[VIRUS]problème windows après supp. virus

Résolu
niglette Messages postés 11 Statut Membre -  
 psycocool -
Bonjour,

j'ai un gros problème et malgrè les quelques connaissances que j'ai en informatique, je n'y arrive pas....

J'ai eu la joyeuse visite de 56 virus et 3 trojans hier soir (détectés par une nouvelle version de kaspersky que je venais d'installer) et j'ai du supprimer tous les fichiers infectés(ils appartenaient pour la plupart au System32 et système volume information)

Depuis, je n'ai plus accès a beaucoup de choses:
je clique sur le panneau de configuration, la configuration par défaut et a peu près tout ce qui concerne windows mais rien ne se passe.Msn ne se connecte plus et quand il veut effectuer un "dépannage" il me dit que mon IP n'est pas valide.

J'ai essayer une restauration de système mais ca n'a pas fonctionné...

J'ai fais pas mal de recherches sur internet pour essayer de me débrouiller toute seule mais sans succès.

Pouvez-vous m'aider car ce PC est beaucoup utilisé par mon mari pour sa société et il ne peut même plus imprimer ses factures et devis ce qui est très génant.

Je vous remercie d'avance pour l'aide que vous pourrez m'apporter
Configuration: windows XP SP2
PC portable HP

7 réponses

  1. Utilisateur anonyme
     
    Bonjour,

    on va regarder ce que l'on peut faire, mais à mon avis il va falloir prévoir une réparation de Windows

    Prècise nous les logiciels anti-spywares que tu as stp

    Télécharge HijackThis:
    http://www.infos-du-net.com/telecharger/HijackThis.html

    Installe le dans son propre dossier:
    -clic droit sur le bureau, choisis "nouveau dossier" puis installe le dedans.
    Lance le, clic sur "do a system scan and save logfile"
    Puis copie et colle le rapport ici

    A++
    0
    1. niglette Messages postés 11 Statut Membre
       
      Bonjour boulepate62 et merci pour ton aide...

      mais il y a encore un problème, j'ai bien effectué le scan mais lorsque je veux ouvrir le rapport, devinez quoi??? il veut rien savoir!!

      comment faire? merci

      @+
      0
  2. Utilisateur anonyme
     
    Salut,

    dis nous les logiciels anti-spywares que tu as

    (Si quelqu'un passe dan sle coin merci de lui faire par de logiciel anti-spywares je vais pas tarder)
    0
    1. niglette Messages postés 11 Statut Membre
       
      bonsoir,

      comme logiciel anti-spyware, j'ai "spybot-search and destroy" plus celui de kaspersky.

      Je viens aussi de recevoir un mail de "orange" ( mon fournisseur internet) qui me dit que des spams ont été envoyés a partir de mon adresse ip...

      merci encore
      0
  3. Utilisateur anonyme
     
    Salut,
    scanne ton PC avec ces logiciels mit à jour

    A² squared: (gratuit en Français)
    A-squared
    Si tu as besoin d'aide avec A-squared regarde ce tutoriel:
    https://www.pcparadise.fr

    Ad-Aware SE Personal: (en Anglais disponible en Français, gratuit)
    Ad-aware
    Si tu as besoin d'aide pour ad-Aware regarde ce tutoriel:
    https://forums.cnetfrance.fr

    Telecharge, installe puis mets à jour ce logiciel(Ewido), une fois que c'est fait, fais un scan complet de ton système, supprime (delete) tout ce qu'il te trouve puis colle le rapport ici avec un nouveau rapport hijackthis
    Ewido: (en Anglais reste gratuit après la période d'essai)
    Ewido
    Si tu as besoin d'aide avec Ewido(devenu AVG-antispyware) regarde ce tutoriel:
    http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html

    0
    1. niglette Messages postés 11 Statut Membre
       
      le problème est toujours le même, le bloc notes ne s'ouvre pas pour que je puisse copier/coller le rapport içi...
      je vais essayer une réparation avec le cd windows, on verra bien...

      merci

      @+
      0
  4. Utilisateur anonyme
     
    nettoye ton PC avant..
    0
    1. niglette Messages postés 11 Statut Membre
       
      c'est a dire?
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Utilisateur anonyme
     
    avec les logiciels que je viens de te donner
    Car tu as beau réparer Windows mais si ton PC est encore infecté ça ne servira pas à grand chose
    0
    1. niglette Messages postés 11 Statut Membre
       
      Bonsoir,

      bon ba j'ai fait tout ce que tu m'as dit, mais je n'arrive toujours pas a ouvrir le rapport pour le mettre içi...
      j'ai pu tout supprimer avec ewido mais il n'a pas pu supprimer un "trojan.mailskinner.a" qui est en quarantaine. il se trouve dans "program files"

      après tout ça, je n'ai toujours pas accès a ce qui bloquait au début ( bloc-notes, centre de sécurité, ajout et supp. de prog., etc...)

      si je répare windows, que risque t'il de se passer avec ce trojan en quarantaine et est-ce que mes fichiers comme "ma musique","mes films","mes receptions tribal web", etc... vont disparaitre?
      et aussi, va t'il me remettre en ordre tous le programmes qui bloquent?

      merci encore pour ton aide
      0
  7. Utilisateur anonyme
     
    Salut,

    ne répare pas Windows si ton PC est encore infecté ça ne servirait à rien

    Fait ce nettoyage: (à faire réguliérement)

    ¤Telecharges et installes ceci:
    CCleaner:
    Ccleaner

    dans la colonne de gauche clic sur "erreurs" coches toutes les cases, puis cliques en bas sur "chercher des erreurs" une fois finit, cliques sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs.
    Les sauvegardes que tu aura faites tu pourra les supprimer si ton ordinateur n'a plus de problémes

    ¤Relance Ccleaner, vas dans l'onglet "nettoyeur" present sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis clic sur "lancer le nettoyage"

    Si tu as besoin d'aide pour Ccleaner, regarde ce tutoriel:
    http://www.tutopat.com/viewtopic.php?t=305

    et

    Fait ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2 (en haut) va se mettre à clignoter, clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
    Une fois qu'il a terminé colle le rapport ici stp

    https://www.bitdefender.com/toolbox/

    0
    1. niglette Messages postés 11 Statut Membre
       
      bonjour,

      bon j'ai employé la manière forte, j'ai réinstallé windows, kaspersky ne trouve plus de virus, ni trojan et tout remarche impeccable. Je te met le rapport de ccleaner:

      NETTOYAGE COMPLET - (78,994 secs)
      ------------------------------------------------------------------------------------------
      108,3MB supprimés.
      ------------------------------------------------------------------------------------------

      Détails des fichiers effacés
      ------------------------------------------------------------------------------------------
      Fichiers Temporaires d'Internet Explorer (fichiers 5188) 59,4MB
      Cookie:steeve valloir@rad.msn.com/(&H100001) 690 bytes
      Cookie:steeve valloir@www.access-moto.com/(&H100001) 109 bytes
      Cookie:steeve valloir@mediaplex.com/(&H100001) 159 bytes
      Cookie:steeve valloir@epona.fr/(&H100001) 349 bytes
      Cookie:steeve valloir@od2.com/(&H100001) 101 bytes
      Cookie:steeve valloir@www.surftraffic.net/(&H100001) 171 bytes
      Cookie:steeve valloir@ebayobjects.com/(&H100001) 82 bytes
      Cookie:steeve valloir@live.com/(&H100001) 100 bytes
      Cookie:steeve valloir@vivastreet.fr/(&H100001) 537 bytes
      Cookie:steeve valloir@boutique.emoto.com/(&H100001) 380 bytes
      Cookie:steeve valloir@assistance.orange.fr/(&H100001) 79 bytes
      Cookie:steeve valloir@81.255.72.210/(&H100001) 367 bytes
      Cookie:steeve valloir@www.moto-deal.com/(&H100001) 78 bytes
      Cookie:steeve valloir@infomoto.org/(&H100001) 369 bytes
      Cookie:steeve valloir@emule-inside.net/(&H100001) 92 bytes
      Cookie:steeve valloir@fr.slidein.clickintext.net/(&H100001) 197 bytes
      Cookie:steeve valloir@edt02.net/(&H100001) 794 bytes
      Cookie:steeve valloir@search.msn.fr/(&H100001) 79 bytes
      Cookie:steeve valloir@login.live.com/(&H100001) 183 bytes
      Cookie:steeve valloir@www.priceminister.com/(&H100001) 213 bytes
      Cookie:steeve valloir@247realmedia.com/(&H100001) 552 bytes
      Cookie:steeve valloir@ad.cibleclick.com/(&H100001) 106 bytes
      Cookie:steeve valloir@sur-la-toile.com/(&H100001) 380 bytes
      Cookie:steeve valloir@google.fr/(&H100001) 130 bytes
      Cookie:steeve valloir@ww3.shoshkeles.com/(&H100001) 120 bytes
      Cookie:steeve valloir@www.smartadserver.com/(&H100001) 413 bytes
      Cookie:steeve valloir@estat.com/(&H100001) 80 bytes
      Cookie:steeve valloir@iapref.orange.fr/(&H100001) 94 bytes
      Cookie:steeve valloir@clickintext.net/(&H100001) 78 bytes
      Cookie:steeve valloir@yourmedia.com/(&H100001) 99 bytes
      Cookie:steeve valloir@www.hobby-caravan.de/(&H100001) 80 bytes
      Cookie:steeve valloir@ebay.com/(&H100001) 94 bytes
      Cookie:steeve valloir@www.01net.com/(&H100001) 79 bytes
      Cookie:steeve valloir@i2as.idregie.com/(&H100001) 101 bytes
      Cookie:steeve valloir@microsoft.com/(&H100001) 364 bytes
      Cookie:steeve valloir@ebay.fr/(&H100001) 1,02KB
      Cookie:steeve valloir@vw.annonz.ch/(&H100001) 368 bytes
      Cookie:steeve valloir@weborama.fr/(&H100001) 256 bytes
      Cookie:steeve valloir@atraxio.com/(&H100001) 128 bytes
      Cookie:steeve valloir@mresapub.com/(&H100001) 334 bytes
      Cookie:steeve valloir@messenger.msn.com/(&H100001) 96 bytes
      Cookie:steeve valloir@statcounter.com/(&H100001) 188 bytes
      Cookie:steeve valloir@www.pixmania.com/fr/fr/s_action/back2school/(&H100001) 120 bytes
      Cookie:steeve valloir@fr.ebayrtm.com/rtm(&H100001) 346 bytes
      Cookie:steeve valloir@msnportal.112.2o7.net/(&H100001) 119 bytes
      Cookie:steeve valloir@promobenef.com/(&H100001) 374 bytes
      Cookie:steeve valloir@attr-search.ebay.fr/(&H100001) 1,18KB
      Cookie:steeve valloir@atdmt.com/(&H100001) 103 bytes
      Cookie:steeve valloir@xiti.com/(&H100001) 100 bytes
      Cookie:steeve valloir@m.webtrends.com/(&H100001) 187 bytes
      Cookie:steeve valloir@sdv.fr/(&H100001) 152 bytes
      Cookie:steeve valloir@207.net/(&H100001) 105 bytes
      Cookie:steeve valloir@search.msn.com/(&H100001) 80 bytes
      Cookie:steeve valloir@orange.fr/(&H100001) 177 bytes
      Cookie:steeve valloir@ad.uk.tangozebra.com/a(&H100001) 99 bytes
      Cookie:steeve valloir@bluestreak.com/(&H100001) 433 bytes
      Cookie:steeve valloir@apmebf.com/(&H100001) 95 bytes
      Cookie:steeve valloir@www.commentcamarche.net/(&H100001) 114 bytes
      Cookie:steeve valloir@www.promobenef.com/(&H100001) 717 bytes
      Cookie:steeve valloir@www.pixmania.com/(&H100001) 1,40KB
      Cookie:steeve valloir@ads.infomoto.fr/(&H100001) 357 bytes
      Cookie:steeve valloir@www.sur-la-toile.com/(&H100001) 179 bytes
      Cookie:steeve valloir@espace.netavenir.com/diffusion/(&H100001) 506 bytes
      Cookie:steeve valloir@microsoftwlmessengermkt.112.2o7.net/(&H100001) 132 bytes
      Cookie:steeve valloir@questionmarket.com/(&H100001) 227 bytes
      Cookie:steeve valloir@www.cibleclick.com/(&H100001) 107 bytes
      Cookie:steeve valloir@doubleclick.net/(&H100001) 82 bytes
      Cookie:steeve valloir@idregie.com/(&H100001) 541 bytes
      Cookie:steeve valloir@www.emule-inside.net/(&H100001) 79 bytes
      Cookie:steeve valloir@www.infomoto.org/(&H100001) 108 bytes
      Cookie:steeve valloir@wanadoo.fr/(&H100001) 81 bytes
      Cookie:steeve valloir@mybloglog.com/(&H100001) 88 bytes
      Cookie:steeve valloir@motoblouz.com/(&H100001) 367 bytes
      Cookie:steeve valloir@rad.microsoft.com/(&H100001) 750 bytes
      Cookie:steeve valloir@yahoo.com/(&H100001) 174 bytes
      Cookie:steeve valloir@www.moto-deal.com/annuaire/(&H100001) 109 bytes
      Cookie:steeve valloir@adserver.aol.fr/(&H100001) 184 bytes
      Cookie:steeve valloir@usenext.to/(&H100001) 483 bytes
      Cookie:steeve valloir@ads.pointroll.com/(&H100001) 504 bytes
      Cookie:steeve valloir@msn.com/(&H100001) 433 bytes
      Cookie:steeve valloir@affiliation.fotovista.com/(&H100001) 249 bytes
      Marqué pour l'effacement: C:\Documents and Settings\Steeve Valloir\Local Settings\Temporary Internet Files\Content.IE5\index.dat
      Marqué pour l'effacement: C:\Documents and Settings\Steeve Valloir\Cookies\index.dat
      C:\WINDOWS\TEMP\S867460.msp 18,3MB
      C:\WINDOWS\TEMP\~DFB0C4.tmp 16,00KB
      C:\WINDOWS\TEMP\~DFB17C.tmp 16,00KB
      C:\WINDOWS\TEMP\~DFB69C.tmp 16,00KB
      C:\WINDOWS\TEMP\~DFB8DC.tmp 16,00KB
      C:\WINDOWS\TEMP\~DFE734.tmp 16,00KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\276281\TBmanifest.cab 7,23KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\287640\stcfg.cab 7,01KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\287640\STmanifest.cab 7,20KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\316656\auconfig.cab 6,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\316656\auconfig64.cab 7,01KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\316656\auconfig9x.cab 7,00KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\316656\auconfigXP.cab 7,00KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\316656\AUmanifest.cab 7,69KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\316656\au_os.cab 23,28KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\5477828\BIT130.tmp 9,55KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\abe3f.mst 96,50KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\ASPNETSetup.log 4,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\au_all.cab 0,29MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\au_res.dll 9,69KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\au_setuph.dll 90,69KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\byeFC.tmp\Disk1\setup.log 176 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\dotNetFx.log 2,14KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\GLC6.tmp 0,16MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\GLF9.tmp 10,50KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\hpzcdl000.log 762 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\hpzpnp000.log 640 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\hpzrcv000.log 953 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\hpzrei000.log 629 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\HPZset000.log 3,41KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IEC10F.tmp 0,32MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IEC3.tmp 0,33MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IEC31.tmp 0,33MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IEC5A.tmp 0,33MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IEC5B.tmp 0,33MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IEC6.tmp 0,33MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IEC62.tmp 0,33MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IECA.tmp 0,33MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IECFB.tmp 0,33MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT106.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT107.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT1B.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT1C.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT1D.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT1E.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT1F.xml 0,77MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT20.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT21.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT22.xml 0,77MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT23.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT24.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT25.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT26.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT27.xml 0,77MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT34.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT35.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT36.xml 0,77MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT3B.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT3C.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT3D.xml 0,77MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT3E.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT3F.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT40.xml 0,77MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT41.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT42.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT43.xml 0,77MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT44.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT45.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT46.xml 0,77MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT47.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT48.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT49.xml 0,77MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT4A.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT4B.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT4C.xml 0,77MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT4D.xml 2,66MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT4E.dtd 1022 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT4F.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT50.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT51.xml 0,77MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT52.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT53.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT54.xml 0,77MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT8.xml 1,98KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\IMT9.xml 426 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\java_install.log 25,34KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\jusched.log 878 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\langpackSetup.log 1,05KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\manifest.cfg 602 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\msnsearch.exe 0,22MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\msntb.cfg 14,01KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\NDCNETOC.INF 430 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\netfxsl.log 10,73KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\Patch_MSN_Messenger.EXE 2,31MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\pcf25F.tmp 533 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\pft26A.tmp\oca_mrk.vbs 30,95KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\qmgr.cab 77,52KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\qmgr.inf 2,02KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\QTInstallerHelper.dll 68,00KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\WER2dc8.dir00\appcompat.txt 28,28KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\WER2dc8.dir00\IEXPLORE.EXE.hdmp 3,51MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\WER2dc8.dir00\IEXPLORE.EXE.mdmp 54,88KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\WER2dc8.dir00\manifest.txt 1,79KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\WERdf66.dir00\appcompat.txt 15,96KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\WERdf66.dir00\manifest.txt 1,79KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\WERdf66.dir00\rundll32.exe.hdmp 2,39MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\WERdf66.dir00\rundll32.exe.mdmp 42,36KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\~190.tmp 0 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\~3B.tmp 0 bytes
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\~DF5C89.tmp 0,16MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\~DF63DD.tmp 64,00KB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\~DF6B3F.tmp 0,16MB
      C:\DOCUME~1\STEEVE~1\LOCALS~1\Temp\~DFECF7.tmp 64,00KB
      C:\WINDOWS\system32\wbem\Logs\FrameWork.log 260 bytes
      C:\WINDOWS\system32\wbem\Logs\mofcomp.log 9,25KB
      C:\WINDOWS\system32\wbem\Logs\replog.log 403 bytes
      C:\WINDOWS\system32\wbem\Logs\setup.log 4,54KB
      C:\WINDOWS\system32\wbem\Logs\wbemcore.log 143 bytes
      C:\WINDOWS\system32\wbem\Logs\wbemess.log 31,89KB
      C:\WINDOWS\system32\wbem\Logs\wbemprox.log 1,48KB
      C:\WINDOWS\system32\wbem\Logs\wmiadap.log 3,71KB
      C:\WINDOWS\system32\wbem\Logs\wmiprov.log 9,68KB
      C:\WINDOWS\system32\wbem\Logs\wbemess.lo_ 64,04KB
      C:\WINDOWS\0.log 0 bytes
      C:\WINDOWS\cmsetacl.log 200 bytes
      C:\WINDOWS\COM+.log 1,51KB
      C:\WINDOWS\comsetup.log 0,16MB
      C:\WINDOWS\DtcInstall.log 133 bytes
      C:\WINDOWS\FaxSetup.log 0,44MB
      C:\WINDOWS\IDNMitigationAPIs.log 6,61KB
      C:\WINDOWS\ie7.log 61,40KB
      C:\WINDOWS\ie7_main.log 23,17KB
      C:\WINDOWS\iis6.log 72,46KB
      C:\WINDOWS\imsins.log 1,36KB
      C:\WINDOWS\InstallInventel5G.log 36,90KB
      C:\WINDOWS\InvInstaller.log 32,55KB
      C:\WINDOWS\KB873339.log 46,84KB
      C:\WINDOWS\KB885835.log 51,43KB
      C:\WINDOWS\KB885836.log 50,70KB
      C:\WINDOWS\KB886185.log 19,61KB
      C:\WINDOWS\KB887472.log 46,85KB
      C:\WINDOWS\KB888302.log 36,71KB
      C:\WINDOWS\KB890859.log 45,26KB
      C:\WINDOWS\KB891781.log 45,94KB
      C:\WINDOWS\KB893756.log 51,62KB
      C:\WINDOWS\KB893803v2.log 6,19KB
      C:\WINDOWS\KB894391.log 30,37KB
      C:\WINDOWS\KB896358.log 48,13KB
      C:\WINDOWS\KB896423.log 45,85KB
      C:\WINDOWS\KB896424.log 51,59KB
      C:\WINDOWS\KB896428.log 32,72KB
      C:\WINDOWS\KB898461.log 6,84KB
      C:\WINDOWS\KB899587.log 54,56KB
      C:\WINDOWS\KB899591.log 51,40KB
      C:\WINDOWS\KB900485.log 10,79KB
      C:\WINDOWS\KB900725.log 38,65KB
      C:\WINDOWS\KB901017.log 51,09KB
      C:\WINDOWS\KB901190.log 34,22KB
      C:\WINDOWS\KB901214.log 41,75KB
      C:\WINDOWS\KB902400.log 51,78KB
      C:\WINDOWS\KB904706.log 34,23KB
      C:\WINDOWS\KB904942.log 10,52KB
      C:\WINDOWS\KB905414.log 42,28KB
      C:\WINDOWS\KB905749.log 34,43KB
      C:\WINDOWS\KB908519.log 28,04KB
      C:\WINDOWS\KB908531.log 34,85KB
      C:\WINDOWS\KB910437.log 31,59KB
      C:\WINDOWS\KB911280.log 50,47KB
      C:\WINDOWS\KB911562.log 49,95KB
      C:\WINDOWS\KB911564.log 27,13KB
      C:\WINDOWS\KB911567.log 30,29KB
      C:\WINDOWS\KB911927.log 51,48KB
      C:\WINDOWS\KB912919.log 35,02KB
      C:\WINDOWS\KB913580.log 34,57KB
      C:\WINDOWS\KB914388.log 43,83KB
      C:\WINDOWS\KB914389.log 33,85KB
      C:\WINDOWS\KB914440.log 5,51KB
      C:\WINDOWS\KB915865.log 7,75KB
      C:\WINDOWS\KB916595.log 34,64KB
      C:\WINDOWS\KB917344.log 43,56KB
      C:\WINDOWS\KB917422.log 40,37KB
      C:\WINDOWS\KB917734.log 31,93KB
      C:\WINDOWS\KB917953.log 41,54KB
      C:\WINDOWS\KB918439.log 46,54KB
      C:\WINDOWS\KB919007.log 43,53KB
      C:\WINDOWS\KB920213.log 43,63KB
      C:\WINDOWS\KB920214.log 51,19KB
      C:\WINDOWS\KB920670.log 47,14KB
      C:\WINDOWS\KB920683.log 28,24KB
      C:\WINDOWS\KB920685.log 50,87KB
      C:\WINDOWS\KB920872.log 11,99KB
      C:\WINDOWS\KB921398.log 48,53KB
      C:\WINDOWS\KB922582.log 24,77KB
      C:\WINDOWS\KB922616.log 50,67KB
      C:\WINDOWS\KB922760.log 37,11KB
      C:\WINDOWS\KB922819.log 53,25KB
      C:\WINDOWS\KB923191.log 38,75KB
      C:\WINDOWS\KB923414.log 51,50KB
      C:\WINDOWS\KB923980.log 50,70KB
      C:\WINDOWS\KB924191.log 53,65KB
      C:\WINDOWS\KB924270.log 49,12KB
      C:\WINDOWS\KB924496.log 48,17KB
      C:\WINDOWS\KB925486.log 37,04KB
      C:\WINDOWS\log.log 176 bytes
      C:\WINDOWS\msgsocm.log 23,13KB
      C:\WINDOWS\NLSDownlevelMapping.log 6,28KB
      C:\WINDOWS\ntdtcsetup.log 97,18KB
      C:\WINDOWS\ocgen.log 0,23MB
      C:\WINDOWS\ocmsn.log 24,77KB
      C:\WINDOWS\regopt.log 1,26KB
      C:\WINDOWS\sessmgr.setup.log 1022 bytes
      C:\WINDOWS\setup.log 184 bytes
      C:\WINDOWS\setupact.log 0,16MB
      C:\WINDOWS\setupapi.log 0,49MB
      C:\WINDOWS\setuperr.log 0 bytes
      C:\WINDOWS\spupdsvc.log 6,76KB
      C:\WINDOWS\Sti_Trace.log 0 bytes
      C:\WINDOWS\tsoc.log 0,17MB
      C:\WINDOWS\updspapi.log 58,75KB
      C:\WINDOWS\wiadebug.log 214 bytes
      C:\WINDOWS\wiaservc.log 50 bytes
      C:\WINDOWS\wmsetup.log 1,85KB
      C:\WINDOWS\xpsp1hfm.log 361 bytes
      C:\WINDOWS\imsins.BAK 1,36KB
      C:\WINDOWS\OEWABLog.txt 833 bytes
      C:\WINDOWS\setuplog.txt 0,71MB
      C:\WINDOWS\Debug\blastcln.log 286 bytes
      C:\WINDOWS\Debug\mrt.log 1,44KB
      C:\WINDOWS\Debug\NetSetup.LOG 2,44KB
      C:\WINDOWS\security\logs\backup.log 3,59KB
      C:\WINDOWS\security\logs\SceRoot.log 626 bytes
      C:\WINDOWS\security\logs\scesetup.log 0,15MB
      C:\WINDOWS\security\logs\scecomp.old 2,45KB
      C:\Documents and Settings\Steeve Valloir\Application Data\Macromedia\Flash Player\#SharedObjects\NG8JXEWW\fotovista.com\settings.sol 87 bytes
      C:\Documents and Settings\Steeve Valloir\Application Data\Macromedia\Flash Player\#SharedObjects\NG8JXEWW\pixmania.com\pixsettings.sol 96 bytes
      C:\Documents and Settings\Steeve Valloir\Application Data\Macromedia\Flash Player\#SharedObjects\NG8JXEWW\pixmania.com\pixsettings_fr.sol 99 bytes
      C:\Documents and Settings\Steeve Valloir\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#fotovista.com\settings.sol 83 bytes
      C:\Documents and Settings\Steeve Valloir\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#pixmania.com\settings.sol 82 bytes
      C:\Documents and Settings\Steeve Valloir\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol 330 bytes
      ------------------------------------------------------------------------------------------
      0
    2. niglette Messages postés 11 Statut Membre
       
      je te rajoute aussi le rapport de Hijackthis:

      Logfile of HijackThis v1.99.1
      Scan saved at 11:43:39, on 22/11/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5730.0011)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
      C:\Program Files\Apoint2K\Apoint.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\Apoint2K\Apntex.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
      C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
      C:\Program Files\TribalWeb.net\tribalweb.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Documents and Settings\Steeve Valloir\Local Settings\Temporary Internet Files\Content.IE5\C5IV8XAJ\HijackThis[1].exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/...
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
      O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1001\en-xu\stmain.dll
      O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
      O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
      O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
      O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - Startup: TribalWeb.net.lnk = C:\Program Files\TribalWeb.net\tribalweb.exe
      O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_05\bin\npjpi142_05.dll
      O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [INTERNATIONAL] International*
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
      O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
      O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
      O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      0
  8. psycocool
     
    bonjour a tous merci a ceux qui on explique pour le scan l'agreable pour moi serait de savoir si oui ou non je suis infecte et comment les supprime je vous remerci d'avance
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 02:50:49, on 27/09/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2800.1106)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    C:\WINDOWS\System32\cisvc.exe
    C:\WINDOWS\System32\FTRTSVC.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\WINDOWS\System32\snmp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\wuauclt.exe
    C:\windows\system\hpsysdrv.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\program files\mailskinner\mailskinner.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Logitech\SetPoint\KEM.exe
    C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
    C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
    C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
    C:\PROGRA~1\Wanadoo\ComComp.exe
    C:\PROGRA~1\Wanadoo\Toaster.exe
    C:\PROGRA~1\Wanadoo\Inactivity.exe
    C:\PROGRA~1\Wanadoo\PollingModule.exe
    C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
    C:\PROGRA~1\Wanadoo\Watch.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\SecondLife\SecondLife.exe
    C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
    C:\Documents and Settings\Propriétaire\Local Settings\Temp\Répertoire temporaire 1 pour hijackthis.zip\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr7.hpwis.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-fr7.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-fr7.hpwis.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-fr7.hpwis.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.hpe.com/h41271/404D.aspx?cc=us&ll=en&url=http://domainredirects.ext.hpe.com/fr7.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: Seekmo /fleok=1D8A83A5C4ED177C9DAC6D2A1FBB39BFE4976E26CAEDA120180A196D6093 - {07AA283A-43D7-4CBE-A064-32A21112D94D} - C:\Program Files\Seekmo\bin\10.0.314.0\HostIE.dll
    O2 - BHO: EoBho Class - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Seekmo - {07AA283A-43D7-4CBE-A064-32A21112D94D} - C:\Program Files\Seekmo\bin\10.0.314.0\HostIE.dll
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
    O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\eoRezo\EoEngine.exe"
    O4 - HKLM\..\Run: [kdmflgu] c:\windows\system32\kdmflgu.exe kdmflgu
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [Controleur de calendrier pour Ulead Photo Express] C:\Program Files\Ulead Systems\Ulead Photo Express 5 SE\calcheck.exe
    O4 - HKLM\..\Run: [iawlzx] c:\windows\system32\iawlzx.exe iawlzx
    O4 - HKLM\..\Run: [dvmaoo] c:\windows\system32\dvmaoo.exe dvmaoo
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [tpbmxdlc] c:\windows\system32\tpbmxdlc.exe tpbmxdlc
    O4 - HKLM\..\Run: [lmuivnog] c:\windows\system32\lmuivnog.exe lmuivnog
    O4 - HKLM\..\Run: [duhdzffaix] c:\windows\system32\duhdzffaix.exe duhdzffaix
    O4 - HKLM\..\Run: [khbcshz] c:\windows\system32\khbcshz.exe khbcshz
    O4 - HKLM\..\Run: [tdfotagt] c:\windows\system32\tdfotagt.exe tdfotagt
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [vlxkkgmvkm] c:\windows\system32\vlxkkgmvkm.exe vlxkkgmvkm
    O4 - HKLM\..\Run: [SeekmoSA] "C:\Program Files\Seekmo\bin\10.0.314.0\SeekmoSA.exe"
    O4 - HKLM\..\Run: [ndocqxei] c:\windows\system32\ndocqxei.exe ndocqxei
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [mkboyjcby] c:\windows\system32\mkboyjcby.exe mkboyjcby
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Spyware-Secure] C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Steam] "c:\valve\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [MailSkinner] c:\program files\mailskinner\mailskinner.exe
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Picture Package Menu.lnk = ?
    O4 - Global Startup: Picture Package VCD Maker.lnk = ?
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?08aef096261049f0871f13eb94dae49d
    O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?08aef096261049f0871f13eb94dae49d
    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://margerite70.spaces.live.com/PhotoUpload/MsnPUpld.cab?10,0,912,0
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/sysreqlab2.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab53083.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxmultijoueurs.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
    O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Windows Service Pack Installer update service (spupdsvc) - Unknown owner - C:\WINDOWS\System32\spupdsvc.exe
    O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
    0