Lecture hijackthis + divers

Bonjour a tous,

je ne sais pas si je suis inscrite car mon adresse email ne marche pas quand je la transmets depuis mon pc maison ????? de quel genre de problème s'agit - il ?

comme depuis quelques temps je rencontrais des pb avec mon pc, j'ai visité plusieurs sites et je suis tombée à plusieurs reprises sur vous (vous etes tres bien construits et tres competents !)

j'ai scanné et nettoye mon pc avec kaspersky, ad adware, spyboot, ccleaner, edwito avec l'aide de votre site et les 2 derniers logiciels me manquaient ... merci a vous

j'ai egalement fait une analyse avec hijack This et voici le rapport :

Logfile of HijackThis v1.99.1
Scan saved at 08:24:11, on 06/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\SpyBro\SpyBro.exe
C:\Program Files\WinTV\Ir.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\HP_Propriétaire\Bureau\WINWORD.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\HP_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\O9UVOPEF\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q105&bd=pavil...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q105&bd=pavil...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AutoTBar] c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
O4 - HKCU\..\Run: [SpyBrowser] "C:\Program Files\SpyBro\SpyBro.exe" /autostart
O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
O4 - Global Startup: desktop(2).ini
O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - https://www.pandasecurity.com/?ref=www.pandasoftware.com/activescan/fr/activescan_principal.htm (file missing)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\program files\bulletproofsoft.com\bps spyware & adware remover\apptoport.dll
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {FD40EC41-D860-4579-8BA4-52671A45C71C} (AxHtChat Class) - http://images.goa.com/it/Woo2/fr/chat/nPaxChat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{1D55BC99-6DCB-4AE5-B1BC-2D964078FC07}: NameServer = 212.151.136.242 212.151.137.170
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

merci pour votre aide qui vu mon illetrisme informatique me sera tres utile...
a tres bientot,
Atomixte

44 réponses

Résumé de la discussion

Un utilisateur signale un problème d'inscription et une adresse email qui ne fonctionne pas depuis son PC domestique, accompagné de ralentissements et d'inquiétudes liées à une potentielle infection suite à plusieurs analyses. Plusieurs outils de sécurité, dont Kaspersky, Ad-Aware, Spybot, Ewido et Avast, ont été exécutés, mais le rapport HijackThis révèle de nombreuses entrées indésirables et des éléments démarrant au boot, notamment SweetIM et SpyBro. Des mesures complémentaires suggérées incluent la suppression des objets de démarrage suspects, la vérification des barres d'outils et des BHO, puis une nouvelle passe de nettoyage avec des outils actualisés et des redémarrages répétés. D'autres analyses pourraient être utiles afin d'éliminer les résidus, notamment des vérifications sur les configurations réseau et les extensions de navigateur, afin de prévenir de futures réinfections et de stabiliser le système.

Bobot (l’IA à votre service)
  1. Bonjour,
    tu as ici un site qui te permettra de faire une analyse, tu copies le log dans la case blanche et tu évalues:
    http://www.hijackthis.de/fr
    0
    1. Contributeur
      hello
      analyse peu fiable par le robot :
      - ne relève pas les infections profondes
      - signale souvent des choses mauvaises alors qu il n en est rien
      donc
      ne pas faire confiance
      0
  2. Merci de m'avoir répondu RCT83,

    j'avais été sur le site d'evaluation mais j'ai lu que le résultat d'analyse n'était pas completement fiable aussi j'ai demandé l'aide d'yeux beaucoup plus avertis....

    en tout cas, merci encore pour l'intéret que tu m'as porté...

    a bientot

    atomixte
    0
    1. Contributeur
      slt,

      Exact pour l'evaluation...

      Redémarres le PC en mode sans échec : tu tapotes sur la touche F8 de ton clavier (ou F5 ) et tu choisis le mode sans échec :

      Ensuite :

      ¤ Lancer et exécuter Ewido pour un scan complet et copier/coller le rapport en forum.
      ***************************************************************
      ¤ Passe Ad-Aware et supprime tout ce qu’il trouve + supprime les quarantaines…
      ***************************************************************
      ¤ Passe Spybot et corrige tout ce qu’il trouve + vaccine + supprime les quarantaines…
      **************************************************************
      ¤ Lance CCleaner.

      Et fais ceci avec Ccleaner :

      ¤Va dans l'onglet "nettoyeur" présent sur la gauche, décoche la dernière case (Avancé si elle est cochée) puis clique sur « lancer le nettoyage »

      Tu peux aussi réparer les erreurs de ton registre avec ce log :
      Dans l'onglet "Erreurs" cliquez sur "Chercher des erreurs" puis clique sur "Réparer les erreurs sélectionnées".
      Si tu n'est pas sur de ce que tu fais, tu peux choisir de sauvegarder les entrées cochées pour les restaurer ultérieurement (comme indiqué).

      ****************************************************************
      ¤ Vide ta Corbeille.
      ****************************************************************
      ¤ Redémarre en mode normal, relance Hijackthis et copie/colle un nouveau rapport sur le forum.

      A+

      0
      1. Merci Seb :),

        je fais tout ca qd l'analyse kaspersky sera finie et je poste

        au fait, j'ai un probleme avec mon email tele2.fr qd je cherche a m'abonner ou a m'inscrire et c'est seulement depuis mon pc : j'ai la fenetre suivante qui s'ouvre : un email doit s'ecrire xx.yy@zz
        as tu une idee d'ou peut provenir mon soucis ?

        merci à toi l'ame genereuse ;)

        atomixte
        0
        1. Contributeur
          j'ai la fenetre suivante qui s'ouvre : un email doit s'ecrire xx.yy@zz

          ??

          Ok profites en pour coller aussi le rapport de Kaspersky.

          Bon ap.

          A+
          0
          1. Bonjour Seb,

            voila j'ai tout fait mais je n'ai pas eu le temps de poster hier...

            le temps que mon pris tous ces scans ! sans compter ceux que j'ai du refaire... mais j'ai l'impression que je ne me suis pas débarrassée de tout sur mon pc : il rame toujours.

            AD ADWARE

            d-Aware SE Build 1.06r1
            Logfile Created on:mardi 6 juin 2006 16:57:57
            Created with Ad-Aware SE Personal, free for private use.
            Using definitions file:SE1R109 22.05.2006
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            References detected during the scan:
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            MRU List(TAC index:0):3 total references
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            Definition File:
            =========================
            Definitions File Loaded:
            Reference Number : SE1R109 22.05.2006
            Internal build : 130
            File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
            File size : 658546 Bytes
            Total size : 2155671 Bytes
            Signature data size : 2118016 Bytes
            Reference data size : 37143 Bytes
            Signatures total : 59230
            CSI Fingerprints total : 2741
            CSI data size : 93032 Bytes
            Target categories : 15
            Target families : 896

            Memory + processor status:
            ==========================
            Number of processors : 1
            Processor architecture : Intel Pentium III
            Memory available:53 %
            Total physical memory:523760 kb
            Available physical memory:275908 kb
            Total page file size:1280232 kb
            Available on page file:1133500 kb
            Total virtual memory:2097024 kb
            Available virtual memory:2023960 kb
            OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)

            Ad-Aware SE Settings
            ===========================
            Set : Search for negligible risk entries
            Set : Search for low-risk threats
            Set : Safe mode (always request confirmation)
            Set : Don't log streams smaller than 0 Bytes
            Set : Scan active processes
            Set : Scan registry
            Set : Deep-scan registry
            Set : Scan my IE Favorites for banned URLs
            Set : Scan within archives
            Set : Scan my Hosts file

            Extended Ad-Aware SE Settings
            ===========================
            Set : Unload recognized processes & modules during scan
            Set : Scan registry for all users instead of current user only
            Set : Always try to unload modules before deletion
            Set : During removal, unload Explorer and IE if necessary
            Set : Let Windows remove files in use at next reboot
            Set : Delete quarantined objects after restoring
            Set : Include basic Ad-Aware settings in log file
            Set : Include additional Ad-Aware settings in log file
            Set : Include reference summary in log file
            Set : Include alternate data stream details in log file
            Set : Play sound at scan completion if scan locates critical objects

            06-06-2006 16:57:57 - Scan started. (Smart mode)

            Listing running processes
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            #:1 [smss.exe]
            FilePath : \SystemRoot\System32\
            ProcessID : 136
            ThreadCreationTime : 06-06-2006 13:14:15
            BasePriority : Normal
            #:2 [csrss.exe]
            FilePath : \??\C:\WINDOWS\system32\
            ProcessID : 200
            ThreadCreationTime : 06-06-2006 13:14:31
            BasePriority : Normal

            #:3 [winlogon.exe]
            FilePath : \??\C:\WINDOWS\system32\
            ProcessID : 224
            ThreadCreationTime : 06-06-2006 13:14:33
            BasePriority : High

            #:4 [services.exe]
            FilePath : C:\WINDOWS\system32\
            ProcessID : 268
            ThreadCreationTime : 06-06-2006 13:14:38
            BasePriority : Normal
            FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
            ProductVersion : 5.1.2600.2180
            ProductName : Système d'exploitation Microsoft® Windows®
            CompanyName : Microsoft Corporation
            FileDescription : Applications Services et Contrôleur
            InternalName : services.exe
            LegalCopyright : © Microsoft Corporation. Tous droits réservés.
            OriginalFilename : services.exe

            #:5 [lsass.exe]
            FilePath : C:\WINDOWS\system32\
            ProcessID : 280
            ThreadCreationTime : 06-06-2006 13:14:38
            BasePriority : Normal
            FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
            ProductVersion : 5.1.2600.2180
            ProductName : Microsoft® Windows® Operating System
            CompanyName : Microsoft Corporation
            FileDescription : LSA Shell (Export Version)
            InternalName : lsass.exe
            LegalCopyright : © Microsoft Corporation. All rights reserved.
            OriginalFilename : lsass.exe

            #:6 [svchost.exe]
            FilePath : C:\WINDOWS\system32\
            ProcessID : 428
            ThreadCreationTime : 06-06-2006 13:14:43
            BasePriority : Normal
            FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
            ProductVersion : 5.1.2600.2180
            ProductName : Microsoft® Windows® Operating System
            CompanyName : Microsoft Corporation
            FileDescription : Generic Host Process for Win32 Services
            InternalName : svchost.exe
            LegalCopyright : © Microsoft Corporation. All rights reserved.
            OriginalFilename : svchost.exe

            #:7 [svchost.exe]
            FilePath : C:\WINDOWS\system32\
            ProcessID : 492
            ThreadCreationTime : 06-06-2006 13:14:45
            BasePriority : Normal
            FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
            ProductVersion : 5.1.2600.2180
            ProductName : Microsoft® Windows® Operating System
            CompanyName : Microsoft Corporation
            FileDescription : Generic Host Process for Win32 Services
            InternalName : svchost.exe
            LegalCopyright : © Microsoft Corporation. All rights reserved.
            OriginalFilename : svchost.exe

            #:8 [msmpeng.exe]
            FilePath : C:\Program Files\Windows Defender\
            ProcessID : 540
            ThreadCreationTime : 06-06-2006 13:14:46
            BasePriority : Normal
            FileVersion : 1.1.1347.0
            ProductVersion : 1.1.1347.0
            ProductName : Windows Defender
            CompanyName : Microsoft Corporation
            FileDescription : Service Executable
            InternalName : MsMpEng.exe
            LegalCopyright : © Microsoft Corporation. All rights reserved.
            OriginalFilename : MsMpEng.exe

            #:9 [svchost.exe]
            FilePath : C:\WINDOWS\system32\
            ProcessID : 588
            ThreadCreationTime : 06-06-2006 13:14:47
            BasePriority : Normal
            FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
            ProductVersion : 5.1.2600.2180
            ProductName : Microsoft® Windows® Operating System
            CompanyName : Microsoft Corporation
            FileDescription : Generic Host Process for Win32 Services
            InternalName : svchost.exe
            LegalCopyright : © Microsoft Corporation. All rights reserved.
            OriginalFilename : svchost.exe

            #:10 [explorer.exe]
            FilePath : C:\WINDOWS\
            ProcessID : 860
            ThreadCreationTime : 06-06-2006 13:15:21
            BasePriority : Normal
            FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
            ProductVersion : 6.00.2900.2180
            ProductName : Système d'exploitation Microsoft® Windows®
            CompanyName : Microsoft Corporation
            FileDescription : Explorateur Windows
            InternalName : explorer
            LegalCopyright : © Microsoft Corporation. Tous droits réservés.
            OriginalFilename : EXPLORER.EXE

            #:11 [ad-aware.exe]
            FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
            ProcessID : 1452
            ThreadCreationTime : 06-06-2006 14:05:50
            BasePriority : Normal
            FileVersion : 6.2.0.236
            ProductVersion : SE 106
            ProductName : Lavasoft Ad-Aware SE
            CompanyName : Lavasoft Sweden
            FileDescription : Ad-Aware SE Core application
            InternalName : Ad-Aware.exe
            LegalCopyright : Copyright © Lavasoft AB Sweden
            OriginalFilename : Ad-Aware.exe
            Comments : All Rights Reserved

            #:12 [a2start.exe]
            FilePath : C:\Program Files\a-squared\
            ProcessID : 1472
            ThreadCreationTime : 06-06-2006 14:08:01
            BasePriority : Normal
            FileVersion : 1.6.5.4
            ProductVersion : 1.6.5
            ProductName : a-squared
            CompanyName : Emsi Software GmbH
            FileDescription : a-squared Startcenter
            InternalName : a2start
            LegalCopyright : Emsi Software GmbH
            OriginalFilename : a2start.exe

            #:13 [a2scan.exe]
            FilePath : C:\Program Files\a-squared\
            ProcessID : 1480
            ThreadCreationTime : 06-06-2006 14:08:04
            BasePriority : Normal
            FileVersion : 1.6.5.14
            ProductVersion : 1.6.5
            ProductName : a-squared
            CompanyName : Emsi Software GmbH
            FileDescription : a-squared Scanner
            InternalName : a2scan
            LegalCopyright : Emsi Software GmbH
            OriginalFilename : a2scan.exe

            #:14 [winword.exe]
            FilePath : C:\Documents and Settings\HP_Propriétaire\Bureau\
            ProcessID : 1916
            ThreadCreationTime : 06-06-2006 14:12:53
            BasePriority : Normal

            Memory scan result:
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            New critical objects: 0
            Objects found so far: 0

            Started registry scan
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            Registry Scan result:
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            New critical objects: 0
            Objects found so far: 0

            Started deep registry scan
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            Deep registry scan result:
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            New critical objects: 0
            Objects found so far: 0

            Started Tracking Cookie scan
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            Tracking cookie scan result:
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            New critical objects: 0
            Objects found so far: 0

            Deep scanning and examining files...
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            Disk Scan Result for C:\WINDOWS
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            New critical objects: 0
            Objects found so far: 0

            Disk Scan Result for C:\WINDOWS\system32
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            New critical objects: 0
            Objects found so far: 0

            Disk Scan Result for C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            New critical objects: 0
            Objects found so far: 0

            MRU List Object Recognized!
            Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\microsoft\search assistant\acmru
            Description : list of recent search terms used with the search assistant

            MRU List Object Recognized!
            Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
            Description : list of recent programs opened

            MRU List Object Recognized!
            Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
            Description : list of recently saved files, stored according to file extension

            Performing conditional scans...
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            Conditional scan result:
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            New critical objects: 0
            Objects found so far: 3

            17:07:12 Scan Complete

            Summary Of This Scan
            »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
            Total scanning time:00:09:14.125
            Objects scanned:73212
            Objects identified:0
            Objects ignored:0
            New critical objects:0

            CCLEANER

            ANALYSE COMPLETE - (3,751 secs)
            ------------------------------------------------------------------------------------------
            16,23KB ont été supprimé. (Taille approximative)
            ------------------------------------------------------------------------------------------
            Détails des fichiers à supprimer (Note: AUCUN fichier n'a pour l'instant été supprimé)
            ------------------------------------------------------------------------------------------
            Fichiers Temporaires d'Internet Explorer (fichiers 2) 134 bytes
            C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\Office 2000 Premium Setup(0002).txt 1,53KB
            C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\Office 2000 Premium Setup(0004).txt 1,53KB
            C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\Office 2000 Premium Setup(0006).txt 1,53KB
            C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\Office 2000 Premium Setup(0008).txt 1,53KB
            C:\Documents and Settings\HP_Propriétaire\Application Data\Lavasoft\Ad-Aware\Logs\Ad-Aware log2006-06-06 16-39-44.txt 9,99KB

            A² / A SQUARED

            Rien trouvé ! J

            EWIDO
            ---------------------------------------------------------
            ewido anti-malware - Rapport de scan
            ---------------------------------------------------------
            + Créé le: 19:23:49, 06/06/2006
            + Somme de contrôle: DA82A55C
            + Résultats du scan:
            Pas de fichiers infectés trouvés!
            ::Fin du rapport

            Kaspersky

            Je n’arrive plus a faire de scan en ligne ca plante et je suis obligée de redemarrer mon pc
            Dois-je le faire en me connectant dans le mode sans echec ?

            Hijackthis

            Logfile of HijackThis v1.99.1
            Scan saved at 23:29:21, on 06/06/2006
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Windows Defender\MsMpEng.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
            C:\windows\system\hpsysdrv.exe
            C:\HP\KBD\KBD.EXE
            C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\WINDOWS\AGRSMMSG.exe
            C:\Program Files\ewido anti-malware\ewidoctrl.exe
            C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
            C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
            C:\Program Files\SpyBro\SpyBro.exe
            C:\WINDOWS\system32\HPZipm12.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\WinTV\Ir.exe
            C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Documents and Settings\HP_Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\O7OZCDMP\HijackThis[1].exe
            C:\WINDOWS\system32\NOTEPAD.EXE

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q105&bd=pavil...
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q105&bd=pavil...
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
            O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
            O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
            O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
            O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
            O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
            O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
            O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
            O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
            O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
            O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
            O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
            O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
            O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
            O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
            O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            O4 - HKLM\..\Run: [AutoTBar] c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
            O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
            O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
            O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
            O4 - HKCU\..\Run: [SpyBrowser] "C:\Program Files\SpyBro\SpyBro.exe" /autostart
            O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
            O4 - Global Startup: desktop(2).ini
            O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
            O9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - https://www.pandasecurity.com/?ref=www.pandasoftware.com/activescan/fr/activescan_principal.htm (file missing)
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O10 - Unknown file in Winsock LSP: c:\program files\bulletproofsoft.com\bps spyware & adware remover\apptoport.dll
            O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
            O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
            O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
            O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
            O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
            O16 - DPF: {FD40EC41-D860-4579-8BA4-52671A45C71C} (AxHtChat Class) - http://images.goa.com/it/Woo2/fr/chat/nPaxChat.cab
            O17 - HKLM\System\CCS\Services\Tcpip\..\{1D55BC99-6DCB-4AE5-B1BC-2D964078FC07}: NameServer = 212.151.136.246 212.151.137.166
            O20 - AppInit_DLLs: MsgPlusLoader.dll
            O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
            O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
            O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
            O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
            O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
            O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

            AUTRES PROBLEMES

            1 - A l’ouverture de mon ordi, j’ai ce message svchost.exe qui s’affiche puis la page web www.amaena.com qui me contacte pour me proposer win anti-virus2006. je dis non a chaque fois mais j’aimerai mieux m’en débarrasser automatiquement.

            2- Lorsque je saisie mon adresse de mail sur un site j’ai un message qui me dit que les adresses email doivent etre transcrite sous forme xx@yy.zz et l’adresse se transforme en xxxxxxxxxxx. il est vrai que mon fournisseur est tele2.fr mais ca ne me le fait que depuis mon pc maison.

            3 – je n’arrive plus a me connecter directement en ouvrant ma page internet, je suis obligée de passer par demarrer\connection\tele2 adsl.

            4 - je n'arrive plus a scanner avec kaspersky : mon ordi se plante et je suis obligée de le redémarrer

            Merci à toi d'avoir pris quelques minutes pour me lire et peut etre a bientot ... en tout cas, j'attends ta réponse avec impatience ;)

            Atomixte
            0
            1. Contributeur
              Ok

              1/Installe correctement Hijackthis comme ceci :

              Dézippe le dans un dossier prévu à cet effet.

              Par exemple C:\hijackthis < Enregistre le bien dans c : !

              Démo (merci à Balltrap) :
              instalation hijackthis
              http://pageperso.aol.fr/balltrap34/Hijenr.gif

              car tu l'as mal installé.Et tu n'auras pas accès au backups.

              Ensuite :

              Affiches tous les fichiers et dossiers :
              cliques sur démarrer/panneau de configuration (en affichage classique)/option des dossiers/affichage
              Cocher « afficher les dossiers et fichiers cachés »

              Décoches la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

              Décoches « masquer les extensions dont le type est connu »
              Puis fais «Ok» pour valider les changements.

              Et « appliquer »

              *********************************************************************************
              ¤Relance HijackThis cliques sur « scanner seulement » ou (« do a scan only »),
              coche les cases devant ces lignes et ensuite clique sur « fixer objets » (ou « fix checked »):

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=Q105&bd=pavilio...
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q105&bd=pavil...
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q105&bd=pavil...
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=Q105&bd=pavilio...

              O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

              O9 - Extra button: Panda ActiveScan - {653D93AF-C741-4e5e-8C1B-59BA43F93E16} - https://www.pandasecurity.com/?ref=www.pandasoftware.com/activescan/fr/activescan_principal.htm (file missing)
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)

              O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
              O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
              O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
              O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
              O16 - DPF: {FD40EC41-D860-4579-8BA4-52671A45C71C} (AxHtChat Class) - http://images.goa.com/it/Woo2/fr/chat/nPaxChat.cab

              O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe


              PS:

              Si tu ne connais pas ce log SpyBrowser fixes aussi cette ligne :

              O4 - HKCU\..\Run: [SpyBrowser] "C:\Program Files\SpyBro\SpyBro.exe" /autostart

              et supprime le log par ajout/suppression de prog.

              Arrête ce service :

              Boonty Games

              Démarrer=>executer=>tape "services.msc" et met le sur arrêté.

              **********************************************************************************
              ¤Démarre en mode sans échec :
              Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
              Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec
              puis tape « entrée ».
              Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
              (Si F8 ne marche pas utilise la touche F5).

              **********************************************************************************
              Fais les mise à jour de ces log avant de les lancer :

              ¤ Lancer et exécuter Ewido pour un scan complet et copier/coller le rapport en forum.
              **********************************************************************************
              ¤ Passe Ad-Aware et supprime tout ce qu’il trouve + supprime les quarantaines…
              **********************************************************************************
              ¤ Passe Spybot et corrige tout ce qu’il trouve + vaccine + supprime les quarantaines…

              Installe Spybot si tu ne l'a pas :

              Spybot (gratuit) :
              voir demo d utilisation
              http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm
              Téléchargement :
              http://telecharger.01net.com/windows/Internet/internet_utlitaire/fiches/26157.html

              **********************************************************************************
              ¤ Lance CCleaner.

              Et fais ceci avec Ccleaner :

              ¤Va dans l'onglet "nettoyeur" présent sur la gauche, décoche la dernière case (Avancé si elle est cochée)
              puis clique sur « lancer le nettoyage »

              Tu peux aussi réparer les erreurs de ton registre avec ce log :
              Dans l'onglet "Erreurs" cliquez sur "Chercher des erreurs" puis clique sur "Réparer les erreurs sélectionnées".
              Si tu n'est pas sur de ce que tu fais,
              tu peux choisir de sauvegarder les entrées cochées pour les restaurer ultérieurement (comme indiqué).

              *********************************************************************************************************************************
              ¤ Vide ta Corbeille.
              *********************************************************************************************************************************
              ¤ Redémarre en mode normal, relance Hijackthis et copie/colle un nouveau rapport sur le forum.

              Et dis nous ou en sont tes problèmes.

              A+

              0
              1. Bonjour... ou bon soir... a cette heure ci je sais plus tres bien :)

                alors j'ai tout fait Seb,

                je t'envoie les 3 scans

                mes pb :
                toujours la page winantivirus 2006 + 1 pub qui s'ouvre dès que j'ouvre une page web

                toujours pas possible de me connecter en direct quand j'ouvre une page web (obligée de passer par démarrer/connection...

                mon email avec tele2.fr ne marche toujours pas --> je passe par un autre fournisseur ! comme si mon mail était bloqué :(

                et pour le scan avec kaspersky : ca plante toujours :( c pas juste !

                merci Seb pour le mal que tu te donnes :) c'est gentil de me venir en aide

                passe une bonne journée et a bientot pour tes nouveaux conseils : les scans suivent et merci encore

                atomixte

                ---------------------------------------------------------
                ewido anti-malware - Rapport de scan
                ---------------------------------------------------------

                + Créé le: 00:07:07, 08/06/2006
                + Somme de contrôle: 41D6FD26

                + Résultats du scan:

                C:\Documents and Settings\HP_Propriétaire\Cookies\hp_propriétaire@zedo[1].txt -> TrackingCookie.Zedo : Nettoyer et sauvegarder
                ::Fin du rapport

                Ad-Aware SE Build 1.06r1
                Logfile Created on:jeudi 8 juin 2006 00:11:29
                Created with Ad-Aware SE Personal, free for private use.
                Using definitions file:SE1R109 22.05.2006
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                References detected during the scan:
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                MRU List(TAC index:0):15 total references
                Tracking Cookie(TAC index:3):1 total references
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                Definition File:
                =========================
                Definitions File Loaded:
                Reference Number : SE1R109 22.05.2006
                Internal build : 130
                File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
                File size : 658546 Bytes
                Total size : 2155671 Bytes
                Signature data size : 2118016 Bytes
                Reference data size : 37143 Bytes
                Signatures total : 59230
                CSI Fingerprints total : 2741
                CSI data size : 93032 Bytes
                Target categories : 15
                Target families : 896

                Memory + processor status:
                ==========================
                Number of processors : 1
                Processor architecture : Intel Pentium III
                Memory available:70 %
                Total physical memory:523760 kb
                Available physical memory:365720 kb
                Total page file size:1280232 kb
                Available on page file:1186224 kb
                Total virtual memory:2097024 kb
                Available virtual memory:2044432 kb
                OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)

                Ad-Aware SE Settings
                ===========================
                Set : Search for negligible risk entries
                Set : Search for low-risk threats
                Set : Safe mode (always request confirmation)
                Set : Don't log streams smaller than 0 Bytes
                Set : Scan active processes
                Set : Scan registry
                Set : Deep-scan registry
                Set : Scan my IE Favorites for banned URLs
                Set : Scan within archives
                Set : Scan my Hosts file

                Extended Ad-Aware SE Settings
                ===========================
                Set : Unload recognized processes & modules during scan
                Set : Scan registry for all users instead of current user only
                Set : Always try to unload modules before deletion
                Set : During removal, unload Explorer and IE if necessary
                Set : Let Windows remove files in use at next reboot
                Set : Delete quarantined objects after restoring
                Set : Include basic Ad-Aware settings in log file
                Set : Include additional Ad-Aware settings in log file
                Set : Include reference summary in log file
                Set : Include alternate data stream details in log file
                Set : Play sound at scan completion if scan locates critical objects

                08-06-2006 00:11:29 - Scan started. (Smart mode)

                Listing running processes
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                #:1 [smss.exe]
                FilePath : \SystemRoot\System32\
                ProcessID : 136
                ThreadCreationTime : 07-06-2006 20:20:01
                BasePriority : Normal

                #:2 [csrss.exe]
                FilePath : \??\C:\WINDOWS\system32\
                ProcessID : 200
                ThreadCreationTime : 07-06-2006 20:20:17
                BasePriority : Normal

                #:3 [winlogon.exe]
                FilePath : \??\C:\WINDOWS\system32\
                ProcessID : 224
                ThreadCreationTime : 07-06-2006 20:20:19
                BasePriority : High

                #:4 [services.exe]
                FilePath : C:\WINDOWS\system32\
                ProcessID : 268
                ThreadCreationTime : 07-06-2006 20:20:25
                BasePriority : Normal
                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                ProductVersion : 5.1.2600.2180
                ProductName : Système d'exploitation Microsoft® Windows®
                CompanyName : Microsoft Corporation
                FileDescription : Applications Services et Contrôleur
                InternalName : services.exe
                LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                OriginalFilename : services.exe

                #:5 [lsass.exe]
                FilePath : C:\WINDOWS\system32\
                ProcessID : 280
                ThreadCreationTime : 07-06-2006 20:20:25
                BasePriority : Normal
                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                ProductVersion : 5.1.2600.2180
                ProductName : Microsoft® Windows® Operating System
                CompanyName : Microsoft Corporation
                FileDescription : LSA Shell (Export Version)
                InternalName : lsass.exe
                LegalCopyright : © Microsoft Corporation. All rights reserved.
                OriginalFilename : lsass.exe

                #:6 [svchost.exe]
                FilePath : C:\WINDOWS\system32\
                ProcessID : 428
                ThreadCreationTime : 07-06-2006 20:20:31
                BasePriority : Normal
                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                ProductVersion : 5.1.2600.2180
                ProductName : Microsoft® Windows® Operating System
                CompanyName : Microsoft Corporation
                FileDescription : Generic Host Process for Win32 Services
                InternalName : svchost.exe
                LegalCopyright : © Microsoft Corporation. All rights reserved.
                OriginalFilename : svchost.exe

                #:7 [svchost.exe]
                FilePath : C:\WINDOWS\system32\
                ProcessID : 488
                ThreadCreationTime : 07-06-2006 20:20:34
                BasePriority : Normal
                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                ProductVersion : 5.1.2600.2180
                ProductName : Microsoft® Windows® Operating System
                CompanyName : Microsoft Corporation
                FileDescription : Generic Host Process for Win32 Services
                InternalName : svchost.exe
                LegalCopyright : © Microsoft Corporation. All rights reserved.
                OriginalFilename : svchost.exe

                #:8 [msmpeng.exe]
                FilePath : C:\Program Files\Windows Defender\
                ProcessID : 524
                ThreadCreationTime : 07-06-2006 20:20:35
                BasePriority : Normal
                FileVersion : 1.1.1347.0
                ProductVersion : 1.1.1347.0
                ProductName : Windows Defender
                CompanyName : Microsoft Corporation
                FileDescription : Service Executable
                InternalName : MsMpEng.exe
                LegalCopyright : © Microsoft Corporation. All rights reserved.
                OriginalFilename : MsMpEng.exe

                #:9 [svchost.exe]
                FilePath : C:\WINDOWS\system32\
                ProcessID : 600
                ThreadCreationTime : 07-06-2006 20:20:37
                BasePriority : Normal
                FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                ProductVersion : 5.1.2600.2180
                ProductName : Microsoft® Windows® Operating System
                CompanyName : Microsoft Corporation
                FileDescription : Generic Host Process for Win32 Services
                InternalName : svchost.exe
                LegalCopyright : © Microsoft Corporation. All rights reserved.
                OriginalFilename : svchost.exe

                #:10 [explorer.exe]
                FilePath : C:\WINDOWS\
                ProcessID : 860
                ThreadCreationTime : 07-06-2006 20:20:59
                BasePriority : Normal
                FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
                ProductVersion : 6.00.2900.2180
                ProductName : Système d'exploitation Microsoft® Windows®
                CompanyName : Microsoft Corporation
                FileDescription : Explorateur Windows
                InternalName : explorer
                LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                OriginalFilename : EXPLORER.EXE

                #:11 [ad-aware.exe]
                FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
                ProcessID : 1604
                ThreadCreationTime : 07-06-2006 22:09:38
                BasePriority : Normal
                FileVersion : 6.2.0.236
                ProductVersion : SE 106
                ProductName : Lavasoft Ad-Aware SE
                CompanyName : Lavasoft Sweden
                FileDescription : Ad-Aware SE Core application
                InternalName : Ad-Aware.exe
                LegalCopyright : Copyright © Lavasoft AB Sweden
                OriginalFilename : Ad-Aware.exe
                Comments : All Rights Reserved

                Memory scan result:
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                New critical objects: 0
                Objects found so far: 0

                Started registry scan
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                Registry Scan result:
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                New critical objects: 0
                Objects found so far: 0

                Started deep registry scan
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                Deep registry scan result:
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                New critical objects: 0
                Objects found so far: 0

                Started Tracking Cookie scan
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                Tracking Cookie Object Recognized!
                Type : IECache Entry
                Data : hp_propriétaire@zedo[1].txt
                TAC Rating : 3
                Category : Data Miner
                Comment : Hits:7
                Value : Cookie:hp_propriétaire@zedo.com/
                Expires : 04-06-2016 21:21:54
                LastSync : Hits:7
                UseCount : 0
                Hits : 7

                Tracking cookie scan result:
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                New critical objects: 1
                Objects found so far: 1

                Deep scanning and examining files...
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                Disk Scan Result for C:\WINDOWS
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                New critical objects: 0
                Objects found so far: 1

                Disk Scan Result for C:\WINDOWS\system32
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                New critical objects: 0
                Objects found so far: 1

                Disk Scan Result for C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                New critical objects: 0
                Objects found so far: 1

                MRU List Object Recognized!
                Location: : C:\Documents and Settings\HP_Propriétaire\recent
                Description : list of recently opened documents

                MRU List Object Recognized!
                Location: : software\microsoft\direct3d\mostrecentapplication
                Description : most recent application to use microsoft direct3d

                MRU List Object Recognized!
                Location: : software\microsoft\direct3d\mostrecentapplication
                Description : most recent application to use microsoft direct X

                MRU List Object Recognized!
                Location: : software\microsoft\directdraw\mostrecentapplication
                Description : most recent application to use microsoft directdraw

                MRU List Object Recognized!
                Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\microsoft\directinput\mostrecentapplication
                Description : most recent application to use microsoft directinput

                MRU List Object Recognized!
                Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\microsoft\directinput\mostrecentapplication
                Description : most recent application to use microsoft directinput

                MRU List Object Recognized!
                Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\microsoft\internet explorer
                Description : last download directory used in microsoft internet explorer

                MRU List Object Recognized!
                Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\microsoft\microsoft management console\recent file list
                Description : list of recent snap-ins used in the microsoft management console

                MRU List Object Recognized!
                Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\microsoft\search assistant\acmru
                Description : list of recent search terms used with the search assistant

                MRU List Object Recognized!
                Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
                Description : list of recent programs opened

                MRU List Object Recognized!
                Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
                Description : list of recently saved files, stored according to file extension

                MRU List Object Recognized!
                Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\nvidia corporation\global\nview\windowmanagement
                Description : nvidia nview cached application window positions

                MRU List Object Recognized!
                Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general
                Description : windows media sdk

                MRU List Object Recognized!
                Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general
                Description : windows media sdk

                MRU List Object Recognized!
                Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\microsoft\windows media\wmsdk\general
                Description : windows media sdk

                Performing conditional scans...
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                Conditional scan result:
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                New critical objects: 0
                Objects found so far: 16

                00:14:29 Scan Complete

                Summary Of This Scan
                »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                Total scanning time:00:03:00.734
                Objects scanned:78933
                Objects identified:1
                Objects ignored:0
                New critical objects:1

                Logfile of HijackThis v1.99.1
                Scan saved at 01:18:24, on 08/06/2006
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Windows Defender\MsMpEng.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\Program Files\ewido anti-malware\ewidoctrl.exe
                C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
                C:\WINDOWS\system32\nvsvc32.exe
                C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
                C:\WINDOWS\system32\HPZipm12.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
                C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                C:\windows\system\hpsysdrv.exe
                C:\WINDOWS\system32\hphmon06.exe
                C:\HP\KBD\KBD.EXE
                C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\iPod\bin\iPodService.exe
                C:\WINDOWS\system32\rundll32.exe
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\WINDOWS\AGRSMMSG.exe
                C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                C:\Program Files\Windows Defender\MSASCui.exe
                C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
                C:\Program Files\WinTV\Ir.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                C:\hijackThis\HijackThis.exe

                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
                O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
                O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
                O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
                O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
                O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
                O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
                O4 - Global Startup: desktop(2).ini
                O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                O10 - Broken Internet access because of LSP provider 'c:\program files\bulletproofsoft.com\bps spyware & adware remover\apptoport.dll' missing
                O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
                O20 - AppInit_DLLs: MsgPlusLoader.dll
                O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

                merci encore !!!!
                0
                1. Contributeur
                  Fixe cette ligne :

                  O10 - Broken Internet access because of LSP provider 'c:\program files\bulletproofsoft.com\bps spyware & adware remover\apptoport.dll' missing

                  Et essaye de scanner avec Bitdefender :

                  https://www.bitdefender.fr/
                  ou
                  http://www.bitdefender.fr/scan/license.php

                  Cliques sur "scan on line" et suis les instructions.

                  Et colle le rapport.

                  A+
                  0
                  1. Contributeur
                    hello seb & co

                    coche et fixe aussi ceci
                    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

                    sans compter que tu as trop de 04 inutiles au run
                    mais ce sera pour plus tard
                    0
                    1. Bonjour Aranjuez 31,

                      comme tu m'as dit : j'ai fait un hijackthis en mode sans echec mais la ligne 010 broken internet cacces because of LSP provider c:\program files\bulletproofsoft.com\bps spyware et adware remover\apptoport.dll missing ne disparait pas

                      je vais scanner avec bitdefender en ligne comme tu me l'as dit et je te redonne des nouvelles.

                      j'ai toujours ma pub 01.net et mon amaena. com qui s'ouvre :(

                      PS : je t'envoie les scans de ad adware et hijackthis au cas ou ca pourrait etre utile...

                      Ad-Aware SE Build 1.06r1
                      Logfile Created on:jeudi 8 juin 2006 14:05:15
                      Created with Ad-Aware SE Personal, free for private use.
                      Using definitions file:SE1R110 31.05.2006
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      References detected during the scan:
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      MRU List(TAC index:0):10 total references
                      Tracking Cookie(TAC index:3):1 total references
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      Definition File:
                      =========================
                      Definitions File Loaded:
                      Reference Number : SE1R110 31.05.2006
                      Internal build : 131
                      File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
                      File size : 673936 Bytes
                      Total size : 2205484 Bytes
                      Signature data size : 2157938 Bytes
                      Reference data size : 47034 Bytes
                      Signatures total : 60724
                      CSI Fingerprints total : 2904
                      CSI data size : 100630 Bytes
                      Target categories : 15
                      Target families : 906

                      Memory + processor status:
                      ==========================
                      Number of processors : 1
                      Processor architecture : Intel Pentium III
                      Memory available:72 %
                      Total physical memory:523760 kb
                      Available physical memory:376452 kb
                      Total page file size:1280232 kb
                      Available on page file:1200588 kb
                      Total virtual memory:2097024 kb
                      Available virtual memory:2044432 kb
                      OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600)

                      Ad-Aware SE Settings
                      ===========================
                      Set : Search for negligible risk entries
                      Set : Search for low-risk threats
                      Set : Safe mode (always request confirmation)
                      Set : Don't log streams smaller than 0 Bytes
                      Set : Scan active processes
                      Set : Scan registry
                      Set : Deep-scan registry
                      Set : Scan my IE Favorites for banned URLs
                      Set : Scan within archives
                      Set : Scan my Hosts file

                      Extended Ad-Aware SE Settings
                      ===========================
                      Set : Unload recognized processes & modules during scan
                      Set : Scan registry for all users instead of current user only
                      Set : Always try to unload modules before deletion
                      Set : During removal, unload Explorer and IE if necessary
                      Set : Let Windows remove files in use at next reboot
                      Set : Delete quarantined objects after restoring
                      Set : Include basic Ad-Aware settings in log file
                      Set : Include additional Ad-Aware settings in log file
                      Set : Include reference summary in log file
                      Set : Include alternate data stream details in log file
                      Set : Play sound at scan completion if scan locates critical objects

                      08-06-2006 14:05:15 - Scan started. (Smart mode)

                      Listing running processes
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      #:1 [smss.exe]
                      FilePath : \SystemRoot\System32\
                      ProcessID : 136
                      ThreadCreationTime : 08-06-2006 11:57:18
                      BasePriority : Normal

                      #:2 [csrss.exe]
                      FilePath : \??\C:\WINDOWS\system32\
                      ProcessID : 200
                      ThreadCreationTime : 08-06-2006 11:57:34
                      BasePriority : Normal

                      #:3 [winlogon.exe]
                      FilePath : \??\C:\WINDOWS\system32\
                      ProcessID : 224
                      ThreadCreationTime : 08-06-2006 11:57:35
                      BasePriority : High

                      #:4 [services.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 268
                      ThreadCreationTime : 08-06-2006 11:57:41
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Système d'exploitation Microsoft® Windows®
                      CompanyName : Microsoft Corporation
                      FileDescription : Applications Services et Contrôleur
                      InternalName : services.exe
                      LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                      OriginalFilename : services.exe

                      #:5 [lsass.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 280
                      ThreadCreationTime : 08-06-2006 11:57:41
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : LSA Shell (Export Version)
                      InternalName : lsass.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : lsass.exe

                      #:6 [svchost.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 428
                      ThreadCreationTime : 08-06-2006 11:57:46
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : Generic Host Process for Win32 Services
                      InternalName : svchost.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : svchost.exe

                      #:7 [svchost.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 488
                      ThreadCreationTime : 08-06-2006 11:57:48
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : Generic Host Process for Win32 Services
                      InternalName : svchost.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : svchost.exe

                      #:8 [msmpeng.exe]
                      FilePath : C:\Program Files\Windows Defender\
                      ProcessID : 540
                      ThreadCreationTime : 08-06-2006 11:57:50
                      BasePriority : Normal
                      FileVersion : 1.1.1347.0
                      ProductVersion : 1.1.1347.0
                      ProductName : Windows Defender
                      CompanyName : Microsoft Corporation
                      FileDescription : Service Executable
                      InternalName : MsMpEng.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : MsMpEng.exe

                      #:9 [svchost.exe]
                      FilePath : C:\WINDOWS\system32\
                      ProcessID : 612
                      ThreadCreationTime : 08-06-2006 11:57:51
                      BasePriority : Normal
                      FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 5.1.2600.2180
                      ProductName : Microsoft® Windows® Operating System
                      CompanyName : Microsoft Corporation
                      FileDescription : Generic Host Process for Win32 Services
                      InternalName : svchost.exe
                      LegalCopyright : © Microsoft Corporation. All rights reserved.
                      OriginalFilename : svchost.exe

                      #:10 [explorer.exe]
                      FilePath : C:\WINDOWS\
                      ProcessID : 968
                      ThreadCreationTime : 08-06-2006 11:59:50
                      BasePriority : Normal
                      FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
                      ProductVersion : 6.00.2900.2180
                      ProductName : Système d'exploitation Microsoft® Windows®
                      CompanyName : Microsoft Corporation
                      FileDescription : Explorateur Windows
                      InternalName : explorer
                      LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                      OriginalFilename : EXPLORER.EXE

                      #:11 [ad-aware.exe]
                      FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
                      ProcessID : 1308
                      ThreadCreationTime : 08-06-2006 12:04:57
                      BasePriority : Normal
                      FileVersion : 6.2.0.236
                      ProductVersion : SE 106
                      ProductName : Lavasoft Ad-Aware SE
                      CompanyName : Lavasoft Sweden
                      FileDescription : Ad-Aware SE Core application
                      InternalName : Ad-Aware.exe
                      LegalCopyright : Copyright © Lavasoft AB Sweden
                      OriginalFilename : Ad-Aware.exe
                      Comments : All Rights Reserved

                      Memory scan result:
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 0
                      Objects found so far: 0

                      Started registry scan
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      Registry Scan result:
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 0
                      Objects found so far: 0

                      Started deep registry scan
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      Deep registry scan result:
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 0
                      Objects found so far: 0

                      Started Tracking Cookie scan
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      Tracking Cookie Object Recognized!
                      Type : IECache Entry
                      Data : hp_propriétaire@zedo[2].txt
                      TAC Rating : 3
                      Category : Data Miner
                      Comment : Hits:6
                      Value : Cookie:hp_propriétaire@zedo.com/
                      Expires : 05-06-2016 13:54:30
                      LastSync : Hits:6
                      UseCount : 0
                      Hits : 6

                      Tracking cookie scan result:
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 1
                      Objects found so far: 1

                      Deep scanning and examining files...
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      Disk Scan Result for C:\WINDOWS
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 0
                      Objects found so far: 1

                      Disk Scan Result for C:\WINDOWS\system32
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 0
                      Objects found so far: 1

                      Disk Scan Result for C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 0
                      Objects found so far: 1

                      MRU List Object Recognized!
                      Location: : C:\Documents and Settings\HP_Propriétaire\recent
                      Description : list of recently opened documents

                      MRU List Object Recognized!
                      Location: : software\microsoft\direct3d\mostrecentapplication
                      Description : most recent application to use microsoft direct3d

                      MRU List Object Recognized!
                      Location: : software\microsoft\direct3d\mostrecentapplication
                      Description : most recent application to use microsoft direct X

                      MRU List Object Recognized!
                      Location: : software\microsoft\directdraw\mostrecentapplication
                      Description : most recent application to use microsoft directdraw

                      MRU List Object Recognized!
                      Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
                      Description : list of recent programs opened

                      MRU List Object Recognized!
                      Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
                      Description : list of recently saved files, stored according to file extension

                      MRU List Object Recognized!
                      Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\nvidia corporation\global\nview\windowmanagement
                      Description : nvidia nview cached application window positions

                      MRU List Object Recognized!
                      Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general
                      Description : windows media sdk

                      MRU List Object Recognized!
                      Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general
                      Description : windows media sdk

                      MRU List Object Recognized!
                      Location: : S-1-5-21-2388939605-828379907-224081223-1007\software\microsoft\windows media\wmsdk\general
                      Description : windows media sdk

                      Performing conditional scans...
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                      Conditional scan result:
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      New critical objects: 0
                      Objects found so far: 11

                      14:08:09 Scan Complete

                      Summary Of This Scan
                      »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                      Total scanning time:00:02:53.16
                      Objects scanned:79325
                      Objects identified:1
                      Objects ignored:0
                      New critical objects:1

                      Logfile of HijackThis v1.99.1
                      Scan saved at 14:04:16, on 08/06/2006
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Windows Defender\MsMpEng.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\hijackThis\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                      O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                      O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
                      O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
                      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                      O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
                      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                      O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                      O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                      O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                      O4 - HKLM\..\Run: [eiungqm] c:\windows\system32\eiungqm.exe eiungqm
                      O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
                      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                      O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
                      O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                      O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
                      O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
                      O4 - Global Startup: desktop(2).ini
                      O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                      O10 - Broken Internet access because of LSP provider 'c:\program files\bulletproofsoft.com\bps spyware & adware remover\apptoport.dll' missing
                      O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
                      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                      O20 - AppInit_DLLs: MsgPlusLoader.dll
                      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                      O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
                      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

                      a de suite et mervi encore

                      atomixte
                      0
                      1. desolée mais j'ai oublié un petit détail : lorsque je passe spybot, je n'arrive pas à corriger :
                        LOG
                        Activiy schedLgU.txt
                        c:\windows\schedLgU.txt

                        merci de m'apporter également de l'aide pour ce probleme également

                        a vous tous merci et a plus

                        atomixte
                        0
                        1. Contributeur
                          Et le rapport de bitdefender ?

                          0
                          1. Contributeur
                            Au fait ton dernier log Hijack a été fait en mode sans echec...

                            Le prochain fais le en "mode normal" .

                            Merci

                            A+
                            0
                            1. Salut Seb :)

                              j'ai passé bitdefender : le scan va jusqu'au bout mais ne finit jamais soit il s'arrete a l'avant dernier fichier soit au dernier mais il ne ferme jamais --> je suis obligée de fermer manuellement et de quitter en passant par le gestionnaire des taches.

                              voici le log hijackthis
                              Logfile of HijackThis v1.99.1
                              Scan saved at 18:18:19, on 09/06/2006
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Windows Defender\MsMpEng.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                              C:\windows\system\hpsysdrv.exe
                              C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              C:\WINDOWS\system32\hphmon06.exe
                              C:\HP\KBD\KBD.EXE
                              C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\Program Files\ewido anti-malware\ewidoctrl.exe
                              C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
                              C:\WINDOWS\system32\nvsvc32.exe
                              C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
                              C:\WINDOWS\system32\HPZipm12.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\rundll32.exe
                              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              C:\WINDOWS\AGRSMMSG.exe
                              C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              C:\Program Files\Windows Defender\MSASCui.exe
                              C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
                              C:\Program Files\WinTV\Ir.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
                              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\hijackThis\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                              O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                              O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                              O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                              O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                              O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
                              O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
                              O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                              O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                              O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                              O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
                              O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                              O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                              O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                              O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                              O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                              O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                              O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
                              O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                              O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                              O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
                              O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
                              O4 - Global Startup: desktop(2).ini
                              O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O10 - Broken Internet access because of LSP provider 'c:\program files\bulletproofsoft.com\bps spyware & adware remover\apptoport.dll' missing
                              O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
                              O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                              O17 - HKLM\System\CCS\Services\Tcpip\..\{1D55BC99-6DCB-4AE5-B1BC-2D964078FC07}: NameServer = 212.151.137.166 212.151.136.242
                              O20 - AppInit_DLLs: MsgPlusLoader.dll
                              O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                              O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                              O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                              O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
                              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                              O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
                              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

                              j'ai remarqué que les pubs et les ouvertures web de fichiers antivirus arrivent quand je vais sur panda, bitdefender, kaspersky
                              ne s'agit il pas d'un virus ? je me rappelle avoir eut un soucis semblable il y a tres longtemps et je crois que s'etait un virus au démarrage. qu'en penses tu ?

                              des que je te poste ce message j'essaye un kaspersky en ligne et je te dirai le resultat

                              si tu sors ce soir : bon we!!!

                              a bientot

                              atomixte
                              0
                              1. Contributeur
                                Télécharges LspFix

                                http://www.spychecker.com/download/download_lspfix.html

                                * Débranches ta connection et fermes tous les programmes en cours,
                                * Lances-le
                                * Coches "I know what I'm doing"
                                * Fais passer de gauche à droite tous les apptoport.dll
                                * Cliques sur "Finish"
                                * Redémarres

                                Par ajout / suppression de programmes du Panneau de configuration, désinstalles bulletproofsoft si présent.

                                Et mets un nouveau HijackThis

                                A+
                                0
                                1. Bravo Seb !

                                  ca change rien a mes pubs par contre j'ai pu lancer un kaspersky et il est en train de tourner : il m'indique deja un virus !!!!!
                                  derriere j'enchainerai avec un bitdefender puis un hijackthis et je te poste tout ca...

                                  a tout a l'heure ou a demain si tu sors....

                                  atomixte
                                  0
                                  1. Alors voila Seb le rapport de
                                    KASPERSKY ON-LINE SCANNER - RAPPORT

                                    samedi 10 juin 2006 00:25:27
                                    Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
                                    Version de Kaspersky On-line Scanner: 5.0.78.0
                                    Dernière mise à jour de la base antivirus Kaspersky : 9/06/2006
                                    Enregistrements dans la base antivirus Kaspersky : 199573

                                    Paramètres d'analyse
                                    Analyser avec la base antivirus suivante étendue
                                    Analyser les archives vrai
                                    Analyser les bases de messagerie. vrai

                                    Cible de l'analyse Poste de travail
                                    C:\
                                    D:\
                                    E:\
                                    F:\
                                    G:\
                                    H:\
                                    I:\
                                    J:\
                                    K:\

                                    Statistiques de l'analyse
                                    Total d'objets analysés : 80669
                                    Nombre de virus trouvés 1
                                    Nombre d'objets infectés 3
                                    Nombre d'objets suspects 0
                                    Durée de l'analyse 01:18:08

                                    Nom de l'objet infecté Nom du virus Dernière action
                                    C:\brute force uninstaller\clean.zip/clean/pskill.exe Infecté: not-a-virus:RiskTool.Win32.PsKill.k ignoré

                                    C:\brute force uninstaller\clean.zip ZIP: infecté - 1 ignoré

                                    C:\System Volume Information\_restore{5864E199-E068-480D-BF55-3BCEB0D80CFD}\RP11\A0002304.exe Infecté: not-a-virus:RiskTool.Win32.PsKill.k ignoré

                                    Analyse terminée.

                                    interessant n'est ce pas ? mais voila, j'ai cherché un patch mais tous sont en langue étrangère et je ne sais pas lequel choisir...
                                    j'attends tes lumières ;)...

                                    a bientot Seb

                                    atomixte
                                    0
                                    1. Contributeur
                                      Tu connais ce log :

                                      C:\brute force uninstaller

                                      Si non vire le.

                                      Ensuite :

                                      Désactive ta restauration système (uniquement si tu es sous XP):
                                      Clic droit sur poste de travail puis,
                                      propriété, tu cliques sur onglet restauration système
                                      tu coches la case « désactiver la restauration » et applique.

                                      Puis,

                                      ¤Réactive ta restauration système (uniquement si tu es sous XP):
                                      Clic droit sur poste de travail puis,
                                      propriété, tu cliques sur onglet restauration système
                                      tu décoches la case « désactiver la restauration » et applique.

                                      http://www.libellules.ch/desactiver_restauration.php

                                      Et cré un nouveau point de restauration

                                      Création d'un point propre :

                                      * Cliquez sur « Démarrer » => tous les programmes=> accessoires=> outils systèmes=> restauration du système=> creer un point de restauration =>nomme le
                                      créer ==> "ok"

                                      --------------------------------------------------------------------------------

                                      mais voila, j'ai cherché un patch mais tous sont en langue étrangère et je ne sais pas lequel choisir...

                                      Tu parles de quoi là ?

                                      Dis moi ou en sont tes problèmes .

                                      Remet un log Hijack.

                                      Bonne journée.

                                      A+

                                      0
                                      1. Salut Seb,

                                        depuis vendredi j'ai fait plein de choses sur mon ordi :

                                        ewido + ccleaner + spybot + ad aware + hijackthis + plus de 15 heures de verif avec avast ... !!! et un kaspersky qui est en train de finir --> rapport sain !! yes !

                                        voici les rapports que j'ai pu récupérer et je voudrais t'envoyer des impressions d'écran (avast --> des fichiers proteges par mot de passe non scannes, ... ce qui me semble etre une intrusion sur mon profil en mode sans echec ?... et un pb de .dll que je rencontre parfois au démarrage) mais je ne sais pas comment faire
                                        j'ai toujours des pubs qui arrivent mais ce n'est plus pour le meme produit

                                        Logfile of HijackThis v1.99.1
                                        Scan saved at 17:32:01, on 11/06/2006
                                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\Program Files\Windows Defender\MsMpEng.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\Explorer.EXE
                                        C:\WINDOWS\system32\spoolsv.exe
                                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                        C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                                        C:\windows\system\hpsysdrv.exe
                                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                        C:\WINDOWS\system32\hphmon06.exe
                                        C:\HP\KBD\KBD.EXE
                                        C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                                        C:\Program Files\iTunes\iTunesHelper.exe
                                        C:\Program Files\ewido anti-malware\ewidoctrl.exe
                                        C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
                                        C:\WINDOWS\system32\rundll32.exe
                                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                        C:\WINDOWS\system32\nvsvc32.exe
                                        C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
                                        C:\WINDOWS\system32\HPZipm12.exe
                                        C:\WINDOWS\AGRSMMSG.exe
                                        C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                        C:\Program Files\Windows Defender\MSASCui.exe
                                        C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
                                        C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
                                        C:\Program Files\WinTV\Ir.exe
                                        C:\Program Files\iPod\bin\iPodService.exe
                                        C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
                                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                        C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                        C:\WINDOWS\system32\wuauclt.exe
                                        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                        C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                                        C:\WINDOWS\system32\spider.exe
                                        C:\hijackThis\HijackThis.exe

                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                        R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                                        O2 - BHO: SWEETIE Class - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                                        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                        O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
                                        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                                        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                                        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                                        O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
                                        O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
                                        O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                        O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                                        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                                        O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
                                        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                                        O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
                                        O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                                        O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                                        O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
                                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                        O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                                        O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                                        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                        O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                                        O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
                                        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                                        O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                                        O4 - HKCU\..\Run: [Acme.PCHButton] C:\PROGRA~1\HELPAN~1\HPQ\XPXWWPP5\plugin\bin\PCHButton.exe
                                        O4 - HKCU\..\Run: [SpyBrowser] "C:\Program Files\SpyBro\SpyBro.exe" /autostart
                                        O4 - Global Startup: AutoStart IR.lnk = C:\Program Files\WinTV\Ir.exe
                                        O4 - Global Startup: desktop(2).ini
                                        O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                                        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                        O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
                                        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                                        O20 - AppInit_DLLs: MsgPlusLoader.dll
                                        O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                        O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                                        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                                        O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                                        O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                        O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
                                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                        O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
                                        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

                                        que penses tu de tout ca ?

                                        merci pour tes lumières et a bientot

                                        atomixte
                                        0
                                        • 1
                                        • 2
                                        • 3