Salut,
Tu fais ctrl+alt+supp et tu arrêtes le processus win32.exe
Tu vas dans c:win32dll et tu supprimes win32.exe
Tu refais un scan, et tu supprimes ce qui est en gras :
(Tu auras certainement la ligne "c:win32dllwin32.exe"(en italique) en moins)
<TABLE BORDER=0 ALIGN=CENTER WIDTH=85%><TR><TD><font size=-1><b>Citation :</b></font></TD></TR></TABLE><TABLE BORDER=1 CELLPADDING=10 BORDERCOLOR=#FF0000 ALIGN=CENTER WIDTH=85%><TR BGCOLOR=#F3F2F4><TD><FONT SIZE=-1>Logfile of HijackThis v1.99.0
Scan saved at 17:53:08, on 12/02/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSSystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesFichiers communsSymantec SharedccSetMgr.exe
C:Program FilesFichiers communsSymantec SharedSNDSrvc.exe
C:Program FilesFichiers communsSymantec SharedccEvtMgr.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesFichiers communsSymantec SharedccProxy.exe
C:PROGRA~1NORTON~1NORTON~2GHOSTS~2.EXE
C:Program FilesNorton SystemWorksNorton Antivirusnavapsvc.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:Program FilesNorton SystemWorksNorton AntivirusSAVScan.exe
C:Program FilesHewlett-PackardHP Share-to-Webhpgs2wnd.exe
C:WINDOWSSystem32hdspmix.exe
C:WINDOWSSystem32hdsp32.exe
C:WINDOWSSystem32spoolDRIVERSW32X863E_S4I0H2.EXE
C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
C:Program FilesSlySoftAnyDVDAnyDVD.exe
C:Program FilesD-Toolsdaemon.exe
C:Program FilesFichiers communsSymantec SharedccApp.exe
C:Program FilesNorton SystemWorksNorton GhostGhostStartTrayApp.exe
C:Program FilesNorton SystemWorksPassword ManagerAcctMgr.exe
C:Program FilesHewlett-PackardHP Share-to-Webhpgs2wnf.exe
C:Program FilesMessengermsmsgs.exe
C:WINDOWSSystem32ctfmon.exe
C:Program FilesInterVideoCommonBinWinCinemaMgr.exe
<I>c:win32dllwin32.exe</I>
c:progra~1intern~1iexplore.exe
C:Program FilesInternet Exploreriexplore.exe
C:WINDOWSSystem32wuauclt.exe
C:Program FilesInternet Exploreriexplore.exe
D:DIAMOND MAXPERMANENTUTILITAIRESspywarehijackthis_199HijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = <a href="
http://fr.audiofanzine.com/" target="_blank">
http://fr.audiofanzine.com/</a>
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Liens
<B>R3 - Default URLSearchHook is missing</B>
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:PROGRA~1SPYBOT~1SDHelper.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:Program FilesFichiers communsSymantec SharedAdBlockingNISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:Program FilesNorton SystemWorksNorton AntivirusNavShExt.dll
O2 - BHO: (no name) - {F750BED3-ED0A-945F-F099-19FF3F18A033} - C:DOCUME~1chubbyAPPLIC~1POKEFA~1UserRect.exe
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - C:PROGRA~1STARDO~1SDIEInt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:Program FilesNorton SystemWorksNorton AntivirusNavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:Program FilesFichiers communsSymantec SharedAdBlockingNISShExt.dll
O4 - HKLM..Run: [Share-to-Web Namespace Daemon] C:Program FilesHewlett-PackardHP Share-to-Webhpgs2wnd.exe
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [HDSPTray2] hdspmix.exe
O4 - HKLM..Run: [HDSPTray1] hdsp32.exe
O4 - HKLM..Run: [EPSON Stylus Photo R200 Series] C:WINDOWSSystem32spoolDRIVERSW32X863E_S4I0H2.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200"
O4 - HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [AnyDVD] C:Program FilesSlySoftAnyDVDAnyDVD.exe
O4 - HKLM..Run: [DAEMON Tools-1033] "C:Program FilesD-Toolsdaemon.exe" -lang 1033
O4 - HKLM..Run: [ccApp] "C:Program FilesFichiers communsSymantec SharedccApp.exe"
O4 - HKLM..Run: [GhostStartTrayApp] C:Program FilesNorton SystemWorksNorton GhostGhostStartTrayApp.exe
O4 - HKLM..Run: [AcctMgr] C:Program FilesNorton SystemWorksPassword ManagerAcctMgr.exe /startup
O4 - HKLM..Run: [Symantec NetDriver Monitor] C:PROGRA~1SYMNET~1SNDMon.exe
<B>O4 - HKLM..Run: [Win32] C:Win32dllWin32k.exe -starthide C:Win32dllWin32.exe -local</B>
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 - HKCU..Run: [AIM THE] C:DOCUME~1chubbyAPPLIC~1GPLPEA~1birddoeseggs.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:Program FilesInterVideoCommonBinWinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O8 - Extra context menu item: Download with Star Downloader - C:Program FilesStar Downloadersdie.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - <a href="res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000" target="_blank">res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000</a>
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - <a href="
http://v5.windowsupdate.microsoft.com/v ... 3366175546" target="_blank">
http://v5.windowsupdate.microsoft.com/v ... 6175546</a>
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - <a href="
http://a840.g.akamai.net/7/840/537/2004 ... scan53.cab" target="_blank">
http://a840.g.akamai.net/7/840/537/2004 ... n53.cab</a>
O17 - HKLMSystemCCSServicesTcpip..{10FE971A-5038-41EA-913F-9FC924865401}: NameServer = 213.228.0.168 212.27.32.5
O17 - HKLMSystemCS1ServicesTcpip..{10FE971A-5038-41EA-913F-9FC924865401}: NameServer = 213.228.0.168 212.27.32.5
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSSystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:Program FilesFichiers communsSymantec SharedccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:Program FilesFichiers communsSymantec SharedccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:Program FilesFichiers communsSymantec SharedccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:Program FilesFichiers communsSymantec SharedccSetMgr.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique - Unknown - C:WINDOWSSystem32dmadmin.exe
O23 - Service: Journal des événements - Unknown - C:WINDOWSsystem32services.exe
O23 - Service: GhostStartService - Symantec Corporation - C:PROGRA~1NORTON~1NORTON~2GHOSTS~2.EXE
O23 - Service: Service COM de gravage de CD IMAPI - Unknown - C:WINDOWSSystem32imapi.exe
O23 - Service: Partage de Bureau à distance NetMeeting - Unknown - C:WINDOWSSystem32mnmsrvc.exe
O23 - Service: Service Norton AntiVirus Auto-Protect - Symantec Corporation - C:Program FilesNorton SystemWorksNorton Antivirusnavapsvc.exe
O23 - Service: DDE réseau - Unknown - C:WINDOWSsystem32netdde.exe
O23 - Service: DSDM DDE réseau - Unknown - C:WINDOWSsystem32netdde.exe
O23 - Service: Plug-and-Play - Unknown - C:WINDOWSsystem32services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance - Unknown - C:WINDOWSsystem32sessmgr.exe
O23 - Service: SAVScan - Symantec Corporation - C:Program FilesNorton SystemWorksNorton AntivirusSAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:PROGRA~1FICHIE~1SYMANT~1SCRIPT~1SBServ.exe
O23 - Service: Prise en charge des cartes à puces - Unknown - C:WINDOWSSystem32SCardSvr.exe
O23 - Service: Carte à puce - Unknown - C:WINDOWSSystem32SCardSvr.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:Program FilesFichiers communsSymantec SharedSNDSrvc.exe
O23 - Service: Journaux et alertes de performance - Unknown - C:WINDOWSsystem32smlogsvc.exe
O23 - Service: Telnet - Unknown - C:WINDOWSSystem32tlntsvr.exe
O23 - Service: Cliché instantané de volume - Unknown - C:WINDOWSSystem32vssvc.exe
O23 - Service: Carte de performance WMI - Unknown - C:WINDOWSSystem32wbemwmiapsrv.exe </FONT></TD></TR></TABLE>