Droit,
une fois en mode sans échec je courais hijectthis et le journal est comme suit
Logfile de HijackThis v1.98.2
Scan sauvé à 14:52:17, le 12.09.2004
Plate-forme: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost. exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ Explorer.EXE
C: \ WINDOWS \ System32 \ taskmgr.exe
C: \ Documents and Settings \ virus \ HijackThis. exe
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Bar =
http://uk.red.clientapps.yahoo.com/cust ... _side.htmlR1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Page =
http://uk.red.clientapps.yahoo.com/cust ... yahoo.com/R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page =
http://www.meshcomputers.comR1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL =
http://uk.red.clientapps.yahoo.com/cust ... yahoo.com/R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Bar =
http://uk.red.clientapps.yahoo.com/cust ... _side.htmlR1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page =
http://uk.red.clientapps.yahoo.com/cust ... yahoo.com/R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Window Title = Tiscali Accès Internet
O2 - BHO: Yahoo! Companion BHO - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C: \ Program Files \ Yahoo! \ Common \ ycomp5_2_3_0.dll
O2 - BHO: AcroIEHlprObj Class - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 6.0 \ Reader \ ActiveX \ AcroIEHelper. dll
O2 - BHO: (no name) - (53707962-6F74-2D53-2644-206D7942484F) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper.dll
O2 - BHO: (no name) - (549B5CA7-4A86-11D7-A4DF-000874180BB3) - (no file)
O2 - BHO: (no name) - (FDD3B846-8D59-4ffb-8758-209B6AD74ACC) - (no file)
O3 - Toolbar: BT Yahoo! Companion - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Program Files \ Yahoo! \ Common \ ycomp5_2_3_0. dll
O3 - Toolbar: & Radio - (8E718888-423F-11D2-876E-00A0C9082467) - C: \ WINDOWS \ System32 \ msdxm.ocx
O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Fichiers communs \ Real \ Update_OB \ realsched.exe"-osboot
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] C: \ Program Files \ Java \ j2re1.4.2_01 \ bin \ jusched.exe
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime
O4 - HKLM \ .. \ Run: [Ptipbmf] rundll32.exe ptipbmf. dll, SetWriteCacheMode
O4 - HKLM \ .. \ Run: [CARPService] carpserv.exe
O4 - HKLM \ .. \ Run: [PinnacleDriverCheck] C: \ WINDOWS \ System32 \ PSDrvCheck.exe
O4 - HKLM \ .. \ Run: [Microsoft Works Update Detection] C: \ Program Files \ Fichiers communs \ Microsoft Shared \ Works Shared \ WKUfind.exe
O4 - HKLM \ .. \ Run: [avserve2.exe] C: \ WINDOWS \ avserve2.exe
O4 - HKLM \ .. \ Run: [D4F181E3] C: \ WINDOWS \ System32 \ tvvothbzu.exe
O4 - HKLM \ .. \ Run: [Microsoft Update] wssvrs.exe
O4 - HKLM \ .. \ Run: [Cryptographic Service] C: \ WINDOWS \ System32 \ wpras.exe
O4 - HKLM \ .. \ Run: [Microsoft Restore] scrgrd.exe
O4 - HKLM \ .. \ Run: [restrictanonymous]
O4 - HKLM \ .. \ Run: [[Ephemeral 2.5] par TreeHugger,] C: \ DOCUME ~ 1 \ ROBERT ~ 1 \ LOCALS ~ 1 \ Temp \ 7.tmp.exe
O4 - HKLM \ .. \ Run: [Outlook Express Config] bbkzh.exe
O4 - HKLM \ .. \ Run: [Outlook Express] znoov.exe
O4 - HKLM \ .. \ Run: [System Update] C: \ WINDOWS \ System32 \ urslwne.exe
O4 - HKLM \ .. \ Run: [blah service] smnp. exe
O4 - HKLM \ .. \ Run: [AVG7_CC] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgcc.exe / STARTUP
O4 - HKLM \ .. \ Run: [AVG7_EMC] C: \ PROGRA ~ 1 \ Grisoft \ AVG7 \ avgemc.exe
O4 - HKLM \ .. \ Run: [SpyHunter] C: \ Program Files \ Enigma Software Group \ SpyHunter \ SpyHunter.exe
O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ WINDOWS \ System32 \ NvCpl.dll, NvStartup
O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / install
O4 - HKLM \ .. \ RunServices: [Microsoft Update] wssvrs.exe
O4 - HKLM \ .. \ RunServices: [4212CFD1] C: \ WINDOWS \ System32 \ tvvothbzu.exe
O4 - HKLM \ .. \ RunServices: [Microsoft Restore] scrgrd.exe
O4 - HKLM \ .. \ RunServices: [EnableDCOM] N
O4 - HKLM \ .. \ RunServices: [MSN Messenger] jdkmety.exe
O4 - HKLM \ .. \ RunServices: [Outlook Express Config] bbkzh.exe
O4 - HKLM \ .. \ RunServices: [Outlook Express] znoov.exe
O4 - HKLM \ .. \ RunServices: [blah service] smnp.exe
O4 - HKCU \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ System32 \ ctfmon.exe
O4 - HKCU \ .. \ Run: [InstantTray] C: \ Program Files \ Pinnacle \ Shared Files \ InstantCDDVD \ PCLETray.exe
O4 - HKCU \ .. \ Run: [IW_Drop_Icon] C: \ Program Files \ Pinnacle \ InstantCDDVD \ InstantWrite \ iwctrl.exe / DropDisc
O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office \ OSA9.exe
O4 - Global Startup: Service Manager.lnk = C: \ Program Files \ Microsoft SQL Server \ 80 \ Tools \ Binn \ sqlmangr.exe
O9 - Extra button: BT Yahoo! Sidebar - (51085E3D-A958-42A2-A6BE-A6A9B0BAF276) - C: \ Program Files \ Yahoo! \ Browser \ ysidebarIE.dll
O9 - Extra "Outils" menuitem: BT & Yahoo! Sidebar - (51085E3D-A958-42A2-A6BE-A6A9B0BAF276) - C: \ Program Files \ Yahoo! \ Browser \ ysidebarIE.dll
O9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ MSMSGS. EXE
O9 - Extra "Outils" menuitem: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O16 - DPF: (315D1BD2-0165-48AE-9F91-9CC271704FBA) (LRNPrint Class) --
file://E : \ Webfiles \ LRN Viewer \ HTML \ lrniehlp. cabine
O16 - DPF: (EF791A6B-FC12-4C68-99EF-FB9E207A39E6) (McFreeScan Class) --
http://download.mcafee.com/molbin/iss-l ... cfscan.cabO18 - Protocol: ms-help - (314111C7-A502-11D2-BBCA-00C04F8EC294) - C: \ Program Files \ Fichiers communs \ Microsoft Shared \ Help \ hxds.dll
Toutes les idées seront très appréciés
merci