Mon ordi rame depuis une semaine

Résolu
Bonjour, voila depuis une semaine mon ordi me mes beaucoup de temps a ouvrir des pages internet ou meme des dossiers perso, se matin quant je l ai allumer ecran blanc puis l image et revnu mais elle sauter, mon antivirus est avast et j'ai également spyware doctor, je pense qu un virus a du s introduire dans mon ordi merci de m'aider pas de conseil trop technique car je suis assez novice en informatique mais je me debrouille,
merci a tous ceux qui voudrons bien me conseiller .
bonne journée.
Configuration: Windows XP
Internet Explorer 7.0

22 réponses

  1. Contributeur sécurité
    Bonjour,

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par random/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Lis le contenu de l'écran Disclaimer puis clique sur Continue (si tu acceptes les conditions).

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    .

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
    1. voila le rapport log.txt
      Logfile of random's system information tool 1.05 (written by random/random)
      Run by HP_Propriétaire at 2009-03-10 08:58:18
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 121 GB (82%) free of 148 GB
      Total RAM: 446 MB (16% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 08:58:47, on 10/03/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16791)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
      C:\Program Files\Windows Live\Family Safety\fsssvc.exe
      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Google\Update\GoogleUpdate.exe
      C:\Program Files\Microsoft LifeCam\MSCamS32.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\Program Files\CDBurnerXP\NMSAccessU.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Spyware Doctor\pctsAuxs.exe
      C:\Program Files\Spyware Doctor\pctsSvc.exe
      C:\Program Files\Java\jre1.5.0\bin\jusched.exe
      C:\windows\system\hpsysdrv.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\WINDOWS\ALCXMNTR.EXE
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\WINDOWS\vVX1000.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\Program Files\QuickTime\QTTask.exe
      C:\HP\KBD\KBD.EXE
      C:\Program Files\Spyware Doctor\pctsTray.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Search Settings\SearchSettings.exe
      C:\Program Files\Windows Live\Family Safety\fsui.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\NETGEAR\WPN111\wpn111.exe
      C:\Documents and Settings\HP_Propriétaire\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.exe
      C:\Documents and Settings\HP_Propriétaire\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
      C:\Program Files\OpenOffice.org 3\program\soffice.bin
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\System32\svchost.exe
      c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Windows Live\Toolbar\wltuser.exe
      C:\Documents and Settings\HP_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\ZUEJ53WB\RSIT[1].exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\Program Files\trend micro\HP_Propriétaire.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/webhp?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?linkId=57777&clcid=0x409
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
      R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
      O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
      O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
      O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
      O4 - Startup: Outil de notification Live Search.lnk = ?
      O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
      O4 - Global Startup: BTTray.lnk = ?
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
      O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?7a0512630fc9484a90cc4cf97870c5b9
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?7a0512630fc9484a90cc4cf97870c5b9
      O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
      O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
      O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
      O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
      O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O15 - Trusted Zone: *.canalplay.com
      O15 - Trusted Zone: *.canalplusactive.com
      O15 - Trusted Zone: *.canalplay.com (HKLM)
      O15 - Trusted Zone: *.canalplusactive.com (HKLM)
      O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
      O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
      O23 - Service: Google Update Service (gupdate1c95c4a6682154a) (gupdate1c95c4a6682154a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
      O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
      0
  2. j'ai fais un nettoyage avec c cleaner, une defragmentation et un nettoyage disque et sa n a rien changer.
    si quelqu un pouvais lire mon rapport sa serai sympa.
    merci a tous
    0
    1. Contributeur sécurité
      Re,

      Télécharge Toolbar-S&D (Team IDN) sur ton Bureau :

      https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

      * Lance l'installation du programme en exécutant le fichier téléchargé.
      * Double-clique maintenant sur le raccourci de Toolbar-S&D.
      * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
      * Choisis maintenant l'option "2" puis valide en appuyant sur "Entrée".
      ! Ne ferme pas la fenêtre lors de la suppression !
      Un rapport sera généré, poste son contenu ici.

      ==================
      Ouvre ce lien (merci a S!RI pour ce programme). http://siri.urz.free.fr/Fix/SmitfraudFix.php
      et télécharge SmitfraudFix.exe.

      Regarde le tuto
      Exécute le en choisissant l’option 1, il va générer un rapport
      Copie/colle le sur le poste stp.

      0
      1. Désolé de ne pas avoir pu repondre avant mais encore merci de tes conseils.

        -----------\\ ToolBar S&D 1.2.8 XP/Vista

        Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
        X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3200+ )
        BIOS : Phoenix - Award BIOS v6.00PG
        USER : HP_Propriétaire ( Administrator )
        BOOT : Normal boot
        Antivirus : avast! antivirus 4.8.1335 [VPS 090309-0] 4.8.1335 (Activated)
        C:\ (Local Disk) - NTFS - Total:144 Go (Free:118 Go)
        D:\ (Local Disk) - FAT32 - Total:5 Go (Free:1 Go)
        E:\ (CD or DVD)
        F:\ (Local Disk) - NTFS - Total:180 Go (Free:51 Go)
        G:\ (Local Disk) - FAT32 - Total:4 Go (Free:0 Go)
        H:\ (USB)
        I:\ (USB)
        J:\ (USB)
        K:\ (USB)

        "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
        Option : [2] ( 10/03/2009|17:36 )

        -----------\\ SUPPRESSION

        Supprime! - C:\DOCUME~1\HP_PRO~1\APPLIC~1\Search Settings\kb127
        Supprime! - C:\Program Files\Search Settings\kb127
        Supprime! - C:\Program Files\Search Settings\SearchSettings.exe
        Supprime! - C:\DOCUME~1\HP_PRO~1\APPLIC~1\Search Settings
        Supprime! - C:\Program Files\Search Settings

        -----------\\ Recherche de Fichiers / Dossiers ...

        -----------\\ [..\Internet Explorer\Main]

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
        "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
        "Start Page"="https://www.google.fr/webhp?gws_rd=ssl"
        "Search Page"="https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC"
        "Default_Page_URL"="https://www.01net.com/telecharger/"
        "SearchMigratedDefaultURL"="https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src={referrer:source?}"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
        "Default_Page_URL"="https://www.01net.com/telecharger/"
        "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
        "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
        "Start Page"="https://www.msn.com/fr-fr/"

        --------------------\\ Recherche d'autres infections

        Aucune autre infection trouvée !

        1 - "C:\ToolBar SD\TB_1.txt" - 10/03/2009|17:38 - Option : [2]

        -----------\\ Fin du rapport a 17:38:31,89
        0
        1. SmitFraudFix v2.401

          Rapport fait à 17:44:22,04, 10/03/2009
          Executé à partir de C:\Documents and Settings\HP_Propri‚taire\Bureau\SmitfraudFix
          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
          Le type du système de fichiers est NTFS
          Fix executé en mode normal

          »»»»»»»»»»»»»»»»»»»»»»»» Process

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
          C:\Program Files\Windows Live\Family Safety\fsssvc.exe
          C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Google\Update\GoogleUpdate.exe
          C:\Program Files\Microsoft LifeCam\MSCamS32.exe
          C:\Program Files\CDBurnerXP\NMSAccessU.exe
          C:\Program Files\Spyware Doctor\pctsAuxs.exe
          C:\Program Files\Spyware Doctor\pctsSvc.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Spyware Doctor\pctsTray.exe
          C:\Program Files\Java\jre1.5.0\bin\jusched.exe
          C:\windows\system\hpsysdrv.exe
          C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
          C:\WINDOWS\ALCXMNTR.EXE
          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          C:\WINDOWS\vVX1000.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\QuickTime\QTTask.exe
          C:\HP\KBD\KBD.EXE
          C:\Program Files\Windows Live\Family Safety\fsui.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\NETGEAR\WPN111\wpn111.exe
          C:\Documents and Settings\HP_Propriétaire\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
          C:\Program Files\OpenOffice.org 3\program\soffice.exe
          C:\Documents and Settings\HP_Propriétaire\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
          C:\Program Files\OpenOffice.org 3\program\soffice.bin
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Live\Contacts\wlcomm.exe
          C:\Program Files\Windows Live\Toolbar\wltuser.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Documents and Settings\HP_Propriétaire\Bureau\SmitfraudFix\Policies.exe
          C:\WINDOWS\system32\cmd.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          »»»»»»»»»»»»»»»»»»»»»»»» C:\

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Propri‚taire

          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Propri‚taire\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HP_PRO~1\Favoris

          »»»»»»»»»»»»»»»»»»»»»»»» Bureau

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          C:\Program Files\Google\googletoolbar1.dll PRESENT !

          »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

          »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
          "Source"="About:Home"
          "SubscribedURL"="About:Home"
          "FriendlyName"="Ma page d'accueil"

          »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          o4Patch
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          Agent.OMZ.Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» VACFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"=""

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
          "System"=""

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Miniport d'ordonnancement de paquets
          DNS Server Search Order: 15.243.128.51
          DNS Server Search Order: 15.243.160.51

          Description: NETGEAR RangeMax(TM) Wireless USB 2.0 Adapter WPN111 - Miniport d'ordonnancement de paquets
          DNS Server Search Order: 192.168.1.1
          DNS Server Search Order: 192.168.1.1

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}: DhcpNameServer=15.243.128.51 15.243.160.51
          HKLM\SYSTEM\CCS\Services\Tcpip\..\{FD9994E8-90D8-4C6E-9700-DCB42E299C3A}: DhcpNameServer=192.168.1.1 192.168.1.1
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}: DhcpNameServer=15.243.128.51 15.243.160.51
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{FD9994E8-90D8-4C6E-9700-DCB42E299C3A}: DhcpNameServer=192.168.1.1 192.168.1.1
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}: DhcpNameServer=15.243.128.51 15.243.160.51
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{FD9994E8-90D8-4C6E-9700-DCB42E299C3A}: DhcpNameServer=192.168.1.1 192.168.1.1
          HKLM\SYSTEM\CS3\Services\Tcpip\..\{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}: DhcpNameServer=15.243.128.51 15.243.160.51
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

          »»»»»»»»»»»»»»»»»»»»»»»» Fin
          0
          1. Contributeur sécurité
            Re,

            le rapport de Smitfraudfix ?
            0
            1. il es juste au dessus de ta question nos reponse on du se croiser
              0
              1. Contributeur sécurité
                Re,

                oui, probable vu les heures.

                Démarre en mode sans échec :
                Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
                Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                (Si F8 ne marche pas utilise la touche F5).
                ----------------------------------------------------------------------------
                Relance le programme Smitfraud,
                Cette fois choisit l’option 2, répond oui a tous ;
                Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

                ================================

                Remets aussi un rapport RSIT.
                0
                1. voila mon rapport,
                  SmitFraudFix v2.401

                  Rapport fait à 18:04:00,10, 10/03/2009
                  Executé à partir de C:\Documents and Settings\HP_Propri‚taire\Bureau\SmitfraudFix
                  OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                  Le type du système de fichiers est NTFS
                  Fix executé en mode sans echec

                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                  127.0.0.1 localhost

                  »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                  VACFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                  S!Ri's WS2Fix: LSP not Found.

                  »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                  GenericRenosFix by S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                  C:\Program Files\Google\googletoolbar1.dll supprimé

                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                  IEDFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix

                  Agent.OMZ.Fix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                  404Fix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» RK

                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}: DhcpNameServer=15.243.128.51 15.243.160.51
                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{FD9994E8-90D8-4C6E-9700-DCB42E299C3A}: DhcpNameServer=192.168.1.1 192.168.1.1
                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}: DhcpNameServer=15.243.128.51 15.243.160.51
                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{FD9994E8-90D8-4C6E-9700-DCB42E299C3A}: DhcpNameServer=192.168.1.1 192.168.1.1
                  HKLM\SYSTEM\CS2\Services\Tcpip\..\{DE246E2C-8697-44FE-A5BB-FA04D12D4DEC}: DhcpNameServer=15.243.128.51 15.243.160.51
                  HKLM\SYSTEM\CS2\Services\Tcpip\..\{FD9994E8-90D8-4C6E-9700-DCB42E299C3A}: DhcpNameServer=192.168.1.1 192.168.1.1
                  HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
                  HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1
                  HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 192.168.1.1

                  »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  "System"=""

                  »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                  »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                  Nettoyage terminé.

                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Fin
                  0
                  1. Contributeur sécurité
                    Re,

                    le nouveau rapport RSIT ?
                    0
                    1. le dernier c est celui que j ai fais en mode sans echec .
                      0
                      1. Contributeur sécurité
                        Re,

                        je veux un rapport RSIT en mode normal
                        0
                        1. Logfile of random's system information tool 1.05 (written by random/random)
                          Run by HP_Propriétaire at 2009-03-10 23:08:19
                          Microsoft Windows XP Édition familiale Service Pack 3
                          System drive C: has 121 GB (82%) free of 148 GB
                          Total RAM: 446 MB (27% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 23:08:36, on 10/03/2009
                          Platform: Windows XP SP3 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16791)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                          C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                          C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          C:\Program Files\Google\Update\GoogleUpdate.exe
                          C:\Program Files\Microsoft LifeCam\MSCamS32.exe
                          C:\Program Files\CDBurnerXP\NMSAccessU.exe
                          C:\Program Files\Spyware Doctor\pctsAuxs.exe
                          C:\Program Files\Spyware Doctor\pctsSvc.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                          C:\Program Files\Spyware Doctor\pctsTray.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                          C:\windows\system\hpsysdrv.exe
                          C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                          C:\WINDOWS\ALCXMNTR.EXE
                          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          C:\WINDOWS\vVX1000.exe
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\Program Files\QuickTime\QTTask.exe
                          C:\HP\KBD\KBD.EXE
                          C:\Program Files\Windows Live\Family Safety\fsui.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\Program Files\NETGEAR\WPN111\wpn111.exe
                          C:\Documents and Settings\HP_Propriétaire\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
                          C:\Program Files\OpenOffice.org 3\program\soffice.exe
                          C:\Documents and Settings\HP_Propriétaire\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
                          C:\Program Files\OpenOffice.org 3\program\soffice.bin
                          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Internet Explorer\IEXPLORE.EXE
                          C:\Program Files\Windows Live\Toolbar\wltuser.exe
                          C:\Documents and Settings\HP_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\BNX2BQQW\RSIT[1].exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe
                          C:\Program Files\trend micro\HP_Propriétaire.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/webhp?gws_rd=ssl
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.01net.com/telecharger/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?linkId=57777&clcid=0x409
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                          O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                          O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                          O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                          O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                          O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                          O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
                          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                          O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
                          O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
                          O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                          O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                          O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                          O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                          O4 - Startup: Outil de notification Live Search.lnk = ?
                          O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
                          O4 - Global Startup: BTTray.lnk = ?
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?
                          O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
                          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                          O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
                          O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?7a0512630fc9484a90cc4cf97870c5b9
                          O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?7a0512630fc9484a90cc4cf97870c5b9
                          O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
                          O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
                          O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                          O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                          O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                          O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                          O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                          O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O15 - Trusted Zone: *.canalplay.com
                          O15 - Trusted Zone: *.canalplusactive.com
                          O15 - Trusted Zone: *.canalplay.com (HKLM)
                          O15 - Trusted Zone: *.canalplusactive.com (HKLM)
                          O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
                          O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
                          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                          O23 - Service: Google Update Service (gupdate1c95c4a6682154a) (gupdate1c95c4a6682154a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                          O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZIPM12.EXE
                          O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                          O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                          O23 - Service: Service CANALPLAY - Canal+ Distribution - C:\Program Files\Lecteur CANALPLAY\CanalPlayService.exe
                          0
                          1. Contributeur sécurité
                            Re,

                            Rends toi sur ce site :

                            https://www.virustotal.com/gui/

                            Clique sur parcourir et cherche ce fichier : C:\UNWISE.EXE

                            Clique sur Send File.

                            Un rapport va s'élaborer ligne à ligne.

                            Attends la fin. Il doit comprendre la taille du fichier envoyé.

                            Sauvegarde le rapport avec le bloc-note.

                            Copie le dans ta réponse.

                            Si VirusTotal indique que le fichier a déjà été analysé, cliquer sur le bouton Reanalyse le fichier maintenant

                            ============================

                            fais un clic droit sur : C:\WINDOWS\ActiveSkin.INI

                            et choisis "modifier"

                            Le fichier va s'ouvrir avec le Bloc-notes. Poste le contenu.
                            0
                            1. Bonjour,
                              j'ai fais se que tu ma dis jusque la mais la je ne vois pas a la fin de ta derniere reponse tu me dis "fais un clic droit sur : C:\WINDOWS\ActiveSkin.INI " je ne vois pas ou sa se trouve.
                              0
                              1. Contributeur sécurité
                                Re,

                                ouvre l'Explorateur Windows et cherche le fichier C:\WINDOWS\ActiveSkin.INI dans le répertoire C:\WINDOWS

                                Si tu ne le trouves pas, fais ceci :

                                ->Affiche tous les fichiers et dossiers :
                                clique sur démarrer/panneau de configuration (en affichage classique)/option des dossiers/affichage

                                [Coche] « afficher les dossiers et fichiers cachés »

                                [Décoche] la case « Masquer les fichiers protégés du système d'exploitation (recommandé) »

                                [Décoche] « masquer les extensions dont le type est connu »

                                Puis fais [appliquer] pour valider les changements.

                                Et [Ok]

                                et recommence la recherche.
                                0
                                1. je les trouver mes en faisant un clique droit je n ai pas "modifier" j ai cliquer dessus en normal et j ai obtenu sa:
                                  ActiveSkin control is registered to:

                                  User Name: "George Emilov, Webmessenger, Inc."
                                  Password: "oviivovufi"
                                  0
                                  1. Contributeur sécurité
                                    Re,

                                    et le rapport VirusTotal de Unwise ?
                                    0
                                    1. Désoler d avoir été si longue a pouvoir poster mon rapport je n etais pas chez moi.
                                      encore merci de ton aide.
                                      Antivirus Version Dernière mise à jour Résultat
                                      a-squared 4.0.0.101 2009.03.11 -
                                      AhnLab-V3 5.0.0.2 2009.03.11 -
                                      AntiVir 7.9.0.109 2009.03.11 -
                                      Authentium 5.1.0.4 2009.03.10 -
                                      Avast 4.8.1335.0 2009.03.10 -
                                      AVG 8.0.0.237 2009.03.11 -
                                      BitDefender 7.2 2009.03.11 -
                                      CAT-QuickHeal 10.00 2009.03.11 -
                                      ClamAV 0.94.1 2009.03.11 -
                                      Comodo 1049 2009.03.11 -
                                      DrWeb 4.44.0.09170 2009.03.11 -
                                      eSafe 7.0.17.0 2009.03.11 -
                                      eTrust-Vet None 2009.03.09 -
                                      F-Prot 4.4.4.56 2009.03.10 -
                                      F-Secure 8.0.14470.0 2009.03.11 -
                                      Fortinet 3.117.0.0 2009.03.11 -
                                      GData 19 2009.03.11 -
                                      Ikarus T3.1.1.45.0 2009.03.11 -
                                      K7AntiVirus 7.10.667 2009.03.11 -
                                      Kaspersky 7.0.0.125 2009.03.11 -
                                      McAfee 5549 2009.03.10 -
                                      McAfee+Artemis 5549 2009.03.10 -
                                      Microsoft 1.4405 2009.03.11 -
                                      NOD32 3927 2009.03.11 -
                                      Norman 6.00.06 2009.03.11 -
                                      nProtect 2009.1.8.0 2009.03.11 -
                                      Panda 10.0.0.10 2009.03.11 -
                                      PCTools 4.4.2.0 2009.03.11 -
                                      Prevx1 V2 2009.03.11 -
                                      Rising 21.20.22.00 2009.03.11 -
                                      SecureWeb-Gateway 6.7.6 2009.03.11 -
                                      Sophos 4.39.0 2009.03.11 -
                                      Sunbelt 3.2.1858.2 2009.03.11 -
                                      Symantec 1.4.4.12 2009.03.11 -
                                      TheHacker 6.3.3.0.279 2009.03.11 -
                                      TrendMicro 8.700.0.1004 2009.03.11 -
                                      ViRobot 2009.3.11.1645 2009.03.11 -
                                      VirusBuster 4.5.11.0 2009.03.11 -
                                      Information additionnelle
                                      File size: 162304 bytes
                                      MD5...: 3a938ed2427df10e571041069e6980cb
                                      SHA1..: c3c96cc03ec6714cf7c98caadb00fbfaa8e82411
                                      SHA256: 4751a3547f3b482bb4a2440d4e91e3dcba9b4b0f5b1bb50416a32fb47ae75c5e
                                      SHA512: cbb15307bc6219b317380f90b3eb44227f86df295bd33f4a7983021e8706ebd1
                                      ac889080b14001592f6852386f43fd675be6e94e28a2c5131e00f12bcd243c85
                                      ssdeep: 1536:Ff6Q/2mS/jdzjrAU74ZBPq/9Cg7Q3469+Yo/nW2vEXLJADHAUs:oQ/2mSNf
                                      r4fPsC7B9+Yo/nWhJwHAU

                                      PEiD..: Armadillo v1.71
                                      TrID..: File type identification
                                      InstallShield setup (42.6%)
                                      Win32 Executable MS Visual C++ (generic) (37.3%)
                                      Win32 Executable Generic (8.4%)
                                      Win32 Dynamic Link Library (generic) (7.5%)
                                      Generic Win/DOS Executable (1.9%)
                                      PEInfo: PE Structure information

                                      ( base data )
                                      entrypointaddress.: 0xcc01
                                      timedatestamp.....: 0x3a49120f (Tue Dec 26 21:47:59 2000)
                                      machinetype.......: 0x14c (I386)

                                      ( 4 sections )
                                      name viradd virsiz rawdsiz ntrpy md5
                                      .text 0x1000 0xf757 0xf800 6.39 7d39dc1da65182dad7741f62d1cc8b0c
                                      .rdata 0x11000 0x1e15 0x2000 5.45 2369e1a654e19e4dbfd20f0815c53ee7
                                      .data 0x13000 0x3fdc 0x3600 2.52 dbad94b2720e19c03440254be00f6eb0
                                      .rsrc 0x17000 0x12640 0x12800 4.29 2da1b3fbd1761f8abe17d0e66544f7dc

                                      ( 6 imports )
                                      > KERNEL32.dll: MoveFileExA, SetFileAttributesA, FindFirstFileA, RemoveDirectoryA, GetFileAttributesA, CreateProcessA, GetVersionExA, GetPrivateProfileStringA, GetLocalTime, CreateDirectoryA, GlobalAlloc, WritePrivateProfileStringA, WaitForSingleObject, FreeResource, SetErrorMode, lstrcatA, LoadLibraryA, GetProcAddress, FreeLibrary, GetWindowsDirectoryA, GlobalUnlock, GlobalFree, SizeofResource, _lcreat, _lwrite, _lclose, WinExec, OpenFile, lstrcpynA, FileTimeToLocalFileTime, MultiByteToWideChar, GetFileTime, _lread, FileTimeToDosDateTime, _llseek, _lopen, GetDriveTypeA, GetSystemDirectoryA, MulDiv, lstrcmpA, lstrcmpiA, lstrcpyA, GetModuleFileNameA, lstrlenA, CopyFileA, GetTempPathA, GetTempFileNameA, LockResource, FindResourceA, LoadResource, GlobalLock, GetPrivateProfileIntA, DeleteFileA, FindNextFileA, FindClose, FreeEnvironmentStringsW, HeapReAlloc, UnhandledExceptionFilter, FreeEnvironmentStringsA, VirtualAlloc, VirtualFree, HeapCreate, ExitProcess, HeapDestroy, GetEnvironmentVariableA, ReadFile, SetFilePointer, WriteFile, GetStdHandle, SetHandleCount, SetStdHandle, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, WideCharToMultiByte, GetCurrentProcess, TerminateProcess, GetVersion, GetCommandLineA, GetStartupInfoA, GetModuleHandleA, HeapFree, HeapAlloc, MoveFileA, CreateFileA, GetFileType, SetEndOfFile, CloseHandle, GetFullPathNameA, SetCurrentDirectoryA, GetCurrentDirectoryA, SetEnvironmentVariableA, GetLastError, GetEnvironmentStrings, GetEnvironmentStringsW, RtlUnwind, GetOEMCP, GetCPInfo, GetACP
                                      > USER32.dll: UpdateWindow, RegisterClassA, LoadBitmapA, ShowWindow, LoadIconA, SetTimer, PeekMessageA, TranslateMessage, DdeUninitialize, GetSystemMetrics, SetWindowTextA, GetMessageA, ExitWindowsEx, GetSysColor, LoadCursorA, SetCursor, EnableWindow, IsWindowVisible, CreateDialogParamA, IsDialogMessageA, wsprintfA, PostMessageA, MessageBoxA, CreateWindowExA, EndPaint, PostQuitMessage, GetClientRect, BeginPaint, ReleaseDC, InvalidateRect, GetDC, DefWindowProcA, MoveWindow, GetWindowRect, SetDlgItemTextA, EndDialog, GetDlgItemTextA, SetRect, ScreenToClient, GetDlgItem, GetWindowTextA, SendDlgItemMessageA, SetFocus, OemToCharA, CharNextA, GetDialogBaseUnits, FillRect, DrawIcon, LoadStringA, GetParent, EnumChildWindows, FindWindowA, SendMessageA, DdeCreateDataHandle, DdeInitializeA, DdeConnect, DdeClientTransaction, DdeGetData, DdeDisconnect, DestroyWindow, DispatchMessageA, DialogBoxParamA, KillTimer, DdeFreeDataHandle, DdeCreateStringHandleA
                                      > GDI32.dll: GetStockObject, TextOutA, SetTextColor, GetTextExtentPointA, CreateFontA, GetDeviceCaps, SetBkMode, BitBlt, CreateCompatibleDC, DeleteDC, CreateSolidBrush, SelectObject, PatBlt, SelectPalette, ExtTextOutA, RealizePalette, MoveToEx, CreatePen, SetBkColor, CreateFontIndirectA, StretchBlt, LineTo, CreateDIBitmap, CreatePalette, CreateCompatibleBitmap, DeleteObject, GetObjectA
                                      > comdlg32.dll: GetOpenFileNameA
                                      > ADVAPI32.dll: RegDeleteKeyA, RegCloseKey, RegQueryValueExA, RegOpenKeyExA, CloseServiceHandle, OpenSCManagerA, RegSetValueA, RegSetValueExA, RegCreateKeyExA, RegEnumKeyExA, RegEnumValueA, RegDeleteValueA, RegEnumKeyA, RegOpenKeyA, DeleteService, ControlService, OpenServiceA
                                      > ole32.dll: CoUninitialize, CoCreateInstance, CoInitialize

                                      ( 4 exports )
                                      _ItemDlg@16, _MainWndProc@16, _PromptDlg@16, _SharedDlg@16

                                      ThreatExpert info: <a href='http://www.threatexpert.com/report.aspx?md5=3a938ed2427df10e571041069e6980cb' target='_blank'>https://www.symantec.com?md5=3a938ed2427df10e571041069e6980cb</a>
                                      0
                                      1. Contributeur sécurité
                                        Re,

                                        Lis bien et exécute cette manip dans l’ordre.

                                        #Télécharge et installe ces logiciels (si tu ne les as pas) pour les 3 premiers
                                        mets les à jour, comme indiqué dans les démos ou tutos.

                                        Ne les utilise pas tout de suite.

                                        Antispywares et autres :

                                        Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton bureau à partir de ce lien :

                                        https://www.malwarebytes.com/

                                        A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

                                        Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

                                        Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

                                        MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue.

                                        Nettoyeurs (de fichiers inutiles) et autres :

                                        *Ccleaner (gratuit)
                                        Téléchargement :
                                        https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
                                        Tuto :
                                        https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

                                        Lors de l’installation, [décoche] l’option qui t’installerait la barre Yahoo !

                                        ========================================
                                        ->Affiche tous les fichiers et dossiers :
                                        clique sur démarrer/panneau de configuration (en affichage classique)/option des dossiers/affichage

                                        [Coche] « afficher les dossiers et fichiers cachés »

                                        [Décoche] la case « Masquer les fichiers protégés du système d'exploitation (recommandé) »

                                        [Décoche] « masquer les extensions dont le type est connu »

                                        Puis fais [appliquer] pour valider les changements.

                                        Et [Ok]
                                        .

                                        =======================================

                                        ========================================
                                        ->Lance CCleaner.

                                        Suppression des fichiers temporaires

                                        Va dans la section "Options" situé dans la marge gauche.
                                        Décoche "Avancé"
                                        Retourne ensuite dans la section "Nettoyeur"
                                        Fais bien attention de cocher toutes ces cases dans la marge gauche (Internet Explorer/Windows Explorer/Système)
                                        • Clique sur [Analyse]
                                        • Patiente le temps du scan, qui peut prendre un peu de temps si c'est la première fois.
                                        • Une fois le scan terminé, clique sur [Lancer le Nettoyage]

                                        ========================================
                                        Lance Malwarebytes AntiMalware

                                        Dans l'onglet analyse, vérifie que "Exécuter un scan rapide" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

                                        MBAM analyse ton ordinateur. L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.

                                        A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

                                        Si des malwares ont été détectés, leur liste s'affiche.
                                        En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

                                        MBAM va ouvrir le bloc-notes et y copier le rapport d'analyse. Ferme le bloc-note. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

                                        Ferme MBAM en cliquant sur Quitter.

                                        Poste le rapport dans ta réponse.
                                        ========================================

                                        ->Relance CCleaner.
                                        Suppression des incohérences du registre

                                        • Clique sur l'icône [Registre] situés dans la marge à gauche
                                        • Puis clique sur [Analyser les erreurs]
                                        • Patiente pendant que CCleaner scan ton registre.
                                        • Une fois le scan terminé, coche toutes les entrèes qu'il t'aura trouvée.
                                        • Tu peux cliquer ensuite sur [Corriger les erreurs].

                                        Si tu n'est pas sur de ce que tu fais, tu peux choisir de sauvegarder les entrées cochées pour les restaurer ultérieurement.
                                        ========================================
                                        ->Vide ta Corbeille.
                                        ========================================

                                        Mets à jour ton antivirus et scanne ton ordi.

                                        Où en sont tes soucis ?
                                        0
                                        • 1
                                        • 2