Bonjour
encore moi mais si ca peut vous aider...
j'ai renommé hijackthis.exe en test.exe et Do a system scan and save the log (j'ai lu quelque part qu'il fallait faire cette manip ).
Voici le rapport:
Logfile of HijackThis v1.99.1
Scan saved at 09:58:30, on 03/03/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\System32\CTsvcCDA.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\Explorer.EXE
C:\Program Files\BitTorrent\bittorrent.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\VPTray.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_monitor.exe
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_JetSend.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\winmsgr.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\WINNT\msagent\AgentSvr.exe
D:\Mes documents\Antivirus\Test.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.orange.fr/
O2 - BHO: (no name) - {0F01FF26-18F5-4613-BFD6-14DE2FBA24C3} - C:\WINNT\system32\awtusss.dll
O2 - BHO: (no name) - {A7C81B74-48E6-4513-9901-6D3225D328E3} - C:\WINNT\system32\ddccc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [HPIJetSend] C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_JetSend.exe
O4 - HKLM\..\Run: [WinMsg] C:\WINNT\winmsgr.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -
http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540004} -
http://freepcscan.com/spyware/Install.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://telisa2.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5CA8D349-C6E7-11D4-8166-009027DF3BB2} (France Telecom MDDK ActiveX Control) -
http://accueil.ava.serveur-ava.com/stkid_data/ocx/mDKid.cab
O16 - DPF: {63308B48-F435-42FD-AB0A-3564C7BEF9D7} (Toontown Installer ActiveX Control French) -
http://idownload.fr.toontown.com/sv1.5.15.6/ttinst-french.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1123939812437
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) -
http://www.securitoo.com/fra/pages/navol/fscax.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A13516A3-BE86-4517-813C-B5FF0C8ACDF3} (Toontown Installer ActiveX Control French) -
https://iplay.fr.toontown.com/download/sv1.5.14.10/ttinst-french.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) -
http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) -
http://www.sibelius.com/download/software/win/InstallScorch.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {C942A79B-01ED-47EE-9DAA-1EFAA70DAB8E} (VacPro.int_ver22b) -
http://www.muiegaozsicur.com/ocx/intES_ver22b.CAB
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/su/ocx/15028/CTPID.cab
O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} -
http://akamai.downloadv3.com/binaries/IA/netslv32_FR.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{9BCB1C8E-39ED-4841-8007-482146C16BF4}: NameServer = 80.10.246.130 80.10.246.3
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - AppInit_DLLs: 52.dll
O20 - Winlogon Notify: awtusss - C:\WINNT\SYSTEM32\awtusss.dll
O20 - Winlogon Notify: ddccc - C:\WINNT\system32\ddccc.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O21 - SSODL: bestreak - {874443fe-aa33-4ebf-a6ac-73208787e62d} - (no file)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
Ajout du 03-03-2007 à 10:01:
ok je suis allé plus vite que la musique.
je suis ta procédure à tout de suite
merci
Ajout du 03-03-2007 à 10:18:
désolé encore une chose
CCleaner n'a pas détruit ce que j'ai peut etre effacé ?
J'ai exécuté tuneup (*.*) mais il ne m'a pas demandé de date et le rapport est tres volumineux.
Dois-je tout restaurer ?
merci
Ajout du 03-03-2007 à 15:36:
Bonjour
Voila j'ai exécuté Virtumundo et j'ai mis le rapport ( vbg.txt en zip car trop lourd ) en attachements et L2me-Destroyer et hijackthis ( test.exe) et je te joins les 2 rapports dans cet ordre-là.
Dans l'attente de ta réponse, merci pour tout
Look2Me-Destroyer V1.0.12
Scanning for infected files.....
Scan started at 03/03/2007 15:11:01
Infected! C:\WINNT\system32\aepmgmts.dll
Infected! C:\WINNT\system32\afi2evxx.dll
Infected! C:\WINNT\system32\auctres.dll
Infected! C:\WINNT\system32\dtvxdec_040c.dll
Infected! C:\WINNT\system32\g022lafo1d2c.dll
Infected! C:\WINNT\system32\h04mlah11d4.dll
Infected! C:\WINNT\system32\hbui.dll
Infected! C:\WINNT\system32\ivakeng.dll
Infected! C:\WINNT\system32\l2r00c9mef.dll
Infected! C:\WINNT\system32\lbexpand.dll
Infected! C:\WINNT\system32\mehtmler.dll
Infected! C:\WINNT\system32\mpvci70.dll
Infected! C:\WINNT\system32\mql_qic.dll
Infected! C:\WINNT\system32\mvdocs.dll
Infected! C:\WINNT\system32\oee2.dll
Infected! C:\WINNT\system32\purfnet.dll
Infected! C:\WINNT\system32\pvdkReg.dll
Infected! C:\WINNT\system32\waw32.dll
Infected! C:\WINNT\system32\wjnsmon.dll
Infected! C:\WINNT\system32\WLNG32.dll
Attempting to delete infected files...
Attempting to delete: C:\WINNT\system32\aepmgmts.dll
C:\WINNT\system32\aepmgmts.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\afi2evxx.dll
C:\WINNT\system32\afi2evxx.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\auctres.dll
C:\WINNT\system32\auctres.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\dtvxdec_040c.dll
C:\WINNT\system32\dtvxdec_040c.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\g022lafo1d2c.dll
C:\WINNT\system32\g022lafo1d2c.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\h04mlah11d4.dll
C:\WINNT\system32\h04mlah11d4.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\hbui.dll
C:\WINNT\system32\hbui.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\ivakeng.dll
C:\WINNT\system32\ivakeng.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\l2r00c9mef.dll
C:\WINNT\system32\l2r00c9mef.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\lbexpand.dll
C:\WINNT\system32\lbexpand.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\mehtmler.dll
C:\WINNT\system32\mehtmler.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\mpvci70.dll
C:\WINNT\system32\mpvci70.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\mql_qic.dll
C:\WINNT\system32\mql_qic.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\mvdocs.dll
C:\WINNT\system32\mvdocs.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\oee2.dll
C:\WINNT\system32\oee2.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\purfnet.dll
C:\WINNT\system32\purfnet.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\pvdkReg.dll
C:\WINNT\system32\pvdkReg.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\waw32.dll
C:\WINNT\system32\waw32.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\wjnsmon.dll
C:\WINNT\system32\wjnsmon.dll Deleted successfully!
Attempting to delete: C:\WINNT\system32\WLNG32.dll
C:\WINNT\system32\WLNG32.dll Deleted successfully!
Making registry repairs.
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{2770F439-C822-4EB8-8BC8-BAFD97D59D0F}"
HKCR\Clsid\{2770F439-C822-4EB8-8BC8-BAFD97D59D0F}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{637562C4-F653-47A6-9D93-8856A03771C5}"
HKCR\Clsid\{637562C4-F653-47A6-9D93-8856A03771C5}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{E87CF1F8-FB52-4D17-B4B5-3AD853F50B01}"
HKCR\Clsid\{E87CF1F8-FB52-4D17-B4B5-3AD853F50B01}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{B585CFEF-953B-4910-BE10-3919B37AE9FF}"
HKCR\Clsid\{B585CFEF-953B-4910-BE10-3919B37AE9FF}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{7C8918F4-AB28-460E-B976-26275A5716AC}"
HKCR\Clsid\{7C8918F4-AB28-460E-B976-26275A5716AC}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{92F57595-292C-4E21-996A-8A790062F78E}"
HKCR\Clsid\{92F57595-292C-4E21-996A-8A790062F78E}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{CC3C9F7D-9A4A-4B0C-9BEF-78BD5CDA0B0D}"
HKCR\Clsid\{CC3C9F7D-9A4A-4B0C-9BEF-78BD5CDA0B0D}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{565A8896-2B35-4864-9A33-BCBBC35AB83D}"
HKCR\Clsid\{565A8896-2B35-4864-9A33-BCBBC35AB83D}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{81C7AF59-6F6A-46D6-8F90-82CD0683ED27}"
HKCR\Clsid\{81C7AF59-6F6A-46D6-8F90-82CD0683ED27}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{3EC3AFEB-9C54-416A-8C66-F337D294563B}"
HKCR\Clsid\{3EC3AFEB-9C54-416A-8C66-F337D294563B}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{7DD6578B-B6B2-4F3F-A32A-75812EAF91F5}"
HKCR\Clsid\{7DD6578B-B6B2-4F3F-A32A-75812EAF91F5}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{8DAE8FAB-27BF-4AC9-8AA8-C9FC79CC4DD3}"
HKCR\Clsid\{8DAE8FAB-27BF-4AC9-8AA8-C9FC79CC4DD3}
Restoring Windows certificates.
Replaced hosts file with default windows hosts file
Restoring SeDebugPrivilege for Administrateurs - Succeeded
ET
Logfile of HijackThis v1.99.1
Scan saved at 15:27:18, on 03/03/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\System32\CTsvcCDA.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_JetSend.exe
C:\WINNT\winmsgr.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
D:\Mes documents\Antivirus\Test.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.orange.fr/
O2 - BHO: MSEvents Object - {0F01FF26-18F5-4613-BFD6-14DE2FBA24C3} - C:\WINNT\system32\awtusss.dll
O2 - BHO: (no name) - {6D5CD084-97B3-4AFD-824B-D11EA1E5B4E7} - C:\WINNT\system32\ddccc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [HPIJetSend] C:\Program Files\Hewlett-Packard\PhotoSmart\Photo Imaging\Hpi_JetSend.exe
O4 - HKLM\..\Run: [WinMsg] C:\WINNT\winmsgr.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -
http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540004} -
http://freepcscan.com/spyware/Install.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://telisa2.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5CA8D349-C6E7-11D4-8166-009027DF3BB2} (France Telecom MDDK ActiveX Control) -
http://accueil.ava.serveur-ava.com/stkid_data/ocx/mDKid.cab
O16 - DPF: {63308B48-F435-42FD-AB0A-3564C7BEF9D7} (Toontown Installer ActiveX Control French) -
http://idownload.fr.toontown.com/sv1.5.15.6/ttinst-french.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1123939812437
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2005111401/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) -
http://www.securitoo.com/fra/pages/navol/fscax.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A13516A3-BE86-4517-813C-B5FF0C8ACDF3} (Toontown Installer ActiveX Control French) -
https://iplay.fr.toontown.com/download/sv1.5.14.10/ttinst-french.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) -
http://www.ravantivirus.com/scan/ravonline.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) -
http://www.sibelius.com/download/software/win/InstallScorch.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {C942A79B-01ED-47EE-9DAA-1EFAA70DAB8E} (VacPro.int_ver22b) -
http://www.muiegaozsicur.com/ocx/intES_ver22b.CAB
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/su/ocx/15028/CTPID.cab
O16 - DPF: {F72BC3F0-6C20-4793-9DDA-258589D8A907} -
http://akamai.downloadv3.com/binaries/IA/netslv32_FR.cab
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - AppInit_DLLs: 52.dll
O20 - Winlogon Notify: awtusss - C:\WINNT\SYSTEM32\awtusss.dll
O20 - Winlogon Notify: ddccc - C:\WINNT\system32\ddccc.dll
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O21 - SSODL: bestreak - {874443fe-aa33-4ebf-a6ac-73208787e62d} - (no file)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTsvcCDA.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
Ajout du 03-03-2007 à 15:41:
je ne sais pas si l'attachement de vbg.zip a fonctionné, je l'espère
encore merci