Win32 : trojan gen

Résolu
Bonjour,

Donc j'ai un souci. avast trouve plusieurs trojan gen et pandasecurity m'a trouvé 15 fichiers infectés. J'ai fais hijackthis puis j'ai suivi les instructions de Pinprenelle27 et voila le résultat : rapport de SDFix et hijackthis. Merci d'avance :

[b]SDFix: Version 1.240 [/b]
Run by utilisateur on 14/01/2009 at 20:21

Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix

[b]Checking Services [/b]:

Restoring Default Security Values
Restoring Default Hosts File

Rebooting

[b]Checking Files [/b]:

Trojan Files Found:

C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\Csrssc.exe - Deleted
C:\WINDOWS\Temp\csrssc.exe - Deleted

Removing Temp Files

[b]ADS Check [/b]:

[b]Final Check [/b]:

_________________________________________________________

et voila hijackthis ( 2ieme rapport = apres avoir lancé sdfix)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:48:50, on 14/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\utilisateur\Bureau\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlogin.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlogin.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe

--
End of file - 7406 bytes

Merci pour ton aide pimprenelle27. ou si quelqu'un d'autre peut m'aider ca me va aussi. merci encore par avance !!
Configuration: Windows XP
Firefox 3.0.5

25 réponses

Résumé de la discussion

Une infection sur Windows XP est décrite où Avast signale plusieurs trojans génériques et Panda Security identifie une quinzaine de fichiers infectés dans le système. Suite à SDFix et HijackThis, les rapports révèlent de nombreuses entrées au démarrage et des composants suspects (BHO, services et programmes divers) indiquant une compromission multi-entrée. Les conseils proposés privilégient Malwarebytes pour un balayage complet, puis le redémarrage en mode sans échec afin de supprimer les éléments détectés et relancer une vérification. D’autres échanges évoquent des nettoyages via Toolbar-S&D et des scans répétés, tout en précisant comment interpréter un scan 'normal' et les outils comme Winamp et d'autres éléments pertinents.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    qui t'a dit de faire sdfix?
    1. ben gen proc. c'est dans les étapes ou alors j'ai pas bien compris
    2. Contributeur sécurité
      @rodezaposte moi le rapport genproc si t là lancer alors. il ne faut pas bruler les étpaes.
    3. @pimprenelle27Rapport GenProc 2.333 [1] - 14/01/2009 - Windows XP

      # Etape 1/ Télécharge :

      - CCleaner https://www.ccleaner.com/ccleaner/download (FileHippo)
      Ce logiciel va permettre de supprimer tous les fichiers temporaires.
      Lance-le et clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
      Par la suite, laisse-le avec ses réglages par défaut. Ferme le programme.

      - SDfix http://downloads.andymanchesta.com/RemovalTools/SDFix.exe (Andy Manchesta) et sauvegarde le sur ton Bureau.
      Double clique sur SDFix.exe et choisis "Install" pour l'extraire dans C:\.

      Redémarre en mode sans échec comme indiqué ici https://www.wekyo.com/demarrer-le-pc-en-mode-sans-echec-windows-7-et-8/ ; pour retrouver le rapport, clique sur le raccourci "GenProc" sur ton bureau. Choisis ta session courante *** utilisateur ***

      # Etape 2/

      Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.cmd pour lancer le script.
      - Appuie sur Y pour commencer le processus de nettoyage.
      - Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche
      pour redémarrer, fais-le pour redémarrer le PC.
      - Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
      - Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.br />- Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.br />- Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.

      # Etape 3/

      Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

      # Etape 4/

      Redémarre normalement et poste, dans la même réponse :

      - Le contenu du fichier Report.txt;
      - Un nouveau rapport HijackThis http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/hijackthis-version-install-sujet_199100_1.htm ;

      Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.

      ____________________________________________________________________________________________________________

      Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
  2. Contributeur sécurité
    Telecharge malwarebytes

    Tu l´instale; le programme va se mettre automatiquement a jour.

    Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

    Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

    Puis click sur "rechercher".

    Laisse le scanner le pc...

    Si des elements on ete trouvés > click sur supprimer la selection.

    si il t´es demandé de redemarrer > click sur "yes".

    A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
    Copie et colle le rapport stp.

    PS : les rapport sont aussi rangé dans l onglet rapport/log

    Tutoriaux
    1. oui j'ai déjà nettoyer avec ccleaner mais y avait que des cookies . maintenant je lance malwarebyte.

    2. voilà le rapport (mais on ne m'a pas demander de redemarrer le PC) :

      Malwarebytes' Anti-Malware 1.32
      Version de la base de données: 1653
      Windows 5.1.2600 Service Pack 3

      14/01/2009 22:09:45
      mbam-log-2009-01-14 (22-09-45).txt

      Type de recherche: Examen complet (C:\|)
      Eléments examinés: 102232
      Temps écoulé: 47 minute(s), 0 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 2
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 1

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jsf8uiw3jnjgffght (Trojan.Agent) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jsf8uiw3jnjgffght (Trojan.Agent) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\WINDOWS\system32\hgfdge4unjdfdg.dll (Trojan.Agent) -> Quarantined and deleted successfully.
  3. voilà le rapport merci :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:21:31, on 14/01/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16762)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
    C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
    C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
    C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\utilisateur\Bureau\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
    O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
    O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
    O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
    O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    1. Contributeur sécurité
      Télécharges ToolBar S&D ( de Eric_71/Team IDN ) :
      https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

      ( Tuto : https://sites.google.com/site/toolbarsd/aideenimages )

      !! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!

      * double-cliques sur l'.exe pour lancer l'installe et laisses toi guider ...
      * Une fois fait, cliques sur le raccourci créé sur ton bureau pour lancer l'outil .
      * Choisis l'option 1 ( "recherche") et tapes "entrée" .
      * Une fois le scan finit , un rapport va apparaître, copie/colles l'intégralité
      de son contenu dans ta prochaine réponse ...
      ( le rapport est en outre sauvegardé ici -> C:\TB.txt )

      1. Au début après avoir choisi la langue, il y a eu un avertissement sur le danger à supprimer certains fichiers. j'ai fais ok et puis j'ai suivie tes instructions. heu est ce que je ferme tool bar après ?? voici le rapport :

        -----------\\ ToolBar S&D 1.2.8 XP/Vista

        Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
        X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3000+ )
        BIOS : Default System BIOS
        USER : utilisateur ( Administrator )
        BOOT : Normal boot
        Antivirus : avast! antivirus 4.8.1296 [VPS 090114-0] 4.8.1296 (Activated)
        A:\ (USB)
        C:\ (Local Disk) - NTFS - Total:149 Go (Free:11 Go)
        D:\ (CD or DVD)

        "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
        Option : [1] ( 14/01/2009|22:38 )

        -----------\\ Recherche de Fichiers / Dossiers ...

        -----------\\ Extensions

        (utilisateur) - {0b38152b-1b20-484d-a11f-5e04a9b0661f} => winamptoolbar

        -----------\\ [..\Internet Explorer\Main]

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
        "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
        "Start Page"="https://www.google.fr/?gws_rd=ssl"
        "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
        "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
        "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
        "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
        "Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"

        --------------------\\ Recherche d'autres infections

        --------------------\\ Cracks & Keygens ..

        C:\DOCUME~1\UTILIS~1\Bureau\torrents\Nero 8 Ultra Edition + Keygens + Crack.rar.torrent

        1 - "C:\ToolBar SD\TB_1.txt" - 14/01/2009|22:39 - Option : [1]

        -----------\\ Fin du rapport a 22:39:03,50
        1. Contributeur sécurité
          Pas bien les crack c'est souvent ce qui ramène les virus. attention.

          Nettoyage avec ToolBar S&D :

          !! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!

          Relances Toolbar-S&D en double-cliquant sur le raccourci.
          -->Tapes sur l'option 2 ( "nettoyage" ) puis tapes sur "Entrée".

          Note : ne touches à rien lors de la suppression !

          Un rapport sera généré à la fin du processus : postes son contenu dans ta prochaine réponse
          accompagné d'un nouveau rapport hijackthis pour analyse ...
          1. ca y est j'ai compris j'avais bien supprimé le dossier mais j'avais oublié le torrent.
            oki Merci pour l'info sur les cracks j'aime pas trop non plus en général. j'ai voulu faire un test et j'ai eu le retour du bâton. vilaine que je suis !!!

            Bon voilà les rapports TB et Hijackthis :

            -----------\\ ToolBar S&D 1.2.8 XP/Vista

            Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
            X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3000+ )
            BIOS : Default System BIOS
            USER : utilisateur ( Administrator )
            BOOT : Normal boot
            Antivirus : avast! antivirus 4.8.1296 [VPS 090114-0] 4.8.1296 (Activated)
            A:\ (USB)
            C:\ (Local Disk) - NTFS - Total:149 Go (Free:11 Go)
            D:\ (CD or DVD)

            "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
            Option : [2] ( 14/01/2009|22:50 )

            -----------\\ Recherche de Fichiers / Dossiers ...

            -----------\\ Extensions

            (utilisateur) - {0b38152b-1b20-484d-a11f-5e04a9b0661f} => winamptoolbar

            -----------\\ [..\Internet Explorer\Main]

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
            "Start Page"="https://www.google.fr/?gws_rd=ssl"
            "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
            "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
            "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
            "Start Page"="https://www.msn.com/fr-fr/"

            --------------------\\ Recherche d'autres infections

            --------------------\\ Cracks & Keygens ..

            C:\DOCUME~1\UTILIS~1\Bureau\torrents\Nero 8 Ultra Edition + Keygens + Crack.rar.torrent

            1 - "C:\ToolBar SD\TB_1.txt" - 14/01/2009|22:39 - Option : [1]
            2 - "C:\ToolBar SD\TB_2.txt" - 14/01/2009|22:50 - Option : [2]

            -----------\\ Fin du rapport a 22:50:57,10

            et hijackthis

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 22:51:35, on 14/01/2009
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16762)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
            C:\WINDOWS\system32\drivers\KodakCCS.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
            C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
            C:\Documents and Settings\utilisateur\Bureau\HiJackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - Default URLSearchHook is missing
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
            O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
            O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
            O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
            O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
            O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
            O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
            O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
            O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
            O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
            O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
            O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
            1. Contributeur sécurité
              refait mi un scan un mode normale de toolbar merci.
              1. qu'est ce que tu appelle un scan "normal" ? c'est l'option 1 : "rechercher" ??
                1. voici le rapport de l'option 1 rechercher avec toolbar SD :

                  -----------\\ ToolBar S&D 1.2.8 XP/Vista

                  Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                  X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3000+ )
                  BIOS : Default System BIOS
                  USER : utilisateur ( Administrator )
                  BOOT : Normal boot
                  Antivirus : avast! antivirus 4.8.1296 [VPS 090114-0] 4.8.1296 (Activated)
                  A:\ (USB)
                  C:\ (Local Disk) - NTFS - Total:149 Go (Free:11 Go)
                  D:\ (CD or DVD)

                  "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                  Option : [1] ( 14/01/2009|23:08 )

                  -----------\\ Recherche de Fichiers / Dossiers ...

                  -----------\\ Extensions

                  (utilisateur) - {0b38152b-1b20-484d-a11f-5e04a9b0661f} => winamptoolbar

                  -----------\\ [..\Internet Explorer\Main]

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                  "Start Page"="https://www.google.fr/?gws_rd=ssl"
                  "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                  "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Start Page"="https://www.msn.com/fr-fr/"

                  --------------------\\ Recherche d'autres infections

                  --------------------\\ Cracks & Keygens ..

                  C:\DOCUME~1\UTILIS~1\Bureau\torrents\Nero 8 Ultra Edition + Keygens + Crack.rar.torrent

                  1 - "C:\ToolBar SD\TB_1.txt" - 14/01/2009|22:39 - Option : [1]
                  2 - "C:\ToolBar SD\TB_2.txt" - 14/01/2009|22:50 - Option : [2]
                  3 - "C:\ToolBar SD\TB_3.txt" - 14/01/2009|23:09 - Option : [1]

                  -----------\\ Fin du rapport a 23:09:11,15
                  1. Contributeur sécurité
                    ils sont encore tout les 2 là donc, il faire l'option 2 en mode sans echec que ça marche et supprime correctement,

                    Redémarre en mode sans échec comme indiqué ici ; Choisis ta session courante.
                2. je ne pense pas que ça ai marché est ce qu'il faut que je le supprime directement le fichier dans le dossier torrent ???
                  voici le nouveau rapport

                  -----------\\ ToolBar S&D 1.2.8 XP/Vista

                  Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                  X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3000+ )
                  BIOS : Default System BIOS
                  USER : utilisateur ( Administrator )
                  BOOT : Fail-safe boot
                  Antivirus : avast! antivirus 4.8.1296 [VPS 090114-0] 4.8.1296 (Activated)
                  A:\ (USB)
                  C:\ (Local Disk) - NTFS - Total:149 Go (Free:13 Go)
                  D:\ (CD or DVD)

                  "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                  Option : [2] ( 14/01/2009|23:23 )

                  -----------\\ Recherche de Fichiers / Dossiers ...

                  -----------\\ Extensions

                  (utilisateur) - {0b38152b-1b20-484d-a11f-5e04a9b0661f} => winamptoolbar

                  -----------\\ [..\Internet Explorer\Main]

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                  "Start Page"="https://www.google.fr/?gws_rd=ssl"
                  "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                  "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Start Page"="https://www.msn.com/fr-fr/"

                  --------------------\\ Recherche d'autres infections

                  --------------------\\ Cracks & Keygens ..

                  C:\DOCUME~1\UTILIS~1\Bureau\torrents\Nero 8 Ultra Edition + Keygens + Crack.rar.torrent

                  1 - "C:\ToolBar SD\TB_1.txt" - 14/01/2009|22:39 - Option : [1]
                  2 - "C:\ToolBar SD\TB_2.txt" - 14/01/2009|22:50 - Option : [2]
                  3 - "C:\ToolBar SD\TB_3.txt" - 14/01/2009|23:09 - Option : [1]
                  4 - "C:\ToolBar SD\TB_4.txt" - 14/01/2009|23:24 - Option : [2]

                  -----------\\ Fin du rapport a 23:24:25,46
                  1. Contributeur sécurité
                    j'ai trouvé autre chose sinono on fera la suppression.

                    Etape 1/ Télécharge :

                    - FindyKill http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe (Chiquitine29) sur le Bureau.

                    Note importante : l'infection bagle s'installant au moyen d'un crack/keygen, tu dois IMPERATIVEMENT supprimer ce type de fichier.

                    # Etape 2/

                    Lance l'installation avec les paramètres par défaut
                    - Double-clique sur le raccourci FindyKill sur le Bureau (sous Vista : clic droit sur le raccourci --> Exécuter en temps qu'Administrateur)
                    - Au menu principal, sélectionne l'option 1 (Recherche)
                    - Le rapport est sauvegardé à la racine du disque dur (C:\FindyKill.txt )
                    Avant de faire quoi que ce soit d'autre, il est fortement recommandé de poster le rapport sur le forum pour avoir l'avis d'un spécialiste.Après confirmation par un intervenant qualifié du forum, passe au nettoyage

                    1. voici le rapport :

                      ----------------- FindyKill V4.712 ------------------

                      * User : utilisateur - MTIMA-C303359FC
                      * Emplacement : C:\Program Files\FindyKill
                      * Outils Mis a jours le 14/01/09 par Chiquitine29
                      * Recherche effectuée à 23:40:54 le 14/01/2009
                      * Windows XP - Internet Explorer 7.0.5730.13

                      ((((((((((((((((( *** Recherche *** ))))))))))))))))))

                      --------------- [ Processus actifs ] ----------------

                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\csrss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                      C:\WINDOWS\SOUNDMAN.EXE
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\Program Files\QuickTime\QTTask.exe
                      C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
                      C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
                      C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
                      C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                      C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
                      C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                      C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
                      C:\WINDOWS\system32\drivers\KodakCCS.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\wdfmgr.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\WINDOWS\system32\wbem\wmiprvse.exe
                      C:\WINDOWS\System32\alg.exe
                      C:\Program Files\Windows Live\Contacts\wlcomm.exe

                      --------------- [ Fichiers/Dossiers infectieux ] ----------------

                      »»»» Presence des fichiers dans C:

                      »»»» Presence des fichiers dans C:\WINDOWS

                      »»»» Presence des fichiers dans C:\WINDOWS\Prefetch

                      »»»» Presence des fichiers dans C:\WINDOWS\system32

                      »»»» Presence des fichiers dans C:\WINDOWS\system32\drivers

                      »»»» Presence des fichiers dans C:\Documents and Settings\utilisateur\Application Data

                      »»»» Presence des fichiers dans C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp

                      --------------- [ Registre / Startup ] ----------------

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                      CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
                      MsnMsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                      StartCCC="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
                      ATIPTA="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                      SoundMan=SOUNDMAN.EXE
                      avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
                      NeroFilterCheck=C:\WINDOWS\system32\NeroCheck.exe
                      SMSTray=C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
                      MAAgent=C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
                      Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                      CanonSolutionMenu=C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
                      CanonMyPrinter=C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
                      SSBkgdUpdate="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                      OpwareSE4="C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
                      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                      <NO NAME>=
                      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
                      Installed=1
                      <NO NAME>=
                      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
                      NoChange=1
                      Installed=1
                      <NO NAME>=
                      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
                      Installed=1
                      <NO NAME>=

                      [HKEY_CURRENT_USER\software\local appwizard-generated applications\Kodak EasyShare]
                      [HKEY_CURRENT_USER\software\local appwizard-generated applications\Samsung Media Studio]

                      --------------- [ Registre / Clés infectieuses ] ----------------

                      --------------- [ Etat / Services ] ----------------

                      +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

                      Ndisuio - Type de démarrage = 3

                      EapHost - Type de démarrage = 3

                      Ip6Fw - Type de démarrage = 3

                      SharedAccess - Type de démarrage = 2

                      wuauserv - Type de démarrage = 2

                      wscsvc - Type de démarrage = 2

                      --------------- [ Recherche dans supports amovibles] ----------------

                      +- Informations :

                      C: - Lecteur fixe

                      +- presence des fichiers :

                      --------------- [ Registre / Mountpoint2 ] ----------------

                      -> Not found !

                      ------------------- ! Fin du rapport ! --------------------

                      1. Contributeur sécurité
                        supprime complètement toolbar. réinstalle le puis fait l'option 2 il devrait marqué suppression mais là rien c'est comme l'option 1.
                        1. -----------\\ ToolBar S&D 1.2.8 XP/Vista

                          Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                          X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3000+ )
                          BIOS : Default System BIOS
                          USER : utilisateur ( Administrator )
                          BOOT : Normal boot
                          Antivirus : avast! antivirus 4.8.1296 [VPS 090114-0] 4.8.1296 (Activated)
                          A:\ (USB)
                          C:\ (Local Disk) - NTFS - Total:149 Go (Free:11 Go)
                          D:\ (CD or DVD)

                          "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                          Option : [2] ( 14/01/2009|23:52 )

                          -----------\\ Recherche de Fichiers / Dossiers ...

                          -----------\\ Extensions

                          (utilisateur) - {0b38152b-1b20-484d-a11f-5e04a9b0661f} => winamptoolbar

                          -----------\\ [..\Internet Explorer\Main]

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                          "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                          "Start Page"="https://www.google.fr/?gws_rd=ssl"
                          "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                          "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                          "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                          "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                          "Start Page"="https://www.msn.com/fr-fr/"

                          --------------------\\ Recherche d'autres infections

                          --------------------\\ Cracks & Keygens ..

                          C:\DOCUME~1\UTILIS~1\Bureau\torrents\Nero 8 Ultra Edition + Keygens + Crack.rar.torrent

                          1 - "C:\ToolBar SD\TB_1.txt" - 14/01/2009|22:39 - Option : [1]
                          2 - "C:\ToolBar SD\TB_2.txt" - 14/01/2009|22:50 - Option : [2]
                          3 - "C:\ToolBar SD\TB_3.txt" - 14/01/2009|23:09 - Option : [1]
                          4 - "C:\ToolBar SD\TB_4.txt" - 14/01/2009|23:24 - Option : [2]
                          5 - "C:\ToolBar SD\TB_5.txt" - 14/01/2009|23:53 - Option : [2]

                          -----------\\ Fin du rapport a 23:53:35,12
                          1. c'est pas encore ça hein ? je crois que je fatigue si tu as la possibilité de revenir demain j'aurais le cerveau en fonction. je suis debout depuis 6h00 du mat et j'ai couru toute la journée et avec plus l'ordi qui fait des siennes..... je suis au bout du rouleau. je vais aller au lit à moins qu'on trouve bientôt le bon médoc ??
                            1. Contributeur sécurité
                              pour winamp suis cette méthode

                              Salut,
                              Un clic sur la flèche à droite de Winamp search, modifier paramètres par défaut, d'abord définir nouveau moteur de recherche par défaut puis supprimer Winamp search!
                              Voilà j'espère que ça jouera pour toi, bon travail!!!
                          2. Contributeur sécurité
                            A demain je ne suis pas là demain matin n'y en début d'après midi.
                            1. Youpi ca a marché j'ai plus rien trop bien merci beaucoup beaucoup
                              enfin j'espère qu'il n'y a plus rien !!!

                              -----------\\ ToolBar S&D 1.2.8 XP/Vista

                              Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                              X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3000+ )
                              BIOS : Default System BIOS
                              USER : utilisateur ( Administrator )
                              BOOT : Normal boot
                              Antivirus : avast! antivirus 4.8.1296 [VPS 090114-0] 4.8.1296 (Activated)
                              A:\ (USB)
                              C:\ (Local Disk) - NTFS - Total:149 Go (Free:11 Go)
                              D:\ (CD or DVD)

                              "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                              Option : [1] ( 15/01/2009| 0:13 )

                              -----------\\ Recherche de Fichiers / Dossiers ...

                              -----------\\ [..\Internet Explorer\Main]

                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                              "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                              "Start Page"="https://www.google.fr/?gws_rd=ssl"
                              "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                              "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                              "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                              "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                              "Start Page"="https://www.msn.com/fr-fr/"

                              --------------------\\ Recherche d'autres infections

                              Aucune autre infection trouvée !

                              1 - "C:\ToolBar SD\TB_1.txt" - 14/01/2009|22:39 - Option : [1]
                              2 - "C:\ToolBar SD\TB_2.txt" - 14/01/2009|22:50 - Option : [2]
                              3 - "C:\ToolBar SD\TB_3.txt" - 14/01/2009|23:09 - Option : [1]
                              4 - "C:\ToolBar SD\TB_4.txt" - 14/01/2009|23:24 - Option : [2]
                              5 - "C:\ToolBar SD\TB_5.txt" - 14/01/2009|23:53 - Option : [2]
                              6 - "C:\ToolBar SD\TB_6.txt" - 15/01/2009| 0:13 - Option : [1]

                              -----------\\ Fin du rapport a 0:13:45,07
                              • 1
                              • 2