Infecté par le virus win32.trojan.dropper

Résolu
Bonjour à vous, Joyeux Noel.
Malheureusement, au cours des dernières journées, mon ordinateur a été touché par ce virus et je suis depuis incapable de l'enlever de mon système. Pourriez-vous m'aider à enlever ce virus?

Voici mon rapport de Hijackthis

Logfile of HijackThis v1.99.1
Scan saved at 11:54:39, on 2006-12-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\msmapi32.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\WINDOWS\vVX6000.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Pat\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?pc=mssh&form=msshhp&ocid=onepro&homepage=http%3a%2f%2fwww.uottawa.ca%2f
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?pc=mssh&form=msshhp&ocid=onepro&homepage=http%3a%2f%2fwww.microsoft.com%2fisapi%2fredir.dll%3fprd%3d{SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.aol.com/
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {00110011-4b0b-44d5-9718-90c88817369b} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {086ae192-23a6-48d6-96ec-715f53797e85} - (no file)
O2 - BHO: (no name) - {11904ce8-632a-4856-a7cc-00b33fe71bd8} - (no file)
O2 - BHO: (no name) - {150fa160-130d-451f-b863-b655061432ba} - (no file)
O2 - BHO: (no name) - {15ACE85C-0BB1-42d1-9E32-07EB0506675A} - (no file)
O2 - BHO: (no name) - {17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} - (no file)
O2 - BHO: (no name) - {1b68470c-2def-493b-8a4a-8e2d81be4ea5} - (no file)
O2 - BHO: (no name) - {1c4da27d-4d52-4465-a089-98e01bb725ca} - (no file)
O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1} - (no file)
O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} - (no file)
O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - (no file)
O2 - BHO: (no name) - {2d38a51a-23c9-48a1-a33c-48675aa2b494} - (no file)
O2 - BHO: (no name) - {2e246fae-8420-11d9-870d-000c2917de7f} - (no file)
O2 - BHO: (no name) - {2e9caff6-30c7-4208-8807-e79d4ec6f806} - (no file)
O2 - BHO: (no name) - {479fd0cf-5be9-4c63-8cda-b6d371c67bd5} - (no file)
O2 - BHO: (no name) - {5753791b-f607-48ca-814e-91c14d081f9e} - (no file)
O2 - BHO: (no name) - {62E2E094-F989-48C6-B947-6E79DA2294F9} - (no file)
O2 - BHO: (no name) - {7070a8f9-08a4-ca47-0ab0-1eb9e4ee1f3b} - (no file)
O2 - BHO: (no name) - {746455fe-d059-47e7-af0e-140e03f5a447} - (no file)
O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
O2 - BHO: (no name) - {7a7e6d97-b492-4884-9abb-c31281dcc4f2} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: ASGP32.ASGP - {82B07A2B-F0AF-45FC-BE44-18D83B01EAD9} - C:\WINDOWS\system32\asgp32.dll
O2 - BHO: (no name) - {860c2f6b-ca82-4282-9187-beccbb66f0af} - (no file)
O2 - BHO: (no name) - {87185e78-a61b-4db3-965a-3235bbd7a622} - (no file)
O2 - BHO: (no name) - {8dc8f96d-34f7-1501-a2a4-631341aa3ac1} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9c5875b8-93f3-429d-ff34-660b206d897a} - (no file)
O2 - BHO: (no name) - {a2595f37-48d0-46a1-9b51-478591a97764} - (no file)
O2 - BHO: (no name) - {a6f42cad-2559-48df-af30-89e480af5dfa} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {b212d577-05b7-4963-911e-4a8588160dfa} - (no file)
O2 - BHO: (no name) - {CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765721306} - (no file)
O2 - BHO: (no name) - {d1ac752e-883f-4ed8-8828-b618c3a72152} - (no file)
O2 - BHO: (no name) - {e2b2b5a1-b48c-4886-a318-723916a01024} - (no file)
O2 - BHO: (no name) - {e2ddf680-9905-4dee-8c64-0a5de7fe133c} - (no file)
O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
O2 - BHO: (no name) - {e6d5237d-a6c7-4c83-a67f-f9f15586fa62} - (no file)
O2 - BHO: (no name) - {e7afff2a-1b57-49c7-bf6b-e5123394c970} - (no file)
O2 - BHO: (no name) - {fcaddc14-bd46-408a-9842-cdbe1c6d37eb} - (no file)
O2 - BHO: (no name) - {fd9bc004-8331-4457-b830-4759ff704c22} - (no file)
O2 - BHO: (no name) - {fe2d25c1-c1db-4b5e-9390-af1cb5302f32} - (no file)
O2 - BHO: (no name) - {ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} - (no file)
O2 - BHO: (no name) - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.aol.com/
O16 - DPF: {02CA9974-B6AC-497E-A371-73580432B0F6} (Eyeball Video Message Control) - http://www.zoom11.com/Redist/EyeballSDK.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
O16 - DPF: {7DFDB8FD-B498-4958-B930-38021B94351D} (imlUCID Class) - https://validate.perfdrive.com/?ssa=1cb613c1-b580-495b-866c-b6fe71718572&ssb=36371211747&ssc=https%3A%2F%2Fimlive.com%2Fchatsource%2FImlCID.cab&ssi=b98a4b26-ba0f-44c8-a2a5-0315e1e966ee&ssk=support@shieldsquare.com&ssm=77124680964133473105650333749186&ssn=7eafd9fa9826c01597307b85effe791743b46ba2f27a-3977-4b0e-988e66&sso=940ea59d-ee88a13130f2489df365438a8b123fc056d418d499c5df48&ssp=15188465711607082399160702401540426&ssq=67141537474651350705574746278120044759785&ssr=OTEuMjA5LjM1LjIxOA==&sst=Mozilla/5.0%20(X11;%20Linux%20x86_64)%20AppleWebKit/537.36%20(KHTML,%20like%20Gecko)%20Chrome/74.0.3729.131%20Safari/537.36&ssv=&ssw=
O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
O16 - DPF: {99D090A6-EA84-466E-8F21-834B36F57E77} (PeerFactor_DL Control) - http://peerfactor.fr/PeerFactor_DL.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B9A296D4-38AC-4566-8168-F7ACAF7D35E6} (Eyeball Video Session Control) - https://imlive.com/ChatSource/gVideoContol.cab
O16 - DPF: {FA30EC32-668B-4B60-B13C-4C84EB90C3C9} (ActiveID Control) - http://www.meetstream.com/activex/activeid1003/activeid.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winbfi32 - winbfi32.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Pourriez-vous m'aider?

Merci beaucoup
Configuration: Windows XP
Internet Explorer 6.0

18 réponses

  1. Modérateur
    Salut

    jolie infection !!!

    # Télécharge ceci: (merci a S!RI pour ce petit programme).

    http://siri.urz.free.fr/Fix/SmitfraudFix.zip

    Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1,
    voila a quoi cela ressemble : http://siri.urz.free.fr/Fix/SmitfraudFix.php
    il va générer un rapport : copie/colle le sur le poste stp.

    ++
    0
    1. SmitFraudFix v2.131

      Scan done at 12:15:02,18, 2006-12-25
      Run from C:\Documents and Settings\Patrice\Desktop\SmitfraudFix
      OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
      The filesystem type is NTFS
      Fix run in normal mode

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      C:\WINDOWS\accesss.exe FOUND !
      C:\WINDOWS\adware-sheriff-box.gif FOUND !
      C:\WINDOWS\adware-sheriff-header.gif FOUND !
      C:\WINDOWS\antispylab-logo.gif FOUND !
      C:\WINDOWS\about_spyware_bg.gif FOUND !
      C:\WINDOWS\astctl32.ocx FOUND !
      C:\WINDOWS\avpcc.dll FOUND !
      C:\WINDOWS\blue-bg.gif FOUND !
      C:\WINDOWS\buy-now-btn.gif FOUND !
      C:\WINDOWS\close-bar.gif FOUND !
      C:\WINDOWS\clrssn.exe FOUND !
      C:\WINDOWS\corner-left.gif FOUND !
      C:\WINDOWS\corner-right.gif FOUND !
      C:\WINDOWS\cpan.dll FOUND !
      C:\WINDOWS\dialup.exe FOUND !
      C:\WINDOWS\facts.gif FOUND !
      C:\WINDOWS\footer.giff FOUND !
      C:\WINDOWS\free-scan-btn.gif FOUND !
      C:\WINDOWS\h-line-gradient.gif FOUND !
      C:\WINDOWS\header-bg.gif FOUND !
      C:\WINDOWS\inetdctr.dll FOUND !
      C:\WINDOWS\infected.gif FOUND !
      C:\WINDOWS\info.gif FOUND !
      C:\WINDOWS\mtwirl32.dll FOUND !
      C:\WINDOWS\no-icon.gif FOUND !
      C:\WINDOWS\notepad32.exe FOUND !
      C:\WINDOWS\olehelp.exe FOUND !
      C:\WINDOWS\reg-freeze-box.gif FOUND !
      C:\WINDOWS\reg-freeze-header.gif FOUND !
      C:\WINDOWS\remove-spyware-btn.gif FOUND !
      C:\WINDOWS\runwin32.exe FOUND !
      C:\WINDOWS\spp3.dll FOUND !
      C:\WINDOWS\spyware-sheriff-header.gif FOUND !
      C:\WINDOWS\spyware-sheriff-box.gif FOUND !
      C:\WINDOWS\star.gif FOUND !
      C:\WINDOWS\star-grey.gif FOUND !
      C:\WINDOWS\systeem.exe FOUND !
      C:\WINDOWS\systemcritical.exe FOUND !
      C:\WINDOWS\time.exe FOUND !
      C:\WINDOWS\true-stories.gif FOUND !
      C:\WINDOWS\users32.exe FOUND !
      C:\WINDOWS\waol.exe FOUND !
      C:\WINDOWS\warning-bar-ico.gif FOUND !
      C:\WINDOWS\win-sec-center-logo.gif FOUND !
      C:\WINDOWS\win32e.exe FOUND !
      C:\WINDOWS\win64.exe FOUND !
      C:\WINDOWS\winajbm.dll FOUND !
      C:\WINDOWS\window.exe FOUND !
      C:\WINDOWS\windows-compatible.gif FOUND !
      C:\WINDOWS\wininet32.exe FOUND !
      C:\WINDOWS\winmgnt.exe FOUND !
      C:\WINDOWS\x.exe FOUND !
      C:\WINDOWS\xplugin.dll FOUND !
      C:\WINDOWS\xxxvideo.hta FOUND !
      C:\WINDOWS\y.exe FOUND !
      C:\WINDOWS\yes-icon.gif FOUND !
      C:\WINDOWS\yod.htm FOUND !

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      C:\WINDOWS\system32\ace16win.dll FOUND !
      C:\WINDOWS\system32\anti_troj.exe FOUND !
      C:\WINDOWS\system32\CWS_iestart.exe FOUND !
      C:\WINDOWS\system32\dload.exe FOUND !
      C:\WINDOWS\system32\exuc32.tmp FOUND !
      C:\WINDOWS\system32\iewd.exe FOUND !
      C:\WINDOWS\system32\kernels64.exe FOUND !
      C:\WINDOWS\system32\lfd.dat FOUND !
      C:\WINDOWS\system32\mirarsearch_toolbar.exe FOUND !
      C:\WINDOWS\system32\mpsegment.exe FOUND !
      C:\WINDOWS\system32\msmapi32.exe FOUND !
      C:\WINDOWS\system32\msmsn.exe FOUND !
      C:\WINDOWS\system32\msvol.tlb FOUND !
      C:\WINDOWS\system32\ncompat.tlb FOUND !
      C:\WINDOWS\system32\netstat2.exe FOUND !
      C:\WINDOWS\system32\oiso.bin FOUND !
      C:\WINDOWS\system32\ot.ico FOUND !
      C:\WINDOWS\system32\pcf.pdf FOUND !
      C:\WINDOWS\system32\perfont.exe FOUND !
      C:\WINDOWS\system32\performent202.dll FOUND !
      C:\WINDOWS\system32\POPCORN72.EXE FOUND !
      C:\WINDOWS\system32\proqlaim.exe FOUND !
      C:\WINDOWS\system32\shellgui32.dll FOUND !
      C:\WINDOWS\system32\sumsw32.exe FOUND !
      C:\WINDOWS\system32\ts.ico FOUND !
      C:\WINDOWS\system32\vxgamet?.exe FOUND !
      C:\WINDOWS\system32\vxh8jkdq?.exe FOUND !
      C:\WINDOWS\system32\win32hp.dll FOUND !
      C:\WINDOWS\system32\winmuse.exe FOUND !

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Patrice

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Patrice\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Patrice\FAVORI~1

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

      »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="My Current Home Page"

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, following keys are not inevitably infected!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

      »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection

      »»»»»»»»»»»»»»»»»»»»»»»» End

      et voilà
      0
      1. Modérateur
        oulala :)

        # Démarre en mode sans échec :
        Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
        Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
        Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
        (Si F8 ne marche pas utilise la touche F5).
        ----------------------------------------------------------------------------
        # Relance le programme Smitfraud :
        Cette fois choisit l’option 2, répond oui a tous ;
        Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

        ensuite : fais le 1/ et 2/ de ce lien :

        virus methode preliminaire de desinfection version fr

        ++

        0
        1. d'accord, jy reviens dès que le repas de Noel est terminé.
          Merci beaucoup déjà pour l'aide
          0
          1. voici mon rapport de Smitfraudfix

            SmitFraudFix v2.131

            Scan done at 13:42:19,87, 2006-12-25
            Run from C:\SmitfraudFix
            OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
            The filesystem type is NTFS
            Fix run in safe mode

            »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
            !!!Attention, following keys are not inevitably infected!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» Killing process

            »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

            GenericRenosFix by S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

            C:\WINDOWS\accesss.exe Deleted
            C:\WINDOWS\adware-sheriff-box.gif Deleted
            C:\WINDOWS\adware-sheriff-header.gif Deleted
            C:\WINDOWS\antispylab-logo.gif Deleted
            C:\WINDOWS\about_spyware_bg.gif Deleted
            C:\WINDOWS\astctl32.ocx Deleted
            C:\WINDOWS\avpcc.dll Deleted
            C:\WINDOWS\blue-bg.gif Deleted
            C:\WINDOWS\buy-now-btn.gif Deleted
            C:\WINDOWS\close-bar.gif Deleted
            C:\WINDOWS\clrssn.exe Deleted
            C:\WINDOWS\corner-left.gif Deleted
            C:\WINDOWS\corner-right.gif Deleted
            C:\WINDOWS\cpan.dll Deleted
            C:\WINDOWS\dialup.exe Deleted
            C:\WINDOWS\facts.gif Deleted
            C:\WINDOWS\footer.gif Deleted
            C:\WINDOWS\free-scan-btn.gif Deleted
            C:\WINDOWS\h-line-gradient.gif Deleted
            C:\WINDOWS\header-bg.gif Deleted
            C:\WINDOWS\inetdctr.dll Deleted
            C:\WINDOWS\infected.gif Deleted
            C:\WINDOWS\info.gif Deleted
            C:\WINDOWS\mtwirl32.dll Deleted
            C:\WINDOWS\no-icon.gif Deleted
            C:\WINDOWS\notepad32.exe Deleted
            C:\WINDOWS\olehelp.exe Deleted
            C:\WINDOWS\reg-freeze-box.gif Deleted
            C:\WINDOWS\reg-freeze-header.gif Deleted
            C:\WINDOWS\remove-spyware-btn.gif Deleted
            C:\WINDOWS\runwin32.exe Deleted
            C:\WINDOWS\spp3.dll Deleted
            C:\WINDOWS\spyware-sheriff-header.gif Deleted
            C:\WINDOWS\spyware-sheriff-box.gif Deleted
            C:\WINDOWS\star.gif Deleted
            C:\WINDOWS\star-grey.gif Deleted
            C:\WINDOWS\true-stories.gif Deleted
            C:\WINDOWS\systeem.exe Deleted
            C:\WINDOWS\systemcritical.exe Deleted
            C:\WINDOWS\time.exe Deleted
            C:\WINDOWS\users32.exe Deleted
            C:\WINDOWS\waol.exe Deleted
            C:\WINDOWS\warning-bar-ico.gif Deleted
            C:\WINDOWS\win-sec-center-logo.gif Deleted
            C:\WINDOWS\win32e.exe Deleted
            C:\WINDOWS\win64.exe Deleted
            C:\WINDOWS\winajbm.dll Deleted
            C:\WINDOWS\window.exe Deleted
            C:\WINDOWS\windows-compatible.gif Deleted
            C:\WINDOWS\wininet32.exe Deleted
            C:\WINDOWS\winmgnt.exe Deleted
            C:\WINDOWS\x.exe Deleted
            C:\WINDOWS\xplugin.dll Deleted
            C:\WINDOWS\xxxvideo.hta Deleted
            C:\WINDOWS\y.exe Deleted
            C:\WINDOWS\yes-icon.gif Deleted
            C:\WINDOWS\yod.htm Deleted
            C:\WINDOWS\system32\ace16win.dll Deleted
            C:\WINDOWS\system32\anti_troj.exe Deleted
            C:\WINDOWS\system32\CWS_iestart.exe Deleted
            C:\WINDOWS\system32\dload.exe Deleted
            C:\WINDOWS\system32\exuc32.tmp Deleted
            C:\WINDOWS\system32\iewd.exe Deleted
            C:\WINDOWS\system32\kernels64.exe Deleted
            C:\WINDOWS\system32\lfd.dat Deleted
            C:\WINDOWS\system32\mirarsearch_toolbar.exe Deleted
            C:\WINDOWS\system32\mpsegment.exe Deleted
            C:\WINDOWS\system32\msmapi32.exe Deleted
            C:\WINDOWS\system32\msmsn.exe Deleted
            C:\WINDOWS\system32\msvol.tlb Deleted
            C:\WINDOWS\system32\ncompat.tlb Deleted
            C:\WINDOWS\system32\netstat2.exe Deleted
            C:\WINDOWS\system32\oiso.bin Deleted
            C:\WINDOWS\system32\ot.ico Deleted
            C:\WINDOWS\system32\pcf.pdf Deleted
            C:\WINDOWS\system32\perfont.exe Deleted
            C:\WINDOWS\system32\performent202.dll Deleted
            C:\WINDOWS\system32\POPCORN72.EXE Deleted
            C:\WINDOWS\system32\proqlaim.exe Deleted
            C:\WINDOWS\system32\shellgui32.dll Deleted
            C:\WINDOWS\system32\smartdrv.exe Deleted
            C:\WINDOWS\system32\sumsw32.exe Deleted
            C:\WINDOWS\system32\ts.ico Deleted
            C:\WINDOWS\system32\vxgamet?.exe Deleted
            C:\WINDOWS\system32\vxh8jkdq?.exe Deleted
            C:\WINDOWS\system32\win32hp.dll Deleted
            C:\WINDOWS\system32\winmuse.exe Deleted

            »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
            !!!Attention, following keys are not inevitably infected!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

            Registry Cleaning done.

            »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
            !!!Attention, following keys are not inevitably infected!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» End

            Ensuite voici le rapport de mon scan avec AVG:

            -------------------------------------------------------
            AVG Anti-Spyware - Scan Report
            ---------------------------------------------------------

            + Created at: 16:25:36 2006-12-25

            + Scan result:

            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7070A8F9-08A4-CA47-0AB0-1EB9E4EE1F3B} -> Adware.CoolWebSearch : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Active Setup\Installed Components\{Y479C6D0-OTRW-U5GH-S1EE-E0AC10B4E666} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00110011-4B0B-44D5-9718-90C88817369B} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{086AE192-23A6-48D6-96EC-715F53797E85} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11904CE8-632A-4856-A7CC-00B33FE71BD8} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{150FA160-130D-451F-B863-B655061432BA} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{15ACE85C-0BB1-42D1-9E32-07EB0506675A} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{17DA0C9E-4A27-4AC5-BB75-5D24B8CDB972} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1C4DA27D-4D52-4465-A089-98E01BB725CA} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFB1} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1F48AA48-C53A-4E21-85E7-AC7CC6B5FFB2} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{202A961F-23AE-42B1-9505-FFE3C818D717} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2D38A51A-23C9-48A1-A33C-48675AA2B494} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E246FAE-8420-11D9-870D-000C2917DE7F} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E9CAFF6-30C7-4208-8807-E79D4EC6F806} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{479FD0CF-5BE9-4C63-8CDA-B6D371C67BD5} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5753791B-F607-48CA-814E-91C14D081F9E} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{746455FE-D059-47E7-AF0E-140E03F5A447} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7A7E6D97-B492-4884-9ABB-C31281DCC4F2} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{860C2F6B-CA82-4282-9187-BECCBB66F0AF} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{87185E78-A61B-4DB3-965A-3235BBD7A622} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8DC8F96D-34F7-1501-A2A4-631341AA3AC1} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9C5875B8-93F3-429D-FF34-660B206D897A} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A2595F37-48D0-46A1-9B51-478591A97764} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A6F42CAD-2559-48DF-AF30-89E480AF5DFA} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA0E28FA-1AFD-4C21-A8DC-70EB5BE2F076} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CF021F40-3E14-23A5-CBA2-717765721306} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D1AC752E-883F-4ED8-8828-B618C3A72152} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2B2B5A1-B48C-4886-A318-723916A01024} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2DDF680-9905-4DEE-8C64-0A5DE7FE133C} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E3EEBBE8-9CAB-4C76-B26A-747E25EBB4C6} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E6D5237D-A6C7-4C83-A67F-F9F15586FA62} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7AFFF2A-1B57-49C7-BF6B-E5123394C970} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD9BC004-8331-4457-B830-4759FF704C22} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE2D25C1-C1DB-4B5E-9390-AF1CB5302F32} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FF1BF4C7-4E08-4A28-A43F-9D60A9F7A880} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF} -> Adware.Generic : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1B68470C-2DEF-493B-8A4A-8E2D81BE4EA5} -> Downloader.Delf : Ignored.
            C:\WINDOWS\system32\ttohzdgd.exe -> Downloader.VB.aeq : Ignored.
            C:\WINDOWS\system32\hvnidrxh.exe -> Downloader.VB.afk : Ignored.
            C:\WINDOWS\system32\nurmqejd.exe -> Downloader.VB.afk : Ignored.
            C:\WINDOWS\system32\ondgtwoa.exe -> Downloader.VB.afk : Ignored.
            C:\Pat\EvID4226Patch223d-en.zip/EvID4226Patch.exe -> Not-A-Virus.Hacktool.EvID : Ignored.
            C:\Documents and Settings\Patrice\Cookies\patrice@247realmedia[2].txt -> TrackingCookie.247realmedia : Ignored.
            C:\Documents and Settings\Patrice\Cookies\patrice@advertising[1].txt -> TrackingCookie.Advertising : Ignored.
            C:\Documents and Settings\Patrice\Cookies\patrice@atdmt[2].txt -> TrackingCookie.Atdmt : Ignored.
            C:\Documents and Settings\Patrice\Cookies\patrice@bluestreak[2].txt -> TrackingCookie.Bluestreak : Ignored.
            C:\Documents and Settings\Patrice\Cookies\patrice@casalemedia[1].txt -> TrackingCookie.Casalemedia : Ignored.
            C:\Documents and Settings\Patrice\Cookies\patrice@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignored.
            C:\Documents and Settings\Patrice\Cookies\patrice@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Ignored.
            C:\Documents and Settings\Patrice\Cookies\patrice@weborama[2].txt -> TrackingCookie.Weborama : Ignored.
            C:\WINDOWS\system32\intr32.dll -> Trojan.AntiSpySoldier.a : Ignored.
            HKU\S-1-5-21-2909678354-621692734-1404286616-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B212D577-05B7-4963-911E-4A8588160DFA} -> Trojan.Delf.nj : Ignored.

            ::Report end

            Est-ce que ca s'en vient un peu mieux de ce que c'était au début?
            0
            1. Modérateur
              ok,

              as tu supprimmer tout ce que AVG t'a touvé ???

              poste le rapport du scan en ligne une fois fini stp !

              c'est un peu mieux oui ;-))

              ++
              0
              1. jai effacer tout ce que AVG a trouvé... le scan enligne est a moitié fini. Je le met enligne dès qu'il est fini.

                merci encore pour l'aide
                0
                1. Voici le rapport de mon scan sur BitDefender:

                  BitDefender Online Scanner

                  Scan report generated at: Mon, Dec 25, 2006 - 18:58:42

                  Scan path: C:\;D:\;E:\;F:\;G:\;H:\;

                  Statistics

                  Time
                  02:28:26

                  Files
                  1165134

                  Folders
                  7475

                  Boot Sectors
                  2

                  Archives
                  11054

                  Packed Files
                  237374

                  Results

                  Identified Viruses
                  8

                  Infected Files
                  14

                  Suspect Files
                  3

                  Warnings
                  0

                  Disinfected
                  0

                  Deleted Files
                  21

                  Engines Info

                  Virus Definitions
                  356998

                  Engine build
                  AVCORE v1.0 (build 2371) (i386) (Dec 13 2006 11:16:42)

                  Scan plugins
                  14

                  Archive plugins
                  38

                  Unpack plugins
                  6

                  E-mail plugins
                  6

                  System plugins
                  1

                  Scan Settings

                  First Action
                  Disinfect

                  Second Action
                  Delete

                  Heuristics
                  Yes

                  Enable Warnings
                  Yes

                  Scanned Extensions
                  *;

                  Exclude Extensions

                  Scan Emails
                  Yes

                  Scan Archives
                  Yes

                  Scan Packed
                  Yes

                  Scan Files
                  Yes

                  Scan Boot
                  Yes

                  Scanned File
                  Status

                  C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\42A43678.51b=>(Quarantine-2)
                  Infected with: Trojan.Downloader.Istbar.RM

                  C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\42A43678.51b=>(Quarantine-2)
                  Disinfection failed

                  C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\42A43678.51b=>(Quarantine-2)
                  Deleted

                  C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\42A43678.exe=>(Quarantine-2)
                  Infected with: Trojan.Downloader.Istbar.RM

                  C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\42A43678.exe=>(Quarantine-2)
                  Disinfection failed

                  C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\42A43678.exe=>(Quarantine-2)
                  Deleted

                  C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6E932D64.exe=>(Quarantine-2)
                  Infected with: Trojan.Clicker.VB.BP

                  C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6E932D64.exe=>(Quarantine-2)
                  Disinfection failed

                  C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\6E932D64.exe=>(Quarantine-2)
                  Deleted

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001330.exe
                  Infected with: Trojan.AntiSpySoldier.A

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001330.exe
                  Disinfection failed

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001330.exe
                  Deleted

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001359.exe
                  Infected with: Trojan.Downloader.VB.I

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001359.exe
                  Disinfection failed

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001359.exe
                  Deleted

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001360.exe
                  Infected with: Trojan.Downloader.VB.I

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001360.exe
                  Disinfection failed

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001360.exe
                  Deleted

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001361.exe
                  Infected with: Trojan.Downloader.VB.I

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001361.exe
                  Disinfection failed

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001361.exe
                  Deleted

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001362.dll
                  Infected with: Trojan.AntiSpySoldier.A

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001362.dll
                  Disinfection failed

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001362.dll
                  Deleted

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001363.exe
                  Infected with: Trojan.Downloader.VB.OY

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001363.exe
                  Disinfection failed

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001363.exe
                  Deleted

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001368.exe=>(Quarantine-2)
                  Infected with: Trojan.Downloader.Istbar.RM

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001368.exe=>(Quarantine-2)
                  Disinfection failed

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001368.exe=>(Quarantine-2)
                  Deleted

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001369.exe=>(Quarantine-2)
                  Infected with: Trojan.Clicker.VB.BP

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001369.exe=>(Quarantine-2)
                  Disinfection failed

                  C:\System Volume Information\_restore{F12F6FCA-02BA-4BDE-887E-CF7AA5F3F6EF}\RP2\A0001369.exe=>(Quarantine-2)
                  Deleted

                  C:\WINDOWS\system32\acdazsie.exe
                  Suspected of: Trojan.Downloader.Tibs.BV

                  C:\WINDOWS\system32\acdazsie.exe
                  Disinfection failed

                  C:\WINDOWS\system32\acdazsie.exe
                  Deleted

                  C:\WINDOWS\system32\asgp32.dll
                  Suspected of: Generic.Malware.Gdld.2FD3D431

                  C:\WINDOWS\system32\asgp32.dll
                  Disinfection failed

                  C:\WINDOWS\system32\asgp32.dll
                  Delete failed

                  C:\WINDOWS\system32\czvirnpl.exe
                  Suspected of: Generic.Malware.dld!.1E4DBDD6

                  C:\WINDOWS\system32\czvirnpl.exe
                  Disinfection failed

                  C:\WINDOWS\system32\czvirnpl.exe
                  Deleted

                  C:\WINDOWS\system32\gftgykfr.exe
                  Infected with: Trojan.Downloader.Tibs.HK

                  C:\WINDOWS\system32\gftgykfr.exe
                  Disinfection failed

                  C:\WINDOWS\system32\gftgykfr.exe
                  Deleted

                  C:\WINDOWS\system32\kcxelecx.exe
                  Infected with: Worm.Glowa.C

                  C:\WINDOWS\system32\kcxelecx.exe
                  Disinfection failed

                  C:\WINDOWS\system32\kcxelecx.exe
                  Deleted

                  C:\WINDOWS\system32\okbvohrh.exe
                  Infected with: Trojan.Downloader.Tibs.U

                  C:\WINDOWS\system32\okbvohrh.exe
                  Disinfection failed

                  C:\WINDOWS\system32\okbvohrh.exe
                  Deleted
                  0
                  1. Voici mon Smitfraudfix et Hijackthis à la suite du scan sur le Web`

                    SmitFraudFix v2.131

                    Scan done at 23:08:30,48, 2006-12-25
                    Run from C:\Documents and Settings\Patrice\Desktop\SmitfraudFix
                    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
                    The filesystem type is NTFS
                    Fix run in normal mode

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                    C:\WINDOWS\system32\oiso.bin FOUND !

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Patrice

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Patrice\Application Data

                    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Patrice\FAVORI~1

                    »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                    "Source"="About:Home"
                    "SubscribedURL"="About:Home"
                    "FriendlyName"="My Current Home Page"

                    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                    !!!Attention, following keys are not inevitably infected!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                    !!!Attention, following keys are not inevitably infected!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                    "AppInit_DLLs"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                    !!!Attention, following keys are not inevitably infected!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                    "System"=""

                    »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

                    »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection

                    »»»»»»»»»»»»»»»»»»»»»»»» End

                    et

                    Logfile of HijackThis v1.99.1
                    Scan saved at 23:09:54, on 2006-12-25
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Windows Defender\MsMpEng.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                    C:\Program Files\Norton Internet Security\ISSVC.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
                    C:\WINDOWS\eHome\ehRecvr.exe
                    C:\WINDOWS\eHome\ehSched.exe
                    C:\Program Files\ewido anti-malware\ewidoctrl.exe
                    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                    C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
                    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
                    C:\Program Files\Canon\CAL\CALMAIN.exe
                    C:\WINDOWS\system32\dllhost.exe
                    C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
                    C:\WINDOWS\ehome\ehtray.exe
                    C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
                    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                    C:\WINDOWS\eHome\ehmsas.exe
                    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                    C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
                    C:\Program Files\Windows Defender\MSASCui.exe
                    C:\Program Files\DAEMON Tools\daemon.exe
                    C:\Program Files\HPQ\SHARED\HPQWMI.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\Program Files\PowerISO\PWRISOVM.EXE
                    C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                    C:\Program Files\iPod\bin\iPodService.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
                    C:\WINDOWS\vVX6000.exe
                    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                    C:\Program Files\MSN Messenger\MsnMsgr.Exe
                    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                    C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\WINDOWS\NOTEPAD.EXE
                    C:\Pat\hijackthis\HijackThis.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?pc=mssh&form=msshhp&ocid=onepro&homepage=http%3a%2f%2fwww.uottawa.ca%2f
                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.aol.com/
                    R3 - Default URLSearchHook is missing
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O2 - BHO: ASGP32.ASGP - {82B07A2B-F0AF-45FC-BE44-18D83B01EAD9} - C:\WINDOWS\system32\asgp32.dll
                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
                    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
                    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
                    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
                    O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                    O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
                    O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                    O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
                    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O14 - IERESET.INF: START_PAGE_URL=https://www.aol.com/
                    O16 - DPF: {02CA9974-B6AC-497E-A371-73580432B0F6} (Eyeball Video Message Control) - http://www.zoom11.com/Redist/EyeballSDK.cab
                    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
                    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                    O16 - DPF: {7DFDB8FD-B498-4958-B930-38021B94351D} (imlUCID Class) - https://validate.perfdrive.com/?ssa=1cb613c1-b580-495b-866c-b6fe71718572&ssb=36371211747&ssc=https%3A%2F%2Fimlive.com%2Fchatsource%2FImlCID.cab&ssi=b98a4b26-ba0f-44c8-a2a5-0315e1e966ee&ssk=support@shieldsquare.com&ssm=77124680964133473105650333749186&ssn=7eafd9fa9826c01597307b85effe791743b46ba2f27a-3977-4b0e-988e66&sso=940ea59d-ee88a13130f2489df365438a8b123fc056d418d499c5df48&ssp=15188465711607082399160702401540426&ssq=67141537474651350705574746278120044759785&ssr=OTEuMjA5LjM1LjIxOA==&sst=Mozilla/5.0%20(X11;%20Linux%20x86_64)%20AppleWebKit/537.36%20(KHTML,%20like%20Gecko)%20Chrome/74.0.3729.131%20Safari/537.36&ssv=&ssw=
                    O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
                    O16 - DPF: {99D090A6-EA84-466E-8F21-834B36F57E77} (PeerFactor_DL Control) - http://peerfactor.fr/PeerFactor_DL.cab
                    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                    O16 - DPF: {B9A296D4-38AC-4566-8168-F7ACAF7D35E6} (Eyeball Video Session Control) - https://imlive.com/ChatSource/gVideoContol.cab
                    O16 - DPF: {FA30EC32-668B-4B60-B13C-4C84EB90C3C9} (ActiveID Control) - http://www.meetstream.com/activex/activeid1003/activeid.cab
                    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                    O20 - Winlogon Notify: winbfi32 - winbfi32.dll (file missing)
                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
                    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
                    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
                    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
                    0
                    1. Modérateur
                      Salut

                      # Démarre en mode sans échec :
                      Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                      Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                      Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                      (Si F8 ne marche pas utilise la touche F5).
                      ----------------------------------------------------------------------------
                      # Relance le programme Smitfraud :
                      Cette fois choisit l’option 2, répond oui a tous ;
                      Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

                      avec un nouveau hijackthis stp

                      ++
                      0
                      1. Voici mon rapport smitfraud: SmitFraudFix v2.131

                        Scan done at 14:19:19,71, 2006-12-26
                        Run from C:\SmitfraudFix
                        OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
                        The filesystem type is NTFS
                        Fix run in safe mode

                        »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
                        !!!Attention, following keys are not inevitably infected!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                        »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                        GenericRenosFix by S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                        C:\WINDOWS\system32\oiso.bin Deleted

                        »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                        !!!Attention, following keys are not inevitably infected!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                        "System"=""

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        Registry Cleaning done.

                        »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
                        !!!Attention, following keys are not inevitably infected!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» End

                        et voici celui de Hijack:

                        Logfile of HijackThis v1.99.1
                        Scan saved at 14:45:57, on 2006-12-26
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Windows Defender\MsMpEng.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                        C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                        C:\Program Files\Norton Internet Security\ISSVC.exe
                        C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                        C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
                        C:\WINDOWS\eHome\ehRecvr.exe
                        C:\WINDOWS\eHome\ehSched.exe
                        C:\Program Files\ewido anti-malware\ewidoctrl.exe
                        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                        C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
                        C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                        C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
                        C:\Program Files\Canon\CAL\CALMAIN.exe
                        C:\WINDOWS\system32\dllhost.exe
                        C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\WINDOWS\ehome\ehtray.exe
                        C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
                        C:\WINDOWS\eHome\ehmsas.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                        C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                        C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
                        C:\Program Files\HPQ\SHARED\HPQWMI.exe
                        C:\Program Files\DAEMON Tools\daemon.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\PowerISO\PWRISOVM.EXE
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                        C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
                        C:\WINDOWS\vVX6000.exe
                        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                        C:\Program Files\MSN Messenger\MsnMsgr.Exe
                        C:\Program Files\Messenger\msmsgs.exe
                        C:\Program Files\MSN Messenger\usnsvc.exe
                        C:\Pat\hijackthis\HijackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?pc=mssh&form=msshhp&ocid=onepro&homepage=http%3a%2f%2fwww.uottawa.ca%2f
                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.aol.com/
                        R3 - Default URLSearchHook is missing
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: ASGP32.ASGP - {82B07A2B-F0AF-45FC-BE44-18D83B01EAD9} - C:\WINDOWS\system32\asgp32.dll
                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
                        O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                        O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
                        O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
                        O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
                        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                        O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                        O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
                        O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                        O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
                        O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
                        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                        O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
                        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
                        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O14 - IERESET.INF: START_PAGE_URL=https://www.aol.com/
                        O16 - DPF: {02CA9974-B6AC-497E-A371-73580432B0F6} (Eyeball Video Message Control) - http://www.zoom11.com/Redist/EyeballSDK.cab
                        O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
                        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                        O16 - DPF: {7DFDB8FD-B498-4958-B930-38021B94351D} (imlUCID Class) - https://validate.perfdrive.com/?ssa=1cb613c1-b580-495b-866c-b6fe71718572&ssb=36371211747&ssc=https%3A%2F%2Fimlive.com%2Fchatsource%2FImlCID.cab&ssi=b98a4b26-ba0f-44c8-a2a5-0315e1e966ee&ssk=support@shieldsquare.com&ssm=77124680964133473105650333749186&ssn=7eafd9fa9826c01597307b85effe791743b46ba2f27a-3977-4b0e-988e66&sso=940ea59d-ee88a13130f2489df365438a8b123fc056d418d499c5df48&ssp=15188465711607082399160702401540426&ssq=67141537474651350705574746278120044759785&ssr=OTEuMjA5LjM1LjIxOA==&sst=Mozilla/5.0%20(X11;%20Linux%20x86_64)%20AppleWebKit/537.36%20(KHTML,%20like%20Gecko)%20Chrome/74.0.3729.131%20Safari/537.36&ssv=&ssw=
                        O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
                        O16 - DPF: {99D090A6-EA84-466E-8F21-834B36F57E77} (PeerFactor_DL Control) - http://peerfactor.fr/PeerFactor_DL.cab
                        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                        O16 - DPF: {B9A296D4-38AC-4566-8168-F7ACAF7D35E6} (Eyeball Video Session Control) - https://imlive.com/ChatSource/gVideoContol.cab
                        O16 - DPF: {FA30EC32-668B-4B60-B13C-4C84EB90C3C9} (ActiveID Control) - http://www.meetstream.com/activex/activeid1003/activeid.cab
                        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                        O20 - Winlogon Notify: winbfi32 - winbfi32.dll (file missing)
                        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                        O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                        O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                        O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                        O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                        O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
                        O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                        O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
                        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                        O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                        O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                        O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                        O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                        O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
                        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                        O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                        O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                        O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
                        O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
                        0
                        1. Modérateur
                          ok,

                          # Désactiver la Restauration du système

                          * Cliquez sur le bouton Démarrer.
                          * Cliquez avec le bouton droit de la souris sur Poste de travail puis cliquez sur Propriétés.
                          * Dans l'onglet Restauration du système, sélectionnez l'option Désactiver la Restauration du système ou Désactiver la Restauration du système sur tous les lecteurs

                          ( tu pourras la réactivé à la fin de la manip )

                          # Relance HijackThis : choisis " do a scan only" coche la case devant les lignes ci-dessous et clique en bas sur "fix checked" :

                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: ASGP32.ASGP - {82B07A2B-F0AF-45FC-BE44-18D83B01EAD9} - C:\WINDOWS\system32\asgp32.dll

                          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
                          O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
                          O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                          O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
                          O4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exe
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

                          O16 - DPF: {02CA9974-B6AC-497E-A371-73580432B0F6} (Eyeball Video Message Control) - http://www.zoom11.com/Redist/EyeballSDK.cab
                          O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB

                          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                          O16 - DPF: {7DFDB8FD-B498-4958-B930-38021B94351D} (imlUCID Class) - https://validate.perfdrive.com/?ssa=1cb613c1-b580-495b-866c-b6fe71718572&ssb=36371211747&ssc=https%3A%2F%2Fimlive.com%2Fchatsource%2FImlCID.cab&ssi=b98a4b26-ba0f-44c8-a2a5-0315e1e966ee&ssk=support@shieldsquare.com&ssm=77124680964133473105650333749186&ssn=7eafd9fa9826c01597307b85effe791743b46ba2f27a-3977-4b0e-988e66&sso=940ea59d-ee88a13130f2489df365438a8b123fc056d418d499c5df48&ssp=15188465711607082399160702401540426&ssq=67141537474651350705574746278120044759785&ssr=OTEuMjA5LjM1LjIxOA==&sst=Mozilla/5.0%20(X11;%20Linux%20x86_64)%20AppleWebKit/537.36%20(KHTML,%20like%20Gecko)%20Chrome/74.0.3729.131%20Safari/537.36&ssv=&ssw=
                          O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) - http://secure2.comned.com/signuptemplates/securelogin-devel.cab
                          O16 - DPF: {99D090A6-EA84-466E-8F21-834B36F57E77} (PeerFactor_DL Control) - http://peerfactor.fr/PeerFactor_DL.cab
                          O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                          O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
                          O16 - DPF: {B9A296D4-38AC-4566-8168-F7ACAF7D35E6} (Eyeball Video Session Control) - https://imlive.com/ChatSource/gVideoContol.cab
                          O16 - DPF: {FA30EC32-668B-4B60-B13C-4C84EB90C3C9} (ActiveID Control) - http://www.meetstream.com/activex/activeid1003/activeid.cab

                          O20 - Winlogon Notify: winbfi32 - winbfi32.dll (file missing)

                          ensuite, télécharge et execute ceci :

                          * CleanUp40 (qui élimine les fichiers temporaires + cookies : gratuit )
                          http://pageperso.aol.fr/Balltrap34/CleanUp40.exe

                          tuto : (merci à Balltrap) http://pageperso.aol.fr/balltrap34/democleanup.htm

                          * Ccleaner : Telecharge et installe ceci, dans la colonne de gauche clique sur "erreurs" coche toute les cases, puis clique en bas sur "chercher des erreurs" une fois finit, clique sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs .

                          *Relance Ccleaner ,vas dans l'onglet "nettoyeur" present sur la gauche, decoche la derniere case (Avancé si elle
                          est cochée) puis clique sur "lancer le nettoyage"

                          ccleaner

                          tuto: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

                          poste un nouveau hijackthis et precise tes soucis s'il en reste

                          @+

                          ;-))

                          On peut aussi bâtir quelque chose de beau avec les pierres qui entravent le chemin (J.W.VON GOETHE
                          )
                          0
                          1. voici mon hijackthis:

                            Logfile of HijackThis v1.99.1
                            Scan saved at 15:56:28, on 2006-12-26
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Windows Defender\MsMpEng.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                            C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                            C:\Program Files\Norton Internet Security\ISSVC.exe
                            C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                            C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                            C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
                            C:\WINDOWS\eHome\ehRecvr.exe
                            C:\WINDOWS\eHome\ehSched.exe
                            C:\Program Files\ewido anti-malware\ewidoctrl.exe
                            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                            C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                            C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
                            C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                            C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
                            C:\Program Files\Canon\CAL\CALMAIN.exe
                            C:\WINDOWS\system32\dllhost.exe
                            C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
                            C:\WINDOWS\ehome\ehtray.exe
                            C:\WINDOWS\eHome\ehmsas.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                            C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                            C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                            C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
                            C:\Program Files\HPQ\SHARED\HPQWMI.exe
                            C:\Program Files\DAEMON Tools\daemon.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
                            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                            C:\Program Files\MSN Messenger\usnsvc.exe
                            C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
                            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Messenger\msmsgs.exe
                            C:\Pat\hijackthis\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.uottawa.ca/
                            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.aol.com/
                            R3 - Default URLSearchHook is missing
                            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                            O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                            O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                            O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                            O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                            O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
                            O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
                            O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
                            O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                            O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
                            O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
                            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
                            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
                            O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
                            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O14 - IERESET.INF: START_PAGE_URL=https://www.aol.com/
                            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                            O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                            O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                            O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                            O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                            O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                            O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
                            O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                            O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
                            O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                            O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                            O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
                            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                            O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                            O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                            O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                            O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                            O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
                            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                            O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                            O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                            O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
                            O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                            O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

                            est-ce que mon ordi est en bien meilleure santé maintenant???
                            0
                            1. Modérateur
                              est-ce que mon ordi est en bien meilleure santé maintenant???

                              à toi de me le dire ???

                              ;-))
                              0
                              1. haha oui, merci beaucoup... une chose, je recois ce message ci quand jouvre windows... This application has failed to start because gdiplus.dll was not found. Re-installating the application may fix this problem... c'est quoi ce .dll??
                                0
                                1. daccord et merci beaucoup encore une fois!!
                                  0
                                  1. Modérateur
                                    pas d'quoi ;-))

                                    un peu de lecture au passage :

                                    https://sebsauvage.net/safehex.html
                                    securite proteger un ordinateur contre les malwares d internet

                                    @+

                                    On peut aussi bâtir quelque chose de beau avec les pierres qui entravent le chemin (J.W.VON GOETHE
                                    )
                                    0