Message erreur au demarrage de windows xp

Résolu
Bonjour,

j'ai windows xp et au démarrage j'ai le message d'erreur suivant:
c:\PROGRA~1\MYWEBS~1\bar\8.bin\MWSBAR.DLL. le module spécifié est introuvable.

Je vous remercie par avance de votre aide
Configuration: Windows XP
Internet Explorer 7.0

28 réponses

Résumé de la discussion

Une erreur au démarrage sous Windows XP signale le module introuvable MWSBAR.DLL et semble associée à l’infection par MyWebSearch. Plusieurs réponses préconisent HijackThis, CCleaner et CleanUp40 pour nettoyer les entrées malware et les barres d’outils, puis vérifier les composants réseau et les processus sensibles. Les étapes essentielles incluent la suppression des entrées indésirables et du fichier rlls.dll dans le cadre d’un problème de Winsock LSP, puis redémarrer en mode sans échec et réinitialiser le catalogue Winsock avec netsh winsock reset catalog. En cas de persistance, des conseils complémentaires recommandent de vérifier les paramètres réseau, d’éviter les variantes douteuses et, si nécessaire, d’effectuer une restauration du système tout en surveillant les réapparitions.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut

    c'est une salté !!!

    Télécharge ceci sur ton bureau :

    Lien : hijackthis

    Démo : http://pageperso.aol.fr/balltrap34/demohijack.htm

    Choisir l'option "do a scan and a logfile", et faire un copier/coller du rapport ainsi générer sur le forum

    ++
    0
    1. voici le scan suite à mon pb au démarrage windows: c:\PROGRA~1\bar\8.bin\MWSBAR.DLL. le module spécifié est introuvable

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
      C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
      C:\WINDOWS\system32\slserv.exe
      C:\WINDOWS\System32\PAStiSvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\ALCWZRD.EXE
      C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
      C:\Apps\Powercinema\PCMService.exe
      C:\apps\ABoard\ABoard.exe
      C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
      C:\apps\ABoard\AOSD.exe
      D:\iTunesHelper.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\DAEMON Tools\daemon.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      D:\3.0\Apps\apdproxy.exe
      C:\WINDOWS\vVX3000.exe
      C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe
      C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe
      C:\Apps\EZHome\EZStatus.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Larousse\Encyclopédie Universelle Larousse\bin\hyperappel.exe
      C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\Program Files\OpenOffice.org1.1.5\program\soffice.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\PROGRA~1\Wanadoo\Watch.exe
      C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
      C:\Program Files\WinRAR\WinRAR.exe
      C:\DOCUME~1\mireille\LOCALS~1\Temp\Rar$EX00.469\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.eagames.com/official/nfs/underground/fr/home.jsp
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
      O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
      O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
      O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
      O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
      O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
      O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
      O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
      O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
      O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
      O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
      O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunesHelper.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "D:\3.0\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\8.bin\MWSBAR.DLL,S
      O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\8.bin\mwsoemon.exe
      O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe"
      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
      O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe"
      O4 - HKCU\..\Run: [EzStatus] C:\Apps\EZHome\EZStatus.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\8.bin\mwsoemon.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CamTray.exe
      O4 - HKCU\..\Run: [msmsgs] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [D:\1&1 Connexion directe\EasyLogin.exe] "1&1 Connexion directe" HIDE
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Startup: OpenOffice.org 1.1.5.lnk = C:\Program Files\OpenOffice.org1.1.5\program\quickstart.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Hyperappel de l'Encyclopédie Universelle Larousse.lnk = ?
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
      O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
      O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
      O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNfox000
      O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
      O11 - Options group: [INTERNATIONAL] International*
      O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
      O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
      O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
      O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
      O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
      O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
      0
      1. Modérateur
        re

        cherche et supprime les fichiers en gras :

        C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL

        C:\Program Files\MyWebSearch

        ensuite, va dans ajout/supprimer un programme et supprime les programmes du même nom !

        et fais le 1/ et 2/ de ce lien stp :

        virus methode preliminaire de desinfection version fr

        @+

        On peut aussi bâtir quelque chose de beau avec les pierres qui entravent le chemin (J.W.VON GOETHE
        )
        0
        1. petit problème:
          je ne retrouve pas ND2FNBAR.dll ni MYWEBSEARCH dans le disque dur.
          Que dois je faire?

          Merci de ton aide
          0
          1. Modérateur
            re

            ok, fais la suite stp

            ++
            0
            1. HKLM\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} -> Adware.2020Search : Ignoré.
              HKU\S-1-5-21-829130471-719648895-3578728738-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} -> Adware.2020Search : Ignoré.
              C:\Documents and Settings\mireille\Local Settings\Temp\asmfiles.cab/asm.exe -> Adware.Altnet : Ignoré.
              C:\Documents and Settings\mireille\Local Settings\Temp\asmfiles.cab/asmps.dll -> Adware.Altnet : Ignoré.
              HKU\S-1-5-21-829130471-719648895-3578728738-1008\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Ignoré.
              C:\Documents and Settings\mireille\Menu Démarrer\Programmes\WhenU -> Adware.SaveNow : Ignoré.
              C:\Documents and Settings\mireille\Menu Démarrer\Programmes\WhenU\Learn More About WhenU Save.url -> Adware.SaveNow : Ignoré.
              C:\Documents and Settings\mireille\Menu Démarrer\Programmes\WhenU\Learn More About WhenU SaveNow.url -> Adware.SaveNow : Ignoré.
              C:\Documents and Settings\mireille\Menu Démarrer\Programmes\WhenU\WhenU.com Website.url -> Adware.SaveNow : Ignoré.
              C:\Program Files\DAEMON Tools\SetupDTSB.exe -> Adware.SaveNow : Ignoré.
              C:\Program Files\Save -> Adware.SaveNow : Ignoré.
              C:\Program Files\Save\store.db -> Adware.SaveNow : Ignoré.
              C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP236\A0037544.exe -> Dropper.Small : Ignoré.
              :mozilla.12:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.247realmedia : Ignoré.
              :mozilla.13:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.247realmedia : Ignoré.
              :mozilla.16:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.247realmedia : Ignoré.
              :mozilla.17:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.247realmedia : Ignoré.
              :mozilla.280:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.
              :mozilla.281:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.
              :mozilla.292:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.
              :mozilla.304:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.
              :mozilla.323:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.
              :mozilla.53:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.
              :mozilla.54:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.
              :mozilla.55:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.
              :mozilla.56:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.
              :mozilla.57:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.
              :mozilla.58:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.
              :mozilla.59:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.
              :mozilla.85:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.
              :mozilla.76:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Adtech : Ignoré.
              :mozilla.77:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Adtech : Ignoré.
              :mozilla.42:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Bluestreak : Ignoré.
              C:\Documents and Settings\mireille\Cookies\mireille@bluestreak[1].txt -> TrackingCookie.Bluestreak : Ignoré.
              :mozilla.115:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Com : Ignoré.
              C:\Documents and Settings\mireille\Cookies\mireille@com[2].txt -> TrackingCookie.Com : Ignoré.
              :mozilla.448:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Comclick : Ignoré.
              :mozilla.449:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Comclick : Ignoré.
              :mozilla.450:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Comclick : Ignoré.
              :mozilla.164:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Estat : Ignoré.
              :mozilla.534:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Googleadservices : Ignoré.
              :mozilla.535:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Googleadservices : Ignoré.
              :mozilla.536:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Googleadservices : Ignoré.
              :mozilla.537:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Googleadservices : Ignoré.
              :mozilla.538:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Googleadservices : Ignoré.
              :mozilla.539:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Googleadservices : Ignoré.
              :mozilla.195:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Hotlog : Ignoré.
              :mozilla.485:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Information : Ignoré.
              :mozilla.216:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Ivwbox : Ignoré.
              :mozilla.483:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Liveperson : Ignoré.
              :mozilla.484:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Liveperson : Ignoré.
              :mozilla.22:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Mediaplex : Ignoré.
              :mozilla.308:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Overture : Ignoré.
              :mozilla.33:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Overture : Ignoré.
              :mozilla.34:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Overture : Ignoré.
              :mozilla.70:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Pointroll : Ignoré.
              :mozilla.71:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Pointroll : Ignoré.
              :mozilla.72:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Pointroll : Ignoré.
              :mozilla.73:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Pointroll : Ignoré.
              :mozilla.498:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Realtracker : Ignoré.
              :mozilla.318:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Revenue : Ignoré.
              :mozilla.35:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.
              :mozilla.36:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.
              :mozilla.37:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.
              :mozilla.38:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.
              :mozilla.39:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.
              :mozilla.40:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Serving-sys : Ignoré.
              :mozilla.460:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Sitestat : Ignoré.
              :mozilla.461:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Sitestat : Ignoré.
              :mozilla.462:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Sitestat : Ignoré.
              :mozilla.30:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.
              :mozilla.31:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.
              :mozilla.32:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.
              C:\Documents and Settings\mireille\Cookies\mireille@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Ignoré.
              :mozilla.338:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Spylog : Ignoré.
              :mozilla.339:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Statcounter : Ignoré.
              :mozilla.340:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Statcounter : Ignoré.
              :mozilla.341:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Statcounter : Ignoré.
              :mozilla.342:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Statcounter : Ignoré.
              :mozilla.352:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.
              :mozilla.353:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.
              :mozilla.354:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Tradedoubler : Ignoré.
              :mozilla.356:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Tribalfusion : Ignoré.
              :mozilla.392:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Web-stat : Ignoré.
              :mozilla.393:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Web-stat : Ignoré.
              :mozilla.394:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Web-stat : Ignoré.
              :mozilla.389:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.
              :mozilla.390:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.
              :mozilla.391:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.
              C:\Documents and Settings\mireille\Cookies\mireille@weborama[2].txt -> TrackingCookie.Weborama : Ignoré.
              :mozilla.413:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignoré.
              :mozilla.414:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignoré.
              :mozilla.415:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignoré.
              :mozilla.416:C:\Documents and Settings\mireille\Application Data\Mozilla\Firefox\Profiles\7mw7akyw.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignoré.
              C:\Documents and Settings\mireille\Cookies\mireille@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Ignoré.

              Fin du rapport
              0
              1. Modérateur
                re

                as tu supprimé tout ce qu'il ta trouvé ???

                ++
                0
                1. oui j'ai tout supprimé et ce soir je vais faire le scan avec bit defender et je te metterai le rapport sur le forum.
                  Merci en tous cas de ton aide
                  A +
                  0
                  1. voici le scan de bit defender:
                    BitDefender Online Scanner

                    Rapport d'analyse généré à: Fri, Jan 19, 2007 - 19:37:37

                    Voie d'analyse: C:\;D:\;E:\;F:\;I:\;J:\;K:\;L:\;

                    Statistiques

                    Temps
                    01:30:00

                    Fichiers
                    545675

                    Directoires
                    8833

                    Secteurs de boot
                    5

                    Archives
                    9324

                    Paquets programmes
                    43364

                    Résultats

                    Virus identifiés
                    1

                    Fichiers infectés
                    2

                    Fichiers suspects
                    0

                    Avertissements
                    0

                    Désinfectés
                    0

                    Fichiers effacés
                    2

                    Info sur les moteurs

                    Définition virus
                    389746

                    Version des moteurs
                    AVCORE v1.0 (build 2371) (i386) (Dec 13 2006 11:16:42)

                    Analyse des plugins
                    14

                    Archive des plugins
                    38

                    Unpack des plugins
                    6

                    E-mail plugins
                    6

                    Système plugins
                    1

                    Paramètres d'analyse

                    Première action
                    Désinfecté

                    Seconde Action
                    Supprimé

                    Heuristique
                    Oui

                    Acceptez les avertissements
                    Oui

                    Extensions analysées
                    *;

                    Excludez les extensions

                    Analyse d'emails
                    Oui

                    Analyse des Archives
                    Oui

                    Analyser paquets programmes
                    Oui

                    Analyse des fichiers
                    Oui

                    Analyse de boot
                    Oui

                    Fichier analysé
                    Statut

                    C:\Documents and Settings\mireille\Local Settings\Temp\iinstall47071.exe=>(NSIS o)=>lzma_solid_nsis0004
                    Infecté par: Trojan.Downloader.IstBar.OK

                    C:\Documents and Settings\mireille\Local Settings\Temp\iinstall47071.exe=>(NSIS o)=>lzma_solid_nsis0004
                    Echec de la désinfection

                    C:\Documents and Settings\mireille\Local Settings\Temp\iinstall47071.exe=>(NSIS o)=>lzma_solid_nsis0004
                    Supprimé

                    C:\Documents and Settings\mireille\Local Settings\Temp\iinstall47071.exe=>(NSIS o)
                    Echec de la mise à jour

                    C:\Documents and Settings\mireille\Local Settings\Temp\iinstall47072.exe=>(NSIS o)=>lzma_solid_nsis0004
                    Infecté par: Trojan.Downloader.IstBar.OK

                    C:\Documents and Settings\mireille\Local Settings\Temp\iinstall47072.exe=>(NSIS o)=>lzma_solid_nsis0004
                    Echec de la désinfection

                    C:\Documents and Settings\mireille\Local Settings\Temp\iinstall47072.exe=>(NSIS o)=>lzma_solid_nsis0004
                    Supprimé

                    C:\Documents and Settings\mireille\Local Settings\Temp\iinstall47072.exe=>(NSIS o)
                    Echec de la mise à jour
                    0
                    1. Modérateur
                      Salut

                      ok, poste un nouveau hijackthis stp

                      @+
                      0
                      1. voilà:
                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                        C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        C:\WINDOWS\System32\FTRTSVC.exe
                        C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                        C:\WINDOWS\system32\slserv.exe
                        C:\WINDOWS\System32\PAStiSvc.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                        C:\WINDOWS\SOUNDMAN.EXE
                        C:\WINDOWS\ALCWZRD.EXE
                        C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
                        C:\Apps\Powercinema\PCMService.exe
                        C:\apps\ABoard\ABoard.exe
                        C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
                        C:\apps\ABoard\AOSD.exe
                        D:\iTunesHelper.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\Program Files\DAEMON Tools\daemon.exe
                        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        D:\3.0\Apps\apdproxy.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\WINDOWS\vVX3000.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe
                        C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
                        C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                        C:\Apps\EZHome\EZStatus.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Messenger\msmsgs.exe
                        C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                        C:\PROGRA~1\Wanadoo\ComComp.exe
                        C:\PROGRA~1\Wanadoo\Toaster.exe
                        C:\PROGRA~1\Wanadoo\Inactivity.exe
                        C:\PROGRA~1\Wanadoo\PollingModule.exe
                        C:\Program Files\MSN Messenger\msnmsgr.exe
                        C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        C:\Program Files\Larousse\Encyclopédie Universelle Larousse\bin\hyperappel.exe
                        C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                        C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                        C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
                        C:\Program Files\OpenOffice.org1.1.5\program\soffice.exe
                        C:\PROGRA~1\Wanadoo\Watch.exe
                        C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\WinRAR\WinRAR.exe
                        C:\DOCUME~1\mireille\LOCALS~1\Temp\Rar$EX00.781\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.eagames.com/official/nfs/underground/fr/home.jsp
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - C:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL (file missing)
                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                        O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                        O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
                        O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                        O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
                        O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                        O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                        O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                        O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
                        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                        O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                        O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
                        O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
                        O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                        O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
                        O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
                        O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunesHelper.exe"
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
                        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [Adobe Photo Downloader] "D:\3.0\Apps\apdproxy.exe"
                        O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\8.bin\MWSBAR.DLL,S
                        O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\8.bin\mwsoemon.exe
                        O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
                        O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                        O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                        O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe"
                        O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                        O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe"
                        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                        O4 - HKCU\..\Run: [EzStatus] C:\Apps\EZHome\EZStatus.exe
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\8.bin\mwsoemon.exe
                        O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                        O4 - HKCU\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CamTray.exe
                        O4 - HKCU\..\Run: [msmsgs] "C:\Program Files\Messenger\msmsgs.exe" /background
                        O4 - HKCU\..\Run: [D:\1&1 Connexion directe\EasyLogin.exe] "1&1 Connexion directe" HIDE
                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                        O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                        O4 - Startup: OpenOffice.org 1.1.5.lnk = C:\Program Files\OpenOffice.org1.1.5\program\quickstart.exe
                        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        O4 - Global Startup: Hyperappel de l'Encyclopédie Universelle Larousse.lnk = ?
                        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                        O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                        O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
                        O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
                        O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNfox000
                        O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                        O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                        O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                        O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                        O11 - Options group: [INTERNATIONAL] International*
                        O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                        O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                        O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                        O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                        O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                        O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                        O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                        O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                        O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                        O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                        O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
                        O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
                        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                        O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                        O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
                        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                        O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe

                        Merci de ton aide
                        0
                        1. Modérateur
                          Salut

                          Télécharge clean.zip
                          http://www.malekal.com/download/clean.zip
                          Décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.
                          Ouvre le dossier Clean qui se trouve sur ton bureau.
                          Double-clic sur clean.cmd.
                          Une fenêtre noire va apparaître, choisis l'option 1
                          Poste le rapport qui se trouve ici C:\rapport_clean.txt

                          ensuite :

                          # Démarre en mode sans échec :
                          Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                          Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                          Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                          (Si F8 ne marche pas utilise la touche F5).
                          - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

                          Double-clic sur clean.cmd.
                          Une fenêtre noire va apparaître, choisis l'option 2
                          Poste le rapport qui se trouve ici C:\rapport_clean.txt

                          et poste un new hijackthis stp

                          ++

                          On peut aussi bâtir quelque chose de beau avec les pierres qui entravent le chemin (J.W.VON GOETHE
                          )
                          0
                          1. voici le rapport de clean:
                            *** Recherche de fichiers sur C:
                            C:\setup.exe FOUND
                            C:\setup.exe FOUND

                            *** Recherche des fichiers dans C:\WINDOWS\
                            C:\WINDOWS\smdat32m.sys FOUND

                            *** Recherche des fichiers dans C:\WINDOWS\system32
                            C:\WINDOWS\system32\f3PSSavr.scr FOUND
                            C:\WINDOWS\system32\cd_clint.dll FOUND
                            C:\WINDOWS\system32\cd_clint.dll FOUND
                            C:\WINDOWS\system32\rlls.dll FOUND

                            "C:\Program Files\msn messenger\riched20.dll" FOUND
                            "C:\Program Files\Need2Find\" FOUND
                            "C:\Program Files\Viewpoint\" FOUND
                            *** Fin du rapport !
                            0
                            1. voici le rapport après le nettoyage par "clean":
                              Microsoft Windows XP [version 5.1.2600]

                              *** Suppression de fichiers sur C:
                              tentative de suppression de C:\setup.exe

                              *** Suppression des fichiers dans C:\WINDOWS\
                              tentative de suppression de C:\WINDOWS\smdat32m.sys

                              *** Suppression des fichiers dans C:\WINDOWS\system32
                              tentative de suppression de C:\WINDOWS\system32\f3PSSavr.scr
                              tentative de suppression de C:\WINDOWS\system32\cd_clint.dll
                              tentative de suppression de C:\WINDOWS\system32\rlls.dll
                              Impossible de supprimer C:\WINDOWS\system32\rlls.dll

                              tentative de suppression de "C:\Program Files\msn messenger\riched20.dll"
                              tentative de suppression de "C:\Program Files\Need2Find\"
                              tentative de suppression de "C:\Program Files\Viewpoint\"

                              *** Suppression des clefs du registre effectuee..
                              *** Fin du rapport !
                              0
                              1. merci encore de ton aide et voici le new hijackthis:

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\WINDOWS\system32\spoolsv.exe
                                c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                C:\WINDOWS\System32\FTRTSVC.exe
                                C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                                C:\WINDOWS\system32\HPZipm12.exe
                                C:\WINDOWS\system32\slserv.exe
                                C:\WINDOWS\System32\PAStiSvc.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                C:\WINDOWS\SOUNDMAN.EXE
                                C:\WINDOWS\ALCWZRD.EXE
                                C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
                                C:\Apps\Powercinema\PCMService.exe
                                C:\apps\ABoard\ABoard.exe
                                C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe
                                C:\apps\ABoard\AOSD.exe
                                D:\iTunesHelper.exe
                                C:\Program Files\QuickTime\qttask.exe
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                C:\Program Files\DAEMON Tools\daemon.exe
                                C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                D:\3.0\Apps\apdproxy.exe
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                C:\WINDOWS\vVX3000.exe
                                C:\Program Files\iPod\bin\iPodService.exe
                                C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe
                                C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                                C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
                                C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                C:\Apps\EZHome\EZStatus.exe
                                C:\WINDOWS\system32\wuauclt.exe
                                C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Messenger\msmsgs.exe
                                C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                                C:\PROGRA~1\Wanadoo\ComComp.exe
                                C:\Program Files\MSN Messenger\msnmsgr.exe
                                C:\PROGRA~1\Wanadoo\Toaster.exe
                                C:\PROGRA~1\Wanadoo\Inactivity.exe
                                C:\PROGRA~1\Wanadoo\PollingModule.exe
                                C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                C:\Program Files\Larousse\Encyclopédie Universelle Larousse\bin\hyperappel.exe
                                C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                                C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
                                C:\Program Files\OpenOffice.org1.1.5\program\soffice.exe
                                C:\PROGRA~1\Wanadoo\Watch.exe
                                C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                C:\Program Files\WinRAR\WinRAR.exe
                                C:\DOCUME~1\mireille\LOCALS~1\Temp\Rar$EX00.547\HijackThis.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.eagames.com/official/nfs/underground/fr/home.jsp
                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                                O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                                O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                                O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
                                O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                                O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                                O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
                                O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                                O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                                O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                                O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
                                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                                O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                                O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
                                O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
                                O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                                O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
                                O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
                                O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunesHelper.exe"
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
                                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                O4 - HKLM\..\Run: [Adobe Photo Downloader] "D:\3.0\Apps\apdproxy.exe"
                                O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
                                O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                                O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                                O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe"
                                O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                                O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe"
                                O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                O4 - HKCU\..\Run: [EzStatus] C:\Apps\EZHome\EZStatus.exe
                                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\8.bin\mwsoemon.exe
                                O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                                O4 - HKCU\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CamTray.exe
                                O4 - HKCU\..\Run: [msmsgs] "C:\Program Files\Messenger\msmsgs.exe" /background
                                O4 - HKCU\..\Run: [D:\1&1 Connexion directe\EasyLogin.exe] "1&1 Connexion directe" HIDE
                                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                O4 - Startup: OpenOffice.org 1.1.5.lnk = C:\Program Files\OpenOffice.org1.1.5\program\quickstart.exe
                                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                O4 - Global Startup: Hyperappel de l'Encyclopédie Universelle Larousse.lnk = ?
                                O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                                O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
                                O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
                                O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNfox000
                                O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
                                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                                O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                O11 - Options group: [INTERNATIONAL] International*
                                O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                                O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
                                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                                O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                                O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                                O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                                O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                                O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                                O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                                O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                                O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                                O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                                O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
                                O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
                                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                                O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                                O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
                                O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                                O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                0
                                1. Modérateur
                                  Salut

                                  ok,

                                  Relance HijackThis : choisis " do a scan only" coche la case devant les lignes ci-dessous et clique en bas sur "fix checked" :

                                  # R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS02

                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

                                  O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll

                                  O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll

                                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                  O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                                  O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                                  O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
                                  O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"

                                  O4 - HKLM\..\Run: [VCSPlayer] "C:\Program Files\Virtual CD v4 SDK\system\vcsplay.exe"
                                  O4 - HKLM\..\Run: [CleanEasyImg] c:\apps\easydvd\cleanall.exe
                                  O4 - HKLM\..\Run: [iTunesHelper] "D:\iTunesHelper.exe"
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                  O4 - HKLM\..\Run: [Adobe Photo Downloader] "D:\3.0\Apps\apdproxy.exe"

                                  O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe"
                                  O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                                  O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe"
                                  O4 - HKCU\..\Run: [EzStatus] C:\Apps\EZHome\EZStatus.exe
                                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\8.bin\mwsoemon.exe

                                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                  O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                  O4 - Startup: OpenOffice.org 1.1.5.lnk = C:\Program Files\OpenOffice.org1.1.5\program\quickstart.exe

                                  O4 - Global Startup: Hyperappel de l'Encyclopédie Universelle Larousse.lnk = ?
                                  O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                  O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
                                  O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?

                                  O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
                                  O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNfox000

                                  O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                  O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                  O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                  O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                  O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                  O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll

                                  => cherche et supprime le fichier en gras :

                                  c:\windows\system32\rlls.dll

                                  # * CleanUp40 (qui élimine les fichiers temporaires + cookies : gratuit )
                                  http://pageperso.aol.fr/Balltrap34/CleanUp40.exe

                                  tuto : (merci à Balltrap) http://pageperso.aol.fr/balltrap34/democleanup.htm

                                  * Ccleaner : Telecharge et installe ceci, dans la colonne de gauche clique sur "erreurs" coche toute les cases, puis clique en bas sur "chercher des erreurs" une fois finit, clique sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs .

                                  *Relance Ccleaner ,vas dans l'onglet "nettoyeur" present sur la gauche, decoche la derniere case (Avancé si elle
                                  est cochée) puis clique sur "lancer le nettoyage"

                                  ccleaner

                                  tuto: https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

                                  ensuite, reposte un nouveau hijackthis et precise tes soucis s'il en reste

                                  @+

                                  On peut aussi bâtir quelque chose de beau avec les pierres qui entravent le chemin (J.W.VON GOETHE
                                  )
                                  0
                                  1. voici le nouveau hijackthis, apparemment plus de message d'erreur quand j'allume mon pc. Merci de ton aide précieuse:
                                    unning processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                    C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                                    C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                                    C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    C:\WINDOWS\System32\FTRTSVC.exe
                                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                                    C:\WINDOWS\system32\slserv.exe
                                    C:\WINDOWS\System32\PAStiSvc.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    C:\WINDOWS\system32\HPZipm12.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\apps\ABoard\ABoard.exe
                                    C:\Program Files\QuickTime\qttask.exe
                                    C:\Program Files\DAEMON Tools\daemon.exe
                                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    C:\WINDOWS\vVX3000.exe
                                    C:\apps\ABoard\AOSD.exe
                                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                    D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                                    C:\Program Files\MSN Messenger\msnmsgr.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                                    C:\PROGRA~1\Wanadoo\ComComp.exe
                                    C:\PROGRA~1\Wanadoo\Toaster.exe
                                    C:\PROGRA~1\Wanadoo\Inactivity.exe
                                    C:\PROGRA~1\Wanadoo\PollingModule.exe
                                    C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                                    C:\PROGRA~1\Wanadoo\Watch.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                    C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
                                    C:\PROGRA~1\Wanadoo\WOOBRO~1\DownloadManager.exe
                                    C:\Program Files\WinRAR\WinRAR.exe
                                    C:\DOCUME~1\mireille\LOCALS~1\Temp\Rar$EX00.328\HijackThis.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.eagames.com/official/nfs/underground/fr/home.jsp
                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                                    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                                    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                                    O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
                                    O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                                    O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
                                    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                                    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                                    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                                    O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
                                    O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
                                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
                                    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                                    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                    O4 - HKLM\..\Run: [Zone Labs Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                                    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                                    O4 - HKCU\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CamTray.exe
                                    O4 - HKCU\..\Run: [D:\1&1 Connexion directe\EasyLogin.exe] "1&1 Connexion directe" HIDE
                                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Fichiers communs\Adobe\Updater\AdobeUpdater.exe
                                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
                                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
                                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                                    O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                                    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                    O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                    O11 - Options group: [INTERNATIONAL] International*
                                    O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
                                    O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
                                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
                                    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                                    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                                    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                                    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                                    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                                    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                                    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                                    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                                    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                                    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
                                    O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
                                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                                    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                                    O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
                                    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                                    O23 - Service: Virtual CD v4 Security service (SDK - Version) (VCSSecS) - H+H Software GmbH - C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe
                                    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                    0
                                    1. Modérateur
                                      re

                                      as tu reussi à supprimer le fichier en gras ???

                                      c:\windows\system32\rlls.dll

                                      ++
                                      0
                                      1. non, je n'y arrive ps il me dit acces refuse
                                        0
                                        1. Modérateur
                                          ok

                                          redemarre en mode sans echec :

                                          * lance hijackthis et clique sur : open the misc tools section

                                          *clique sur : delete a file on reboot
                                          * dans la fenêtre qui s'ouvre, colle ce chemin :
                                          c:\windows\system32\rlls.dll

                                          * repond oui à la demande de reboot

                                          ensuite : Relance HijackThis : choisis " do a scan only" coche la case devant les lignes ci-dessous et clique en bas sur "fix checked" :

                                          O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                          O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                          O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                          O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                          O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll
                                          O10 - Unknown file in Winsock LSP: c:\windows\system32\rlls.dll

                                          et poste un nouveau hijackthis stp

                                          ++

                                          La sagesse, c'est d'avoir des rêves suffisamment grands pour ne pas les perdre de vue lorsqu'on les poursuit. (Oscar Wilde)
                                          0
                                          • 1
                                          • 2