Merci beaucoup Angélique, je n'ai plus le message d'erreur au demarrage de window et apparement plus aucune trace de winlogin.exe.
Je te mets ci-joint les résultats d'analyse de AGV et JhackThis !
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 13:34:51 26/04/2007
+ Résultat de l'analyse:
C:\Documents and Settings\Nyanko\Bureau\log\MSNFix\backup\photo album.zip/photo album2007.pif -> Backdoor.IRCBot.aaq : Nettoyé.
C:\System Volume Information\_restore{B8EC9942-2252-4C36-95EE-DE0016C1D623}\RP70\A0020164.pif -> Backdoor.IRCBot.aaq : Nettoyé.
C:\System Volume Information\_restore{B8EC9942-2252-4C36-95EE-DE0016C1D623}\RP93\A0028358.dll -> Backdoor.IRCBot.aaq : Nettoyé.
C:\WINDOWS\system32\tables.ini -> Backdoor.Zapchast.NY : Nettoyé.
:mozilla.98:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.114:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.116:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.117:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
:mozilla.104:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.105:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.66:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.68:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.75:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.76:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.77:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.80:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.102:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.103:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.111:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.23:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Netflame : Nettoyé.
:mozilla.46:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Paypal : Nettoyé.
:mozilla.64:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.65:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.67:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.122:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.88:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Webtrends : Nettoyé.
:mozilla.82:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Webtrendslive : Nettoyé.
:mozilla.39:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.40:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.41:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.42:C:\Documents and Settings\Nyanko\Application Data\Mozilla\Firefox\Profiles\wkc4pr9u.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
G:\System Volume Information\_restore{A1FB5A27-CD54-4209-B828-0E433EA02C96}\RP272\A0084234.exe -> Trojan.Small : Nettoyé.
Fin du rapport
Logfile of HijackThis v1.99.1
Scan saved at 16:54:15, on 26/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\vVX3000.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\uTorrent\utorrent.exe
C:\PROGRA~1\INCRED~1\bin\ImApp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.gozobil.lx.ro
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gozobil.lx.ro
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gozobil.lx.ro
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gozobil.lx.ro
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [LXBSCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBStime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [µTorrent] "C:\Program Files\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [incrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O11 - Options group: [iNTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1173532156752
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: rdihost - {92CBCC95-FC3A-4FBC-9694-E5A72B25D8E2} - rdihost.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: lxbs_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbscoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe