[trojan] comment supprimer un trojan

Bonjour
Bonne année !

Pour moi, ça commence mal. Je pense avoir un trojan qui ralentit nettement ma connexion et rend le surf très pénible. Antivir a signalé que le fichier rlls.dll était infecté. Ad-aware, Spybot et Avast ne détectent rien.
J'ai réalisé un rapport Hijackthis. Je suis sous windows XP.

Y aurait-il une personne compétente pour m'aider à désinfecter mon ordinateur svp ?

Merci beaucoup.
Configuration: Windows XP
Internet Explorer 7.0

18 réponses

  1. Contributeur
    bonsoir postes le raport hijack stp

    a++++
    0
    1. Logfile of HijackThis v1.99.1
      Scan saved at 17:38:07, on 29/12/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
      C:\WINDOWS\system32\CTsvcCDA.EXE
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Apoint2K\Apoint.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      C:\Program Files\Apoint2K\Apntex.exe
      C:\WINDOWS\system32\hphmon05.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
      C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
      C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
      C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe
      C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqgalry.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
      C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Documents and Settings\Sophie\Mes documents\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
      O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
      O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_48.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
      O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
      O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
      O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
      O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
      O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
      O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
      O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
      O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [Device Detector] "C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" -autorun
      O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL,S
      O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
      O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
      O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqthb08.exe
      O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMremind.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
      O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZN
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
      O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSetup1.0.0.15.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
      O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
      O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

      Merci...
      0
      1. Contributeur
        bonsoir ouvre hijack coches ces lignes ensuite click sur fix checked

        R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
        O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL

        O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
        O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_48.dll

        O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
        O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\MWSBAR.DLL,S

        O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s

        redemare en mode sans echec (redemarrage + tapotte sans arret sur la touche F8 desque l'ordi s'allume)

        cherches et supprime les fichiers ou dossiers en gras :

        C:\Program Files\SpySpotter3
        C:\Program Files\MyWebSearch
        C:\Program Files\NewDotNet

        vide la corbeille

        redemare en mode normal

        telecharge et execute ces antispywares ( pense a les mettre a jour avant de les lancées)
        (1) ad-aware version 1.06

        (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite
        voir demo
        http://pageperso.aol.fr/balltrap34/adwseflash.zip

        tutorial
        https://forums.cnetfrance.fr
        ***
        (2) spybot version 1.4

        (ici) http://www.florensac-chasse-trap.com/ section virus/logiciel de securite

        voir demo d utilisation
        http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm
        ***

        ps : un grand merci a balltrap pour les lien :)

        (3) AVG anti spyware
        https://www.01net.com/telecharger/

        (n'oublie pas de le mettre a jour avant de lancer le scan)

        Relance AVG AS puis choisis l'onglet "Analyse"
        Puis l'onglet "Paramètres"
        Sous la question "Comment réagir ?", clique sur "Actions recommandées" et choisis "Quarantaine"
        Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"

        /!\ Si un fichier est infecté en fin d'analyse /!\
        Clique sur "Appliquer toutes les actions "

        Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous"
        Enregistre ce fichier texte sur ton bureau ensuite colle le raport ici

        supprime les fichiers inutiles (fichiers temporaire , cookies .. ect avec ceci

        Ccleaner
        https://www.malekal.com/tutoriel-ccleaner/

        - Nettoye ta base de registre avec regcleaner : https://www.malekal.com/nettoyer-sa-base-de-registre-avec-windows-registry-cleaner/

        tutorial
        https://forums.cnetfrance.fr

        a++++++
        0
        1. Merci de ton aide.
          J'ai suivi tes conseils à la lettre.

          Voici le rapport AVG AS

          ---------------------------------------------------------
          AVG Anti-Spyware - Rapport d'analyse
          ---------------------------------------------------------

          + Créé à: 21:39:56 02/01/2007

          + Résultat de l'analyse:

          C:\Program Files\Common Files\Companion Wizard\compwiz.exe -> Adware.Companion : Nettoyé et sauvegardé (mise en quarantaine).
          C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP190\A0041512.exe -> Adware.NewDotNet : Nettoyé et sauvegardé (mise en quarantaine).
          C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP190\A0041537.dll -> Adware.NewDotNet : Nettoyé et sauvegardé (mise en quarantaine).
          C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP201\A0046428.exe -> Adware.NewDotNet : Nettoyé et sauvegardé (mise en quarantaine).
          C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP201\A0046493.exe -> Adware.NewDotNet : Nettoyé et sauvegardé (mise en quarantaine).
          C:\WINDOWS\NDNuninstall7_44.exe -> Adware.NewDotNet : Nettoyé et sauvegardé (mise en quarantaine).
          C:\WINDOWS\NDNuninstall7_48.exe -> Adware.NewDotNet : Nettoyé et sauvegardé (mise en quarantaine).
          HKU\S-1-5-21-1576833891-2962542265-4215684491-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Nettoyé et sauvegardé (mise en quarantaine).
          C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP150\A0031891.exe -> Adware.RK : Nettoyé et sauvegardé (mise en quarantaine).
          C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP161\A0033219.exe -> Adware.RK : Nettoyé et sauvegardé (mise en quarantaine).
          HKLM\SOFTWARE\Classes\WUSN.1 -> Adware.SaveNow : Nettoyé et sauvegardé (mise en quarantaine).
          HKU\S-1-5-21-1576833891-2962542265-4215684491-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4} -> Adware.WinAntiVirus : Nettoyé et sauvegardé (mise en quarantaine).
          :mozilla.8:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
          :mozilla.9:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
          :mozilla.33:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
          :mozilla.34:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Adbrite : Nettoyé.
          C:\Documents and Settings\Sophie\Cookies\sophie@adbrite[2].txt -> TrackingCookie.Adbrite : Nettoyé.
          :mozilla.50:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
          :mozilla.51:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
          :mozilla.163:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Com : Nettoyé.
          C:\Documents and Settings\Sophie\Cookies\sophie@com[1].txt -> TrackingCookie.Com : Nettoyé.
          :mozilla.957:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
          :mozilla.958:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
          :mozilla.959:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
          C:\Documents and Settings\Sophie\Cookies\sophie@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Nettoyé.
          :mozilla.830:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
          :mozilla.831:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
          :mozilla.832:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
          :mozilla.833:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Googleadservices : Nettoyé.
          C:\Documents and Settings\Sophie\Cookies\sophie@ilead.itrack[2].txt -> TrackingCookie.Itrack : Nettoyé.
          :mozilla.383:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Ivwbox : Nettoyé.
          C:\Documents and Settings\Sophie\Cookies\sophie@ivwbox[1].txt -> TrackingCookie.Ivwbox : Nettoyé.
          C:\Documents and Settings\Sophie\Cookies\sophie@data2.perf.overture[1].txt -> TrackingCookie.Overture : Nettoyé.
          C:\Documents and Settings\Sophie\Cookies\sophie@ads.planetactive[1].txt -> TrackingCookie.Planetactive : Nettoyé.
          :mozilla.44:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
          :mozilla.45:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
          :mozilla.46:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
          :mozilla.128:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
          :mozilla.608:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
          :mozilla.609:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
          :mozilla.610:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
          :mozilla.611:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
          :mozilla.612:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
          :mozilla.294:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.295:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.296:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.297:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.298:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.299:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.300:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.301:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.302:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.303:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.377:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.378:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.379:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.380:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.704:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
          :mozilla.966:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
          :mozilla.967:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
          :mozilla.968:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
          C:\Documents and Settings\Sophie\Cookies\sophie@starware[2].txt -> TrackingCookie.Starware : Nettoyé.
          :mozilla.749:C:\Documents and Settings\Sophie\Application Data\Mozilla\Firefox\Profiles\hin5pe3z.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
          C:\Documents and Settings\Sophie\Local Settings\Temp\NI.UWA6PV_0001_N69M2803\setup.exe -> Trojan.Fakealert : Nettoyé et sauvegardé (mise en quarantaine).
          0
          1. Contributeur
            Bonsoir postes un log hijack pour voir si tout est ok :)

            a+++
            0
            1. Logfile of HijackThis v1.99.1
              Scan saved at 23:20:22, on 02/01/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.5730.0011)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\CTsvcCDA.EXE
              C:\WINDOWS\system32\nvsvc32.exe
              C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Apoint2K\Apoint.exe
              C:\WINDOWS\AGRSMMSG.exe
              C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
              C:\WINDOWS\system32\hphmon05.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
              C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
              C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
              C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
              C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
              C:\Program Files\Apoint2K\Apntex.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\WINDOWS\system32\wscntfy.exe
              C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Documents and Settings\Sophie\Mes documents\Logiciels téléchargés\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
              O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
              O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
              O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
              O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
              O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
              O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
              O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
              O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [Device Detector] "C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" -autorun
              O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
              O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe" /m=0
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
              O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
              O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZN
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
              O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
              O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
              O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
              O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
              O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
              O11 - Options group: [INTERNATIONAL] International*
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
              O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
              O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
              O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
              O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

              Merci...
              0
              1. Contributeur
                bonsoir ouvre hijack , coches ces lignes ensuite click sur fix checked

                O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe" /m=0
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)

                cherche et supprime le dossier en gras :

                C:\Program Files\MyWebSearch

                lance spybot / met le ajour ( c tres important) / scan ton pc avec et supprime les spyware trouvé

                Regarde la demo d'utilisation :
                http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm

                je vois que tu n'as un antivirus :p donc installe avast

                Avast (antivirus)
                https://www.clubic.com/telecharger-fiche11113-avast-antivirus-gratuit.html

                tutorial
                https://forums.cnetfrance.fr

                scan ton pc avec et supprime les virus qu'il te trouve

                quand t'aura fini repost un log hijack :)

                a++++
                0
                1. J'ai fait ce que tu me demandais sur hijackthis.
                  pas de trace de dossier mywebsearch.

                  Je n'avais d'anti virus en effet :) car j'hésitais entre 2 antivirus et je venais donc de désinstaller avast car je sais qu'il ne faut pas 2 antivirus installés sur un PC (j'ai quand même qques connaissances. Ouf!:D)

                  Merci infiniment de m'aider. Grâce à toi j'ai retrouvé une connexion rapide et la navigation est redevenue agréable.
                  0
                  1. Contributeur
                    bonsoir :) il reste ces lignes a supprimé

                    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll

                    normalement spybot devrais les supprimé sans probleme

                    j'attend ton log hijackthis :)

                    a+++
                    0
                    1. Dois-je supprimer ces lignes avec Hijachthis et fix checked ? Spybot ne trouve aucun mouchard !

                      Le scan avast est en train de se faire.

                      Merci à toi.
                      0
                      1. Contributeur
                        Dois-je supprimer ces lignes avec Hijachthis et fix checked

                        Non surtout pas !! , tu risque de perdre la connexion internet

                        t'es sure que spybot est ajour? il faut lui faire les mise ajour avant de le lancé

                        sinon essay avec ce programe

                        1)Télécharges LSPfix sur le bureau
                        http://www.cexx.org/lspfix.htm et Installe-le sur le Bureau. C'est tout pour l'instant

                        Lance LSPfix et agrandis la fenêtre qui, par défaut, est trop petite et fait apparaître les ascenseurs horizontaux et verticaux, masquant un bouton.
                        Coche la case "I know what I'm doing" ("Je sais ce que je fais").
                        Sélectionne toutes les instances de la dll suivante si tu la trouves.
                        Rien d'autre uniquement la dll suivante.

                        c:\windows\system32\rlls.dll et fais les glisser du panneau de gauche, appelé "keep" au panneau de droite, appelé "Remove".
                        Clique sur le bouton "Finish".

                        quand t'aura fini repost un log hijack

                        a++++
                        0
                        1. Oui spybot est à jour. Avast lui-même n'a détecté aucun fichier infecté.
                          Je ferai demain matin ce que tu me conseilles.

                          Merci pour l'aide précieuse que tu m'apportes.

                          Bonne nuit :)
                          0
                          1. Me revoilà !
                            J'ai utlisé Lspfix comme tu disais.
                            Voici le nouveau log hijackthis.

                            Logfile of HijackThis v1.99.1
                            Scan saved at 22:22:53, on 04/01/2007
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.5730.0011)

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            C:\WINDOWS\system32\CTsvcCDA.EXE
                            C:\WINDOWS\system32\nvsvc32.exe
                            C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            C:\Program Files\Apoint2K\Apoint.exe
                            C:\WINDOWS\AGRSMMSG.exe
                            C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                            C:\WINDOWS\system32\hphmon05.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\Program Files\QuickTime\qttask.exe
                            C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
                            C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                            C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                            C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                            C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe
                            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\Program Files\Apoint2K\Apntex.exe
                            C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
                            C:\Program Files\Messenger\msmsgs.exe
                            C:\Program Files\MSN Messenger\msnmsgr.exe
                            C:\Documents and Settings\Sophie\Mes documents\Logiciels téléchargés\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                            O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                            O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                            O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                            O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
                            O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
                            O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                            O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
                            O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
                            O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                            O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                            O4 - HKLM\..\Run: [Device Detector] "C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" -autorun
                            O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
                            O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
                            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                            O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
                            O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZN
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O11 - Options group: [INTERNATIONAL] International*
                            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                            O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                            O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                            O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
                            O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
                            O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                            O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                            0
                            1. Contributeur
                              bonsoir ouvre hijack coches ces ligne ensuite click sur fix checked :

                              O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe

                              O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZN

                              cherche et supprime le dossier en gras :

                              C:\Program Files\MyWebSearch

                              ta version java est perimé pour plus de securité

                              télécharge la dernière version https://www.java.com/fr/

                              Après installation et redémarrage , va dans panneau de configuration/Ajouter-Supprimer des programmes afin de désinstaller l'ancienne version, ceci pour récupérer de l'espace disque et éventuellement pour virer les failles présentes dans cette ancienne version.

                              Retourne ensuite chez Java ci-dessus et clique sur le bouton "Vérifier l'installation" pour t'assurer que tout est en ordre.

                              - installe un parefeu ca va renforcé la securité de l'ordi je te conseille un firewall gratuit ( si tu peu te procurer la version payant c'est encore mieu :)

                              Kerio (parefeu)

                              https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html

                              tuto

                              http://www.malekal.com/kerio_firewall.php

                              ensuite refait un scan hijack et colle le resultat ici
                              a+++
                              0
                              1. Pas de trace du dossier mywebsearch.

                                voici le nouveau rapport :
                                Logfile of HijackThis v1.99.1
                                Scan saved at 22:59:48, on 04/01/2007
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v7.00 (7.00.5730.0011)

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\WINDOWS\system32\CTsvcCDA.EXE
                                C:\WINDOWS\system32\nvsvc32.exe
                                C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                C:\Program Files\Apoint2K\Apoint.exe
                                C:\WINDOWS\AGRSMMSG.exe
                                C:\WINDOWS\system32\hphmon05.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\Program Files\QuickTime\qttask.exe
                                C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
                                C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                                C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                                C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                                C:\Program Files\iPod\bin\iPodService.exe
                                C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe
                                C:\Program Files\Apoint2K\Apntex.exe
                                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
                                C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\WINDOWS\system32\msiexec.exe
                                C:\Documents and Settings\Sophie\Mes documents\Logiciels téléchargés\HijackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                                O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" /r
                                O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
                                O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
                                O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
                                O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
                                O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                                O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                                O4 - HKLM\..\Run: [Device Detector] "C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" -autorun
                                O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
                                O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
                                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
                                O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O11 - Options group: [INTERNATIONAL] International*
                                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - https://onedrive.live.com/
                                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
                                O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                                O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                                O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
                                O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
                                O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                                O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

                                Merci :)
                                0
                                1. Contributeur
                                  bonsoir ton log est propre apart cette ligne a fixé

                                  O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe

                                  pour finir quelque conseil de base

                                  - passe reglierement les antispyware (adaware , spybot , avg .. ect) pense a les mettre ajour avant de les lancé c'est tres important

                                  -supprime regulierement les fichiers inutiles (fichiers temporaire , cookies .. ect a l'aide de CCleaner https://www.malekal.com/tutoriel-ccleaner/

                                  -maintenant que ton ordinateur est propre je te conseille de creer un point de restauration comme ca en cas de probleme (virus , plantage ..ect) tu poura tjr revenir en arriere
                                  http://www.aidoforum.com/tutoriaux-371-creer-un-point-de-restauration-sous-windows.html

                                  a++

                                  bon surf :)
                                  0
                                  1. Je te remercie infiniment pour ta présence et tes conseils.
                                    Mon ordinateur navigue formidablement bien et c'est grâce à toi.
                                    Je suivrai tes conseils pour éviter qu'il ne soit à nouveau infecté.

                                    A +++ :) :)
                                    0