Se connecter / S'enregistrer
Votre question

[Résolu] Popups intempestives winantivirus

Tags :
  • Internet Explorer
  • Sécurité
Dernière réponse : dans Sécurité et virus
6 Juin 2007 12:16:02

Bonjour à tous,

J'ai des popus qui s'ouvrent sans arrêt avec IE. Impossible de les enlever et mon antivirus (Trend Micro) n'a rien trouvé.
A tout hasard je poste ici le log hijackthis si quelqu'un peut m'aider...

Merci d'avance !
=================================
Logfile of HijackThis v1.99.1
Scan saved at 12:00:18, on 06/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\IPSSVC.EXE
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
c:\veritas\bpws\bpws.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\DkLog.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\VERITAS\NETBAC~1\bin\bpinetd.exe
C:\OfficeScan NT\ntrtscan.exe
C:\VERITAS\NETBAC~1\bin\BPJAVA-msvc.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\OfficeScan NT\tmlisten.exe
C:\WINDOWS\System32\TPHDEXLG.EXE
C:\WINDOWS\system32\TpKmpSVC.exe
C:\PROGRA~1\MI4F93~1\webtool.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\System32\dkcktkn.exe
C:\OfficeScan NT\OfcPfwSvc.exe
C:\WINDOWS\TEMP\JSE195.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\TpShocks.exe
C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
C:\VERITAS\NetBackup\bin\tracker.exe
C:\OfficeScan NT\pccntmon.exe
C:\windows\system32\sysnetdrv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\OpenSTA\Server\DaemonCFG.exe
C:\PROGRA~1\OpenSTA\Server\OmniOrb\OMNINA~1.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\EasyPHP1-8\EasyPHP.exe
C:\PROGRA~1\EASYPH~1\Apache\apache.exe
C:\PROGRA~1\EASYPH~1\Apache\apache.exe
C:\PROGRA~1\EASYPH~1\MySql\bin\mysqld.exe
C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5w.exe
C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
C:\Program Files\Zend\ZendStudio-5.5.0\bin\ZDE.exe
C:\Program Files\Zend\ZendStudio-5.5.0\jre\bin\javaw.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\OpenSTA\BaseUI\OSCommander.exe
E:\users\eqm\programmes\putty.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\eqm.DS\Desktop\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsinteraction
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dsinteraction
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://instms/connect.vbs
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.0.40.46;10.0.40.45;128.3.14.90:8003;*.eno.ds;*.enovia-clt.com;*.dsag.com;*.deneb.com;*.dskk;heino2e:8004;*.ds;*.dsy.ds;*.dassault-systemes.fr;cpds.ds;*.abaqus.com;mobility.3ds.com;192.168.15.5;*.dds.ds;*.dassault-data-services.fr;thezone.matrixone.net;<local>
O1 - Hosts: 128.2.13.90 jolyjump
O1 - Hosts: 128.5.12.29 hector
O1 - Hosts: 128.1.2.113 gooddsy
O1 - Hosts: 128.3.10.6 baddsy
O1 - Hosts: 128.3.14.7 ross
O1 - Hosts: 128.40.20.132 eqm.punkdsy.dsy.ds nico.punkdsy.dsy.ds rtj.punkdsy.dsy.ds bmi.punkdsy.dsy.ds julien.punkdsy.dsy.ds
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0777FDE1-50AB-4E2F-8DC8-23548E111F93} - C:\WINDOWS\system32\iiffcbx.dll
O2 - BHO: (no name) - {28232870-A368-4A60-9462-229043EB466A} - C:\WINDOWS\system32\ssqpm.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O2 - BHO: (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - C:\WINDOWS\system32\jxvfbpod.dll
O3 - Toolbar: Zend Studio - {95188727-288F-4581-A48D-EAB3BD027314} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
O4 - HKLM\..\Run: [VERITAS NetBackup Client Job Tracker] C:\VERITAS\NetBackup\bin\tracker.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [FWConfig] c:\windows\FirewallWifiConfiguration.vbs
O4 - HKLM\..\Run: [Sysnetdrv] "c:\windows\system32\sysnetdrv.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\system32\coeuybyl.dll",realset
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: IBM NotesBuddy for Notes.lnk = C:\Program Files\IBM\NotesBuddy\NotesBuddy.exe
O4 - Global Startup: Integrity Client.lnk = C:\Program Files\Zone Labs\Integrity Client\iclient.exe
O4 - Global Startup: OpenSTA NameServer.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Zend Studio - Debug current page - res://C:\Program Files\Zend\ZendStudio-5.5.0\bin\ZendIEToolbar.dll/DebugCurrent.html
O8 - Extra context menu item: Zend Studio - Debug next page - res://C:\Program Files\Zend\ZendStudio-5.5.0\bin\ZendIEToolbar.dll/DebugNext.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Zend Studio Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
O9 - Extra 'Tools' menuitem: Zend Studio - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://dsinteraction
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dsy.ds
O17 - HKLM\Software\..\Telephony: DomainName = dsy.ds
O17 - HKLM\System\CCS\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
O17 - HKLM\System\CCS\Services\Tcpip\..\{3704A196-9C31-4368-8E3F-3C5C062DA803}: Domain = dsy.ds
O17 - HKLM\System\CCS\Services\Tcpip\..\{4D5B7F6B-7B8F-4AEB-8FFA-65181EF3B562}: Domain = dsy.ds
O17 - HKLM\System\CCS\Services\Tcpip\..\{DDE74ACD-B062-46F5-BCF1-91D7454B0B15}: Domain = dsy.ds
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = dsy.ds
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = dsy.ds
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
O17 - HKLM\System\CS2\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
O20 - Winlogon Notify: AwayNotify - C:\Program Files\Lenovo\AwayTask\AwayNotify.dll
O20 - Winlogon Notify: iiffcbx - C:\WINDOWS\SYSTEM32\iiffcbx.dll
O20 - Winlogon Notify: ssqpm - C:\WINDOWS\system32\ssqpm.dll
O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
O20 - Winlogon Notify: wincqt32 - C:\WINDOWS\SYSTEM32\wincqt32.dll
O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: NetBackup Warning Service (BpPortable) - Dassault-Systemes - c:\veritas\bpws\bpws.exe
O23 - Service: ccmsetup - Unknown owner - C:\WINDOWS\system32\ccmsetup\Ccmsetup.exe" /runservice /source:"\\ds\SysVol\ds\scripts\dsy" SMSSITECODE=DSY SMSCACHESIZE=500 (file missing)
O23 - Service: Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
O23 - Service: Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IBM Nodelock License Server (IBM LUM NDL) - IBM - C:\IFOR\WIN\BIN\I4LLMD.EXE
O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
O23 - Service: NetBackup Client Service (NetBackup INET Daemon) - VERITAS Software Corporation - C:\VERITAS\NETBAC~1\bin\bpinetd.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\OfficeScan NT\OfcPfwSvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe
O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe" //RS//Tomcat5 (file missing)
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Autres pages sur : resolu popups intempestives winantivirus

a b 8 Sécurité
6 Juin 2007 13:15:07

Bonjour,

Télécharge R-Hosts.exe (de S!ri)
Lance R-Hosts puis clique sur "Restaurer".
Valide la modification en appuyant sur OK.

&

Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
  • Double-clique VundoFix.exe afin de le lancer
  • Clique sur le bouton Scan for Vundo
  • Lorsque le scan est complété, clique sur le bouton Remove Vundo
  • Une invite te demandera si tu veux supprimer les fichiers, clique YES
  • Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
  • Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK
  • Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse
    Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".
    6 Juin 2007 14:14:18

    Merci Angeldark,
    R-Hosts a réinitialisé mon fichier hosts.

    Voilà le rapport C:\vundofix.txt

    =========================

    VundoFix V6.4.2

    Checking Java version...

    Java version is 1.5.0.5
    Old versions of java are exploitable and should be removed.

    Java version is 1.5.0.7
    Old versions of java are exploitable and should be removed.

    Scan started at 13:57:17 06/06/2007

    Listing files found while scanning....

    C:\WINDOWS\system32\coeuybyl.dll
    C:\WINDOWS\system32\iiffcbx.dll
    C:\WINDOWS\system32\jxvfbpod.dll
    C:\WINDOWS\system32\khfdefd.dll
    C:\WINDOWS\system32\lybyueoc.ini
    C:\WINDOWS\system32\mpqss.bak1
    C:\WINDOWS\system32\mpqss.bak2
    C:\WINDOWS\system32\mpqss.ini
    C:\WINDOWS\system32\ssqpm.dll
    C:\WINDOWS\system32\vturspp.dll

    Beginning removal...

    Attempting to delete C:\WINDOWS\system32\coeuybyl.dll
    C:\WINDOWS\system32\coeuybyl.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\iiffcbx.dll
    C:\WINDOWS\system32\iiffcbx.dll Could not be deleted.

    Attempting to delete C:\WINDOWS\system32\jxvfbpod.dll
    C:\WINDOWS\system32\jxvfbpod.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\khfdefd.dll
    C:\WINDOWS\system32\khfdefd.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\lybyueoc.ini
    C:\WINDOWS\system32\lybyueoc.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\mpqss.bak1
    C:\WINDOWS\system32\mpqss.bak1 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\mpqss.bak2
    C:\WINDOWS\system32\mpqss.bak2 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\mpqss.ini
    C:\WINDOWS\system32\mpqss.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\ssqpm.dll
    C:\WINDOWS\system32\ssqpm.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\vturspp.dll
    C:\WINDOWS\system32\vturspp.dll Has been deleted!

    Performing Repairs to the registry.
    Done!

    Beginning removal...

    Attempting to delete C:\WINDOWS\system32\iiffcbx.dll
    C:\WINDOWS\system32\iiffcbx.dll Has been deleted!

    Performing Repairs to the registry.
    Done!
    =================================

    Et maintenant le nouveau hijackthis.log

    Logfile of HijackThis v1.99.1
    Scan saved at 14:13:11, on 06/06/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\ibmpmsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\IPSSVC.EXE
    C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    c:\veritas\bpws\bpws.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\DkLog.exe
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\VERITAS\NETBAC~1\bin\bpinetd.exe
    C:\OfficeScan NT\ntrtscan.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\VERITAS\NETBAC~1\bin\BPJAVA-msvc.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\OfficeScan NT\tmlisten.exe
    C:\WINDOWS\System32\TPHDEXLG.EXE
    C:\WINDOWS\system32\TpKmpSVC.exe
    C:\PROGRA~1\MI4F93~1\webtool.exe
    C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    C:\WINDOWS\system32\CCM\CcmExec.exe
    C:\WINDOWS\System32\dkcktkn.exe
    C:\OfficeScan NT\OfcPfwSvc.exe
    C:\WINDOWS\system32\msiexec.exe
    C:\WINDOWS\TEMP\VJ656E.EXE
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    C:\WINDOWS\system32\RunDll32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\TpShocks.exe
    C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    C:\VERITAS\NetBackup\bin\tracker.exe
    C:\OfficeScan NT\pccntmon.exe
    C:\windows\system32\sysnetdrv.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft Office Communicator\Communicator.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\IBM\NotesBuddy\NotesBuddy.exe
    C:\Program Files\OpenSTA\Server\DaemonCFG.exe
    C:\PROGRA~1\OpenSTA\Server\OmniOrb\OMNINA~1.EXE
    C:\PROGRA~1\OpenSTA\Server\archmgrdmn.exe
    C:\PROGRA~1\OpenSTA\Server\cyrdmn.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Documents and Settings\eqm.DS\Desktop\scanner.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsinteraction
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dsinteraction
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://instms/connect.vbs
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.0.40.46;10.0.40.45;128.3.14.90:8003;*.eno.ds;*.enovia-clt.com;*.dsag.com;*.deneb.com;*.dskk;heino2e:8004;*.ds;*.dsy.ds;*.dassault-systemes.fr;cpds.ds;*.abaqus.com;mobility.3ds.com;192.168.15.5;*.dds.ds;*.dassault-data-services.fr;thezone.matrixone.net;<local>
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {0777FDE1-50AB-4E2F-8DC8-23548E111F93} - C:\WINDOWS\system32\iiffcbx.dll (file missing)
    O2 - BHO: (no name) - {28232870-A368-4A60-9462-229043EB466A} - C:\WINDOWS\system32\ssqpm.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O3 - Toolbar: Zend Studio - {95188727-288F-4581-A48D-EAB3BD027314} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
    O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
    O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
    O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
    O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    O4 - HKLM\..\Run: [VERITAS NetBackup Client Job Tracker] C:\VERITAS\NetBackup\bin\tracker.exe
    O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
    O4 - HKLM\..\Run: [FWConfig] c:\windows\FirewallWifiConfiguration.vbs
    O4 - HKLM\..\Run: [Sysnetdrv] "c:\windows\system32\sysnetdrv.exe"
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\system32\coeuybyl.dll",realset
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: IBM NotesBuddy for Notes.lnk = C:\Program Files\IBM\NotesBuddy\NotesBuddy.exe
    O4 - Global Startup: Integrity Client.lnk = C:\Program Files\Zone Labs\Integrity Client\iclient.exe
    O4 - Global Startup: OpenSTA NameServer.lnk = ?
    O8 - Extra context menu item: Add Person to NotesBuddy... - C:\Program Files\IBM\NotesBuddy\AddPersonN.html
    O8 - Extra context menu item: Add Picture to NotesBuddy... - C:\Program Files\IBM\NotesBuddy\AddImageN.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Zend Studio - Debug current page - res://C:\Program Files\Zend\ZendStudio-5.5.0\bin\ZendIEToolbar.dll/DebugCurrent.html
    O8 - Extra context menu item: Zend Studio - Debug next page - res://C:\Program Files\Zend\ZendStudio-5.5.0\bin\ZendIEToolbar.dll/DebugNext.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Zend Studio Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O9 - Extra 'Tools' menuitem: Zend Studio - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://dsinteraction
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\Software\..\Telephony: DomainName = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3704A196-9C31-4368-8E3F-3C5C062DA803}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4D5B7F6B-7B8F-4AEB-8FFA-65181EF3B562}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DDE74ACD-B062-46F5-BCF1-91D7454B0B15}: Domain = dsy.ds
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O17 - HKLM\System\CS1\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O17 - HKLM\System\CS2\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
    O20 - Winlogon Notify: AwayNotify - C:\Program Files\Lenovo\AwayTask\AwayNotify.dll
    O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
    O20 - Winlogon Notify: wincqt32 - C:\WINDOWS\SYSTEM32\wincqt32.dll
    O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: NetBackup Warning Service (BpPortable) - Dassault-Systemes - c:\veritas\bpws\bpws.exe
    O23 - Service: ccmsetup - Unknown owner - C:\WINDOWS\system32\ccmsetup\Ccmsetup.exe" /runservice /source:"\\ds\SysVol\ds\scripts\dsy" SMSSITECODE=DSY SMSCACHESIZE=500 (file missing)
    O23 - Service: Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
    O23 - Service: Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: IBM Nodelock License Server (IBM LUM NDL) - IBM - C:\IFOR\WIN\BIN\I4LLMD.EXE
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
    O23 - Service: NetBackup Client Service (NetBackup INET Daemon) - VERITAS Software Corporation - C:\VERITAS\NETBAC~1\bin\bpinetd.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
    O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\OfficeScan NT\OfcPfwSvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe
    O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe" //RS//Tomcat5 (file missing)
    O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
    O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    Contenus similaires
    a b 8 Sécurité
    6 Juin 2007 14:22:30

    Re,

    Citation :
    S'il vous plaît, aller ici pour uploader un fichier douteux pour analyse.
  • "Your Username:" - Entrez votre pseudo sur ce forum
  • "Topic Where File Was Requested:" - Copiez-collez le lien vers cette discussion
  • "File(s) To Submit:" - Bouton "Parcourir..." pour naviguer vers ce nom de fichier : C:\WINDOWS\SYSTEM32\wincqt32.dll
  • "Comments Or Further Info:" - Mentionnez s'il vous plaît que je vous ai demandé d'uploader ce fichier
  • Cliquez sur Send File


  • Télécharge combofix.exe (par sUBs) sur ton Bureau.
  • Double clique combofix.exe.
  • Tape sur la touche Y (Yes) pour démarrer le scan.
  • Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

    NOTE : Le rapport se trouve également ici : C:\Combofix.txt
    6 Juin 2007 14:29:53

    Angeldark,

    Est-ce que ta citation fait bien partie de ta réponse ?
    6 Juin 2007 14:45:16

    J'ai uploadé le fichier sur uploadmalware.
    Sinon voici le rapport combofix

    "EQM" - 2007-06-06 14:35:47 Service Pack 2 NTFS
    ComboFix 07-06-3B - Running from: "C:\Documents and Settings\eqm.DS\Desktop\"


    (((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))


    C:\WINDOWS\system32\wiyqfobu.dll
    C:\WINDOWS\system32\wincqt32.dll


    * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *


    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


    -------\LEGACY_NM
    -------\nm


    ((((((((((((((((((((((((( Files Created from 2007-05-06 to 2007-06-06 )))))))))))))))))))))))))))))))


    2007-06-06 13:57 <DIR> d-------- C:\VundoFix Backups
    2007-06-04 18:02 2,580 --a------ C:\WINDOWS\system32\jhlgoufo.exe
    2007-06-03 18:05 2,580 --a------ C:\WINDOWS\system32\mghsuewu.exe
    2007-06-02 09:46 <DIR> d-------- C:\Program Files\IE7
    2007-06-02 09:41 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    2007-06-01 15:53 <DIR> d-------- C:\DOCUME~1\eqm.DS\APPLIC~1\TortoiseSVN
    2007-06-01 09:56 <DIR> d-------- C:\Program Files\Microsoft Office Communicator
    2007-05-30 10:32 832 --a------ C:\WINDOWS\Outlook-UserAccountActivate.vbs
    2007-05-30 10:32 832 --a------ C:\temp\Outlook-UserAccountActivate.vbs
    2007-05-30 10:32 3,498 --a------ C:\temp\Outlook-UserAccountActivate-Install.vbs
    2007-05-29 18:32 <DIR> d-------- C:\Program Files\Dassault Systemes
    2007-05-25 21:04 <DIR> d-------- C:\Program Files\UltimateZip 2007
    2007-05-24 15:59 <DIR> d-------- C:\Program Files\MSXML 6.0
    2007-05-09 14:11 <DIR> d-------- C:\DOCUME~1\eqm.DS\APPLIC~1\Agency9
    2007-05-08 12:03 <DIR> d-------- C:\Program Files\Skype
    2007-05-08 12:03 <DIR> d-------- C:\DOCUME~1\eqm.DS\APPLIC~1\Skype
    2007-05-08 12:03 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype


    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    2007-06-06 12:10:49 86,016 ----a-w C:\Program Files\pslist.exe
    2007-06-06 08:14:41 -------- d-----w C:\Program Files\Mozilla Thunderbird
    2007-06-01 07:56:46 -------- d-----w C:\Program Files\Messenger
    2007-05-21 19:13:44 -------- d-----w C:\Program Files\Nortel Networks
    2007-05-16 07:02:46 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
    2007-05-03 11:52:07 664 ----a-w C:\WINDOWS\system32\d3d9caps.dat
    2007-05-03 11:52:06 552 ----a-w C:\WINDOWS\system32\d3d8caps.dat
    2007-05-03 11:25:55 -------- d-----w C:\Program Files\Google
    2007-05-03 11:25:54 -------- d--h--w C:\Program Files\InstallShield Installation Information
    2007-05-03 09:43:16 -------- d-----w C:\DOCUME~1\eqm.DS\APPLIC~1\SecondLife
    2007-05-03 09:42:15 -------- d-----w C:\Program Files\SecondLife
    2007-04-27 21:59:26 -------- d-----w C:\DOCUME~1\eqm.DS\APPLIC~1\dvdcss
    2007-04-27 21:58:54 -------- d-----w C:\DOCUME~1\eqm.DS\APPLIC~1\vlc
    2007-04-27 21:58:08 -------- d-----w C:\Program Files\VideoLAN
    2007-04-27 16:19:58 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2007-04-27 16:16:06 -------- d-----w C:\Program Files\IKEA HomePlanner
    2007-04-27 05:15:22 -------- d-----w C:\DOCUME~1\eqm.DS\APPLIC~1\DassaultSystemes
    2007-04-25 15:24:45 -------- d-----w C:\DOCUME~1\eqm.DS\APPLIC~1\Google
    2007-04-25 15:07:46 -------- d-----w C:\Program Files\Dassault Systemes 3D PrintScreen
    2007-04-24 14:51:27 -------- d-----w C:\Program Files\TechSmith
    2007-04-20 20:20:22 -------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
    2007-04-17 17:40:04 -------- d-----w C:\Program Files\MSECache
    2007-04-11 11:14:01 -------- d-----w C:\Program Files\OpenSTA
    2007-03-24 17:36:58 41,528 ---ha-w C:\WINDOWS\system32\mlfcache.dat
    2007-03-20 11:17:22 11,675 ----a-w C:\WINDOWS\mozver.dat
    2007-03-19 21:08:56 50,784 ----a-w C:\WINDOWS\system32\csvidcap.dll
    2007-03-19 06:30:24 102,400 ----a-w C:\WINDOWS\system32\tsccvid.dll
    2007-03-18 21:49:21 335 ----a-w C:\WINDOWS\nsreg.dat
    2007-03-18 21:49:16 99,024 ----a-w C:\WINDOWS\MozillaUninstall.exe
    2007-03-18 21:49:08 98,512 ----a-w C:\WINDOWS\GREUninstall.exe
    2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
    2007-03-15 13:24:18 36,352 ----a-w C:\Program Files\wc.exe
    2007-03-15 13:22:17 46 ----a-w C:\1837648855668385.bat
    2007-03-15 13:22:15 51,200 ----a-w C:\Program Files\grep.exe
    2007-03-15 13:22:15 442,425 ----a-w C:\WINDOWS\system32\sysnetdrv.exe
    2007-03-15 13:22:15 36,352 ----a-w C:\Program Files\kill.exe
    2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
    2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
    2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
    2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys


    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 20:38]
    {0777FDE1-50AB-4E2F-8DC8-23548E111F93}=C:\WINDOWS\system32\iiffcbx.dll []
    {28232870-A368-4A60-9462-229043EB466A}=C:\WINDOWS\system32\ssqpm.dll []
    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll [2006-05-03 03:14]
    {AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar2.dll [2007-01-20 00:56]
    {CC7E636D-39AA-49b6-B511-65413DA137A1}=C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll [2007-03-01 15:05]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 02:56 C:\WINDOWS\system32\bthprops.cpl]
    "PRONoMgrWired"="C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe" [2003-08-06 16:08]
    "ACTray"="C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe" [2006-01-31 22:19]
    "ACWLIcon"="C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe" [2006-01-31 22:12]
    "SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-12-15 14:19]
    "SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2005-05-06 14:06]
    "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41]
    "TPHOTKEY"="C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2005-12-15 14:00]
    "TPKMAPHELPER"="C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe" [2005-10-28 19:04]
    "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-09-15 13:57]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-09-15 13:57]
    "EZEJMNAP"="C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2005-11-17 02:22]
    "BMMGAG"="C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll" [2005-04-20 01:38]
    "BMMLREF"="C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE" [2005-04-20 01:38]
    "BMMMONWND"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll" [2005-04-20 01:38]
    "BLOG"="C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-04-20 01:38]
    "TpShocks"="TpShocks.exe" [2005-11-07 11:14 C:\WINDOWS\system32\TpShocks.exe]
    "AwaySch"="C:\Program Files\Lenovo\AwayTask\AwaySch.EXE" [2006-04-13 02:05]
    "LPManager"="C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe" [2006-09-05 16:12]
    "VERITAS NetBackup Client Job Tracker"="C:\VERITAS\NetBackup\bin\tracker.exe" [2004-05-11 23:17]
    "OfficeScanNT Monitor"="C:\OfficeScan NT\pccntmon.exe" [2007-01-08 20:20]
    "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 23:48]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00]
    "Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe" [2005-11-30 03:51]
    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2005-05-09 15:00]

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
    "Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "HideStartupScripts"=1 (0x1)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "SetVisualStyle"=

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    @=
    "LinkResolveIgnoreLinkInfo"=1 (0x1)

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
    @=
    "LinkResolveIgnoreLinkInfo"=1 (0x1)

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{0777FDE1-50AB-4E2F-8DC8-23548E111F93}"="C:\WINDOWS\system32\iiffcbx.dll" []

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify]
    ACNotify.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AwayNotify]
    C:\Program Files\Lenovo\AwayTask\AwayNotify.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
    tphklock.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Notification Packages scecli psqlpwd

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\0\0]
    "Script"=mac_addre.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\1\0]
    "Script"=\\ds\SysVol\ds\scripts\dsy\AddLocalAdminForSMS.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\2\0]
    "Script"=\\ds\SysVol\ds\scripts\dsy\CheckSvcsAndGrp.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Startup\3\0]
    "Script"=AddLocalAdmin.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-842925246-2139871995-725345543-10394\Scripts\Logon\0\0]
    "Script"=logonSuresnes.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-842925246-2139871995-725345543-12702\Scripts\Logon\0\0]
    "Script"=logonDSY.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-842925246-2139871995-725345543-12702\Scripts\Logon\1\0]
    "Script"=logonSuresnes.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-842925246-2139871995-725345543-1316\Scripts\Logon\0\0]
    "Script"=logonDSY.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-842925246-2139871995-725345543-1316\Scripts\Logon\1\0]
    "Script"=logonSuresnes.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-842925246-2139871995-725345543-33619\Scripts\Logon\0\0]
    "Script"=logonDSY.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-842925246-2139871995-725345543-33619\Scripts\Logon\1\0]
    "Script"=logonSuresnes.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-842925246-2139871995-725345543-360328\Scripts\Logon\0\0]
    "Script"=logonDSY.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-842925246-2139871995-725345543-360328\Scripts\Logon\1\0]
    "Script"=\\ds\SysVol\ds\scripts\Password_Reset_check.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-842925246-2139871995-725345543-360328\Scripts\Logon\2\0]
    "Script"=logonSuresnes.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-842925246-2139871995-725345543-360328\Scripts\Logon\2\1]
    "Script"=LogScript-SiteDSY.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-842925246-2139871995-725345543-49936\Scripts\Logon\0\0]
    "Script"=logonSuresnes.vbs

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
    backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office OneNote 2003 Quick Launch.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office OneNote 2003 Quick Launch.lnk
    backup=C:\WINDOWS\pss\Microsoft Office OneNote 2003 Quick Launch.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Outil de mise à jour Google.lnk]
    path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Outil de mise à jour Google.lnk
    backup=C:\WINDOWS\pss\Outil de mise à jour Google.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^eqm.DS^Start Menu^Programs^Startup^Adobe Gamma.lnk]
    path=C:\Documents and Settings\eqm.DS\Start Menu\Programs\Startup\Adobe Gamma.lnk
    backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^eqm.DS^Start Menu^Programs^Startup^Lancement rapide de Microsoft Office OneNote 2003.lnk]
    path=C:\Documents and Settings\eqm.DS\Start Menu\Programs\Startup\Lancement rapide de Microsoft Office OneNote 2003.lnk
    backup=C:\WINDOWS\pss\Lancement rapide de Microsoft Office OneNote 2003.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    "C:\Program Files\iTunes\iTunesHelper.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    "C:\Program Files\Messenger\msmsgs.exe" /background

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
    "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    "C:\Program Files\QuickTime\qttask.exe" -atboottime

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SwPrnMon]
    "C:\Program Files\Common Files\Sowedoo Shared\Sowedoo PDF Printer V4\SwPrnMon.exe"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    bthsvcs BthServ

    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*


    Contents of the 'Scheduled Tasks' folder
    2007-06-03 13:03:00 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
    2007-03-19 19:55:00 C:\WINDOWS\tasks\BMMTask.job

    **************************************************************************

    catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-06-06 14:40:55
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001000-0000-1000-8000-00805f9b34fb}]


    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\BTHPORT\Parameters\Services\{00001115-0000-1000-8000-00805f9b34fb}]


    Completion time: 2007-06-06 14:42:54 - machine was rebooted
    C:\ComboFix-quarantined-files.txt ... 2007-06-06 14:42

    --- E O F ---
    a b 8 Sécurité
    6 Juin 2007 15:00:00

    La citation faisait bien partie de la procédure :) 

    Télécharge OTMoveIt (d'OldTimer). Sauvegarde-le sur ton Bureau.
    Sélectionne TOUS les emplacements en gras ci-dessous :

    C:\WINDOWS\system32\jhlgoufo.exe
    C:\WINDOWS\system32\mghsuewu.exe


    ---> Clique-droit puis Copier (ou Ctrl+C)

    Double-clique sur OTMoveIt.exe afin de le lancer.
    Fais un Clique-droit sur le cadre de gauche puis choisis Coller (ou Ctrl+V).
    Clique maintenant sur [#ff0000]MoveIt![/#f]

    [#ff0000]Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
    Accepte en cliquant sur YES.[/#f]

    Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
    Le nom du rapport correspond au moment de sa création : date_heure.log
    6 Juin 2007 16:59:42

    Voilà le rapport d'OTMoveIt, je n'ai pas eu à redemarrer cette fois

    C:\WINDOWS\system32\jhlgoufo.exe moved successfully.
    C:\WINDOWS\system32\mghsuewu.exe moved successfully.

    Created on 06-06-2007 16:58:32
    a b 8 Sécurité
    6 Juin 2007 17:17:15

    Reposte un rapport Hijackthis.
    6 Juin 2007 17:20:44

    et voilà le rapport, à noter que pour l'instant je n'ai plus les popups.

    Logfile of HijackThis v1.99.1
    Scan saved at 17:19, on 2007-06-06
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\ibmpmsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\IPSSVC.EXE
    C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    c:\veritas\bpws\bpws.exe
    C:\WINDOWS\System32\DkLog.exe
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\VERITAS\NETBAC~1\bin\bpinetd.exe
    C:\OfficeScan NT\ntrtscan.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\VERITAS\NETBAC~1\bin\BPJAVA-msvc.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\OfficeScan NT\tmlisten.exe
    C:\WINDOWS\System32\TPHDEXLG.EXE
    C:\WINDOWS\system32\TpKmpSVC.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\PROGRA~1\MI4F93~1\webtool.exe
    C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    C:\WINDOWS\system32\CCM\CcmExec.exe
    C:\WINDOWS\System32\dkcktkn.exe
    C:\OfficeScan NT\OfcPfwSvc.exe
    C:\WINDOWS\TEMP\XH182.EXE
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
    C:\WINDOWS\system32\RunDll32.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\TpShocks.exe
    C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    C:\VERITAS\NetBackup\bin\tracker.exe
    C:\OfficeScan NT\pccntmon.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft Office Communicator\Communicator.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Zone Labs\Integrity Client\iclient.exe
    C:\Program Files\OpenSTA\Server\DaemonCFG.exe
    C:\PROGRA~1\OpenSTA\Server\OmniOrb\OMNINA~1.EXE
    C:\PROGRA~1\OpenSTA\Server\archmgrdmn.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\IBM\NotesBuddy\NotesBuddy.exe
    C:\notes\nminder.exe
    C:\notes\NLNOTES.EXE
    C:\notes\ntaskldr.EXE
    C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\eqm.DS\Desktop\scanner.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsinteraction
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dsinteraction
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://instms/connect.vbs
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.0.40.46;10.0.40.45;128.3.14.90:8003;*.eno.ds;*.enovia-clt.com;*.dsag.com;*.deneb.com;*.dskk;heino2e:8004;*.ds;*.dsy.ds;*.dassault-systemes.fr;cpds.ds;*.abaqus.com;mobility.3ds.com;192.168.15.5;*.dds.ds;*.dassault-data-services.fr;thezone.matrixone.net;<local>
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {0777FDE1-50AB-4E2F-8DC8-23548E111F93} - C:\WINDOWS\system32\iiffcbx.dll (file missing)
    O2 - BHO: (no name) - {28232870-A368-4A60-9462-229043EB466A} - C:\WINDOWS\system32\ssqpm.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: (no name) - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)
    O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O3 - Toolbar: Zend Studio - {95188727-288F-4581-A48D-EAB3BD027314} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
    O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
    O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
    O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
    O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    O4 - HKLM\..\Run: [VERITAS NetBackup Client Job Tracker] C:\VERITAS\NetBackup\bin\tracker.exe
    O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: IBM NotesBuddy for Notes.lnk = C:\Program Files\IBM\NotesBuddy\NotesBuddy.exe
    O4 - Global Startup: Integrity Client.lnk = C:\Program Files\Zone Labs\Integrity Client\iclient.exe
    O4 - Global Startup: OpenSTA NameServer.lnk = ?
    O8 - Extra context menu item: Add Person to NotesBuddy... - C:\Program Files\IBM\NotesBuddy\AddPersonN.html
    O8 - Extra context menu item: Add Picture to NotesBuddy... - C:\Program Files\IBM\NotesBuddy\AddImageN.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Zend Studio - Debug current page - res://C:\Program Files\Zend\ZendStudio-5.5.0\bin\ZendIEToolbar.dll/DebugCurrent.html
    O8 - Extra context menu item: Zend Studio - Debug next page - res://C:\Program Files\Zend\ZendStudio-5.5.0\bin\ZendIEToolbar.dll/DebugNext.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Zend Studio Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O9 - Extra 'Tools' menuitem: Zend Studio - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://dsinteraction
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\Software\..\Telephony: DomainName = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3704A196-9C31-4368-8E3F-3C5C062DA803}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4D5B7F6B-7B8F-4AEB-8FFA-65181EF3B562}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DDE74ACD-B062-46F5-BCF1-91D7454B0B15}: Domain = dsy.ds
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O17 - HKLM\System\CS1\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O17 - HKLM\System\CS2\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
    O20 - Winlogon Notify: AwayNotify - C:\Program Files\Lenovo\AwayTask\AwayNotify.dll
    O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
    O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: NetBackup Warning Service (BpPortable) - Dassault-Systemes - c:\veritas\bpws\bpws.exe
    O23 - Service: ccmsetup - Unknown owner - C:\WINDOWS\system32\ccmsetup\Ccmsetup.exe" /runservice /source:"\\ds\SysVol\ds\scripts\dsy" SMSSITECODE=DSY SMSCACHESIZE=500 (file missing)
    O23 - Service: Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
    O23 - Service: Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: IBM Nodelock License Server (IBM LUM NDL) - IBM - C:\IFOR\WIN\BIN\I4LLMD.EXE
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
    O23 - Service: NetBackup Client Service (NetBackup INET Daemon) - VERITAS Software Corporation - C:\VERITAS\NETBAC~1\bin\bpinetd.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
    O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\OfficeScan NT\OfcPfwSvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe
    O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe" //RS//Tomcat5 (file missing)
    O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
    O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    a b 8 Sécurité
    6 Juin 2007 17:28:05

    Re,

    Télécharge puis installe AVG Anti-Spyware (AVG AS)
    Fais les mises à jour mais ne lance pas de scan pour le moment.
    AIDE : Tuto sur AVG Anti-Spyware (Malekal)

    Redémarre en mode sans échec

    Relance AVG AS :
    - Choisis l'onglet "Analyse"
    - Puis l'onglet "Paramètres"
    - Sous la question "Comment réagir ?", clique sur "Actions recommandées" et choisis "Quarantaine"
    - Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"

    [#ff0000]Si un fichier est infecté en fin d'analyse, clique sur "Appliquer toutes les actions"[/#f]

    Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous"
    Enregistre ce fichier texte sur ton bureau.

    Redémarre normalement.
    Poste le rapport AVG AS ainsi qu'un rapport Hijackthis.
    7 Juin 2007 09:42:11

    Le rapport avast:

    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 09:40:53 07/06/2007

    + Scan result:



    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} -> Adware.RogueSuspect : Cleaned with backup (quarantined).
    HKU\S-1-5-21-842925246-2139871995-725345543-360328\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} -> Adware.RogueSuspect : Cleaned with backup (quarantined).
    C:\Documents and Settings\eqm.DS\Desktop\backups\backup-20070605-221214-800.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{4CABC292-AD7B-4B5A-8ADD-46396889D90E}\RP116\A0028109.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{4CABC292-AD7B-4B5A-8ADD-46396889D90E}\RP116\A0028111.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{4CABC292-AD7B-4B5A-8ADD-46396889D90E}\RP116\A0028160.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
    C:\VundoFix Backups\iiffcbx.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined).
    C:\VundoFix Backups\khfdefd.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined).
    C:\VundoFix Backups\vturspp.dll.bad -> Adware.Virtumonde : Cleaned with backup (quarantined).
    C:\Documents and Settings\eqm.DS\Cookies\eqm@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@fnac.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@karavel.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@lucent.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@msnaccountservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@opodo.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@2.adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@ads.adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@rotator.adjuggler[2].txt -> TrackingCookie.Adjuggler : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@www.adobe[2].txt -> TrackingCookie.Adobe : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.133:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    :mozilla.134:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
    C:\Documents and Settings\eqm.DS\Desktop\eqm sur plate2\Cookies\eqm@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@adviva[2].txt -> TrackingCookie.Adviva : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@iv2.bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
    :mozilla.159:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
    :mozilla.160:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
    C:\Documents and Settings\eqm.DS\Desktop\eqm sur plate2\Cookies\eqm@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
    :mozilla.214:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
    C:\Documents and Settings\eqm.DS\Desktop\eqm sur plate2\Cookies\eqm@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@ads.cnn[1].txt -> TrackingCookie.Cnn : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@com[1].txt -> TrackingCookie.Com : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@fl01.ct2.comclick[2].txt -> TrackingCookie.Comclick : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
    :mozilla.72:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\eqm.DS\Desktop\eqm sur plate2\Cookies\eqm@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
    :mozilla.135:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@estat[1].txt -> TrackingCookie.Estat : Cleaned.
    :mozilla.199:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
    C:\Documents and Settings\eqm.DS\Desktop\eqm sur plate2\Cookies\eqm@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
    :mozilla.170:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.215:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@ehg-hollywood.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@ehg-legonewyorkinc.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@ehg-oreilly.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@ehg-techtarget.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@ehg-youtube.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\eqm.DS\Desktop\eqm sur plate2\Cookies\eqm@ehg-techtarget.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\eqm.DS\Desktop\eqm sur plate2\Cookies\eqm@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.254:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@counter.hitslink[1].txt -> TrackingCookie.Hitslink : Cleaned.
    C:\Documents and Settings\eqm.DS\Desktop\eqm sur plate2\Cookies\eqm@counter.hitslink[1].txt -> TrackingCookie.Hitslink : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@hotlog[2].txt -> TrackingCookie.Hotlog : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@searchportal.information[1].txt -> TrackingCookie.Information : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@ie.search.msn[1].txt -> TrackingCookie.Msn : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Cleaned.
    :mozilla.195:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
    :mozilla.196:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@stat.onestat[2].txt -> TrackingCookie.Onestat : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@overture[1].txt -> TrackingCookie.Overture : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@www.paypal[1].txt -> TrackingCookie.Paypal : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@realmedia[2].txt -> TrackingCookie.Realmedia : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@revsci[1].txt -> TrackingCookie.Revsci : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@site.skype[1].txt -> TrackingCookie.Skype : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@skype[1].txt -> TrackingCookie.Skype : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@support.skype[1].txt -> TrackingCookie.Skype : Cleaned.
    :mozilla.139:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
    :mozilla.140:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
    :mozilla.141:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@smartadserver[1].txt -> TrackingCookie.Smartadserver : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Cleaned.
    :mozilla.45:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
    :mozilla.46:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
    :mozilla.47:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
    :mozilla.48:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@h.starware[1].txt -> TrackingCookie.Starware : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@try.starware[1].txt -> TrackingCookie.Starware : Cleaned.
    :mozilla.80:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.81:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.82:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.83:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.84:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.85:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
    C:\Documents and Settings\eqm.DS\Desktop\eqm sur plate2\Cookies\eqm@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.162:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.165:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.166:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned.
    :mozilla.185:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
    C:\Documents and Settings\eqm.DS\Desktop\eqm sur plate2\Cookies\eqm@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@trafic[1].txt -> TrackingCookie.Trafic : Cleaned.
    :mozilla.143:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
    C:\Documents and Settings\eqm.DS\Desktop\eqm sur plate2\Cookies\eqm@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
    :mozilla.102:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@weborama[2].txt -> TrackingCookie.Weborama : Cleaned.
    C:\Documents and Settings\eqm.DS\Desktop\eqm sur plate2\Cookies\eqm@weborama[1].txt -> TrackingCookie.Weborama : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@m.webtrends[1].txt -> TrackingCookie.Webtrends : Cleaned.
    :mozilla.230:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned.
    C:\Documents and Settings\eqm.DS\Desktop\eqm sur plate2\Cookies\eqm@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned.
    :mozilla.157:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
    :mozilla.158:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@yadro[1].txt -> TrackingCookie.Yadro : Cleaned.
    :mozilla.69:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.70:C:\Documents and Settings\eqm.DS\Application Data\Mozilla\Firefox\Profiles\n0ohdeqm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
    C:\Documents and Settings\eqm.DS\Cookies\eqm@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\jhlgoufo.exe -> Trojan.Agent.anr : Cleaned with backup (quarantined).
    C:\_OTMoveIt\MovedFiles\WINDOWS\system32\mghsuewu.exe -> Trojan.Agent.anr : Cleaned with backup (quarantined).


    ::Report end
    7 Juin 2007 09:42:41

    Et le log Hijackthis

    Logfile of HijackThis v1.99.1
    Scan saved at 09:42:23, on 07/06/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\ibmpmsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\IPSSVC.EXE
    C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    c:\veritas\bpws\bpws.exe
    C:\WINDOWS\System32\DkLog.exe
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\VERITAS\NETBAC~1\bin\bpinetd.exe
    C:\OfficeScan NT\ntrtscan.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\VERITAS\NETBAC~1\bin\BPJAVA-msvc.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\OfficeScan NT\tmlisten.exe
    C:\WINDOWS\System32\TPHDEXLG.EXE
    C:\WINDOWS\system32\TpKmpSVC.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\PROGRA~1\MI4F93~1\webtool.exe
    C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
    C:\WINDOWS\System32\dkcktkn.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    C:\WINDOWS\system32\CCM\CcmExec.exe
    C:\OfficeScan NT\OfcPfwSvc.exe
    C:\WINDOWS\TEMP\EC4CF3.EXE
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    C:\WINDOWS\system32\RunDll32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\TpShocks.exe
    C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
    C:\VERITAS\NetBackup\bin\tracker.exe
    C:\OfficeScan NT\pccntmon.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft Office Communicator\Communicator.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\IBM\NotesBuddy\NotesBuddy.exe
    C:\Program Files\Zone Labs\Integrity Client\iclient.exe
    C:\Program Files\OpenSTA\Server\DaemonCFG.exe
    C:\PROGRA~1\OpenSTA\Server\OmniOrb\OMNINA~1.EXE
    C:\PROGRA~1\OpenSTA\Server\archmgrdmn.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\notes\nminder.exe
    C:\notes\nNOTESMM.EXE
    C:\notes\NLNOTES.EXE
    C:\notes\ntaskldr.EXE
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\eqm.DS\Desktop\scanner.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsinteraction/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dsinteraction
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://instms/connect.vbs
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 10.0.40.46;10.0.40.45;128.3.14.90:8003;*.eno.ds;*.enovia-clt.com;*.dsag.com;*.deneb.com;*.dskk;heino2e:8004;*.ds;*.dsy.ds;*.dassault-systemes.fr;cpds.ds;*.abaqus.com;mobility.3ds.com;192.168.15.5;*.dds.ds;*.dassault-data-services.fr;thezone.matrixone.net;<local>
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {0777FDE1-50AB-4E2F-8DC8-23548E111F93} - C:\WINDOWS\system32\iiffcbx.dll (file missing)
    O2 - BHO: (no name) - {28232870-A368-4A60-9462-229043EB466A} - C:\WINDOWS\system32\ssqpm.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O3 - Toolbar: Zend Studio - {95188727-288F-4581-A48D-EAB3BD027314} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
    O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
    O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
    O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
    O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    O4 - HKLM\..\Run: [VERITAS NetBackup Client Job Tracker] C:\VERITAS\NetBackup\bin\tracker.exe
    O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: IBM NotesBuddy for Notes.lnk = C:\Program Files\IBM\NotesBuddy\NotesBuddy.exe
    O4 - Global Startup: Integrity Client.lnk = C:\Program Files\Zone Labs\Integrity Client\iclient.exe
    O4 - Global Startup: OpenSTA NameServer.lnk = ?
    O8 - Extra context menu item: Add Person to NotesBuddy... - C:\Program Files\IBM\NotesBuddy\AddPersonN.html
    O8 - Extra context menu item: Add Picture to NotesBuddy... - C:\Program Files\IBM\NotesBuddy\AddImageN.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Zend Studio - Debug current page - res://C:\Program Files\Zend\ZendStudio-5.5.0\bin\ZendIEToolbar.dll/DebugCurrent.html
    O8 - Extra context menu item: Zend Studio - Debug next page - res://C:\Program Files\Zend\ZendStudio-5.5.0\bin\ZendIEToolbar.dll/DebugNext.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Zend Studio Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O9 - Extra 'Tools' menuitem: Zend Studio - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://dsinteraction
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\Software\..\Telephony: DomainName = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3704A196-9C31-4368-8E3F-3C5C062DA803}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4D5B7F6B-7B8F-4AEB-8FFA-65181EF3B562}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DDE74ACD-B062-46F5-BCF1-91D7454B0B15}: Domain = dsy.ds
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O17 - HKLM\System\CS1\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O17 - HKLM\System\CS2\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
    O20 - Winlogon Notify: AwayNotify - C:\Program Files\Lenovo\AwayTask\AwayNotify.dll
    O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
    O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: NetBackup Warning Service (BpPortable) - Dassault-Systemes - c:\veritas\bpws\bpws.exe
    O23 - Service: ccmsetup - Unknown owner - C:\WINDOWS\system32\ccmsetup\Ccmsetup.exe" /runservice /source:"\\ds\SysVol\ds\scripts\dsy" SMSSITECODE=DSY SMSCACHESIZE=500 (file missing)
    O23 - Service: Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
    O23 - Service: Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: IBM Nodelock License Server (IBM LUM NDL) - IBM - C:\IFOR\WIN\BIN\I4LLMD.EXE
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
    O23 - Service: NetBackup Client Service (NetBackup INET Daemon) - VERITAS Software Corporation - C:\VERITAS\NETBAC~1\bin\bpinetd.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
    O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\OfficeScan NT\OfcPfwSvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe
    O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe" //RS//Tomcat5 (file missing)
    O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
    O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    a b 8 Sécurité
    7 Juin 2007 13:13:10

    Re,

    Télécharge Clean.zip (de Malekal),
    Décompresse-le sur ton bureau (Clique-Droit/Extraire tout), tu dois obtenir un dossier Clean.
    Ouvre le dossier clean, double-clique sur clean.cmd.
    Choisis l'option 1 puis patiente. Poste ensuite le contenu du rapport.
    7 Juin 2007 13:36:51

    Voilà le rapport de Clean

    07/06/2007 a 13:35:59,17

    *** Recherche C:

    *** Recherche C:\WINDOWS\

    *** Recherche C:\WINDOWS\system32
    C:\WINDOWS\system32\mcrh.tmp FOUND
    C:\WINDOWS\system32\tphklock.dll FOUND

    *** Recherche C:\Program Files
    *** End of the report !
    a b 8 Sécurité
    7 Juin 2007 13:55:45

    Re,

    Redémarre en mode sans échec

    Ouvre le dossier clean, double-clique sur clean.cmd.
    Choisis l'option 2 puis patiente.

    Redémarre normalement.

    Poste le rapport clean : C:\rapport_clean.txt
    7 Juin 2007 20:02:09

    Re,

    Je te fais une confiance aveugle mais j'avoue que le rapport de clean est flippant surtout au moment "suppression C:" :wahoo: 

    Script executed in Safe Mode
    Rapport clean par Malekal_morte - http://www.malekal.com
    Script executed in Safe Mode Thu 06/07/2007 a 19:52:16.26

    Microsoft Windows XP [Version 5.1.2600]

    *** Suppression C:

    *** Suppression C:\WINDOWS\

    *** Suppression C:\WINDOWS\system32
    tentative de suppression de C:\WINDOWS\system32\mcrh.tmp
    tentative de suppression de C:\WINDOWS\system32\tphklock.dll
    Impossible de supprimer C:\WINDOWS\system32\tphklock.dll

    *** Suppression C:\Program Files

    *** Deletion of the registry keys successful..
    *** End of the report !
    7 Juin 2007 20:03:24

    Et un HijackThis !

    Logfile of HijackThis v1.99.1
    Scan saved at 20:02:38, on 07/06/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\ibmpmsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\IPSSVC.EXE
    C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    c:\veritas\bpws\bpws.exe
    C:\WINDOWS\system32\ccmsetup\Ccmsetup.exe
    C:\WINDOWS\System32\DkLog.exe
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\VERITAS\NETBAC~1\bin\bpinetd.exe
    C:\OfficeScan NT\ntrtscan.exe
    C:\VERITAS\NETBAC~1\bin\BPJAVA-msvc.EXE
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\OfficeScan NT\tmlisten.exe
    C:\WINDOWS\System32\TPHDEXLG.EXE
    C:\WINDOWS\system32\TpKmpSVC.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\PROGRA~1\MI4F93~1\webtool.exe
    C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    C:\WINDOWS\system32\CCM\CcmExec.exe
    C:\WINDOWS\System32\dkcktkn.exe
    C:\OfficeScan NT\OfcPfwSvc.exe
    C:\WINDOWS\TEMP\MS3769.EXE
    C:\WINDOWS\system32\msiexec.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    C:\WINDOWS\system32\RunDll32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\TpShocks.exe
    C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    C:\VERITAS\NetBackup\bin\tracker.exe
    C:\OfficeScan NT\pccntmon.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft Office Communicator\Communicator.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\IBM\NotesBuddy\NotesBuddy.exe
    C:\Program Files\Zone Labs\Integrity Client\iclient.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\eqm.DS\Desktop\scanner.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsinteraction
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dsinteraction
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://instms/connect.vbs
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {0777FDE1-50AB-4E2F-8DC8-23548E111F93} - C:\WINDOWS\system32\iiffcbx.dll (file missing)
    O2 - BHO: (no name) - {28232870-A368-4A60-9462-229043EB466A} - C:\WINDOWS\system32\ssqpm.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O3 - Toolbar: Zend Studio - {95188727-288F-4581-A48D-EAB3BD027314} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
    O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
    O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
    O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
    O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    O4 - HKLM\..\Run: [VERITAS NetBackup Client Job Tracker] C:\VERITAS\NetBackup\bin\tracker.exe
    O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: IBM NotesBuddy for Notes.lnk = C:\Program Files\IBM\NotesBuddy\NotesBuddy.exe
    O4 - Global Startup: Integrity Client.lnk = C:\Program Files\Zone Labs\Integrity Client\iclient.exe
    O8 - Extra context menu item: Add Person to NotesBuddy... - C:\Program Files\IBM\NotesBuddy\AddPersonN.html
    O8 - Extra context menu item: Add Picture to NotesBuddy... - C:\Program Files\IBM\NotesBuddy\AddImageN.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Zend Studio - Debug current page - res://C:\Program Files\Zend\ZendStudio-5.5.0\bin\ZendIEToolbar.dll/DebugCurrent.html
    O8 - Extra context menu item: Zend Studio - Debug next page - res://C:\Program Files\Zend\ZendStudio-5.5.0\bin\ZendIEToolbar.dll/DebugNext.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Zend Studio Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O9 - Extra 'Tools' menuitem: Zend Studio - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://dsinteraction
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\Software\..\Telephony: DomainName = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3704A196-9C31-4368-8E3F-3C5C062DA803}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4D5B7F6B-7B8F-4AEB-8FFA-65181EF3B562}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DDE74ACD-B062-46F5-BCF1-91D7454B0B15}: Domain = dsy.ds
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O17 - HKLM\System\CS1\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O17 - HKLM\System\CS2\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
    O20 - Winlogon Notify: AwayNotify - C:\Program Files\Lenovo\AwayTask\AwayNotify.dll
    O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
    O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: NetBackup Warning Service (BpPortable) - Dassault-Systemes - c:\veritas\bpws\bpws.exe
    O23 - Service: ccmsetup - Unknown owner - C:\WINDOWS\system32\ccmsetup\Ccmsetup.exe" /runservice /source:"\\ds\SysVol\ds\scripts\dsy" SMSSITECODE=DSY SMSCACHESIZE=500 (file missing)
    O23 - Service: Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
    O23 - Service: Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: IBM Nodelock License Server (IBM LUM NDL) - IBM - C:\IFOR\WIN\BIN\I4LLMD.EXE
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
    O23 - Service: NetBackup Client Service (NetBackup INET Daemon) - VERITAS Software Corporation - C:\VERITAS\NETBAC~1\bin\bpinetd.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
    O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\OfficeScan NT\OfcPfwSvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe
    O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe" //RS//Tomcat5 (file missing)
    O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
    O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    a b 8 Sécurité
    7 Juin 2007 20:31:07

    Re,

    - Lance Hijackthis ->Do a system scan only
    ->Coche les lignes ci-dessous :

    O2 - BHO: (no name) - {0777FDE1-50AB-4E2F-8DC8-23548E111F93} - C:\WINDOWS\system32\iiffcbx.dll (file missing)
    O2 - BHO: (no name) - {28232870-A368-4A60-9462-229043EB466A} - C:\WINDOWS\system32\ssqpm.dll (file missing)

    Clique sur Fix checked (en bas à gauche)
    7 Juin 2007 20:36:00

    Voilà j'ai fixé, un dernier rapport HijackThis

    Logfile of HijackThis v1.99.1
    Scan saved at 20:34:10, on 07/06/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\ibmpmsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\IPSSVC.EXE
    C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    c:\veritas\bpws\bpws.exe
    C:\WINDOWS\system32\ccmsetup\Ccmsetup.exe
    C:\WINDOWS\System32\DkLog.exe
    C:\WINDOWS\system32\inetsrv\inetinfo.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\VERITAS\NETBAC~1\bin\bpinetd.exe
    C:\OfficeScan NT\ntrtscan.exe
    C:\VERITAS\NETBAC~1\bin\BPJAVA-msvc.EXE
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\OfficeScan NT\tmlisten.exe
    C:\WINDOWS\System32\TPHDEXLG.EXE
    C:\WINDOWS\system32\TpKmpSVC.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\PROGRA~1\MI4F93~1\webtool.exe
    C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
    C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    C:\WINDOWS\system32\CCM\CcmExec.exe
    C:\WINDOWS\System32\dkcktkn.exe
    C:\OfficeScan NT\OfcPfwSvc.exe
    C:\WINDOWS\TEMP\MS3769.EXE
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    C:\WINDOWS\system32\RunDll32.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\TpShocks.exe
    C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    C:\VERITAS\NetBackup\bin\tracker.exe
    C:\OfficeScan NT\pccntmon.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft Office Communicator\Communicator.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\IBM\NotesBuddy\NotesBuddy.exe
    C:\Program Files\Zone Labs\Integrity Client\iclient.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\WINDOWS\system32\notepad.exe
    C:\Documents and Settings\eqm.DS\Desktop\scanner.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsinteraction
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dsinteraction
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://instms/connect.vbs
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy:8080
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: IE Developer Toolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O3 - Toolbar: Zend Studio - {95188727-288F-4581-A48D-EAB3BD027314} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
    O4 - HKLM\..\Run: [ACTray] C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
    O4 - HKLM\..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
    O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
    O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
    O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
    O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
    O4 - HKLM\..\Run: [BLOG] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
    O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
    O4 - HKLM\..\Run: [AwaySch] C:\Program Files\Lenovo\AwayTask\AwaySch.EXE
    O4 - HKLM\..\Run: [LPManager] C:\PROGRA~1\THINKV~2\PrdCtr\LPMGR.exe
    O4 - HKLM\..\Run: [VERITAS NetBackup Client Job Tracker] C:\VERITAS\NetBackup\bin\tracker.exe
    O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: IBM NotesBuddy for Notes.lnk = C:\Program Files\IBM\NotesBuddy\NotesBuddy.exe
    O4 - Global Startup: Integrity Client.lnk = C:\Program Files\Zone Labs\Integrity Client\iclient.exe
    O8 - Extra context menu item: Add Person to NotesBuddy... - C:\Program Files\IBM\NotesBuddy\AddPersonN.html
    O8 - Extra context menu item: Add Picture to NotesBuddy... - C:\Program Files\IBM\NotesBuddy\AddImageN.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Zend Studio - Debug current page - res://C:\Program Files\Zend\ZendStudio-5.5.0\bin\ZendIEToolbar.dll/DebugCurrent.html
    O8 - Extra context menu item: Zend Studio - Debug next page - res://C:\Program Files\Zend\ZendStudio-5.5.0\bin\ZendIEToolbar.dll/DebugNext.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
    O9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Zend Studio Toolbar - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O9 - Extra 'Tools' menuitem: Zend Studio - {A26ABCF0-1C8F-46e7-A67C-0489DC21B9CC} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
    O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://dsinteraction
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\Software\..\Telephony: DomainName = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{3704A196-9C31-4368-8E3F-3C5C062DA803}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{4D5B7F6B-7B8F-4AEB-8FFA-65181EF3B562}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\..\{DDE74ACD-B062-46F5-BCF1-91D7454B0B15}: Domain = dsy.ds
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O17 - HKLM\System\CS1\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = dsy.ds
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O17 - HKLM\System\CS2\Services\Tcpip\..\{08223B36-7720-4554-A4D3-8005833EB3E9}: Domain = dsy.ds
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = dsy.ds,dsee.ds,ds,dassault-systemes.fr,abaqus.com
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: ACNotify - ACNotify.dll (file missing)
    O20 - Winlogon Notify: AwayNotify - C:\Program Files\Lenovo\AwayTask\AwayNotify.dll
    O20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll
    O23 - Service: Ac Profile Manager Service (AcPrfMgrSvc) - Unknown owner - C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
    O23 - Service: Access Connections Main Service (AcSvc) - Lenovo - C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: NetBackup Warning Service (BpPortable) - Dassault-Systemes - c:\veritas\bpws\bpws.exe
    O23 - Service: ccmsetup - Unknown owner - C:\WINDOWS\system32\ccmsetup\Ccmsetup.exe" /runservice /source:"\\ds\SysVol\ds\scripts\dsy" SMSSITECODE=DSY SMSCACHESIZE=500 (file missing)
    O23 - Service: Datakey's Log Service (DkLogger) - Datakey, Inc. - C:\WINDOWS\System32\DkLog.exe
    O23 - Service: Datakey's Token Service (DkTknSrv) - Datakey, Inc. - C:\WINDOWS\System32\dkcktkn.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: IBM Nodelock License Server (IBM LUM NDL) - IBM - C:\IFOR\WIN\BIN\I4LLMD.EXE
    O23 - Service: ThinkPad PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IPS Core Service (IPSSVC) - Lenovo Group Limited - C:\WINDOWS\system32\IPSSVC.EXE
    O23 - Service: NetBackup Client Service (NetBackup INET Daemon) - VERITAS Software Corporation - C:\VERITAS\NETBAC~1\bin\bpinetd.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
    O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\OfficeScan NT\OfcPfwSvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe
    O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe" //RS//Tomcat5 (file missing)
    O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
    O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    a b 8 Sécurité
    7 Juin 2007 20:36:28

    Tu as toujours des problèmes ?
    7 Juin 2007 20:46:55

    Non je n'ai plus de problèmes, je n'ai eu aucune popup aujourd'hui. Et même je trouve mon pc plus rapide :-)

    Je n'ai plus de cleaner à lancer cette fois ?

    Sinon merci beaucoup pour le temps que tu passes à aider des inconnus !
    7 Juin 2007 20:49:05

    Ah oui j'ai encore une question... est-ce qu'il y a un risque que toutes les données qui concernent mon pc restent dans ce forum et soit utilisées par des personnes malintentionnées ?
    a b 8 Sécurité
    7 Juin 2007 20:55:54

    Citation :
    Ah oui j'ai encore une question... est-ce qu'il y a un risque que toutes les données qui concernent mon pc restent dans ce forum et soit utilisées par des personnes malintentionnées ?

    No.

    Je pense qu'on a terminé.
    7 Juin 2007 20:58:49

    Merci Angeldark, je marque la discussion comme résolue :) 
    a b 8 Sécurité
    7 Juin 2007 21:04:23

    Bon surf !
    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS