[ralentissement] intempestif de mon PC

BONJOUR!

Voila, depuis ce matin, mon odinateur subit des ralentissements importants,même lorqu'aucune application n'est lancée. Lorsque je lance de la musique ou une video, l'image ou le son se coupe pendant une demi-seconde toutes les 3 ou 4 secondes. De plus (je ne sais pas si c'est lié) je recoit des publicités (fenêtres) pour win antivrus pro de facon systematique. Je ne trouve pas de solution sur le forum donc je fait appel a une ame charitable et compétente... Voici le rapport hijackthis:

Logfile of HijackThis v1.99.1
Scan saved at 19:12:07, on 14/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Fichiers communs\{320D180E-06C1-1036-0509-050330050021}\Update.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\802.11 Wireless LAN\WlanMonitor.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\ominpbgu.dll",setvm
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Bsqnlt] C:\WINDOWS\?icrosoft\w?crtupd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Moniteur & Configuration.lnk = ?
O4 - Startup: .protected
O4 - Global Startup: .protected
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart17.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: (no name) - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - D:\traducteur\PRMTIE\prmtie5.htm
O9 - Extra 'Tools' menuitem: Traduire - {7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - D:\traducteur\PRMTIE\prmtie5.htm
O9 - Extra button: (no name) - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - D:\traducteur\PRMTIE\options.htm
O9 - Extra 'Tools' menuitem: Personnaliser les options de traduction - {7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - D:\traducteur\PRMTIE\options.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{70A2EC3F-6301-47B3-838E-6F70A77EE917}: Domain = ensieta.fr
O17 - HKLM\System\CCS\Services\Tcpip\..\{70A2EC3F-6301-47B3-838E-6F70A77EE917}: NameServer = 84.103.237.140,86.64.145.140
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe

Voila. Je me sert de ce pc pour mon travail et j'aurais besoin d'une solution rapide. MERCI d'avance et BONNE ANNEE A TOUS!!
Configuration: Windows XP
Internet Explorer 7.0

39 réponses

Résumé de la discussion

Le fil décrit des ralentissements importants et des coupures audio/vidéo récurrentes, accompagnés de fenêtres publicitaires pour un antivirus, évoquant une infection potentielle et des outils de détection comme HijackThis. Plusieurs intervenants proposent des analyses et des scans avec AVG Anti-Spyware ou des variantes de SmitFraudFix, et suggèrent d’analyser puis de mettre en quarantaine ou supprimer les fichiers suspects identifiés. D'autres conseils portent sur la restauration de driver audio, l'emploi d'outils comme KillBox pour éliminer les éléments tenaces et la vérification des processus et services listés par HijackThis pour isoler les composants malveillants. En complément, le fil évoque les rapports HijackThis et VundoFix, et la suppression d’un fichier persistant (ssttq.dll) en attendant des actions plus lourdes.

Bobot (l’IA à votre service)
  1. Contributeur
    bonsoir telecharge SmitfraudFix

    http://siri.urz.free.fr/Fix/SmitfraudFix.zip
    decompresse le, Double click sur Smitfraudfix.cmd choisit l’option 1, il va générer un rapport
    Copie/colle le sur le poste stp.
    0
    1. Voila le rapport smitfraudFix

      SmitFraudFix v2.118

      Rapport fait à 23:12:03,34, 14/01/2007
      Executé à partir de C:\Documents and Settings\Seb\Bureau\Smitfraudfix\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Seb

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Seb\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\SEB\FAVORIS

      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""

      »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin

      Merci de me donner un coup de main.
      0
      1. Contributeur
        ree :) le raport smitfraud et propre

        telecharge AVG anti spyware
        https://www.01net.com/telecharger/

        (n'oublie pas de le mettre a jour avant de lancer le scan)

        Relance AVG AS puis choisis l'onglet "Analyse"
        Puis l'onglet "Paramètres"
        Sous la question "Comment réagir ?", clique sur "Actions recommandées" et choisis "Quarantaine"
        Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"

        /!\ Si un fichier est infecté en fin d'analyse /!\
        Clique sur "Appliquer toutes les actions "

        Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous"
        Enregistre ce fichier texte sur ton bureau ensuite colle le raport ici

        a+++
        0
        1. j'ai lancé AVG mais l'analyse prend un temps fou. Je le laisse tourner cette nuit. Il se fait un peu tard, je continuerai demain soir. Merci pour le coup de main, j'espere avoir de tes news demain soir. @++
          0
      2. Re salut!

        j'ai eu le temps de faire deux analyses avec AVG. Je te poste le denier rapport AVG puis le nouveau rapport hijack:

        RAPPORT AVG:

        ---------------------------------------------------------
        AVG Anti-Spyware - Rapport d'analyse
        ---------------------------------------------------------

        + Créé à: 21:57:35 15/01/2007

        + Résultat de l'analyse:

        C:\System Volume Information\_restore{188E40F0-ED0E-4229-A9C6-C6CA03F40F1B}\RP391\A0119511.exe -> Adware.Casino : Nettoyé et sauvegardé (mise en quarantaine).
        C:\System Volume Information\_restore{188E40F0-ED0E-4229-A9C6-C6CA03F40F1B}\RP391\A0119510.exe -> Adware.ClickSpring : Nettoyé et sauvegardé (mise en quarantaine).
        C:\iklpbort.dll -> Adware.PurityScan : Nettoyé et sauvegardé (mise en quarantaine).
        C:\System Volume Information\_restore{188E40F0-ED0E-4229-A9C6-C6CA03F40F1B}\RP391\A0119512.exe -> Adware.SaveNow : Nettoyé et sauvegardé (mise en quarantaine).
        C:\WINDOWS\Temp\idd23E.tmp.exe -> Dialer.IDialer.m : Nettoyé et sauvegardé (mise en quarantaine).
        C:\WINDOWS\Temp\idd243.tmp.exe -> Dialer.IDialer.m : Nettoyé et sauvegardé (mise en quarantaine).
        C:\WINDOWS\Temp\idd274.tmp.exe -> Dialer.IDialer.m : Nettoyé et sauvegardé (mise en quarantaine).
        C:\WINDOWS\Temp\idd276.tmp.exe -> Dialer.IDialer.m : Nettoyé et sauvegardé (mise en quarantaine).
        C:\WINDOWS\Temp\idd29B.tmp.exe -> Dialer.IDialer.m : Nettoyé et sauvegardé (mise en quarantaine).
        C:\WINDOWS\Temp\idd29D.tmp.exe -> Dialer.IDialer.m : Nettoyé et sauvegardé (mise en quarantaine).
        C:\System Volume Information\_restore{188E40F0-ED0E-4229-A9C6-C6CA03F40F1B}\RP391\A0119508.dll -> Downloader.Small.ece : Nettoyé et sauvegardé (mise en quarantaine).
        C:\System Volume Information\_restore{188E40F0-ED0E-4229-A9C6-C6CA03F40F1B}\RP391\A0119509.exe -> Dropper.DollarR.b : Nettoyé et sauvegardé (mise en quarantaine).
        C:\Documents and Settings\Seb\Cookies\seb@247realmedia[2].txt -> TrackingCookie.247realmedia : Nettoyé.
        C:\Documents and Settings\Seb\Cookies\seb@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
        C:\Documents and Settings\Seb\Cookies\seb@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
        C:\Documents and Settings\Seb\Cookies\seb@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
        C:\Documents and Settings\Seb\Cookies\seb@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Nettoyé.
        C:\System Volume Information\_restore{188E40F0-ED0E-4229-A9C6-C6CA03F40F1B}\RP391\A0119507.exe -> Trojan.Small : Nettoyé et sauvegardé (mise en quarantaine).

        Fin du rapport

        RAPPORT HIJACK:

        Logfile of HijackThis v1.99.1
        Scan saved at 22:00:40, on 15/01/2007
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.5730.0011)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
        C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Acer\eManager\anbmServ.exe
        C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        C:\Program Files\Norton AntiVirus\navapsvc.exe
        C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
        C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
        C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - Startup: .protected
        O4 - Global Startup: .protected
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
        O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
        O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
        O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
        O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
        O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
        O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
        O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
        O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe

        Voili voilou. En esperant que ca puisse aider. Derniere chose, je recoit maintenant des fenetres porno avec dialer... Super.

        Merci d'avance!!
        0
        1. Petit bonus: un logiciel (DriveCleaner) m'envoie des fenetres avec des messages bizarres... C'est lié au pb?
          0
          1. Contributeur
            bonsoir Télécharge Blacklight (de F-Secure)
            https://www.f-secure.com/en
            https://europe.f-secure.com/exclude/blacklight/index.shtml

            et sauvegarde le sur ton Bureau.

            Double-clique blbeta.exe et accepte la licence ; laisse [X]scan through Windows Explorer activé ; clique Scan puis Next

            Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).

            Copie et colle le contenu de ce rapport dans ta prochaine réponse

            a+++
            0
            1. Voila le rapport demandé

              01/15/07 22:19:06 [Info]: BlackLight Engine 1.0.55 initialized
              01/15/07 22:19:06 [Info]: OS: 5.1 build 2600 (Service Pack 2)
              01/15/07 22:19:09 [Note]: 7019 4
              01/15/07 22:19:09 [Note]: 7005 0
              01/15/07 22:19:20 [Note]: 7006 0
              01/15/07 22:19:20 [Note]: 7011 1276
              01/15/07 22:19:20 [Note]: 7026 0
              01/15/07 22:19:20 [Note]: 7026 0
              01/15/07 22:19:36 [Note]: FSRAW library version 1.7.1021
              01/15/07 22:21:15 [Note]: 2000 1012
              01/15/07 22:21:15 [Note]: 2000 1012
              01/15/07 22:21:15 [Note]: 2000 1012
              01/15/07 22:21:15 [Note]: 2000 1012
              01/15/07 22:21:15 [Note]: 2000 1012
              01/15/07 22:21:15 [Note]: 2000 1012
              01/15/07 22:21:15 [Note]: 2000 1012
              01/15/07 22:21:15 [Note]: 2000 1012
              01/15/07 22:21:15 [Note]: 2000 1012
              0
              1. A fait c'est quoi ca " [X]scan through Windows Explorer "?

                J'ai pas eu de message me demandant d'activer quoi que ce soit...
                0
                1. j'ai oublié une ligne

                  01/15/07 22:41:05 [Note]: 7007 0

                  Voili voilou...
                  0
              2. Contributeur
                t'es sure que le scan est complet? peu tu refaire stp

                click droit sur le programe hijackthis et renome le abcd

                ensuite fait un scan et colle le resultat ici

                a++
                0
                1. Logfile of HijackThis v1.99.1
                  Scan saved at 22:48:48, on 15/01/2007
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.5730.0011)

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Acer\eManager\anbmServ.exe
                  C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  C:\Program Files\Norton AntiVirus\navapsvc.exe
                  C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                  C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
                  C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
                  D:\Secu PC\HijackThis\abcd.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
                  O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
                  O2 - BHO: (no name) - {58CCD0E9-6FAC-3F07-35B7-041EB6558299} - C:\WINDOWS\system32\rvueach.dll (file missing)
                  O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
                  O2 - BHO: (no name) - {652E87F1-4832-19B9-4296-3791FAD188BB} - C:\WINDOWS\system32\rcudsmk.dll (file missing)
                  O2 - BHO: (no name) - {70BE21BF-B356-CBA3-2C57-CACE689EEB9E} - C:\WINDOWS\system32\yxqgnwjw.dll (file missing)
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                  O2 - BHO: (no name) - {7642E90A-2ABB-0E44-C349-5B0795D5ECC0} - C:\WINDOWS\system32\iklpbort.dll (file missing)
                  O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\ktbjwarg.dll
                  O2 - BHO: (no name) - {9B351929-A7E9-4AA5-8280-D1F885196AF5} - C:\WINDOWS\system32\ssttq.dll
                  O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                  O2 - BHO: (no name) - {C8F5C294-0505-01DB-2580-7645777971E3} - C:\WINDOWS\system32\rdaetd.dll (file missing)
                  O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                  O4 - HKLM\..\Run: [UDial] C:\WINDOWS\system32/udial.exe
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
                  O4 - Startup: .protected
                  O4 - Global Startup: .protected
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                  O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
                  O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                  O20 - Winlogon Notify: ssttq - C:\WINDOWS\system32\ssttq.dll
                  O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                  O20 - Winlogon Notify: winrvc32 - C:\WINDOWS\SYSTEM32\winrvc32.dll
                  O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
                  O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                  O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                  O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                  O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                  O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                  O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
                  O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                  O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                  O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                  O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                  0
                  1. Contributeur
                    t'as une infection vundo ..

                    Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
                    http://www.atribune.org/ccount/click.php?id=4

                    Double-clique VundoFix.exe afin de le lancer.
                    Coche Run VundoFix as a task.
                    Un message t'avertira que l'outil va se fermer et s'ouvrir à nouveau : clique Ok
                    Clique sur le bouton Scan for Vundo.

                    Lorsque le scan est complété, clique sur le bouton Remove Vundo.
                    Une invite te demandera si tu veux supprimer les fichiers, clique YES
                    Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
                    Tu verras une invite qui t'annonce que ton PC va s'éteindre ("shutdown") ; clique OK
                    Démarre ton PC à nouveau.
                    Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis! dans ta prochaine réponse

                    a++
                    0
                    1. Re :-)

                      Helas, pas d'amélioration des lags du pc. Voila toutefois le rapport VundoFix:

                      VundoFix V6.3.2

                      Checking Java version...

                      Java version is 1.5.0.6

                      Java version is 1.5.0.9

                      Scan started at 22:53:12 15/01/2007

                      Listing files found while scanning....

                      C:\Documents and settings\Seb\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
                      C:\Documents and settings\Seb\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
                      C:\Program Files\VSAdd-in\VSAdd-in.dll
                      C:\WINDOWS\system32\aplusatd.dll
                      C:\WINDOWS\system32\asaaovji.ini
                      C:\WINDOWS\system32\bgjfqbnd.dll
                      C:\WINDOWS\system32\fcgmdwaj.dll
                      C:\WINDOWS\system32\hcdptgmk.dll
                      C:\WINDOWS\system32\ijvoaasa.dll
                      C:\WINDOWS\system32\ktbjwarg.dll
                      C:\WINDOWS\system32\qftlojps.dll
                      C:\WINDOWS\system32\qttss.bak1
                      C:\WINDOWS\system32\qttss.bak2
                      C:\WINDOWS\system32\qttss.ini
                      C:\WINDOWS\system32\qttss.ini2
                      C:\WINDOWS\system32\qttss.tmp
                      C:\WINDOWS\system32\spjoltfq.ini
                      C:\WINDOWS\system32\ssttq.dll
                      C:\WINDOWS\system32\yaiheoes.dll
                      C:\WINDOWS\system32\yinfgcyf.dll
                      C:\WINDOWS\system32\ypdbypju.dll

                      Beginning removal...

                      Attempting to delete C:\Documents and settings\Seb\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
                      C:\Documents and settings\Seb\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt Has been deleted!

                      Attempting to delete C:\Documents and settings\Seb\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
                      C:\Documents and settings\Seb\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt Has been deleted!

                      Attempting to delete C:\WINDOWS\system32\asaaovji.ini
                      C:\WINDOWS\system32\asaaovji.ini Has been deleted!

                      Attempting to delete C:\WINDOWS\system32\bgjfqbnd.dll
                      C:\WINDOWS\system32\bgjfqbnd.dll Has been deleted!

                      Attempting to delete C:\WINDOWS\system32\fcgmdwaj.dll
                      C:\WINDOWS\system32\fcgmdwaj.dll Has been deleted!

                      Attempting to delete C:\WINDOWS\system32\hcdptgmk.dll
                      C:\WINDOWS\system32\hcdptgmk.dll Has been deleted!

                      Attempting to delete C:\WINDOWS\system32\ijvoaasa.dll
                      C:\WINDOWS\system32\ijvoaasa.dll Has been deleted!

                      Attempting to delete C:\WINDOWS\system32\ktbjwarg.dll
                      C:\WINDOWS\system32\ktbjwarg.dll Has been deleted!

                      Attempting to delete C:\WINDOWS\system32\qftlojps.dll
                      C:\WINDOWS\system32\qftlojps.dll Has been deleted!

                      Attempting to delete C:\WINDOWS\system32\qttss.bak1
                      C:\WINDOWS\system32\qttss.bak1 Has been deleted!

                      Attempting to delete C:\WINDOWS\system32\qttss.bak2
                      C:\WINDOWS\system32\qttss.bak2 Has been deleted!

                      Attempting to delete C:\WINDOWS\system32\qttss.ini
                      C:\WINDOWS\system32\qttss.ini Has been deleted!

                      Attempting to delete C:\WINDOWS\system32\qttss.ini2
                      C:\WINDOWS\system32\qttss.ini2 Has been deleted!

                      Attempting to delete C:\WINDOWS\system32\qttss.tmp
                      C:\WINDOWS\system32\qttss.tmp Has been deleted!

                      Attempting to delete C:\WINDOWS\system32\spjoltfq.ini
                      C:\WINDOWS\system32\spjoltfq.ini Has been deleted!

                      Attempting to delete C:\WINDOWS\system32\ssttq.dll
                      C:\WINDOWS\system32\ssttq.dll Could not be deleted.

                      Attempting to delete C:\WINDOWS\system32\ypdbypju.dll
                      C:\WINDOWS\system32\ypdbypju.dll Has been deleted!

                      Performing Repairs to the registry.
                      Done!

                      Beginning removal...

                      Et le rapport hijack:

                      Logfile of HijackThis v1.99.1
                      Scan saved at 23:34:41, on 15/01/2007
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.5730.0011)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Acer\eManager\anbmServ.exe
                      C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                      C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
                      C:\Program Files\Norton AntiVirus\navapsvc.exe
                      C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                      C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      D:\Secu PC\HijackThis\abcd.exe
                      C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
                      C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                      C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
                      C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
                      C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
                      C:\WINDOWS\system32\NOTEPAD.EXE

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
                      O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
                      O2 - BHO: (no name) - {58CCD0E9-6FAC-3F07-35B7-041EB6558299} - C:\WINDOWS\system32\rvueach.dll (file missing)
                      O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
                      O2 - BHO: (no name) - {652E87F1-4832-19B9-4296-3791FAD188BB} - C:\WINDOWS\system32\rcudsmk.dll (file missing)
                      O2 - BHO: (no name) - {70BE21BF-B356-CBA3-2C57-CACE689EEB9E} - C:\WINDOWS\system32\yxqgnwjw.dll (file missing)
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
                      O2 - BHO: (no name) - {7642E90A-2ABB-0E44-C349-5B0795D5ECC0} - C:\WINDOWS\system32\iklpbort.dll (file missing)
                      O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\ktbjwarg.dll (file missing)
                      O2 - BHO: (no name) - {9B351929-A7E9-4AA5-8280-D1F885196AF5} - C:\WINDOWS\system32\ssttq.dll (file missing)
                      O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                      O2 - BHO: (no name) - {C8F5C294-0505-01DB-2580-7645777971E3} - C:\WINDOWS\system32\rdaetd.dll (file missing)
                      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
                      O4 - Startup: .protected
                      O4 - Global Startup: .protected
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                      O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
                      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                      O20 - Winlogon Notify: winrvc32 - C:\WINDOWS\SYSTEM32\winrvc32.dll
                      O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                      O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
                      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
                      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                      O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                      O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                      O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
                      O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe

                      Voila...
                      0
                      1. Il m'a dit aussi qu'il ne pouvait pas supprimer ssttq.dll. J'ai recommencé l'opération et ca a l'air de l'avoir supprimer.
                        0
                        1. Contributeur
                          ree :)

                          ouvre hijack , coches ces lignes puis clic sur fix checked

                          O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
                          O2 - BHO: (no name) - {58CCD0E9-6FAC-3F07-35B7-041EB6558299} - C:\WINDOWS\system32\rvueach.dll (file missing)
                          O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
                          O2 - BHO: (no name) - {652E87F1-4832-19B9-4296-3791FAD188BB} - C:\WINDOWS\system32\rcudsmk.dll (file missing)
                          O2 - BHO: (no name) - {70BE21BF-B356-CBA3-2C57-CACE689EEB9E} - C:\WINDOWS\system32\yxqgnwjw.dll (file missing)
                          O2 - BHO: (no name) - {7642E90A-2ABB-0E44-C349-5B0795D5ECC0} - C:\WINDOWS\system32\iklpbort.dll (file missing)
                          O2 - BHO: (no name) - {7DA39570-5FD2-4f18-94B4-20730CB3F727} - C:\WINDOWS\system32\ktbjwarg.dll (file missing)
                          O2 - BHO: (no name) - {9B351929-A7E9-4AA5-8280-D1F885196AF5} - C:\WINDOWS\system32\ssttq.dll (file missing)
                          O2 - BHO: (no name) - {C8F5C294-0505-01DB-2580-7645777971E3} - C:\WINDOWS\system32\rdaetd.dll (file missing)

                          il ne reste plus que cette ligne a viré

                          O20 - Winlogon Notify: winrvc32 - C:\WINDOWS\SYSTEM32\winrvc32.dll

                          telecharge the killbox

                          http://www.killbox.net/downloads/KillBox.exe

                          Double clic sur killbox.exe (Pocket Killbox)

                          - coche: delete on reboot
                          - Dans "Full Path of File to Delete"
                          copie et colle:

                          C:\WINDOWS\SYSTEM32\winrvc32.dll

                          - clique sur la croix rouge
                          - une fenêtre va apparaître pour confirmation de suppression clique sur YES
                          - une seconde fenêtre te demande si tu veux redémarrer clique sur YES

                          Si ce message s’affiche ignore le :
                          http://tinypic.com/images/goodbye.jpg
                          Laisse le pc redémarrer ou redemarre manuellement s il le fait pas.
                          Et après reposte un log HijackThis.

                          a+++
                          a+++++
                          0
                          1. voila le rapport

                            Logfile of HijackThis v1.99.1
                            Scan saved at 00:02:50, on 16/01/2007
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.5730.0011)

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Acer\eManager\anbmServ.exe
                            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                            C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
                            C:\Program Files\Norton AntiVirus\navapsvc.exe
                            C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                            C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
                            C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                            D:\Secu PC\HijackThis\abcd.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                            O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
                            O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                            O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
                            O4 - Startup: .protected
                            O4 - Global Startup: .protected
                            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                            O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
                            O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
                            O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
                            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                            O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
                            O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                            O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
                            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                            O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                            O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                            O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                            O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
                            O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                            O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                            O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                            0
                            1. Contributeur
                              rebonsoir :) ouvre hijack coches ces lignes puis clic sur fix checked

                              O4 - Startup: .protected
                              O4 - Global Startup: .protected

                              supprime les fichiers inutiles (fichiers temporaire , cookies .. ect avec ceci

                              Ccleaner
                              https://www.malekal.com/tutoriel-ccleaner/

                              - Nettoye ta base de registre avec

                              regcleaner :

                              https://www.malekal.com/nettoyer-sa-base-de-registre-avec-windows-registry-cleaner/

                              tutorial

                              lance regcleaner /click sur le menu option / netoyage du registre/sauvegardes/ coches creé une sauvegarde globale

                              ensuite pour effectuer un netoyage du regsitre :

                              click sur le menu outils / netoyage du registre/ tout faire

                              apres la fin du scan

                              click sur le menu selection / tout / ensuite click sur surpprimé la selection ( en bas a droite)

                              a++++
                              0
                              1. Bon je vais me coucher. J'ai passé le pc sous ccleaner, puis regcleaner, sans amelioration visible. Je n'arrive pas a supprimer les deux lignes que tu m'a demandé de supprimer (hijack me dit que ce sont des ^processus en cours d'utilisation mais je ne les vois nulle part (meme avec task manager))

                                Je laisse un rapport hijack:

                                Logfile of HijackThis v1.99.1
                                Scan saved at 02:24:10, on 16/01/2007
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v7.00 (7.00.5730.0011)

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\Ati2evxx.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\Ati2evxx.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Acer\eManager\anbmServ.exe
                                C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
                                C:\Program Files\Norton AntiVirus\navapsvc.exe
                                C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                                C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                D:\Secu PC\HijackThis\abcd.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
                                O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                                O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                                O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8
                                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                                O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
                                O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
                                O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
                                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
                                O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\AVG Anti-Spyware 7.5\guard.exe
                                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                                O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                                O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                                O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
                                O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
                                O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                                O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe

                                J'ai essayé de passer par le mode sans echec mais sans plus de resultat (ca devient vraiment chiant ces put... de virus hein?)

                                Merci d'avoir pris de ton temps pour me donner un coup de main, je reregarderai demain(je bosse pas de la journée -la chance-)

                                @++++
                                0
                                1. Contributeur
                                  bonjour :) ton log est propre

                                  as tu tjr des dysfonctionements?

                                  a+++
                                  0
                                  1. salut oui, j'ai toujours les disfonctionnements. j'ai relancé il y a bientot 2h30 une nouvelle analyse AVG. On va bien voir. Tu veux que je poste le rapport?
                                    0
                                    1. Contributeur
                                      ok :) poste le raport avg et explique avec precision tes problemes

                                      a++
                                      0
                                      • 1
                                      • 2