Bonjour Lyonnais92 j'ai fait tout les manip ds l'ordre et je pense que les spyware ont ete suprimes
car j'ai plus de message d'infection.
mais au demarrage de windows je recoit com message d'erreur:
le ficjier winsys16_061230.dll est introuvable
voici le rapport de DESS:
Deckard's System Scanner v20071014.68
Run by Admin on 2008-02-19 10:48:22
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-02-19 09:48:30 UTC - RP1 - Point de vérification système
Backed up registry hives.
Performed disk cleanup.
[color=red]Total Physical Memory: 256 MiB (512 MiB recommended)./color
-- HijackThis (run as Admin.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:50:41, on 19/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Topro\tppoll.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\Admin\Bureau\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Admin.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\iexplore.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_061230.dll start
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKLM\..\Run: [SpeedOptimizer] "C:\Program Files\SpeedOptimizer\SPO.exe"
O4 - HKLM\..\Run: [tppoll] C:\Program Files\Topro\tppoll.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [EC21] C:\Documents and Settings\Admin\Bureau\Program Files\EC21Messenger\EZQ.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [xydzyh] C:\WINDOWS\system32\xydzyh.exe
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Indexing Helps (Indexingbox) - Unknown owner - C:\WINDOWS\system\svchest.exe
O23 - Service: OESH (Office Source Engine Help) - Unknown owner - C:\Program.exe (file missing)
End of file - 5243 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
S0 BTHidMgr (Bluetooth HID Manager Service) - c:\windows\system32\drivers\bthidmgr.sys (file missing)
S3 BlueletAudio (Bluetooth Audio Service) - c:\windows\system32\drivers\blueletaudio.sys (file missing)
S3 BT (Bluetooth PAN Network Adapter) - c:\windows\system32\drivers\btnetdrv.sys (file missing)
S3 Btcsrusb (Bluetooth USB For Bluetooth Service) - c:\windows\system32\drivers\btcusb.sys (file missing)
S3 BTHidEnum (Bluetooth HID Enumerator) - c:\windows\system32\drivers\vbtenum.sys (file missing)
S3 DCamUSBIntel (USB Video Camera) - c:\windows\system32\drivers\tp6800.sys <Not Verified; Microsoft Corporation; Microsoft(R) Windows NT(R) Operating System>
S3 VComm (Virtual Serial port driver) - c:\windows\system32\drivers\vcomm.sys (file missing)
S3 VcommMgr (Bluetooth VComm Manager Service) - c:\windows\system32\drivers\vcommmgr.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S2 Indexingbox (Indexing Helps) - c:\windows\system\svchest.exe
S2 Office Source Engine Help (OESH) - c:\program files\netmeeting\msmsgs
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2008-01-19 and 2008-02-19 -----------------------------
2008-02-19 10:41:20 0 d-------- C:\Program Files\Trend Micro
2008-02-19 10:17:02 116 --a------ C:\myDelm.bat
2008-02-19 10:16:34 0 d-------- C:\WINDOWS\CSC
2008-02-19 09:59:39 2572 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-19 09:55:03 85504 --a------ C:\WINDOWS\system32\VACFix.exe <Not Verified; S!Ri.URZ; VACFix>
2008-02-19 09:55:02 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-02-19 09:55:02 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-02-19 09:55:02 82432 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-02-19 09:55:01 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-02-19 09:55:01 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-02-19 09:54:59 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; Command Line Process Utility>
2008-02-19 09:00:52 79872 -r-hs---- C:\WINDOWS\system32\winsys32_061230.dll
2008-02-19 09:00:52 30720 -r-hs---- C:\WINDOWS\system32\winsys16_061230.dll
2008-02-19 09:00:52 30720 -r-hs---- C:\WINDOWS\system32\scrsys16_061230.scr
2008-02-18 19:36:59 1740 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-02-18 13:24:20 0 d-------- C:\Program Files\Panda Security
2008-02-18 08:30:26 63488 ---hs---- C:\WINDOWS\system32\xydzyh.exe
2008-02-16 20:05:09 2566 --a------ C:\WINDOWS\system\svchest.reg
2008-02-16 20:05:09 118201 --a------ C:\WINDOWS\system\svchest.exe
2008-02-16 20:04:47 167041 --a------ C:\WINDOWS\system32\dd.exe
2008-02-16 20:04:24 167936 -r-hs---- C:\WINDOWS\system32\scrsys061230.scr
2008-02-16 20:04:23 167936 -r-hs---- C:\WINDOWS\system32\AlxRes061230.exe
2008-02-16 20:02:34 42496 --a------ C:\WINDOWS\quit.exe
2008-02-14 12:42:10 0 d-------- C:\Program Files\EC21Messenger
2008-02-13 14:17:13 0 d-------- C:\Documents and Settings\Admin\Application Data\Grisoft
2008-02-11 14:37:32 32 --a------ C:\Documents and Settings\All Users\Application Data\ezsid.dat
2008-02-11 14:37:32 0 d-------- C:\Documents and Settings\Admin\Application Data\skypePM
2008-02-11 14:35:43 0 d-------- C:\Documents and Settings\Admin\Application Data\Skype
2008-02-11 14:34:17 0 d-------- C:\Program Files\Skype
2008-02-11 14:34:02 0 d-------- C:\Program Files\Fichiers communs\Skype
2008-02-11 14:32:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-02-06 17:04:32 0 d-------- C:\Program Files\LDSoft
2008-02-06 11:27:35 0 d-------- C:\Documents and Settings\Admin\Application Data\AVS4YOU
2008-02-06 11:26:41 0 d-------- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-02-06 11:19:48 0 d-------- C:\Program Files\Fichiers communs\AVSMedia
2008-02-06 11:18:15 638976 --a------ C:\WINDOWS\system32\divx.dll <Not Verified; DivXNetworks, Inc.; DivX Video for Windows Codec>
2008-02-06 11:18:14 261632 --a------ C:\WINDOWS\system32\mcdvd_32.dll <Not Verified; MainConcept; MainConcept DV Codec "2.0.4>
2008-02-06 11:18:13 413760 --a------ C:\WINDOWS\system32\mpg4c32.dll <Not Verified; Microsoft Corporation; Microsoft MPEG-4 Video Codec>
2008-02-06 11:18:12 0 d-------- C:\Program Files\AVS4YOU
2008-02-02 15:09:07 28672 --a------ C:\WINDOWS\tpsti.exe
2008-02-02 15:09:07 221184 --a------ C:\WINDOWS\ToproUI.exe <Not Verified; ; TPCap Application>
2008-02-02 15:09:07 1523712 --a------ C:\WINDOWS\system32\ToproVC.dll
2008-02-02 15:09:07 197556 --a------ C:\WINDOWS\system32\drivers\TP6800.sys <Not Verified; Microsoft Corporation; Microsoft(R) Windows NT(R) Operating System>
2008-02-02 15:09:07 65536 --a------ C:\WINDOWS\system32\camlib.dll
2008-02-02 15:09:05 0 d-------- C:\Program Files\Topro
2008-01-31 09:33:56 0 d-------- C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-01-31 09:23:20 0 d-------- C:\Program Files\IVT Corporation
2008-01-30 18:36:14 327168 --a------ C:\WINDOWS\IsUninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
2008-01-30 18:31:56 0 d-------- C:\Documents and Settings\Admin\Application Data\GetRightToGo
2008-01-30 18:31:24 299520 --a------ C:\WINDOWS\uninst.exe <Not Verified; InstallShield Corporation, Inc.; InstallShield unInstaller>
2008-01-25 14:20:00 0 d--h----- C:\WINDOWS\PIF
2008-01-24 17:34:29 0 d-------- C:\Program Files\MIKSOFT
2008-01-23 23:43:41 0 d-------- C:\Cool
2008-01-23 18:52:21 0 d-------- C:\Program Files\SpeedOptimizer
2008-01-23 18:41:45 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-23 18:41:16 50688 --a------ C:\WINDOWS\system32\wbhelp2.dll <Not Verified; Stardock.Net, Inc; WindowBlinds for Win32 x86 machines>
2008-01-23 18:41:12 0 d-------- C:\Program Files\DAP
2008-01-23 15:39:22 0 d-------- C:\WINDOWS\system32\appmgmt
2008-01-23 15:20:03 0 d-------- C:\Documents and Settings\Admin\Application Data\TypingMaster7
2008-01-23 14:55:18 0 dr------- C:\Program Files\TypingMaster
2008-01-23 11:36:40 168632 --a------ C:\WINDOWS\system32\nsinet.exe
2008-01-22 12:19:25 0 d-------- C:\Documents and Settings\Admin\Application Data\pdf995
2008-01-22 12:16:05 0 d-------- C:\Documents and Settings\All Users\Application Data\pdf995
2008-01-22 12:16:04 249856 --a------ C:\WINDOWS\system32\pdfmona.dll <Not Verified; TODO: <Company name>; TODO: <Product name>>
2008-01-22 12:16:04 51716 --a------ C:\WINDOWS\system32\pdf995mon.dll
2008-01-22 12:15:58 0 d-------- C:\Program Files\pdf995
2008-01-21 10:34:56 0 d-------- C:\Program Files\Macrogaming
2008-01-21 09:16:26 0 dr-h----- C:\$VAULT$.AVG
2008-01-19 19:53:09 101888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL <Not Verified; Microsoft Corporation; Microsoft® Visual Basic for Windows>
2008-01-19 17:45:44 0 d-------- C:\Downloads
2008-01-19 15:36:25 0 d-------- C:\Program Files\TubeMaster
2008-01-19 15:09:52 27632 --a------ C:\WINDOWS\system\CTL3DV2.DLL <Not Verified; Microsoft Corporation; 3D Windows Control>
2008-01-19 15:09:52 0 d-------- C:\Documents and Settings\Admin\WINDOWS
2008-01-19 13:20:47 0 d-------- C:\Documents and Settings\Admin\Application Data\vlc
2008-01-19 09:04:09 0 d-------- C:\Program Files\VideoLAN
2008-01-19 08:55:09 0 d-------- C:\Documents and Settings\Admin\Contacts
-- Find3M Report ---------------------------------------------------------------
2008-02-19 09:08:36 1390 --a------ C:\STAT.DAT
2008-02-19 09:01:48 0 d-------- C:\Documents and Settings\Admin\Application Data\AVG7
2008-02-14 17:21:59 0 d-------- C:\Program Files\Yahoo!
2008-02-11 14:34:02 0 d-------- C:\Program Files\Fichiers communs
2008-01-31 09:34:51 370832 --a------ C:\WINDOWS\system32\perfh00C.dat
2008-01-31 09:34:51 49734 --a------ C:\WINDOWS\system32\perfc00C.dat
2008-01-23 15:38:30 580 --a------ C:\Documents and Settings\Admin\Application Data\MyPhrases.dta
2008-01-18 20:21:46 0 --a------ C:\WINDOWS\nsreg.dat
2008-01-18 20:21:30 0 d-------- C:\Documents and Settings\Admin\Application Data\Mozilla
2008-01-18 16:45:12 0 d-------- C:\Program Files\MSECache
2008-01-18 16:08:55 0 d-------- C:\Documents and Settings\Admin\Application Data\Macromedia
2008-01-18 16:07:07 0 d-------- C:\Documents and Settings\Admin\Application Data\Adobe
2008-01-18 14:07:45 0 d-------- C:\Documents and Settings\Admin\Application Data\Help
2008-01-18 13:41:14 0 d-------- C:\Program Files\Microsoft.NET
2008-01-18 13:33:33 0 d-------- C:\Program Files\ScanDrv6
2008-01-18 13:33:09 0 d-------- C:\Program Files\Fichiers communs\InstallShield
2008-01-18 13:29:12 0 d-------- C:\Program Files\MSN Messenger
2008-01-18 13:02:33 0 d-------- C:\Program Files\Fichiers communs\ODBC
2008-01-18 13:02:28 0 d-------- C:\Program Files\Fichiers communs\SpeechEngines
2008-01-18 13:01:41 62 --ahs---- C:\Documents and Settings\Admin\Application Data\desktop.ini
2008-01-18 12:50:01 0 d-------- C:\Program Files\CCP Server 4
2008-01-18 12:41:38 0 d-------- C:\Program Files\SuperCopier2
2008-01-18 12:36:56 0 d-------- C:\Program Files\Common Files
2008-01-18 12:29:23 0 d-------- C:\Documents and Settings\Admin\Application Data\Identities
2008-01-18 12:19:15 0 d-------- C:\Program Files\Windows NT
2008-01-18 12:19:15 0 d-------- C:\Program Files\msn gaming zone
2008-01-18 12:19:15 0 d-------- C:\Program Files\movie maker
2008-01-18 12:19:15 0 d-------- C:\Program Files\microsoft frontpage
2008-01-18 12:17:50 0 -rahs---- C:\MSDOS.SYS
2008-01-18 12:17:50 0 -rahs---- C:\IO.SYS
2008-01-18 12:17:50 0 --a------ C:\CONFIG.SYS
2008-01-18 12:17:50 0 --a------ C:\AUTOEXEC.BAT
2008-01-18 12:14:27 0 d--h----- C:\Program Files\WindowsUpdate
2008-01-18 12:14:21 0 d-------- C:\Program Files\Services en ligne
2008-01-18 12:12:57 0 d-------- C:\Program Files\Fichiers communs\MSSoap
2008-01-18 12:10:54 21892 --a------ C:\WINDOWS\system32\emptyregdb.dat
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [18/01/2008 12:38]
"DownloadAccelerator"="C:\Program Files\DAP\DAP.exe" [23/01/2008 18:41]
"SpeedOptimizer"="C:\Program Files\SpeedOptimizer\SPO.exe" [23/01/2008 18:52]
"tppoll"="C:\Program Files\Topro\tppoll.exe" [02/03/2005 17:12]
"BluetoothAuthenticationAgent"="bthprops.cpl" [19/08/2004 15:10 C:\WINDOWS\system32\bthprops.cpl]
"EC21"="C:\Documents and Settings\Admin\Bureau\Program Files\EC21Messenger\EZQ.EXE" [13/02/2008 10:21]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [11/06/2007 10:25]
"xydzyh"="C:\WINDOWS\system32\xydzyh.exe" [13/02/2008 21:18]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"="C:\Program Files\SuperCopier2\SuperCopier2.exe" [07/07/2006 17:45]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [19/01/2007 12:55]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [30/08/2007 17:43]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"Config"=%systemroot%\system32\run.cmd
"nlsf"=cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll"
"tscuninstall"=%systemroot%\system32\tscupgrd.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=1 (0x1)
"NoLowDiskSpaceChecks"=1 (0x1)
"NoStartBanner"=01000000
"NoSMHelp"=1 (0x1)
"MemCheckBoxInRunDlg"=1 (0x1)
"NoSMBalloonTip"=1 (0x1)
"NoDesktopCleanupWizard"=1 (0x1)
"NoWelcomeScreen"=1 (0x1)
"NoAutoUpdate"=1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"=1 (0x1)
"NoLowDiskSpaceChecks"=1 (0x1)
"NoStartBanner"=01000000
"NoSMHelp"=1 (0x1)
"MemCheckBoxInRunDlg"=1 (0x1)
"NoSMBalloonTip"=1 (0x1)
"NoDesktopCleanupWizard"=1 (0x1)
"NoWelcomeScreen"=1 (0x1)
"NoAutoUpdate"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="C:\WINDOWS\system32\userinit.exe,rundll32.exe C:\WINDOWS\system32\winsys16_061230.dll start"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06b2620e-d619-11dc-a343-000b0d0b0305}]
AutoRun\command- h.cmd
explore\Command- h.cmd
open\Command- h.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{12000289-c5be-11dc-a329-00eeb10237c7}]
AutoRun\command- G:\tio8x6.cmd
explore\Command- G:\tio8x6.cmd
open\Command- G:\tio8x6.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3841c327-d09b-11dc-a33c-000000000000}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe WillPolo.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{44006b30-c8c4-11dc-a32f-00eeb10237c7}]
AutoRun\command- G:\ntde1ect.com
explore\Command- G:\ntde1ect.com
open\Command- G:\ntde1ect.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{62d5a020-d165-11dc-a33d-000b0d0b0305}]
Auto\command- wscript "Sex City.jpg.wsf"
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript "Sex City.jpg.wsf"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a7692bf8-ca51-11dc-a332-00eeb10237c7}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe WillPolo.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a7692bf9-ca51-11dc-a332-00eeb10237c7}]
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe WillPolo.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a7692c00-ca51-11dc-a332-00eeb10237c7}]
AutoRun\command- G:\xfoolavp.com
explore\Command- G:\xfoolavp.com
open\Command- G:\xfoolavp.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aca714b0-dbcb-11dc-a34e-00eeb10237c7}]
AutoRun\command- G:\d.com
explore\Command- G:\d.com
open\Command- G:\d.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c4235dd2-d6eb-11dc-a344-000b0d0b0305}]
AutoRun\command- H:\xfoolavp.com
explore\Command- H:\xfoolavp.com
open\Command- H:\xfoolavp.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d8e67850-c763-11dc-a32d-00eeb10237c7}]
Auto\command- wscript "Sex City.jpg.wsf"
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript "Sex City.jpg.wsf"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d8e67860-c763-11dc-a32d-00eeb10237c7}]
AutoRun\command- fooool.exe
explore\Command- fooool.exe
open\Command- fooool.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0615b40-cbf5-11dc-a334-00eeb10237c7}]
AutoRun\command- ntde1ect.com
explore\Command- ntde1ect.com
open\Command- ntde1ect.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f6cb0434-d2fd-11dc-a33f-000b0d0b0305}]
AutoRun\command- u.bat
explore\Command- u.bat
open\Command- u.bat
-- End of Deckard's System Scanner: finished at 2008-02-19 10:57:04 ------------
merci beaucoup pour le doc
à+++