bjr tlm .. je sais pas si je suis  sur le bon forum,Mais bon vous me le direz .Donc  voila le pb  d'un ami.Il a constament une page  noire affichée sur son bureau avec un texte suivant Computer danger etc....je suppose  qu'il aurait comme qui dirait des machins, trucs bidules dans la machine Voici son log par  hijackis Si vous avez l'âme de pouvoir  l'aider ,gentil à vous de repondre Merci 
  
Logfile of HijackThis v1.99.0 
Scan saved at 15:12:46, on 19/01/2005 
Platform: Windows XP SP1 (WinNT 5.01.2600) 
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) 
  
Running processes: 
C:\WINDOWS\System32\smss.exe 
C:\WINDOWS\system32\winlogon.exe 
C:\WINDOWS\system32\services.exe 
C:\WINDOWS\system32\lsass.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\System32\svchost.exe 
C:\WINDOWS\system32\spoolsv.exe 
C:\WINDOWS\System32\Ati2evxx.exe 
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe 
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe 
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe 
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe 
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe 
C:\WINDOWS\System32\svchost.exe 
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe 
C:\WINDOWS\Explorer.EXE 
C:\Program Files\Winamp\winampa.exe 
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe 
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe 
C:\WINDOWS\System32\cmd32.exe 
C:\WINDOWS\System32\RunDll32.exe 
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe 
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe 
C:\Documents and Settings\alainh\Application Data\wahc.exe 
C:\Program Files\Microsoft ActiveSync\wcescomm.exe 
C:\WINDOWS\System32\izxczxcr.exe 
C:\Program Files\MSN Messenger\msnmsgr.exe 
C:\Program Files\Internet Explorer\iexplore.exe 
C:\Program Files\Internet Explorer\IEXPLORE.EXE 
C:\Documents and Settings\alainh\Bureau\HijackThis.exe 
  
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank 
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens 
O2 - BHO: CDownCom Class - {031B6D43-CBC4-46A5-8E46-CF8B407C1A33} - C:\WINDOWS\Downloaded Program Files\ipreg32.dll 
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll 
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll 
O2 - BHO: (no name) - {84165FBD-FD48-4FE5-AA9F-A08E7CCE6715} - (no file) 
O2 - BHO: (no name) - {8785E4CB-55CA-444D-8B34-6388DEFA7992} - C:\WINDOWS\System32\gnoebaa.dll (file missing) 
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll 
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll 
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll 
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll 
O3 - Toolbar: (no name) - {6b95678d-30a4-4ff8-a72f-4208340c1f7f} - (no file) 
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx 
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" 
O4 - HKLM\..\Run: [urlLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe 
O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe 
O4 - HKLM\..\Run: [sSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe 
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime 
O4 - HKLM\..\Run: [iE Menu Extension toolbar] rundll32.exe "C:\PROGRA~1\IEMENU~1\tbextn.dll" DllShowTB 
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" 
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe 
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\System32\cmd32.exe internat.dll,LoadKeyboardProfile 
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd 
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" 
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe 
O4 - HKCU\..\Run: [iued] C:\Documents and Settings\alainh\Application Data\wahc.exe 
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe" 
O4 - HKCU\..\Run: [Csot] C:\Documents and Settings\alainh\Application Data\mrcr.exe 
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE 
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm 
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 
O9 - Extra button: Créer un Favori de l'appareil mobile - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll 
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll 
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll 
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm 
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm 
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE 
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE 
O15 - Trusted Zone: *.blazefind.com 
O15 - Trusted Zone: *.clickspring.net 
O15 - Trusted Zone: *.flingstone.com 
O15 - Trusted Zone: *.mt-download.com 
O15 - Trusted Zone: *.my-internet.info 
O15 - Trusted Zone: *.searchbarcash.com 
O15 - Trusted Zone: *.searchmiracle.com 
O15 - Trusted Zone: *.skoobidoo.com 
O15 - Trusted Zone: *.slotch.com 
O15 - Trusted Zone: *.slotchbar.com 
O15 - Trusted Zone: *.windupdates.com 
O15 - Trusted Zone: *.xxxtoolbar.com 
O15 - Trusted Zone: *.ysbweb.com 
O15 - Trusted Zone: *.blazefind.com (HKLM) 
O15 - Trusted Zone: *.clickspring.net (HKLM) 
O15 - Trusted Zone: *.flingstone.com (HKLM) 
O15 - Trusted Zone: *.mt-download.com (HKLM) 
O15 - Trusted Zone: *.my-internet.info (HKLM) 
O15 - Trusted Zone: *.searchbarcash.com (HKLM) 
O15 - Trusted Zone: *.searchmiracle.com (HKLM) 
O15 - Trusted Zone: *.skoobidoo.com (HKLM) 
O15 - Trusted Zone: *.slotch.com (HKLM) 
O15 - Trusted Zone: *.slotchbar.com (HKLM) 
O15 - Trusted Zone: *.windupdates.com (HKLM) 
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM) 
O15 - Trusted Zone: *.ysbweb.com (HKLM) 
O15 - Trusted IP range: 67.19.185.246 
O15 - Trusted IP range: 67.19.185.246 (HKLM) 
O16 - DPF: fdjeux - https://www.fdjeux.net/classes/fdjeux.cab 
O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure...teleir_cert.cab 
O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:\foo.mht!http://82.179.166.145/x14.chm::/trs14.exe 
O16 - DPF: {41ACD49D-1974-791A-0981-AA9872721044} (GINBOARDS Class) - http://67.15.101.3/g_bin/eng/boards_2_0_0_15.cab 
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab 
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200411...meInstaller.exe 
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} - http://67.19.185.246/i/8/loader2.ocx 
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsIns....cab?refid=4116 
O16 - DPF: {A031D222-B496-11D2-9CC8-00105A10AAF6} (WONWebLauncher Class) - http://hoylegames.sierra.com/cab/WONWebLauncherControl.cab 
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab 
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup...er/imloader.cab 
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab 
O18 - Filter: text/html - {A7ABFA46-7C69-489F-BCE9-0F492EB6936A} - C:\WINDOWS\System32\gnoebaa.dll 
O18 - Filter: text/plain - {A7ABFA46-7C69-489F-BCE9-0F492EB6936A} - C:\WINDOWS\System32\gnoebaa.dll 
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe 
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe 
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe 
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe 
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe 
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe 
O23 - Service: Service d'administration du Gestionnaire de disque logique - Unknown - C:\WINDOWS\System32\dmadmin.exe 
O23 - Service: Journal des événements - Unknown - C:\WINDOWS\system32\services.exe 
O23 - Service: Service COM de gravage de CD IMAPI - Unknown - C:\WINDOWS\System32\imapi.exe 
O23 - Service: Partage de Bureau à distance NetMeeting - Unknown - C:\WINDOWS\System32\mnmsrvc.exe 
O23 - Service: Service Norton AntiVirus Auto-Protect - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe 
O23 - Service: DDE réseau - Unknown - C:\WINDOWS\system32\netdde.exe 
O23 - Service: DSDM DDE réseau - Unknown - C:\WINDOWS\system32\netdde.exe 
O23 - Service: Plug-and-Play - Unknown - C:\WINDOWS\system32\services.exe 
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance - Unknown - C:\WINDOWS\system32\sessmgr.exe 
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe 
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe 
O23 - Service: Prise en charge des cartes à puces - Unknown - C:\WINDOWS\System32\SCardSvr.exe 
O23 - Service: Carte à puce - Unknown - C:\WINDOWS\System32\SCardSvr.exe 
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe 
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe 
O23 - Service: Journaux et alertes de performance - Unknown - C:\WINDOWS\system32\smlogsvc.exe 
O23 - Service: Telnet - Unknown - C:\WINDOWS\System32\tlntsvr.exe 
O23 - Service: Cliché instantané de volume - Unknown - C:\WINDOWS\System32\vssvc.exe 
O23 - Service: Carte de performance WMI - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe 
  
Donc  je vous dis a +