWS\system32\wuauclt.exe
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/?gws_rd=ssl
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                                F3 - REG:win.ini: load=C:\WINDOWS\system32\pmkhh.exe
                                O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
                                O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
                                O4 - HKLM\..\Run: [Gestionnaire de sécurité Sympatico] C:\Program Files\Bell\Gestionnaire de securite\RPS.exe
                                O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
                                O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Bell\Gestionnaire de securite\ZkRunOnceR.exe"
                                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - c:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                                O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra button: Correcteur - {F7C8E5F6-B6D1-45db-8D91-2BCFA5DF11A9} - C:\PROGRA~1\Druide\Antidote\Internet Explorer\7\Antidote K - IE 7.htm (HKCU)
                                O9 - Extra button: Dictionnaires - {F9B969E8-58D0-4dd9-AC8A-EE2336FF8F65} - C:\PROGRA~1\Druide\Antidote\Internet Explorer\7\Antidote D - IE 7.htm (HKCU)
                                O9 - Extra button: Guides - {FA089E36-3F1B-4c51-9A1A-C4E7012483AF} - C:\PROGRA~1\Druide\Antidote\Internet Explorer\7\Antidote G - IE 7.htm (HKCU)
                                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                                O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-CA/a-UNO1/GAME_UNO1.cab
                                O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                O20 - AppInit_DLLs: C:\WINDOWS\system32\wowfx.dll
                                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
                                O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                                O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
                                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
                                O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
                                O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
                                0
                                1. Euh je vais faire sa sans cocher les 02...
                                  0
                                  1. Contributeur sécurité
                                    je n'ai pas compris ce dont tu parles. As tu fait les manips comme demandées avec the avenger ou pas ?
                                    0
                                2. Contributeur sécurité
                                  il en reste

                                  poste le rapport de the avenger stp, j'en ai besoin
                                  0
                                  1. Non et bien je n'ais pas encore faites la marche à suivre 4 messages plus haut, je vais la faire.
                                    0
                                    1. Contributeur sécurité
                                      alors fait toutes les manips, les lignes que tu ne trouves plus laisse les, mais fait tout à la suite stp.

                                      et poste ensuite les rapports the avenger et un nouveau rapport hijackthis
                                      0
                                      1. Exuse moi j'étais un peu mêler, bon voilà les deux rapports que tu m'avais demmandé au message 14 :

                                        Registry values to replace with dummy:
                                        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs

                                        Registry keys to delete:
                                        HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\nnnnolk
                                        HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winzzd32
                                        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{036C7917-26A1-48F9-AF95-7EAB7A139815}
                                        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3C060EA2-E6A9-4E49-A530-D4657B8C449A}
                                        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{428B4950-16E5-4B66-A15A-BDFF47987B2F}
                                        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{457CD76E-394E-4140-A8C6-DA071658C8A5}
                                        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6F6E975E-A2D8-4ABB-BBED-D98082BBB5CB}
                                        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0C3B9AB-6707-4A19-BCBA-04B148954E36}
                                        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DB0B918E-A0A8-482B-8D75-A682816B0C7B}
                                        HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD629340-DAC0-4BA0-83E2-5EA6121A4E0A}

                                        Files to delete:
                                        C:\WINDOWS\system32\wowfx.dll
                                        C:\WINDOWS\SYSTEM32\nnnnolk.dll
                                        C:\WINDOWS\system32\pmkhh.exe

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 17:48, on 2007-12-29
                                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                                        MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\system32\spoolsv.exe
                                        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        C:\WINDOWS\arservice.exe
                                        C:\Program Files\Bonjour\mDNSResponder.exe
                                        C:\WINDOWS\eHome\ehRecvr.exe
                                        C:\WINDOWS\eHome\ehSched.exe
                                        C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                                        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                        C:\WINDOWS\system32\nvsvc32.exe
                                        C:\WINDOWS\system32\HPZipm12.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\Program Files\Viewpoint\Common\ViewpointService.exe
                                        C:\WINDOWS\system32\dllhost.exe
                                        C:\WINDOWS\system32\wuauclt.exe
                                        C:\WINDOWS\system32\userinit.exe
                                        C:\WINDOWS\Explorer.EXE
                                        C:\WINDOWS\system32\ctfmon.exe
                                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/?gws_rd=ssl
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                                        F3 - REG:win.ini: load=C:\WINDOWS\system32\pmkhh.exe
                                        O2 - BHO: (no name) - {188E09DC-2205-44CE-ABE9-136CB7705E5F} - (no file)
                                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O2 - BHO: (no name) - {6EDB745E-FDED-4860-86DF-133AC8C0E52F} - C:\WINDOWS\system32\pmkhh.dll
                                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                        O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
                                        O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
                                        O4 - HKLM\..\Run: [Gestionnaire de sécurité Sympatico] C:\Program Files\Bell\Gestionnaire de securite\RPS.exe
                                        O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
                                        O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Bell\Gestionnaire de securite\ZkRunOnceR.exe"
                                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                        O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                        O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
                                        O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - c:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                                        O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O9 - Extra button: Correcteur - {F7C8E5F6-B6D1-45db-8D91-2BCFA5DF11A9} - C:\PROGRA~1\Druide\Antidote\Internet Explorer\7\Antidote K - IE 7.htm (HKCU)
                                        O9 - Extra button: Dictionnaires - {F9B969E8-58D0-4dd9-AC8A-EE2336FF8F65} - C:\PROGRA~1\Druide\Antidote\Internet Explorer\7\Antidote D - IE 7.htm (HKCU)
                                        O9 - Extra button: Guides - {FA089E36-3F1B-4c51-9A1A-C4E7012483AF} - C:\PROGRA~1\Druide\Antidote\Internet Explorer\7\Antidote G - IE 7.htm (HKCU)
                                        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                        O23 - Service: Eset HTTP Server (EhttpSrv) - Unknown owner - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
                                        O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                                        O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                        O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
                                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                        O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
                                        O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                        O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
                                        O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
                                        0
                                        • 1
                                        • 2
                                        • 3
                                        • 4
                                        • 5
                                        • 6
                                        • 7