Problèmes spywares sous Vista

Bonsoir tout le monde,

Innondé de fenêtres qui s'ouvrent toutes seules, du genre .... "Votre ordinateur est infecté" .... "Spyware-Secure" .... ou simples pages de publicités non désirées, je suis à la recherche de quelqu'un qui pourrait m'aiguiller vers une solution radicale pour éradiquer ces phénomènes.

Mon ordi tourne avec Vista (édition familiale premium) et IE7.
Mon antivirus est Avast 4.7 édition familiale.
Tous les programmes sont à jour

N'étant pas informaticien très chevronné, je ne sais plus quoi faire.

Merci de votre aide.

Marco
Configuration: Windows Vista édition familiale
Internet Explorer 7.0
Antivirus Avast

28 réponses

Résumé de la discussion

Un utilisateur décrit une infection sous Windows Vista et IE7, avec des fenêtres publicitaires et des messages "Votre ordinateur est infecté" qui s'ouvrent sans raison. Plusieurs réponses recommandent de désinstaller les logiciels indésirables, démarrer en mode sans échec et nettoyer les fichiers suspects via Spybot, HijackThis et CCleaner. D'autres conseils portent sur la désactivation du UAC, la vérification de fichiers cachés et la suppression manuelle de clés ou services potentiellement malveillants, ainsi que des recommandations pour le pare-feu et les paramètres réseau. Par ailleurs, des contributions soulignent que Vista et IE7 peuvent compliquer les nettoyages et que les conseils diffèrent selon le niveau d'expérience, certains préconisant des méthodes manuelles tandis que d'autres privilégient outils automatisés.

Bobot (l’IA à votre service)
  1. bonsoir ,
    telecharge ceci spybot
    fait un scan et dis nous le resultat
    bon courage a+
    2
    1. Si tu as installé un de ces logiciels :
      # go-astro
      # GoRecord
      # HotTVPlayer
      # MailSkinner
      # Messenger Skinner
      # Instant Access
      # InternetGameBox
      # sudoplanet
      # Webmediaplayer

      Tu le désinstalles et supprime le dossier de Program Files

      Ensuite redémarre en mode sans échec,

      Supprime tous les fichiers commencant par
      hbcwqkehbu

      dans C:\Users\ton nom\AppData\Local\Microsoft
      Fais une recherche de fichiers sur
      hbcwqkehbu
      en activant dans les options avancées la recherche des fichiers cachés/systèmes.

      Supprime tout ce qu'il trouve.

      C:\Windows\pack.epk
      C:\Windows\system32\nvs2.inf

      Redémarre l'ordinateur

      2
      1. Salut

        Désactive le contrôle des comptes utilisateurs (tu le réactiveras lorsque tu auras obtenu le rapport):
        - Vas dans démarrer puis panneau de configuration
        - Double Clique sur l'icône "Comptes d'utilisateurs"
        - Clique ensuite sur désactiver et valide.
        Connecte toi en tant qu’ ADMINISTRATEUR

        Télécharge maintenant Navilog1VistaBeta :
        http://perso.orange.fr/il.mafioso/Navifix/Navilog1VistaBeta.zip

        Enregistre-le sur ton bureau.
        Fais un clic-droit dessus et choisis tout extraire.

        Fais un clic-droit sur le fichier Navilog1.bat et choisis "Exécuter en tant qu'administrateur".

        Lance Navilog1.bat

        Laisse toi guider et patiente.
        A la fin du scan, le blocnote va s'ouvrir.
        Copie-colle l'intégralité du rapport dans une réponse.
        Referme le blocnote

        Le rapport fixnavi.txt est en outre sauvegardé dans %systemdrive%. (Racine de ton disque )

        1
        1. Merci de ta rapidité!!

          Un premier passage de Spybot n'a indiquéque des cookies.... je les ai éliminés

          En cliquant sur "sauvegardes" (icône à gauche), il m'a ressorti "Spyware-Secure" et "Viruel Mundo" .... que je lui ai fait virer également.

          Un nouveau passage de Spybot donne ceci:

          Félicitations!
          Aucun mouchard n'a été trouvé.

          Par contre, lorsque j'essaie de vacciner, la barre verte ne me semble pas aller tout à fait jusqu'au bout à droite! il reste à peu près 1/2cm.

          C'est grave Docteur?? ;-) .... un autre test??
          0
          1. Histoire de gagner un peu de temps, j'ai téléchargé (et utilisé) Hijakthis

            Vu que c'est du chinois (pour moi en tout cas), je suis à l'écoute de vos bienveillants conseils!

            Voici le résultat actuel:

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 23:58:03, on 24/08/2007
            Platform: Windows Vista (WinNT 6.00.1904)
            MSIE: Internet Explorer v7.00 (7.00.6000.16512)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
            C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
            C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Program Files\TOSHIBA\Utilities\VolControl.exe
            C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
            C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
            C:\Program Files\Synaptics\SynTP\SynToshiba.exe
            C:\Program Files\Alwil Software\Avast4\ashDisp.exe
            C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe
            C:\Windows\WindowsMobile\wmdc.exe
            C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
            C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Program Files\Yahoo Messenger\Messenger\ymsgr_tray.exe
            C:\PROGRA~1\INCRED~1\bin\IMApp.exe
            C:\Windows\System32\mobsync.exe
            C:\Windows\system32\wbem\unsecapp.exe
            C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\PROGRA~1\INCRED~1\bin\ImNotfy.exe
            C:\Windows\system32\conime.exe
            C:\Program Files\MSN Messenger\msnmsgr.exe
            C:\Hijakthis\HiJackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            O1 - Hosts: ::1 localhost
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
            O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
            O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
            O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [TOSHIBA Volume Indicator] "C:\Program Files\Toshiba\Utilities\VolControl.exe"
            O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
            O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
            O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [TerraTec Remote Control] "C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe"
            O4 - HKLM\..\Run: [ImInstaller_IncrediMail] C:\Users\marc\AppData\Local\Temp\ImInstaller\IncrediMail\IncrediMail_Install.exe -startup -product IncrediMail -skip_dialog info -skip_dialog language
            O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdc.exe
            O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
            O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [zzz_ImInstaller_IncrediMail] C:\Users\marc\AppData\Local\Temp\ImInstaller\IncrediMail\IncrediMail_Install.exe -startup -product IncrediMail -skip_dialog info -skip_dialog language
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
            O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
            O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo Messenger\Messenger\YahooMessenger.exe" -quiet
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
            O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
            O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
            O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
            O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
            O13 - Gopher Prefix:
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
            O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
            O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
            O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
            O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
            0
            1. J'ai toujours des fenêtres non désiées qui s'ouvrent.

              En allant sur le site ANPE.fr par exemple, il m'ouvre une fenêtre.... pour "Cadre-online.com".... c'est franchement gonflant!!
              0
              1. Bonjour,

                Mon problème persiste toujours, et non seulement il persiste..... mais j'ai l'impression que c'est pire qu'avant!!!

                Les fenêtres diverses me paraissent s'ouvrir de plus en plus vite (intervalle entre 2 ouverture de fenêtres), au premier plan, et en prenant toute la largeur de l'écran.
                Auparavant, cela se limitait à un nouvel onglet dans IE7...

                Que me cnseillez vous??
                D'avance merci
                0
                1. Search Navipromo Vista Beta 1 commencé le 25/08/2007 à 11:11:11,26

                  !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                  !!! Poster ce rapport sur le forum pour le faire analyser !!!
                  !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

                  Fix lancé depuis C:\Users\marc\Desktop\Navilog1VistaBeta
                  Mise a jour le 08.08.2007 a 18h00 by IL-MAFIOSO

                  Executé en mode normal

                  *** Recherche Programmes installes ***

                  *** Recherche dossiers dans C:\Windows ***

                  *** Recherche dossiers dans C:\Program Files ***

                  *** Recherche dossiers dans C:\ProgramData ***

                  *** Recherche dossiers dans C:\Users\marc\AppData\Roaming ***

                  *** Recherche fichiers ***

                  C:\Windows\pack.epk trouvé !
                  C:\Windows\system32\nvs2.inf trouvé !

                  *** Recherche cles registre ***

                  Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]

                  Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]

                  Recherche Clé Magic Control

                  HKEY_CURRENT_USER\Software\Lanconfig trouvé !

                  *** Module de Recherche complémentaire ***
                  (Recherche fichiers spécifiques)

                  1)Recherche fichiers connus:

                  2)Recherche Heuristique :
                  *
                  **
                  ***
                  ****
                  *****
                  ******
                  *******
                  ********

                  *
                  C:\Users\marc\AppData\Local\Microsoft\hbcwqkehbu.dat trouvé !
                  **
                  C:\Users\marc\AppData\Local\Microsoft\hbcwqkehbu.dat trouvé !
                  ***
                  ****
                  C:\Users\marc\AppData\Local\Microsoft\hbcwqkehbu_navps.dat trouvé !
                  *****
                  ******
                  *******
                  ********

                  3)Recherche Certificats :

                  *** Recherche avec GenericNaviSearch Beta ***
                  !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
                  !!! A verifier impérativement avant toute suppression manuelle !!!

                  Fichiers trouvés :

                  C:\Windows\system32\hbcwqkehbu.exe trouvé !
                  C:\Users\marc\AppData\Local\Microsoft\hbcwqkehbu.exe trouvé !

                  Fichiers suspects :

                  Aucun Fichier suspect trouvé !

                  *** Analyse Terminé le 25/08/2007 à 11:12:01,07 ***
                  0
                  1. J'avais effectivement installé webmédiaplayer (et viré quelques jours plus tard, car il ne répondait pas tout à fait à mes attentes).

                    Tout ce qui ressemblait à hbcwqkehbu (quelle que soit l'extension) a été viré, ainsi que Pack.epk et nvs2.inf.

                    J'ai repassé Navilog, et voici le résultat....

                    Search Navipromo Vista Beta 1 commencé le 25/08/2007 à 14:07:48,86

                    !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                    !!! Poster ce rapport sur le forum pour le faire analyser !!!
                    !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

                    Fix lancé depuis C:\Users\marc\Desktop\Navilog1VistaBeta
                    Mise a jour le 08.08.2007 a 18h00 by IL-MAFIOSO

                    Executé en mode normal

                    *** Recherche Programmes installes ***

                    *** Recherche dossiers dans C:\Windows ***

                    *** Recherche dossiers dans C:\Program Files ***

                    *** Recherche dossiers dans C:\ProgramData ***

                    *** Recherche dossiers dans C:\Users\marc\AppData\Roaming ***

                    *** Recherche fichiers ***

                    *** Recherche cles registre ***

                    Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]

                    Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]

                    Recherche Clé Magic Control

                    HKEY_CURRENT_USER\Software\Lanconfig trouvé !

                    *** Module de Recherche complémentaire ***
                    (Recherche fichiers spécifiques)

                    1)Recherche fichiers connus:

                    2)Recherche Heuristique :
                    *
                    **
                    ***
                    ****
                    *****
                    ******
                    *******
                    ********

                    *
                    **
                    ***
                    ****
                    *****
                    ******
                    *******
                    ********

                    3)Recherche Certificats :

                    *** Recherche avec GenericNaviSearch Beta ***
                    !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
                    !!! A verifier impérativement avant toute suppression manuelle !!!

                    Fichiers trouvés :

                    Aucun Fichier trouvé !

                    Fichiers suspects :

                    Aucun Fichier suspect trouvé !

                    *** Analyse Terminé le 25/08/2007 à 14:09:31,18 ***
                    0
                    1. Merci pour ton aide!!

                      depuis quelques minutes, c'est apparemment terminé!

                      Y a t-il quelque chose à faire (ou à installer) pour être certain que cela ne revienne plus?

                      J'avais tout de même ces publicités en étant en "mode protégé" de Vista, avec le bloqueur de fenêtres intempestives d'IE7 coché et l'antivirus Avast à jour!!
                      0
                      1. Il n'y a qu'à demander! ;-)

                        Voici le résultat:

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 15:52:18, on 25/08/2007
                        Platform: Windows Vista (WinNT 6.00.1904)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16512)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
                        C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
                        C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        C:\Program Files\TOSHIBA\Utilities\VolControl.exe
                        C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                        C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
                        C:\Program Files\Synaptics\SynTP\SynToshiba.exe
                        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                        C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe
                        C:\Windows\WindowsMobile\wmdc.exe
                        C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                        C:\Windows\system32\wbem\unsecapp.exe
                        C:\Program Files\Yahoo Messenger\Messenger\ymsgr_tray.exe
                        C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Windows\system32\conime.exe
                        C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\MSN Messenger\msnmsgr.exe
                        C:\Hijakthis\HiJackThis\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                        O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                        O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                        O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        O4 - HKLM\..\Run: [TOSHIBA Volume Indicator] "C:\Program Files\Toshiba\Utilities\VolControl.exe"
                        O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                        O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [TerraTec Remote Control] "C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe"
                        O4 - HKLM\..\Run: [ImInstaller_IncrediMail] C:\Users\marc\AppData\Local\Temp\ImInstaller\IncrediMail\IncrediMail_Install.exe -startup -product IncrediMail -skip_dialog info -skip_dialog language
                        O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdc.exe
                        O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
                        O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
                        O4 - HKLM\..\Run: [hbcwqkehbu] c:\users\marc\appdata\local\microsoft\hbcwqkehbu.exe hbcwqkehbu
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                        O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                        O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo Messenger\Messenger\YahooMessenger.exe" -quiet
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                        O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                        O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                        O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
                        O13 - Gopher Prefix:
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                        O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                        O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                        O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                        O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                        O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                        0
                        1. problemes spywares sous vista#dernier
                          1/ Télécharge et installe CCleaner

                          http://www.clubic.com/lancer-le-telechargement-20932-0-ccleaner-crap-cleaner-.html

                          2/ Redémarre en mode sans échec (Pour cela : démarrer le PC en tapotant sur la touche F8 du clavier jusqu'à ce que le menu des options avancées de Windows apparaisse puis avec les touches fléchées du clavier, sélectionner Mode sans échec puis appuyer sur la touche Entrée...)
                          Attention tu n'as pas accès à Internet dans ce mode donc note ou imprime les consignes qui suivent.

                          3/ Lance HijackThis
                          puis --> Do a system scan only
                          coche les lignes indiquées ci-dessous
                          puis --> Fix checked
                          puis oui à la question de confirmation

                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                          O9 - Extra button: eBay - {C08CAF1D-C0A3-40D5-9970-06D067EAC017} - http://www.webtip.ch/cgi-bin/toshiba/tracker_url.pl?FR (file missing)
                          O13 - Gopher Prefix:
                          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                          O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab

                          4/ Assure-toi que tu as accès aux fichiers cachés.
                          (Démarrer->Poste de travail->Outils->Options des dossiers...->Affichage
                          "Afficher les fichiers et dossiers cachés" ->coché
                          "Masquer les extensions des fichiers dont le type est connu" ->décoché)

                          5/ ensuite supprime les fichiers et/ou dossiers suivants si présents :
                          6/ Lance CCleaner puis bouton Analyse ensuite Bouton Lancer le Nettoyage
                          7/ Redémarre normalement et poste un nouveau rapport HijackThis.

                          as-tu encore des dysfonctionnements ?

                          Installe un pare feu
                          Zone Alarme
                          zonealarm
                          Tu désactiveras cela de windaube
                          0
                          1. Petite question subsidiaire....

                            Comment arrives-t-on au Poste de travail sous Vista??
                            Je m'y prend peut-être mal, mais je n'ai pas ce choix dans le menu "Démarrer"!!

                            En 5/ .... Que faut-il supprimer?
                            0
                            1. Le Poste de Travail se nomme Ordinateur sous Vista :
                              Démarrer > tu trouves Ordinateur dans la colonne de droite.
                              Pour le mettre sur le Bureau : clic-droit sur Ordinateur dans le menu démarrer, et cocher "Afficher sur le Bureau".
                              0
                              1. Désolé, je suis doit être aveugle, mais je ne trouve pas où agir pour afficher les fichiers cachés!

                                Les lignes en 3/ sont virées
                                Je ne sais pas si il y a une relation Cause/Effet..... mais j'ai dû réinitialiser la Livebox pour me connecter, après avoir viré ces fichiers.

                                Ccleaner a nettoyé quasiment 20Mo de fichiers...

                                et voici le dernier test:

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 18:36:43, on 25/08/2007
                                Platform: Windows Vista (WinNT 6.00.1904)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16512)
                                Boot mode: Normal

                                Running processes:
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\Explorer.EXE
                                C:\Program Files\Windows Defender\MSASCui.exe
                                C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
                                C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
                                C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                C:\Program Files\TOSHIBA\Utilities\VolControl.exe
                                C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                                C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
                                C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe
                                C:\Windows\WindowsMobile\wmdc.exe
                                C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
                                C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                C:\Program Files\Windows Sidebar\sidebar.exe
                                C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
                                C:\Program Files\Synaptics\SynTP\SynToshiba.exe
                                C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                                C:\Windows\System32\rundll32.exe
                                C:\Program Files\Windows Sidebar\sidebar.exe
                                C:\Windows\system32\wbem\unsecapp.exe
                                C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
                                C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Program Files\MSN Messenger\msnmsgr.exe
                                C:\Program Files\Yahoo Messenger\Messenger\YahooMessenger.exe
                                C:\Hijakthis\HiJackThis\HijackThis.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                O1 - Hosts: ::1 localhost
                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                                O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                                O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                                O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                O4 - HKLM\..\Run: [TOSHIBA Volume Indicator] "C:\Program Files\Toshiba\Utilities\VolControl.exe"
                                O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                                O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                                O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                O4 - HKLM\..\Run: [TerraTec Remote Control] "C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe"
                                O4 - HKLM\..\Run: [ImInstaller_IncrediMail] C:\Users\marc\AppData\Local\Temp\ImInstaller\IncrediMail\IncrediMail_Install.exe -startup -product IncrediMail -skip_dialog info -skip_dialog language
                                O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdc.exe
                                O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
                                O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
                                O4 - HKLM\..\Run: [hbcwqkehbu] c:\users\marc\appdata\local\microsoft\hbcwqkehbu.exe hbcwqkehbu
                                O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                                O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                                O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo Messenger\Messenger\YahooMessenger.exe" -quiet
                                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                                O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                                O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                                O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                                O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                                O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                                O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                                O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
                                O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                0
                                1. Afficher les dossiers cachés
                                  Démarrer > Panneau de configuration > Affichage classique > Options des dossiers > Affichage (paramètres avancés)
                                  0
                                  1. ok merci.

                                    C'est ok pour les fichiers systèmes ( et cachés), ils sont visibles.

                                    J'ai repassé Ccleaner en mode sans echec. 54Mo éffacés et éffacé les erreurs système qu'il a trouvé. Il y avait pas mal de Dll manquantes

                                    J'ai toujours ce problème de rapidité pour ouvrir IE et charger les pages voulues.

                                    Ci dessous, le Hijackthis après avoir fait tout ca.

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 21:16:17, on 25/08/2007
                                    Platform: Windows Vista (WinNT 6.00.1904)
                                    MSIE: Internet Explorer v7.00 (7.00.6000.16512)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\Windows\system32\taskeng.exe
                                    C:\Windows\system32\Dwm.exe
                                    C:\Windows\Explorer.EXE
                                    C:\Program Files\Windows Defender\MSASCui.exe
                                    C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
                                    C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
                                    C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                    C:\Program Files\TOSHIBA\Utilities\VolControl.exe
                                    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                                    C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
                                    C:\Program Files\Synaptics\SynTP\SynToshiba.exe
                                    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                    C:\Windows\System32\rundll32.exe
                                    C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe
                                    C:\Windows\WindowsMobile\wmdc.exe
                                    C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
                                    C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
                                    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                    C:\Program Files\Windows Sidebar\sidebar.exe
                                    C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                                    C:\Program Files\Yahoo Messenger\Messenger\ymsgr_tray.exe
                                    C:\Program Files\Windows Sidebar\sidebar.exe
                                    C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                                    C:\Windows\system32\wbem\unsecapp.exe
                                    C:\Hijakthis\HiJackThis\HijackThis.exe
                                    C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe

                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                    O1 - Hosts: ::1 localhost
                                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                    O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                                    O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                                    O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                                    O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                    O4 - HKLM\..\Run: [TOSHIBA Volume Indicator] "C:\Program Files\Toshiba\Utilities\VolControl.exe"
                                    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                                    O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                                    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKLM\..\Run: [TerraTec Remote Control] "C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe"
                                    O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdc.exe
                                    O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
                                    O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
                                    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                                    O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                                    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo Messenger\Messenger\YahooMessenger.exe" -quiet
                                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
                                    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                                    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                                    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                    O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                                    O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                                    O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                                    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                                    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
                                    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                    0
                                    • 1
                                    • 2