Acces Registre Bloqué; Infection Virtumundo?

Résolu
Bonjour a tous,

Tout d'abord merci pour ce forum.
Depuis quelques temps j'ai les problèmes suivants:
- impossible de rétablir un point de restauration quelques soit la date du point
- accès a la base de registre impossible, la fenêtre s'ouvre 1 sec puis se referme
- mon antivirus Symantec ne se lance plus automatiquement au demarrage, cependant le systeme autoprotec fonctionne toujours.
- fermeture intempestive de Firefox, ou Internet Explorer
- fermeture intempestive de skype
- augmentation de la frequence de bug sur Excel ou Word ( peut etre pas du tout corrélé)

J'ai scanner mon ordinateur avec Symantec il m'a trouvé:
-trojan Dropper
- trojan non identifie
il les a tous les deux eliminé

J'ai scanné avec Spyboot et il m'a trouvé
- un probleme sur l'acces au regsitre
- virtumundo

Mais meme apres "fixation" du problème avec spyboot, je n'ai toujours pas accés au registre et mon antivirus ne se lance toujours pas automatiquement au demarrage. Si je relance une analyse spyboot, il me detecte de nouveau Virtumundo.

Je ne suis pas douée du tout en informatique, mais j'ai passé un peu de temps sur le forum.
J'ai donc suivi es conseils suivant:
- nettoyage avec CCleaner
- scan avec Hijackthis, dont je vous poste le rapport.

Ma configuration, Windows XP pro, Version 2002, Service Pack 3

je vous remercie beaucoup par avance de l'aide que vous pourrez m'apporter.
R

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:01:19 PM, on 4/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\StacSV.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Trend Micro\HijackThis\elimine.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=6080415
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/hws/sb/dell-row-rel/fr/side.html?channel=fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr/hws/sb/dell-row-rel/fr/side.html?channel=fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dell.com/fr-fr?c=fr&l=fr&s=gen&redirect=1
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.dell.com/fr-fr?c=fr&l=fr&s=gen&redirect=1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/hws/sb/dell-row-rel/fr/side.html?channel=fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=6080415
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
O4 - HKLM\..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [kmw_run.exe] kmw_run.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [HP Network Registry Agent] C:\WINDOWS\system32\hpnra.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: gemsafe - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll
O23 - Service: Broadcom ASF IP and SMBIOS Mailbox Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lmab_device - Lexmark International, Inc. - C:\WINDOWS\system32\LMabcoms.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

--
End of file - 14224 bytes
Configuration: Windows XP
Firefox 3.0.10

16 réponses

Résumé de la discussion

Plusieurs problèmes touchent un PC sous Windows XP Professionnel SP3 : impossibilité de rétablir des points de restauration, accès au registre bloqué et fermeture rapide des outils de sécurité. Des symptômes en cascade incluent des plantages de Firefox et Internet Explorer, des fermetures intempestives de Skype et des ralentissements ou bugs accrues dans Word et Excel. Les analyses ont repéré des menaces, notamment Trojan Dropper et Virtumundo, puis l’utilisateur a tenté des nettoyages avec Spybot, CCleaner et HijackThis, mais les problèmes persistent. La suite de l’échange met en lumière le besoin d’un diagnostic plus approfondi sur les dépendances d’accès au registre et sur les services de sécurité, afin de rétablir les services au démarrage.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Très bien, ton ordinateur n'est plus infecté !

    Avant de retourner surfer sur internet, il y a certaines choses que tu dois faire pour finir le nettoyage et améliorer sensiblement la sécurité de ton ordinateur, ça t'évitera peut-être de devoir revenir ici avec une nouvelle infection dans le futur ;) Mais sache qu'aucun logiciel de sécurité ne te protègera à 100%, ce qui fait la différence, c'est ta vigilance lorsque tu télécharges ou installes quelque chose : pour en savoir plus, je t'invite à bien lire la page indiquée tout en bas de ce message (7).

    1) Les barres d'outils

    Souvent installées avec d'autres logiciels sans que l'utilisateur y fasse attention, les barres d'outils se multiplient sur les ordinateurs et ont deux résultats : ralentir les ordinateurs et provoquer des bugs des navigateurs.
    Je te conseille de désinstaller la tienne qui est inutile (barre d'outil Google).
    Pour ça, ferme ton navigateur, puis Menu démarrer --> Panneau de configuration --> ajout/suppression de programmes --> désinstalle la Google Toolbar.

    2) Sécurise ton ordinateur

    • Anti-virus :
    Norton est lourd, cher, et malgré tout peu efficace ! Je te conseille vivement de le supprimer et d’utiliser un antivirus plus efficace (Antivir, Kaspersky...). Il en existe des gratuits qui sont excellents aussi (Antivir ou AVG).
    Pour supprimer Norton :
    Vide la quarantaine, puis désactive la protection résidente.
    Ensuite, clique sur Menu démarrer --> panneau de configuration --> ajout/suppression de programmes --> désinstalle tous les produits Norton et Symantec. Puis, utilise ceci pour supprimer les traces : Outil de désinstallation Norton

    Si tu choisis Antivir gratuit, télécharge le ici.
    Pour Antivir Premium (payant), c'est ici
    Pour Kaspersky, c'est ici

    • Anti-spyware :
    * Désinstalle Ad-Aware qui ne sert à rien (pas de protection résidente, un scan médiocre, et une consommation de mémoire permanente malgré tout...)
    * Installe Spyware Blaster : il ne prend pas de mémoire, c'est juste un logiciel qui vaccine ton pc contre certaines infections. Il faut le mettre à jour manuellement (« Updates »), tous les 15 jours environ, et activer toutes les protections (« Enable all protection »)
    * En complément, garde MalwareBytes pour son scan de nettoyage performant.

    • Pour naviguer sur internet plus en sécurité et à l’abri des publicités, je te conseille vivement d’installer et d'utiliser le navigateur Firefox. Une fois que c'est fait, lance le et installe les deux extensions de sécurité suivantes :
    AdBlockPlus pour bloquer les publicités ;
    WOT, pour t'avertir des sites web dangereux.

    • Java n'est pas à jour, c'est une faille de sécurité.
    Il faut d'abord désinstaller l'ancienne version : Ouvre le menu démarrer --> panneau de configuration --> ajout/suppression de programmes --> sélectionne toutes les versions de java présentes et désinstalle les.
    Ensuite, télécharge et installe la nouvelle version depuis le site officiel de java : https://java.com/fr/

    • Adobe Reader n’est pas à jour, c’est une faille de sécurité. Désinstalle le en allant dans menu démarrer --> panneau de configuration --> ajout/suppression de programmes. Puis télécharge et installe la nouvelle version.

    • Tu dois aussi mettre à jour tous tes autres programmes pour combler des failles de sécurité... Vérifie les mises disponibles à l'aide de ce petit programme (choisis la version sans installation) : Update Checker

    3) Relance Hijackthis (pour la dernière fois), choisis "scan system only" et coche les lignes suivantes qui sont inutiles (j'ai intégré les barres d'outils dans cette liste) :

    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
    O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

    Si tu as bien mis à jour Adobe Reader comme je te l'ai recommandé, cette ligne devrait apparaitre, tu peux la cocher : O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

    Coche également toutes les lignes commençant par 016

    Ensuite, clique sur "Fix checked"

    4) Télécharge ToolsCleaner sur ton Bureau pour nettoyer l'ordi de tous les outils qu'on a utilisé : ToolsCleaner
    Lance le, clique sur Recherche et laisse le scan se finir, puis clique sur Suppression pour nettoyer.
    Tu peux aussi supprimer les fichiers temporaires.
    Ensuite, supprime manuellement ToolsCleaner (mets le à la corbeille).
    S'il ne supprime pas tout, supprime manuellement ce qui reste.

    5) Télécharge et installe CCleaner (si ce n’est déjà fait) : https://www.ccleaner.com/ccleaner/download

    Lance CCleaner
    Clique sur Option --> avancé --> décoche « effacer uniquement les fichiers plus vieux que 48h »
    Puis Nettoyeur --> Analyse > Lancer le nettoyage, puis sur OK dans la fenêtre qui s' affiche.
    Enfin, Registre --> corrige toutes les erreurs, et recommence jusqu'à ce qu'il ne trouve plus d'erreurs.

    (Tu peux garder ce logiciel et l'utiliser régulièrement).

    6) Pour finir le nettoyage, il faut purger la restauration du système (pour supprimer les points de restauration infectés).

    • Fais un clic droit sur poste de travail (qui est sur ton Bureau ou dans le menu démarrer), puis propriétés.
    • Sélectionne l'onglet restauration du système
    • Coche l'option Désactiver la restauration du système sur tous les lecteurs
    • Clique sur OK.

    Puis refais la manipulation inverse pour réactiver la restauration système.

    7) Je t'invite enfin à visiter cette page qui t'apportera des informations de prévention et de protection contre les infections (environ 15 minutes de lecture très instructive et utile) : Prévention et sécurité sur internet

    Bonne lecture, bon courage, et n'hésite pas à poser des questions en cas de besoin ;)
    2
    1. Bonsoir

      Tout d'abord un immense merci pour le temps que vous avez passé et les informations de votre dernier mail.
      merci.
      Je vais suivre chacune des etapes.
      il y a un temps j'avais clean up qui me permettait d'éliminer les fichiers temporaires, mais maintenant il est payant donc.. est ce que ToolsCleaner en est un equivalent?

      Sinon il semble que tout ne soit pas réglé:
      - j'ai fais un scan avec Spyboot il me trouve toujours Virtumundo....
      - je n'arrive pas a désactiver la restauration système , l'option désactiver la restauration système est grisée...
      - enfin je voudrais desinstaller msn, mais je ne le vois pas dans les programmes installés?

      Désolé encore des questions....
      R
      0
    2. Rebonjour
      Merci pour votre email.
      pour ce qui est de fixer les lignes j'ai quelques questions: (desolé)
      Est ce qu'une fois les entrées fixeés le programme correspondant est inutilisable? est il automatiquement desintallé? ou seulement il ne se lancera plus au demarrage?
      En cas d'erreur peut on revenir en arriere? pdt combien de tps?

      Si cela elimine completement le programme, n'est il pas possible notamment pour le quicckset par exemple etc... d'empecher qu'il ne se lnce automatiquement, ou faut il l'eliminer?
      Merci bcp et desolée encore pour toutes ces questions, mais pour une fois que je peux les poser et obtenir de reponses claires, et bien j'en profite, desolé.
      R

      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll


      ayant desintallé la google toolbar, ces ligne sn'apparaissent plus.

      O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
      a quoi sert ce programme?

      O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
      ce n'est pas important?

      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      Avec ces deux lignes supprimées j'élimine l a mise anjour automatique du logiciel INSTALL shield c'est bien ca? Install shield est un logiciel qui crée des installateur de logiel? il n'est pas essentiel?
      si j'elimine la mise a jour, ne dois je pas elimine le programme en lui meme?

      O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
      Non utile?

      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

      "sert à gérer les entrées de saisie texte alternatives telles que les logiciels de reconnaissance de la voix (Speech recognition), les logiciels de reconnaissance d'écriture, les claviers braille ou toute alternative au clavier. " je n'en ai pas besoin?


      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

      OK

      O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
      OK
      O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
      OK
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      OK

      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      OK

      016
      OK
      0
  2. Contributeur sécurité
    ToolsCleaner supprime seulement les outils de désinfection, tu pourras t'en débarrasser après.
    C'est CCleaner qui est équivalent à Clean up et qui supprime les fichiers temporaires.

    Pour la restauration du système, une fois que tu auras fait tout le reste, fais ceci :
    Menu démarrer --> programmes --> Accessoires --> Outils système --> Nettoyage de disque
    S'il te le demande, choisis ton disque C, puis laisse le analyser le disque. Ensuite, rends toi dans "Autres options", et dans la partie "Restauration du système" clique sur "Nettoyer".

    Tu n'as apparemment pas MSN, mais uniquement Windows Messenger (différent de Windows Live Messenger). C'est la messagerie intégrée à Windows, on ne peut pas la désinstaller.
    Par contre, tu peux l'empêcher de se lancer automatiquement au démarrage en fixant la ligne suivante avec Hijackthis :
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    Pour Spybot, est-ce que tu peux faire un copié/collé complet de ce qu'il détecte stp ?

    1
    1. Contributeur sécurité
      Bonjour,

      Peux-tu utiliser ce logiciel de diagnostic stp, il est plus complet que hijackthis :

      • Télécharge Random's System Information Tool (RSIT) de random/random, et enregistre le sur ton Bureau.
      • Double clique sur RSIT.exe pour lancer l'outil.
      • Clique sur ' continue ' à l'écran Disclaimer.
      • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
      • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés

      Tutoriel illustré pour t'aider : https://www.androidworld.fr/

      0
      1. Bonjour Anthony

        Merci pour ton message
        j ai telecharge le logiciel et voici le rapport info.txt

        merci.

        info.txt logfile of random's system information tool 1.06 2009-04-29 20:23:52

        ======Uninstall list======

        -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
        -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        32 Bit HP BiDi Channel Components Installer-->MsiExec.exe /I{9DE3F260-B88E-42CE-90E7-73C78C37D95E}
        Ad-Aware-->"C:\Documents and Settings\All Users\Application Data\{2BAE6915-8510-4B9F-B498-02DA86258AA0}\Ad-AwareAE.exe" REMOVE=TRUE MODIFY=FALSE
        Ad-Aware-->C:\Documents and Settings\All Users\Application Data\{2BAE6915-8510-4B9F-B498-02DA86258AA0}\Ad-AwareAE.exe
        Adobe Acrobat 7.1.0 Standard - English, Français, Deutsch-->msiexec /I {AC76BA86-1033-F400-BA7E-100000000002}
        Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
        Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
        AuthenTec Fingerprint Sensor Minimum Install-->MsiExec.exe /I{EB4DF30B-102B-4F0C-927A-D50E037A325D}
        biolsp patch-->MsiExec.exe /I{9593C6E5-205E-45C3-B785-05CF146CA76A}
        Bluetooth Stack for Windows by Toshiba-->MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
        Broadcom ASF Management Applications-->MsiExec.exe /I{27E25625-DB51-42E6-BEB7-0C8DC878770C}
        Broadcom Management Programs-->MsiExec.exe /X{C99C0593-3B48-41D9-B42F-6E035B320449}
        Browser Address Error Redirector-->MsiExec.exe /I{62230596-37E5-4618-A329-0D21F529A86F}
        CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
        CleanUp-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\CleanUp\Uninst.isu"
        Conexant HDA D330 MDC V.92 Modem-->C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2C06&SUBSYS_14F1000F\UIU32m.exe -U -Idel000f5.INF
        Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
        Correctif pour Windows XP (KB961118)-->"C:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
        Data Access Objects (DAO) 3.5-->C:\Program Files\Fichiers communs\Microsoft Shared\DAO\Remove.EXE C:\WINDOWS\UNINST.EXE -fC:\PROGRA~1\FICHIE~1\MICROS~1\DAO\DeIsL1.isu
        Dell Drivers MSI-->MsiExec.exe /I{5EC5F187-9D2B-4051-8906-88656819A869}
        Dell Embassy Trust Suite by Wave Systems-->C:\WINDOWS\Downloaded Installations\{ABBA2EA4-740E-4052-902B-9CA70B081E3F}\Installer.exe
        Dell Touchpad-->C:\Program Files\DellTPad\Uninstap.exe ADDREMOVE
        DellSupport-->MsiExec.exe /X{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}
        Désinstallation du logiciel Lexmark-->C:\Program Files\Lexmark_HostCD\Install\Uninstall.exe
        Digital Line Detect-->C:\Program Files\InstallShield Installation Information\{E646DCF0-5A68-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x040c -removeonly
        Document Manager Lite-->C:\Program Files\InstallShield Installation Information\{51AE9E42-640D-4C14-A9B6-43F64AA4E3E2}\setup.exe -runfromtemp -l0x040c
        DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
        EMBASSY Security Center-->C:\Program Files\InstallShield Installation Information\{EEAFE1E5-076B-430A-96D9-B567792AFA88}\setup.exe -runfromtemp -l0x040c
        EMBASSY Security Setup-->C:\Program Files\InstallShield Installation Information\{53333479-6A52-4816-8497-5C52B67ED339}\setup.exe -runfromtemp -l0x040c
        EMBASSY Trust Suite by Wave Systems-->C:\Program Files\InstallShield Installation Information\{F1802FA6-54E9-4B24-BD2A-B50866819795}\setup.exe -runfromtemp -l0x040c -removeonly
        ESC Home Page Plugin-->C:\Program Files\InstallShield Installation Information\{E738A392-F690-4A9D-808E-7BAF80E0B398}\setup.exe -runfromtemp -l0x040c
        Free Easy Burner V 3.8-->"C:\Program Files\Free Easy Burner\unins000.exe"
        Gemalto-->MsiExec.exe /I{EF05BA0F-AC15-4D12-AC5C-276225F5E751}
        GemSafe Standard Edition 5.1-->MsiExec.exe /X{4BF18ED6-C888-4BCF-A4AF-AC7A16305BC1}
        Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_BDA1448D3D255554.exe" /uninstall
        Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
        High Definition Audio Driver Package - KB835221-->C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
        HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
        Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
        hp color LaserJet 4600 Uninstaller-->C:\Program Files\Hewlett-Packard\CLJ4600\Uninstall\unhp.exe ciuninst.ini
        HP LaserJet P4010_P4510 Series-->"C:\Program Files\Hewlett-Packard\Install Engines\HP LaserJet P4010_P4510 Series\setup.exe" /x
        Intel(R) Graphics Media Accelerator Driver-->C:\WINDOWS\system32\igxpun.exe -uninstall
        IntelliSonic Speech Enhancement-->MsiExec.exe /X{D9FCA292-1186-421F-8D93-9A5D272AD5D0}
        J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
        Kensington MouseWorks-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57764780-E33B-11D1-96ED-00A024A83A15}\setup.exe" -l0x40c -u
        LiveUpdate 3.1 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
        Logiciel Intel(R) PROSet/Wireless-->C:\WINDOWS\Installer\iProInst.exe
        Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
        mCore-->MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}
        mDrWiFi-->MsiExec.exe /I{F6090A17-0967-4A8A-B3C3-422A1B514D49}
        mHlpDell-->MsiExec.exe /I{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}
        Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
        Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
        Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
        Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{72AD53CC-CCC0-3757-8480-9EE176866A7C}
        Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
        Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - FRA-->MsiExec.exe /I{0BD83598-C2EF-3343-847B-7D2E84599128}
        Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
        Microsoft .NET Framework 3.5 Language Pack SP1 - fra-->MsiExec.exe /I{3E31821C-7917-367E-938E-E65FC413EA31}
        Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
        Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
        Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
        Microsoft Kernel-Mode Driver Framework Feature Pack 1.5-->"C:\WINDOWS\$NtUninstallWdf01005$\spuninst\spuninst.exe"
        Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
        Microsoft Office 2000 Professional-->MsiExec.exe /I{0001040C-78E1-11D2-B60F-006097C998E7}
        Microsoft Office Access Runtime (French) 2007-->MsiExec.exe /X{90120000-001C-040C-0000-0000000FF1CE}
        Microsoft Office Excel Viewer-->MsiExec.exe /I{95120000-003F-0409-0000-0000000FF1CE}
        Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
        Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
        Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
        mIWA-->MsiExec.exe /I{3E9D596A-61D4-4239-BD19-2DB984D2A16F}
        mLogView-->MsiExec.exe /I{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}
        mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
        Mobily Connect Card-->C:\PROGRA~1\MOBILY~1\Uninstall.exe
        Module linguistique Microsoft .NET Framework 3.5 SP1- fra-->c:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 Language Pack SP1 - fra\setup.exe
        Mozilla Firefox (3.0.10)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
        mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
        mPfWiz-->MsiExec.exe /I{90B0D222-8C21-4B35-9262-53B042F18AF9}
        mProSafe-->MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
        mSCfg-->MsiExec.exe /I{829CD169-E692-48E8-9BDE-A3E8D8B65538}
        mSSO-->MsiExec.exe /I{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}
        MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
        MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
        MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{1787603C-E6E3-42D4-8034-55F358486F1D}
        mWlsSafe-->MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
        mWMI-->MsiExec.exe /I{63DB9CCD-2B56-4217-9A3D-507AC78320CA}
        mZConfig-->MsiExec.exe /I{94658027-9F16-4509-BBD7-A59FE57C3023}
        neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
        NetWaiting-->C:\Program Files\InstallShield Installation Information\{3F92ABBB-6BBF-11D5-B229-002078017FBF}\setup.exe -runfromtemp -l0x040c -removeonly
        NTRU TCG Software Stack-->MsiExec.exe /I{FEC193E4-6C5F-40E9-A249-7D8C8404A9EC}
        Outil de diagnostic de modem-->MsiExec.exe /I{F63A3748-B93D-4360-9AD4-B064481A5C7B}
        PowerDVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{281ECE39-F043-492B-8337-F2E546B5604A}\Setup.exe" -l0x40c -cluninstall
        Preboot Manager-->MsiExec.exe /I{3A6BE9F4-5FC8-44BB-BE7B-32A29607FEF6}
        Private Information Manager-->C:\Program Files\InstallShield Installation Information\{0B0A2153-58A6-4244-B458-25EDF5FCD809}\setup.exe -runfromtemp -l0x040c
        QuickSet-->C:\Program Files\InstallShield Installation Information\{C5074CC4-0E26-4716-A307-960272A90040}\setup.exe -runfromtemp -l0x040c APPDRVNT4 -removeonly
        Roxio Creator Audio-->MsiExec.exe /I{83FFCFC7-88C6-41c6-8752-958A45325C82}
        Roxio Creator Copy-->MsiExec.exe /I{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
        Roxio Creator Data-->MsiExec.exe /I{0D397393-9B50-4c52-84D5-77E344289F87}
        Roxio Creator DE-->MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
        Roxio Creator Tools-->MsiExec.exe /I{0394CDC8-FABD-4ed8-B104-03393876DFDF}
        Roxio Drag-to-Disc-->MsiExec.exe /I{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}
        Roxio Express Labeler-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
        Roxio Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
        Secure Update-->C:\Program Files\InstallShield Installation Information\{D1E829E9-88B8-47C6-A75E-0D40E2C09D50}\setup.exe -runfromtemp -l0x040c
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
        Security Wizards-->C:\Program Files\InstallShield Installation Information\{EC84E3E6-C2D6-4DFB-81E0-448324C8FDF4}\setup.exe -runfromtemp -l0x040c
        Skype™ 3.6-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
        Sonic Activation Module-->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
        Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
        Stat/Transfer-->C:\PROGRA~1\STATTR~1\UNWISE.EXE C:\PROGRA~1\STATTR~1\INSTALL.LOG
        Stata 9-->MsiExec.exe /X{BCA47D24-273B-47B6-99CF-C4CFD1F3EFED}
        Symantec AntiVirus-->MsiExec.exe /I{50E125D1-88E5-48CE-80AE-98EC9698E639}
        Symantec KB-DocID:2003093015493306-->MsiExec.exe /I{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}
        Symantec Technical Support Web Controls-->MsiExec.exe /X{DDC63227-BA06-4855-B002-BDB49E9F677E}
        Trusted Drive Manager-->MsiExec.exe /I{A093D83F-429A-4AB2-A0CD-1F7E9C7B764A}
        tsp patch-->MsiExec.exe /I{24A494F3-5B5F-4183-9F7D-9CE82812C1FC}
        upekmsi-->MsiExec.exe /I{FBEC50B7-537C-4A0E-8B0B-F7A8F8BF13CE}
        Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
        Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
        VLC media player 0.9.9-->C:\Program Files\VideoLAN\VLC\uninstall.exe
        Wave Infrastructure Installer-->MsiExec.exe /I{ECC22AFA-B905-4A6A-8072-10F52B9E09B7}
        Wave Support Software-->C:\Program Files\InstallShield Installation Information\{07D618CD-B016-438A-ADC9-A75BD23F85CE}\setup.exe -runfromtemp -l0x040c
        Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
        Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
        WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
        XML Paper Specification Shared Components Language Pack 1.0-->"C:\WINDOWS\$NtUninstallXPSEPSCLP$\spuninst\spuninst.exe"

        ======Hosts File======

        127.0.0.1 www.007guard.com
        127.0.0.1 007guard.com
        127.0.0.1 008i.com
        127.0.0.1 www.008k.com
        127.0.0.1 008k.com
        127.0.0.1 www.00hq.com
        127.0.0.1 00hq.com
        127.0.0.1 010402.com
        127.0.0.1 www.032439.com
        127.0.0.1 032439.com

        ======Security center information======

        AV: Lavasoft Ad-Watch Live! Anti-Virus
        AV: Symantec AntiVirus Corporate Edition

        ======System event log======

        Computer Name: MJAUD
        Event Code: 6005
        Message: Le service d'Enregistrement d'événement a démarré.

        Record Number: 16305
        Source Name: EventLog
        Time Written: 20090318144627.000000+060
        Event Type: Informations
        User:

        Computer Name: MJAUD
        Event Code: 6009
        Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 3 Multiprocessor Free.

        Record Number: 16304
        Source Name: EventLog
        Time Written: 20090318144627.000000+060
        Event Type: Informations
        User:

        Computer Name: MJAUD
        Event Code: 6006
        Message: Le service d'Enregistrement d'événement a été arrêté.

        Record Number: 16303
        Source Name: EventLog
        Time Written: 20090317194058.000000+060
        Event Type: Informations
        User:

        Computer Name: MJAUD
        Event Code: 50
        Message: {L'écriture décalée a échoué}
        Windows n'a pas pu sauvegarder toutes les données pour le fichier hs. Les données ont été perdues.
        Cette erreur peut être due à une panne de votre matériel ou de votre connexion réseau. Essayez de sauvegarder ce fichier à un autre emplacement.

        Record Number: 16302
        Source Name: Fastfat
        Time Written: 20090317194028.000000+060
        Event Type: Avertissement
        User:

        Computer Name:
        Event Code: 26
        Message: Application popup : Windows - L'écriture décalée a échoué : Windows n'a pas pu sauvegarder toutes les données pour le fichier \Device\HarddiskVolume3. Les données ont été perdues. Cette erreur peut être due à une panne de votre matériel ou de votre connexion réseau. Essayez de sauvegarder ce fichier à un autre emplacement.

        Record Number: 16301
        Source Name: Application Popup
        Time Written: 20090317194027.000000+060
        Event Type: Informations
        User:

        =====Application event log=====

        Computer Name:
        Event Code: 3
        Message:

        Analyse lancée sur tous les lecteurs et toutes les extensions.

        Record Number: 9653
        Source Name: Symantec AntiVirus
        Time Written: 20090111134145.000000+060
        Event Type: Informations
        User:

        Computer Name:
        Event Code: 2002
        Message:
        Record Number: 9652
        Source Name: EAPOL
        Time Written: 20090111134142.000000+060
        Event Type: Informations
        User:

        Computer Name:
        Event Code: 2003
        Message:
        Record Number: 9651
        Source Name: EAPOL
        Time Written: 20090111134142.000000+060
        Event Type: Informations
        User:

        Computer Name:
        Event Code: 16
        Message:

        Téléchargement du fichier de définitions de virus à partir de Serveur LiveUpdate réussi.

        Record Number: 9650
        Source Name: Symantec AntiVirus
        Time Written: 20090111134119.000000+060
        Event Type: Informations
        User:

        Computer Name:
        Event Code: 7
        Message:

        Nouveau fichier de définitions de virus chargé. Version : 110110c.

        Record Number: 9649
        Source Name: Symantec AntiVirus
        Time Written: 20090111134109.000000+060
        Event Type: Informations
        User:

        ======Environment variables======

        "ComSpec"=%SystemRoot%\system32\cmd.exe
        "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\;C:\Program Files\Wave Systems Corp\Gemalto\Access Client\v5\;C:\Program Files\Gemplus\GemSafe Libraries\BIN;C:\Program Files\Fichiers communs\Roxio Shared\DLLShared\
        "windir"=%SystemRoot%
        "FP_NO_HOST_CHECK"=NO
        "OS"=Windows_NT
        "PROCESSOR_ARCHITECTURE"=x86
        "PROCESSOR_LEVEL"=6
        "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
        "PROCESSOR_REVISION"=0f0d
        "NUMBER_OF_PROCESSORS"=2
        "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        "TEMP"=%SystemRoot%\TEMP
        "TMP"=%SystemRoot%\TEMP
        "RoxioCentral"=C:\Program Files\Fichiers communs\Roxio Shared\9.0\Roxio Central33\

        -----------------EOF-----------------
        0
        1. Voici le rapport log.txt

          merci
          Logfile of random's system information tool 1.06 (written by random/random)
          Run by at 2009-04-29 20:23:28
          Microsoft Windows XP Professionnel Service Pack 3
          System drive C: has 104 GB (68%) free of 152 GB
          Total RAM: 2038 MB (66% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 8:23:48 PM, on 4/29/2009
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16827)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
          C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
          C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
          C:\Program Files\Symantec AntiVirus\DefWatch.exe
          C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          C:\WINDOWS\system32\StacSV.exe
          C:\Program Files\Symantec AntiVirus\Rtvscan.exe
          C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\WINDOWS\explorer.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Symantec AntiVirus\VPC32.exe
          C:\Documents and Settings\\Bureau\RSIT.exe
          C:\Program Files\Trend Micro\HijackThis\.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=6080415
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/hws/sb/dell-row-rel/fr/side.html?channel=fr
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr/hws/sb/dell-row-rel/fr/side.html?channel=fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=6080415
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www1.euro.dell.com/content/default.aspx?c=fr&l=fr&s=gen
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www1.euro.dell.com/content/default.aspx?c=fr&l=fr&s=gen
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/hws/sb/dell-row-rel/fr/side.html?channel=fr
          R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=6080415
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=6080415
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://revelec.inra.fr/revelec.pac
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
          O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
          O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
          O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
          O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
          O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
          O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
          O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
          O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
          O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
          O4 - HKLM\..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
          O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe
          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
          O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
          O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe
          O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
          O4 - HKLM\..\Run: [kmw_run.exe] kmw_run.exe
          O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
          O4 - HKLM\..\Run: [HP Network Registry Agent] C:\WINDOWS\system32\hpnra.exe
          O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Bluetooth Manager.lnk = ?
          O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
          O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
          O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
          O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
          O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
          O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
          O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
          O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
          O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
          O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O15 - Trusted Zone: http://wits.worldbank.org
          O15 - Trusted IP range: http://192.86.99.9
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
          O20 - Winlogon Notify: gemsafe - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll
          O23 - Service: Broadcom ASF IP and SMBIOS Mailbox Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
          O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
          O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
          O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
          O23 - Service: lmab_device - Lexmark International, Inc. - C:\WINDOWS\system32\LMabcoms.exe
          O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
          O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
          O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
          O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
          O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
          O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
          O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV.exe
          O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe
          O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
          O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
          O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
          O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
          O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe
          O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
          0
          1. Contributeur sécurité
            Il y a une infection de disque amovible :

            Télécharge UsbFix (de Chiquitine29 et C_XX) sur ton Bureau
            • Lance l'installation avec les paramètres par défaut
            • Branche tes sources de données externes à ton PC (clé USB, disque dur externe, lecteur mp3 etc...) sans les ouvrir
            • Double clique sur le raccourci UsbFix sur ton Bureau
            • Au menu principal, choisis l'option 1 (recherche)
            • Un rapport USBFix.txt apparaitra à la fin, poste le dans ta prochaine réponse stp

            Ensuite, fais ce scan de vérification stp :

            • Télécharge et installe Malwarebytes' Anti-Malware
            • A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée
            • Lance MBAM et laisse les Mises à jour se télécharger (sinon fais les manuellement au lancement du programme)
            • Puis va dans l'onglet "Recherche", coche "Exécuter un examen complet" puis "Rechercher"
            • Sélectionne tes disques durs" puis clique sur "Lancer l’examen"
            • A la fin du scan, clique sur Afficher les résultats
            • Coche tous les éléments détectés puis clique sur Supprimer la sélection
            • Enregistre le rapport
            • S'il t'est demandé de redémarrer, clique sur Yes

            • Poste dans ta prochaine réponse le rapport apparaissant après la suppression stp

            0
            1. Bonjour
              Desolé pour le retard je n'ai pas eu accés a internet avant.
              voici le rapport du scan de Malwarebyte. j'avais la version du 6 avril 2009.en effet mon pare feu empéchait la mise a jour maisje n'ai pas su autoriser le telechargement de la mise a jour pour Malware byte.
              J'ai regardé sur le site directement et j'ai vu que la derniere version du programme datait du 6 avril. si j'ai bien compris.

              Sinon j' ai telechargé Usbfix, mais le programme ne se lance pas, comme si il était bloqué par un virus.
              je viens de rallumer mon ordinateur aujour dhui, et la depuis 10 min symantec n'arrete pas de me detecter un trojan Backdoor.trojan.
              En fait le virus apparait reapparait et syumantec essaye de l'eliminer.
              Mon ordinateur est a 100% d'utilisation de l'UC....
              Donc je ne sais plus quoi faire, ca ne va pas mieux du tout.
              Toujours pas accés au registre etc.
              Je us un peu désepérée et inquiète surtout.

              merci de ton aide.

              Malwarebytes' Anti-Malware 1.36
              Version de la base de données: 1945
              Windows 5.1.2600 Service Pack 3

              5/2/2009 12:59:47 PM
              mbam-log-2009-05-02 (12-59-47).txt

              Type de recherche: Examen complet (C:\|D:\|E:\|F:\|)
              Eléments examinés: 159616
              Temps écoulé: 50 minute(s), 39 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 1
              Valeur(s) du Registre infectée(s): 0
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 0

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{ce7c3cf0-4b15-11d1-abed-709549c10000} (Trojan.BHO) -> Quarantined and deleted successfully.

              Valeur(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              (Aucun élément nuisible détecté)
              0
            2. Rapport USBFIX, scan mode normal,

              merci

              ############################## [ UsbFix V3.016 # Scan ]

              # User : (Administrateurs) #
              # Update on 02/05/09 by Chiquitine29, C_XX & Chimay8
              # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
              # Start at: 6:40:32 PM | 5/3/2009

              # Intel(R) Core(TM)2 Duo CPU T7250 @ 2.00GHz
              # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
              # Internet Explorer 8.0.6001.18702
              # Windows Firewall Status : Enabled
              # AV : Lavasoft Ad-Watch Live! Anti-Virus [ Enabled | Updated ]
              # AV : Symantec AntiVirus Corporate Edition 10.1.6.6000 [ Enabled | Updated ]

              # C:\ # Disque fixe local # 148.87 Go (101.45 Go free) # NTFS
              # D:\ # Disque CD-ROM
              # E:\ # Disque amovible # 1.86 Go (1.85 Go free) [STORE'N'GO] # FAT
              # F:\ # Disque fixe local # 465.65 Go (344.75 Go free) [IOMEGA_HDD] # FAT32

              ############################## [ Processus actifs ]

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
              C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
              C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\System32\SCardSvr.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
              C:\Program Files\Symantec AntiVirus\DefWatch.exe
              C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
              C:\WINDOWS\system32\StacSV.exe
              C:\Program Files\Symantec AntiVirus\Rtvscan.exe
              C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
              C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
              C:\WINDOWS\system32\dllhost.exe
              C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\WINDOWS\system32\wbem\unsecapp.exe
              C:\WINDOWS\system32\dllhost.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\WINDOWS\system32\msdtc.exe
              C:\WINDOWS\System32\alg.exe
              C:\WINDOWS\system32\igfxsrvc.exe
              C:\WINDOWS\system32\igfxpers.exe
              C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
              C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
              C:\Program Files\Dell\QuickSet\quickset.exe
              C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
              C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
              C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
              C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
              C:\WINDOWS\system32\KADxMain.exe
              C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
              C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
              C:\PROGRA~1\SYMANT~1\vptray.exe
              C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
              C:\WINDOWS\system32\kmw_run.exe
              C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
              C:\WINDOWS\system32\hpnra.exe
              C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
              C:\WINDOWS\system32\KMW_SHOW.EXE
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\DellSupport\DSAgnt.exe
              C:\Program Files\Symantec AntiVirus\DoScan.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
              C:\Program Files\Digital Line Detect\DLG.exe
              C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
              C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
              C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
              C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
              C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe

              ################## [ Registre # Startup ]

              HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
              HKCU_Main: "Search Page"="http://www.google.fr/hws/sb/dell-row-rel/fr/side.html?channel=fr"
              HKCU_Main: "Start Page"="https://www.google.fr"
              HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
              HKLM_logon: "DefaultUserName"=""
              HKLM_logon: "AltDefaultUserName"=""
              HKLM_logon: "LegalNoticeCaption"=""
              HKLM_logon: "LegalNoticeText"=""
              HKLM_Run: Apoint=C:\Program Files\DellTPad\Apoint.exe
              HKLM_Run: IgfxTray=C:\WINDOWS\system32\igfxtray.exe
              HKLM_Run: HotKeysCmds=C:\WINDOWS\system32\hkcmd.exe
              HKLM_Run: Persistence=C:\WINDOWS\system32\igfxpers.exe
              HKLM_Run: SunJavaUpdateSched=C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
              HKLM_Run: SigmatelSysTrayApp=%ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
              HKLM_Run: Dell QuickSet=C:\Program Files\Dell\QuickSet\quickset.exe
              HKLM_Run: IntelZeroConfig="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
              HKLM_Run: IntelWireless="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
              HKLM_Run: WavXMgr=C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
              HKLM_Run: SecureUpgrade=C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
              HKLM_Run: KADxMain=C:\WINDOWS\system32\KADxMain.exe
              HKLM_Run: ISUSPM Startup=C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
              HKLM_Run: ISUSScheduler="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
              HKLM_Run: PDVDDXSrv="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
              HKLM_Run: ECenter=C:\Dell\E-Center\EULALauncher.exe
              HKLM_Run: ccApp="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
              HKLM_Run: vptray=C:\PROGRA~1\SYMANT~1\\vptray.exe
              HKLM_Run: Acrobat Assistant 7.0="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
              HKLM_Run: kmw_run.exe=kmw_run.exe
              HKLM_Run: MSWheel=
              HKLM_Run: RoxioDragToDisc="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
              HKLM_Run: CleanUp=
              HKLM_Run: HP Network Registry Agent=C:\WINDOWS\system32\hpnra.exe
              HKLM_Run: Ad-Watch=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
              HKLM_Run: MSConfig=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
              HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
              HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
              HKCU_Run: DellSupport="C:\Program Files\DellSupport\DSAgnt.exe" /startup
              HKCU_Run: MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background
              HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

              ################## [ Informations ]

              ################## [ Fichiers # Dossiers infectieux ]

              ################## [ Registre # Clés Run infectieuses ]

              ################## [ Registre # Mountpoints2 ]

              HKCU\Software\Microsoft\....\MountPoints2\{0cc20dc1-05ad-11de-9cac-001e37c5d638}\Shell\AutoRun\command
              HKCU\Software\Microsoft\....\MountPoints2\{0cc20dc5-05ad-11de-9cac-001e37c5d638}\Shell\AutoRun\command
              HKCU\Software\Microsoft\....\MountPoints2\{0cc20dc6-05ad-11de-9cac-001c23478a89}\Shell\AutoRun\command
              HKCU\Software\Microsoft\....\MountPoints2\{0cc20dc7-05ad-11de-9cac-001c23478a89}\Shell\AutoRun\command
              HKCU\Software\Microsoft\....\MountPoints2\{1ae0be7a-9070-11dd-9bed-001e37c5d638}\Shell\AutoRun\command
              HKCU\Software\Microsoft\....\MountPoints2\{e205e9f4-0680-11de-9cae-001e37c5d638}\Shell\AutoRun\command
              HKCU\Software\Microsoft\....\MountPoints2\{e205e9f5-0680-11de-9cae-001e37c5d638}\Shell\AutoRun\command

              ################## [ ! Fin du rapport # UsbFix V3.016 ! ]
              0
          2. merci je fais cela et je vous poste le rapport
            j ai en effet un disque dur externe et un cle usb, qui elle a été detectee comme infectée par mon ordinateur

            merci bcp.
            bon 1er mai
            0
            1. Contributeur sécurité
              "J'ai regardé sur le site directement et j'ai vu que la derniere version du programme datait du 6 avril. si j'ai bien compris. "

              ==> il y a plusieurs mises à jour par jour pour MalwareBytes, la dernière version de la base de donnée ne date pas du 6 avril mais d'aujourd'hui ;)

              Peux-tu réessayer stp ? S'il le faut, désactive ton pare-feu pour faire la mise à jour.

              Pour USBFix, supprime le.
              Ensuite, désactive tes logiciels de protections temporairement, puis retourne le télécharger et réessaye stp

              0
              1. Bonsoir Anthony,

                Alors depuis mon dernier message et avant de lire le tien,
                -j'ai scanné mon ordinateur en mode sans echec avec SAV
                SAV systeme auto-protect avait identifié comme je te le disais dans mon dernier msg, plein de copies du vers Backdoor.trojan et me conseillait de redemarrer pour que les risques soient definitivement eliminés.

                - j'ai scanné mon ordi +clé USB+ disque dur externe avec USBfix, qui cette fois marchait
                je te poste le rapport plus bas

                J'ai ensuite rallumé mon ordi en mode normal et la:
                - acces au registre retablit
                - demarrage de SAV naturel
                - systeme SAV auto protect m'indique que tous les tojan back door ont ete eliminés.

                en gros tout ce qui semblait ne plus fontionner, refonctionne....
                comme cela me semble trop beau pour etre vrai, j'ai suivi les conseils de ton mail,
                1/ j'ai mis a jour Malware, (la mise a jour s'est faite automatiquement sans que j'ai besoin de modifier les pptés de mon parefeu, est ce normal?)
                je mets le rapport dans le prochain msg

                2/j'ai relancé un scan avec usbfix, que j'ai retéléchagé
                je mets le rapport dans le prochain msg

                Merci
                ############################## [ UsbFix V3.015 # Scan ]

                # User : () #
                # Update on 30/04/09 by Chiquitine29, C_XX & Chimay8
                # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
                # Start at: 2:31:12 PM | 5/3/2009

                # Intel(R) Core(TM)2 Duo CPU T7250 @ 2.00GHz
                # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                # Internet Explorer 7.0.5730.13
                # Windows Firewall Status : Disabled
                # AV : Lavasoft Ad-Watch Live! Anti-Virus [ Enabled | Updated ]
                # AV : Symantec AntiVirus Corporate Edition 10.1.6.6000 [ Enabled | Updated ]

                # C:\ # Disque fixe local # 148.87 Go (103.65 Go free) # NTFS
                # D:\ # Disque CD-ROM
                # E:\ # Disque amovible # 1.86 Go (1.85 Go free) [STORE'N'GO] # FAT
                # F:\ # Disque fixe local # 465.65 Go (344.75 Go free) [IOMEGA_HDD] # FAT32

                ############################## [ Processus actifs ]

                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\wbem\unsecapp.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Symantec AntiVirus\VPC32.exe
                C:\Program Files\Microsoft Office\Office\WINWORD.EXE
                C:\WINDOWS\system32\wbem\wmiprvse.exe

                ################## [ Registre # Startup ]

                HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                HKCU_Main: "Search Page"="http://www.google.fr/hws/sb/dell-row-rel/fr/side.html?channel=fr"
                HKCU_Main: "Start Page"="https://www.google.fr"
                HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                HKLM_logon: "DefaultUserName"=""
                HKLM_logon: "AltDefaultUserName"=""
                HKLM_logon: "LegalNoticeCaption"=""
                HKLM_logon: "LegalNoticeText"=""
                HKLM_Run: Apoint=C:\Program Files\DellTPad\Apoint.exe
                HKLM_Run: IgfxTray=C:\WINDOWS\system32\igfxtray.exe
                HKLM_Run: HotKeysCmds=C:\WINDOWS\system32\hkcmd.exe
                HKLM_Run: Persistence=C:\WINDOWS\system32\igfxpers.exe
                HKLM_Run: SunJavaUpdateSched=C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                HKLM_Run: SigmatelSysTrayApp=%ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
                HKLM_Run: Dell QuickSet=C:\Program Files\Dell\QuickSet\quickset.exe
                HKLM_Run: IntelZeroConfig="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
                HKLM_Run: IntelWireless="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
                HKLM_Run: WavXMgr=C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
                HKLM_Run: SecureUpgrade=C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
                HKLM_Run: KADxMain=C:\WINDOWS\system32\KADxMain.exe
                HKLM_Run: ISUSPM Startup=C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                HKLM_Run: ISUSScheduler="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                HKLM_Run: PDVDDXSrv="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
                HKLM_Run: ECenter=C:\Dell\E-Center\EULALauncher.exe
                HKLM_Run: ccApp="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                HKLM_Run: vptray=C:\PROGRA~1\SYMANT~1\\vptray.exe
                HKLM_Run: Acrobat Assistant 7.0="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
                HKLM_Run: kmw_run.exe=kmw_run.exe
                HKLM_Run: MSWheel=
                HKLM_Run: RoxioDragToDisc="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
                HKLM_Run: CleanUp=
                HKLM_Run: HP Network Registry Agent=C:\WINDOWS\system32\hpnra.exe
                HKLM_Run: Ad-Watch=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                HKLM_Run: KernelFaultCheck=%systemroot%\system32\dumprep 0 -k
                HKLM_Run: MSConfig=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
                HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
                HKCU_Run: DellSupport="C:\Program Files\DellSupport\DSAgnt.exe" /startup
                HKCU_Run: MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background
                HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

                ################## [ Informations ]

                ################## [ Fichiers # Dossiers infectieux ]

                ################## [ Registre # Clés Run infectieuses ]

                ################## [ Registre # Mountpoints2 ]

                HKCU\Software\Microsoft\....\MountPoints2\{0cc20dc1-05ad-11de-9cac-001e37c5d638}\Shell\AutoRun\command
                HKCU\Software\Microsoft\....\MountPoints2\{0cc20dc5-05ad-11de-9cac-001e37c5d638}\Shell\AutoRun\command
                HKCU\Software\Microsoft\....\MountPoints2\{0cc20dc6-05ad-11de-9cac-001c23478a89}\Shell\AutoRun\command
                HKCU\Software\Microsoft\....\MountPoints2\{0cc20dc7-05ad-11de-9cac-001c23478a89}\Shell\AutoRun\command
                HKCU\Software\Microsoft\....\MountPoints2\{1ae0be7a-9070-11dd-9bed-001e37c5d638}\Shell\AutoRun\command
                HKCU\Software\Microsoft\....\MountPoints2\{e205e9f4-0680-11de-9cae-001e37c5d638}\Shell\AutoRun\command
                HKCU\Software\Microsoft\....\MountPoints2\{e205e9f5-0680-11de-9cae-001e37c5d638}\Shell\AutoRun\command

                ################## [ ! Fin du rapport # UsbFix V3.015 ! ]
                0
                1. Contributeur sécurité
                  Ok, par contre tu n'as pas posté le nouveau rapport de MalwareBytes ?

                  Pour USBFix :

                  • Branche tous tes disques amovibles (clés USB, lecteurs mp3, disques durs externes, iPod...) et clique sur OK.
                  • Relance USBFix
                  • Choisis cette fois l'option 2 (Suppression)
                  • Ton Bureau va disparaitre, puis l'ordinateur va redémarrer --> c'est normal
                  • Laisse travailler l'outil jusqu'au bout
                  • A la fin, le rapport USBFix.txt va s'afficher --> poste le dans ta prochaine réponse stp

                  0
                  1. Voila le scann de Malwarebyte vient de se terminer
                    voila le rapport

                    Malwarebytes' Anti-Malware 1.36
                    Version de la base de données: 2070
                    Windows 5.1.2600 Service Pack 3

                    5/3/2009 8:19:14 PM
                    mbam-log-2009-05-03 (20-19-14).txt

                    Type de recherche: Examen complet (C:\|D:\|E:\|F:\|)
                    Eléments examinés: 173103
                    Temps écoulé: 1 hour(s), 6 minute(s), 21 second(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 0
                    Valeur(s) du Registre infectée(s): 0
                    Elément(s) de données du Registre infecté(s): 0
                    Dossier(s) infecté(s): 0
                    Fichier(s) infecté(s): 0

                    Processus mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Valeur(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Elément(s) de données du Registre infecté(s):
                    (Aucun élément nuisible détecté)

                    Dossier(s) infecté(s):
                    (Aucun élément nuisible détecté)

                    Fichier(s) infecté(s):
                    (Aucun élément nuisible détecté)
                    0
                  2. voici le rapport de USBfix avec option 2-suppression

                    merci de votre aide
                    ############################## [ UsbFix V3.016 # Cleaning ]

                    # User : (Administrateurs) #
                    # Update on 02/05/09 by Chiquitine29, C_XX & Chimay8
                    # WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
                    # Start at: 8:26:41 PM | 5/3/2009

                    # Intel(R) Core(TM)2 Duo CPU T7250 @ 2.00GHz
                    # Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                    # Internet Explorer 8.0.6001.18702
                    # Windows Firewall Status : Enabled
                    # AV : Lavasoft Ad-Watch Live! Anti-Virus [ Enabled | Updated ]
                    # AV : Symantec AntiVirus Corporate Edition 10.1.6.6000 [ Enabled | Updated ]

                    # C:\ # Disque fixe local # 148.87 Go (101.46 Go free) # NTFS
                    # D:\ # Disque CD-ROM
                    # E:\ # Disque amovible # 1.86 Go (1.85 Go free) [STORE'N'GO] # FAT
                    # F:\ # Disque fixe local # 465.65 Go (344.75 Go free) [IOMEGA_HDD] # FAT32

                    ############################## [ Processus actifs ]

                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\csrss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                    C:\WINDOWS\system32\logonui.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\System32\SCardSvr.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
                    C:\Program Files\Symantec AntiVirus\DefWatch.exe
                    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                    C:\WINDOWS\system32\StacSV.exe
                    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
                    C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
                    C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
                    C:\WINDOWS\system32\dllhost.exe
                    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                    C:\WINDOWS\system32\dllhost.exe
                    C:\WINDOWS\system32\wbem\unsecapp.exe
                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                    C:\WINDOWS\System32\alg.exe
                    C:\WINDOWS\system32\msdtc.exe
                    C:\WINDOWS\Explorer.EXE

                    ################## [ Fichiers # Dossiers infectieux ]

                    ################## [ Registre # Clés Run infectieuses ]

                    ################## [ Registre # Mountpoints2 ]

                    Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{0cc20dc1-05ad-11de-9cac-001e37c5d638}\Shell\AutoRun\command
                    Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{0cc20dc5-05ad-11de-9cac-001e37c5d638}\Shell\AutoRun\command
                    Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{0cc20dc6-05ad-11de-9cac-001c23478a89}\Shell\AutoRun\command
                    Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{0cc20dc7-05ad-11de-9cac-001c23478a89}\Shell\AutoRun\command
                    Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{1ae0be7a-9070-11dd-9bed-001e37c5d638}\Shell\AutoRun\command
                    Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{e205e9f4-0680-11de-9cae-001e37c5d638}\Shell\AutoRun\command
                    Deleted ! HKCU\Software\Microsoft\....\MountPoints2\{e205e9f5-0680-11de-9cae-001e37c5d638}\Shell\AutoRun\command

                    ################## [ Listing des fichiers présent ]

                    [05/03/2009 08:25 PM|--a------|4700] - C:\aaw7boot.log
                    [08/19/2004 02:18 PM|--a------|0] - C:\AUTOEXEC.BAT
                    [05/03/2009 06:09 PM|-rahs----|212] - C:\boot.ini
                    [08/05/2004 01:00 PM|-rahs----|4952] - C:\Bootfont.bin
                    [08/19/2004 02:18 PM|--a------|0] - C:\CONFIG.SYS
                    [?|?|?] - C:\hiberfil.sys
                    [10/29/2008 06:44 PM|--a------|4128] - C:\INFCACHE.1
                    [01/16/2009 05:29 PM|-rahs----|0] - C:\IO.SYS
                    [01/16/2009 05:29 PM|-rahs----|0] - C:\MSDOS.SYS
                    [08/05/2004 01:00 PM|-rahs----|47564] - C:\NTDETECT.COM
                    [05/07/2008 06:18 PM|-rahs----|252240] - C:\ntldr
                    [?|?|?] - C:\pagefile.sys
                    [01/09/2009 02:48 PM|--a------|94626570] - C:\SYM_REGISTRY_BACKUP.reg
                    [05/03/2009 08:27 PM|--a------|4281] - C:\UsbFix.txt
                    [04/28/2009 09:19 AM|--a------|50] - C:\winzip.log
                    [04/27/2009 11:10 AM|--a------|782336] - E:\27_04_09_MJ.ppt
                    [04/03/2009 03:12 PM|--a------|460473] - E:\cadot carrere kukenova strauss-kahn 2009-2.pdf
                    [02/26/2009 01:30 PM|--ah-----|4096] - E:\._.Trashes
                    [08/06/2008 09:23 AM|--a------|51712] - E:\euro-frch.xls
                    [04/17/2009 03:30 PM|--a------|570368] - E:\standards5_rev2.doc
                    [04/27/2009 11:11 AM|--a------|241077] - E:\27_04_09_MJ.pdf
                    [10/31/2008 11:11 AM|--a------|265] - F:\logOLS-Theil_hs8m_Madina_UNBAL22.log

                    ################## [ Vaccination ]

                    # C:\autorun.inf -> Folder created by UsbFix.
                    # E:\autorun.inf -> Folder created by UsbFix.
                    # F:\autorun.inf -> Folder created by UsbFix.

                    ################## [ Cracks / Keygens / Serials ]

                    # -> Nothing found !

                    ################## [ ! Fin du rapport # UsbFix V3.016 ! ]
                    0
                2. Contributeur sécurité
                  Très bien, poste un nouveau rapport RSIT, et dis moi si tu as encore des problème stp

                  0
                  1. Bonjour
                    voila le dernier rapport RSIT
                    Logfile of random's system information tool 1.06 (written by random/random)
                    Run by at 2009-05-04 08:43:12
                    Microsoft Windows XP Professionnel Service Pack 3
                    System drive C: has 104 GB (68%) free of 152 GB
                    Total RAM: 2038 MB (57% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 8:43:24 AM, on 5/4/2009
                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\hkcmd.exe
                    C:\WINDOWS\system32\igfxsrvc.exe
                    C:\WINDOWS\system32\igfxpers.exe
                    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                    C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
                    C:\Program Files\Dell\QuickSet\quickset.exe
                    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
                    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
                    C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
                    C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
                    C:\WINDOWS\system32\KADxMain.exe
                    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                    C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                    C:\PROGRA~1\SYMANT~1\vptray.exe
                    C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
                    C:\WINDOWS\system32\kmw_run.exe
                    C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
                    C:\WINDOWS\system32\hpnra.exe
                    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\DellSupport\DSAgnt.exe
                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    C:\WINDOWS\system32\KMW_SHOW.EXE
                    C:\Program Files\Symantec AntiVirus\DoScan.exe
                    C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
                    C:\Program Files\Symantec AntiVirus\DefWatch.exe
                    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
                    C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
                    C:\Program Files\Digital Line Detect\DLG.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                    C:\WINDOWS\system32\StacSV.exe
                    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
                    C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
                    C:\WINDOWS\system32\dllhost.exe
                    C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
                    C:\WINDOWS\system32\dllhost.exe
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
                    C:\Program Files\Symantec AntiVirus\VPC32.exe
                    C:\Program Files\Mozilla Firefox\firefox.exe
                    C:\Documents and Settings\\Bureau\Entretien\RSIT.exe
                    C:\Program Files\trend micro\.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=6080415
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/hws/sb/dell-row-rel/fr/side.html?channel=fr
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr/hws/sb/dell-row-rel/fr/side.html?channel=fr
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/hws/sb/dell-row-rel/fr/side.html?channel=fr
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row-rel&channel=fr&ibd=6080415
                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.fr
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL =
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
                    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
                    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                    O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
                    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                    O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
                    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
                    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
                    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
                    O4 - HKLM\..\Run: [WavXMgr] C:\Program Files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe
                    O4 - HKLM\..\Run: [SecureUpgrade] C:\Program Files\Wave Systems Corp\SecureUpgrade.exe
                    O4 - HKLM\..\Run: [KADxMain] C:\WINDOWS\system32\KADxMain.exe
                    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                    O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
                    O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\\vptray.exe
                    O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
                    O4 - HKLM\..\Run: [kmw_run.exe] kmw_run.exe
                    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
                    O4 - HKLM\..\Run: [HP Network Registry Agent] C:\WINDOWS\system32\hpnra.exe
                    O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
                    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - Global Startup: Bluetooth Manager.lnk = ?
                    O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                    O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
                    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                    O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                    O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                    O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                    O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                    O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                    O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                    O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                    O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O15 - Trusted Zone:
                    O15 - Trusted IP range:
                    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{E1C387A6-A160-47FD-94BF-60C94E29ADF9}: NameServer = 129.199.96.11
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                    O20 - Winlogon Notify: gemsafe - C:\Program Files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll
                    O23 - Service: Broadcom ASF IP and SMBIOS Mailbox Monitor (ASFIPmon) - Broadcom Corporation - C:\Program Files\Broadcom\ASFIPMon\AsfIpMon.exe
                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
                    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
                    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                    O23 - Service: lmab_device - Lexmark International, Inc. - C:\WINDOWS\system32\LMabcoms.exe
                    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
                    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
                    O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Secure Storage Manager\SecureStorageService.exe
                    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                    O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\StacSV.exe
                    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe
                    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
                    O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\FICHIE~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                    O23 - Service: NTRU TSS v1.2.1.25 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe
                    O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Trusted Drive Manager\TdmService.exe
                    O23 - Service: WaveEnrollmentService - Wave Systems Corp. - C:\Program Files\Wave Systems Corp\Authentication Manager\WaveEnrollmentService.exe
                    O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
                    0
                  2. Re bonjour

                    Je n'ai plus de problème apparent mais est ce que j'ai bien tout éliminé?
                    comment en être sure?

                    - pour finir par quel virus étais je infecté?

                    - en particulier n'y a t'il aucune entrée registre a supprimer?
                    j'avais ete infecté il y a quelques temps par trojan.hachilem, mais SAV semblait s'en etre debarrassé, mais symantec suggérait d'eliminer des entree dans le registre correspondant au virus
                    donc peut etre en est il de meme dans ce cas ci.

                    - puis je rétablir la restauration système?
                    - pour le virus virtumundo, pour finir étais je bien infecté par ce virus? ou pas?car j'avais lu qu'il etait difficile a éliminer.

                    - enfin j'ai sur mon ordinateur, a la fois spyboot, et ad_aware. a prirori ils ne sont pas incompatibles. ,Mais auparavant Spyboot se lancait tout seul et assurait une protection en trame de fond, indiquant quand un processus essayait notamment de modifier une cle du regsitre. mais il ne le fait plus, est ce parce que j'ai installé Ad _aware?

                    Désolée pour toutes ces questions, mais je souhaiterais pouvoir me protéger au mieux dans l'avenir. Et votre aide est vraiment très utile.

                    Merci encore

                    R
                    0
                  3. Je viens de faire un scan avec spyboot
                    et il trouve encore une infection par virtumundo, comment faire pour l'eliminer.

                    merci encore
                    R
                    0
                3. 1/pour la restauration syteme est ce que cela peut etre du a un virus?

                  2/Scan spyboot

                  A/voici le log file de spyboot, scan de ce matin

                  --- Report generated: 2009-05-04 10:39 ---

                  Microsoft.Windows.Explorer: [SBI $A0C5C610] User settings (Registry change, fixed)
                  HKEY_USERS\S-1-5-21-4063445143-4225957295-2903901907-1005\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun

                  Microsoft.Windows.Explorer: [SBI $DA080EA7] User settings (Registry change, fixed)
                  HKEY_USERS\S-1-5-21-4063445143-4225957295-2903901907-1005\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions

                  Microsoft.Windows.System: [SBI $268E3020] Settings (Registry change, fixed)
                  HKEY_USERS\S-1-5-21-4063445143-4225957295-2903901907-1005\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind

                  Virtumonde: [SBI $92386332] Library (File, fixed)
                  C:\WINDOWS\system32\zipfldr.dll

                  --- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---

                  2008-01-28 blindman.exe (1.0.0.7)
                  2008-01-28 SDDelFile.exe (1.0.2.4)
                  2008-01-28 SDMain.exe (1.0.0.5)
                  2007-10-07 SDShred.exe (1.0.1.2)
                  2008-01-28 SDUpdate.exe (1.0.8.8)
                  2008-01-28 SDWinSec.exe (1.0.0.11)
                  2008-01-28 SpybotSD.exe (1.5.2.20)
                  2009-03-05 TeaTimer.exe (1.6.6.32)
                  2008-04-17 unins000.exe (51.49.0.0)
                  2008-01-28 Update.exe (1.4.0.6)
                  2008-10-22 advcheck.dll (1.6.2.13)
                  2007-04-02 aports.dll (2.1.0.0)
                  2007-11-17 DelZip179.dll (1.79.7.4)
                  2008-01-28 SDFiles.dll (1.5.1.19)
                  2008-09-15 SDHelper.dll (1.6.2.14)
                  2008-10-22 Tools.dll (2.1.6.8)
                  2009-03-25 Includes\Adware.sbi (*)
                  2009-04-28 Includes\AdwareC.sbi (*)
                  2009-01-22 Includes\Cookies.sbi (*)
                  2009-03-31 Includes\Dialer.sbi (*)
                  2009-04-21 Includes\DialerC.sbi (*)
                  2009-01-22 Includes\HeavyDuty.sbi (*)
                  2009-04-21 Includes\Hijackers.sbi (*)
                  2009-04-28 Includes\HijackersC.sbi (*)
                  2009-03-17 Includes\Keyloggers.sbi (*)
                  2009-04-28 Includes\KeyloggersC.sbi (*)
                  2004-11-29 Includes\LSP.sbi (*)
                  2009-04-07 Includes\Malware.sbi (*)
                  2009-04-28 Includes\MalwareC.sbi (*)
                  2009-03-25 Includes\PUPS.sbi (*)
                  2009-04-28 Includes\PUPSC.sbi (*)
                  2009-01-22 Includes\Revision.sbi (*)
                  2009-01-13 Includes\Security.sbi (*)
                  2009-04-21 Includes\SecurityC.sbi (*)
                  2008-06-03 Includes\Spybots.sbi (*)
                  2008-06-03 Includes\SpybotsC.sbi (*)
                  2009-04-07 Includes\Spyware.sbi (*)
                  2009-04-28 Includes\SpywareC.sbi (*)
                  2009-04-07 Includes\Tracks.uti
                  2009-04-29 Includes\Trojans.sbi (*)
                  2009-04-29 Includes\TrojansC.sbi (*)
                  2008-03-04 Plugins\Chai.dll
                  2008-03-05 Plugins\Fennel.dll
                  2008-02-26 Plugins\Mate.dll
                  2007-12-24 Plugins\TCPIPAddress.dll

                  B/Scan spyboot du 28 avril avec le meme virtumundo!!! qui change de nom

                  --- Report generated: 2009-04-28 13:56 ---

                  Microsoft.WindowsSecurityCenter.RegistryTools: [SBI $D60CD1E3] Settings (Registry change, fixed)
                  HKEY_USERS\S-1-5-21-4063445143-4225957295-2903901907-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableRegistryTools

                  Virtumonde: [SBI $92386332] Library (File, fixed)
                  C:\WINDOWS\system32\zipfldr.dll

                  DoubleClick: Tracking cookie (Internet Explorer: ) (Cookie, fixed)

                  BlueStreak: Tracking cookie (Internet Explorer: ) (Cookie, fixed)

                  Tradedoubler: Tracking cookie (Internet Explorer: ) (Cookie, fixed)

                  --- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---

                  2008-01-28 blindman.exe (1.0.0.7)
                  2008-01-28 SDDelFile.exe (1.0.2.4)
                  2008-01-28 SDMain.exe (1.0.0.5)
                  2007-10-07 SDShred.exe (1.0.1.2)
                  2008-01-28 SDUpdate.exe (1.0.8.8)
                  2008-01-28 SDWinSec.exe (1.0.0.11)
                  2008-01-28 SpybotSD.exe (1.5.2.20)
                  2009-03-05 TeaTimer.exe (1.6.6.32)
                  2008-04-17 unins000.exe (51.49.0.0)
                  2008-01-28 Update.exe (1.4.0.6)
                  2008-10-22 advcheck.dll (1.6.2.13)
                  2007-04-02 aports.dll (2.1.0.0)
                  2007-11-17 DelZip179.dll (1.79.7.4)
                  2008-01-28 SDFiles.dll (1.5.1.19)
                  2008-09-15 SDHelper.dll (1.6.2.14)
                  2008-10-22 Tools.dll (2.1.6.8)
                  2009-03-25 Includes\Adware.sbi (*)
                  2009-04-21 Includes\AdwareC.sbi (*)
                  2009-01-22 Includes\Cookies.sbi (*)
                  2009-03-31 Includes\Dialer.sbi (*)
                  2009-04-21 Includes\DialerC.sbi (*)
                  2009-01-22 Includes\HeavyDuty.sbi (*)
                  2009-04-21 Includes\Hijackers.sbi (*)
                  2009-04-21 Includes\HijackersC.sbi (*)
                  2009-03-17 Includes\Keyloggers.sbi (*)
                  2009-04-21 Includes\KeyloggersC.sbi (*)
                  2004-11-29 Includes\LSP.sbi (*)
                  2009-04-07 Includes\Malware.sbi (*)
                  2009-04-21 Includes\MalwareC.sbi (*)
                  2009-03-25 Includes\PUPS.sbi (*)
                  2009-03-31 Includes\PUPSC.sbi (*)
                  2009-01-22 Includes\Revision.sbi (*)
                  2009-01-13 Includes\Security.sbi (*)
                  2009-04-21 Includes\SecurityC.sbi (*)
                  2008-06-03 Includes\Spybots.sbi (*)
                  2008-06-03 Includes\SpybotsC.sbi (*)
                  2009-04-07 Includes\Spyware.sbi (*)
                  2009-04-21 Includes\SpywareC.sbi (*)
                  2009-04-07 Includes\Tracks.uti
                  2009-04-21 Includes\Trojans.sbi (*)
                  2009-04-21 Includes\TrojansC.sbi (*)
                  2008-03-04 Plugins\Chai.dll
                  2008-03-05 Plugins\Fennel.dll
                  2008-02-26 Plugins\Mate.dll
                  2007-12-24 Plugins\TCPIPAddress.dll

                  C/Scan du 27 avril pas de VIRTUMUNDO:

                  --- Report generated: 2008-04-27 12:29 ---

                  DoubleClick: Tracking cookie (Firefox: default) (Cookie, fixed)

                  Tradedoubler: Tracking cookie (Firefox: default) (Cookie, fixed)

                  Tradedoubler: Tracking cookie (Firefox: default) (Cookie, fixed)

                  --- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) ---

                  2008-01-28 blindman.exe (1.0.0.7)
                  2008-01-28 SDDelFile.exe (1.0.2.4)
                  2008-01-28 SDMain.exe (1.0.0.5)
                  2007-10-07 SDShred.exe (1.0.1.2)
                  2008-01-28 SDUpdate.exe (1.0.8.8)
                  2008-01-28 SDWinSec.exe (1.0.0.11)
                  2008-01-28 SpybotSD.exe (1.5.2.20)
                  2008-01-28 TeaTimer.exe (1.5.2.16)
                  2008-04-17 unins000.exe (51.49.0.0)
                  2008-01-28 Update.exe (1.4.0.6)
                  2008-01-28 advcheck.dll (1.5.4.5)
                  2007-04-02 aports.dll (2.1.0.0)
                  2007-11-17 DelZip179.dll (1.79.7.4)
                  2008-01-28 SDFiles.dll (1.5.1.19)
                  2008-01-28 SDHelper.dll (1.5.0.11)
                  2008-01-28 Tools.dll (2.1.3.3)
                  2008-04-16 Includes\Adware.sbi (*)
                  2008-04-24 Includes\AdwareC.sbi (*)
                  2008-04-24 Includes\Cookies.sbi (*)
                  2007-12-26 Includes\Dialer.sbi (*)
                  2008-04-24 Includes\DialerC.sbi (*)
                  2008-04-24 Includes\HeavyDuty.sbi (*)
                  2008-03-19 Includes\Hijackers.sbi (*)
                  2008-04-24 Includes\HijackersC.sbi (*)
                  2008-02-27 Includes\Keyloggers.sbi (*)
                  2008-04-24 Includes\KeyloggersC.sbi (*)
                  2004-11-29 Includes\LSP.sbi (*)
                  2008-04-22 Includes\Malware.sbi (*)
                  2008-04-24 Includes\MalwareC.sbi (*)
                  2008-03-26 Includes\PUPS.sbi (*)
                  2008-04-24 Includes\PUPSC.sbi (*)
                  2008-04-24 Includes\Revision.sbi (*)
                  2008-01-09 Includes\Security.sbi (*)
                  2008-04-24 Includes\SecurityC.sbi (*)
                  2008-04-16 Includes\Spybots.sbi (*)
                  2008-04-24 Includes\SpybotsC.sbi (*)
                  2008-04-16 Includes\Spyware.sbi (*)
                  2008-04-24 Includes\SpywareC.sbi (*)
                  2007-11-06 Includes\Tracks.uti
                  2008-04-24 Includes\Trojans.sbi (*)
                  2008-04-24 Includes\TrojansC.sbi (*)
                  2008-03-04 Plugins\Chai.dll
                  2008-03-05 Plugins\Fennel.dll
                  2008-02-26 Plugins\Mate.dll
                  2007-12-24 Plugins\TCPIPAddress.dll
                  0
                  1. Contributeur sécurité
                    C'est un faux-positif :

                    https://www.bleepingcomputer.com/filedb/zipfldr.dll-3192.html
                    https://www.processlibrary.com/en/search?q=zipfldr

                    Ce fichier n'est pas néfaste
                    Y a-t-il une possibilité de mettre le fichier en exception pour qu'il ne soit plus scanné par Spybot ?

                    0
                    1. Bonjour
                      Je pense que c'est possible je vais regarder dans les options spyboot

                      Mais est ce que le fait que la restauration système ne marche pas est lié a une infection?

                      Sinon j'ai effectué les opérations pour améliorer la securité de mon ordi.
                      1) Les barres d'outils OK
                      2) Sécurise ton ordinateur
                      je pense conserver SAV car c'est le logiciel que nous utilisons au bureau.
                      j'ai d autre pas desinstallé Ad aware et installé spyware blaster

                      ok pour firefox
                      Pour java j' ai simplement fait uen mise a jour sans desinstaller reinstaller.
                      Pour acrobat, je dispose de la version standard qui offre plus de fonctionalités que la simple version Reader. donc???

                      je continue...
                      merci encore
                      0
                  2. Contributeur sécurité
                    Re,

                    "je pense conserver SAV car c'est le logiciel que nous utilisons au bureau"

                    SAV ?

                    "Pour java j' ai simplement fait uen mise a jour sans desinstaller reinstaller"

                    Il faut impérativement désinstaller les anciennes versions de Java, car ça ne se fait pas tout seul, et ton ordinateur reste vulnérable si les anciennes versions sont toujours présentes.

                    Et pour répondre à ton dernier message :

                    Chaque ligne 04 du rapport indique des programmes qui se lancent automatiquement au démarrage de l'ordinateur, et les lignes que je t'ai indiqué correspondent toutes à des programmes qui ne sont pas essentiels au démarrage. Fixer ces lignes ne supprime pas ces programme, elle désactive seulement leur démarrage automatique.
                    0
                    1. Bonjour,
                      Désolé pour ma reponse tardive.

                      Merci bcp pour votres aide.

                      SAV=Symantec anti virus

                      Ok pour Java

                      Ok pour Ccleaner.

                      Il n'y a plus qu'une seule chose qui coince je n'arrive toujours a retablir la restauration systeme, la case a cicher est en grisée et non accéssible

                      Merci bcp
                      0
                    2. Bonjour,

                      Je ne sais pas si vous vous souvenez, j'avais eu un probleme de virus et d'acces a la base de registre, pour lequel vous m'aviez tres bien aidé.
                      Aussi etant donné que je rencontre de nouveau un probleme, je voulais savoir s'il etait possible de vous redemander directement conseil, ou vaut il mieux que je poste un message sur le forum directement?

                      Je vous remercie

                      R
                      0
                  3. Contributeur sécurité
                    Bonjour,

                    Ca dépend si c'est un problème qui entre dans la catégorie "Virus/Sécurité" ou non ;)
                    Si oui, tu peux poster ici en expliquant tes problèmes et en ajoutant un rapport RSIT.
                    Sinon, il faut ouvrir un nouveau sujet dans la catégorie adaptée à ton problème.

                    0
                    1. Bonjour, merci pour votre reponse
                      je pense qu'il s agit d un pblm virus, j ai ouvert un sujet tout a l heure dans la categorie Virus/securite il s'intitule "TROJAN/Error Parsing Framework v1.1.43222"
                      j y ai mis une description de mon pblm ainsi que le rapport de RSIT.

                      Est ce que je ferme le sujet "TROJAN/Error Parsing Framework v1.1.43222", et je recolle l information dans ce sujet ci "Acces bloquué..."?
                      merci

                      R
                      0