Vrus?? trojan??

Résolu
Bonjour, mon ordinateur est vraiment ralentit ces derniers temps , j'ai effectué un full scan avec kaspersky et spybot et je n'ai rien trouvé!! Je dois vraiment patienter longtemps pour l'affichage des pages sur internet ou les videos , alors que c'était immédiat il y a quelques jours!! merçi de votre aide :))
Configuration: Windows Vista
Firefox 2.0.0.10

23 réponses

  1. Bonjour

    Pour Vista, il faut cette version de HijackThis :la 2.0.2
    https://www.pcastuces.com/logitheque/hijackthis.htm
    Veille à ce que le contrôle des comptes utilisateurs (UAC) soit désactivé.
    Clic droit sur l'icône de HJT
    L'exécuter en tant qu'administrateur

    Dézippe le dans un dossier prévu à cet effet.
    Par exemple C:\hijackthis < Enregistre le bien dans c : !
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/Hijenr.gif
    http://pageperso.aol.fr/balltrap34/Hijenr.gif
    Lance le puis:
    Clique sur "do a system scan and save logfile" (cf démo)
    Faire un copier coller du log entier sur le forum
    Démo : (Merci a Balltrap34 pour cette réalisation)
    http://pageperso.aol.fr/balltrap34/demohijack.htmhttp://pageperso.aol.fr/balltrap34/demohijack.htm
    http://www.tutoriaux-excalibur.com/hijackthis.htmhttp://www.tutoriaux-excalibur.com/hijackthis.htm

    0
    1. Salut merçi pour la réponse :)) voici le logLogfile of Trend Micro HijackThis v2.0.2
      Scan saved at 17:51:28, on 02/12/2007
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16546)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\DellTPad\Apoint.exe
      C:\Windows\OEM02Mon.exe
      C:\Program Files\Java\jre1.6.0\bin\jusched.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
      C:\Windows\ehome\ehtray.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\Digital Line Detect\DLG.exe
      C:\Program Files\Dell\QuickSet\quickset.exe
      C:\Program Files\DellTPad\ApMsgFwd.exe
      C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\DellTPad\HidFind.exe
      C:\Program Files\DellTPad\Apntex.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\System32\mobsync.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Windows\system32\Taskmgr.exe
      C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
      C:\Windows\system32\SearchFilterHost.exe
      C:\Users\Kam\Desktop\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: IeMonitorBho Class - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
      O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
      O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
      O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
      O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: QuickSet.lnk = ?
      O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
      O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
      O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
      O9 - Extra button: Casino-On-Net - {3015DB92-158E-4b77-9020-85C8E311FBB5} - C:\PROGRA~1\CASINO~1\casino.exe
      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O13 - Gopher Prefix:
      O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.euro.dell.com/systemprofiler/SysPro.CAB
      O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
      O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://casinoclassic.microgaming.com/casinoclassic/FlashAX.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
      O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll (file missing)
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
      O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
      O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
      O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      0
      1. Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

        - Va dans démarrer puis panneau de configuration
        - Double Clique sur l'icône "Comptes d'utilisateurs"
        - Clique ensuite sur désactiver et valide.

        Télécharge maintenant Navilog1 depuis-ce lien :

        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

        Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
        Ensuite double clique sur navilog1.exe pour lancer l'installation.
        Une fois l'installation terminée, Fais un Clic-droit sur le raccourci Navilog1 présent sur ton bureau et choisis
        "Exécuter en tant qu'administrateur".

        Au menu principal, Fais le choix 1
        Laisse toi guider et patiente.
        Patiente jusqu'au message :
        *** Analyse Termine le ..... ***
        Appuie sur une touche le blocnote va s'ouvrir.
        Copie-colle l'intégralité du rapport dans une réponse.
        Referme le blocnote
        Le rapport fixnavi.txt est en outre sauvegardé dans %systemdrive%.

        Bon courage
        A++
        0
        1. Ok merçi ! n'avais je pas desactivé l'UAC? en allant dans comptes utilistateurs je pouvais uniquement cocher la case pour activer le controle..
          Voici le rapport :

          Search Navipromo version 3.3.6 commencé le 02/12/2007 à 18:25:10,44

          Outil exécuté depuis C:\Program Files\navilog1
          Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO

          Microsoft Windows Vista 6.0.6000
          Internet Explorer : 7.0.6000.16546

          *** Recherche Programmes installés ***

          *** Recherche dossiers dans C:\Windows ***

          *** Recherche dossiers dans C:\Program Files ***

          *** Recherche dossiers dans C:\ProgramData ***

          *** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***

          *** Recherche dossiers dans C:\USERS\KAM\APPDATA\ROAMING\MICROS~1\WINDOWS\STARTM~1\PROGRAMS ***

          *** Recherche dossiers dans C:\Users\Kam\AppData\Local\virtualstore\Program Files ***

          *** Recherche dossiers dans C:\Users\Kam\AppData\Roaming ***

          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
          pour + d'infos : http://www.gmer.net

          Aucun fichier trouvé dans :

          - C:\Users\Kam\AppData\Local\Microsoft
          - C:\Users\Kam\AppData\Local\virtualstore\windows\system32
          - C:\Users\Kam\AppData\Local

          *** Recherche avec GenericNaviSearch ***
          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
          !!! A vérifier impérativement avant toute suppression manuelle !!!

          * Recherche dans C:\Windows\system32 *

          * Recherche dans C:\Users\Kam\AppData\Local\Microsoft *

          * Recherche dans C:\Users\Kam\AppData\Local\virtualstore\windows\system32 *

          * Recherche dans C:\Users\Kam\AppData\Local *

          *** Recherche fichiers ***

          *** Recherche clés spécifiques dans le Registre ***

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche fichiers connus:

          2)Recherche Heuristique :

          3)Recherche Certificats :

          Certificat Egroup absent !

          *** Analyse terminée le 02/12/2007 à 18:26:17,31 ***
          0
          1. Re

            Télécharge sur ton bureau : http://www.malekal.com/download/clean.zip
            Tuto
            http://mickael.barroux.free.fr/securite/clean.php
            Une fois sur le bureau, tu fais un clic droit sur ton fichier clean.zip et dans le menu déroulant, tu clics sur extrait tout ou extraire ici.
            Cela va créer un dossier clean.
            Double-clic sur ce dossier clean, tu y trouveras dedans plusieurs fichiers.
            Double-clic sur clean. Cela va ouvrir une fenêtre noire.
            Un menu va apparaître, choisis l'option 1 en appuyant sur la touche 1 de ton clavier.
            Clean va travailler.
            Un rapport Va etre généré, colle le contenu entier ici.

            (- Où est le rapport clean ? : « Poste de travail » / double clic sur disque « C / » double-clic sur « rapport_clean.txt » et « copier/coller le contenu » sur le forum. )

            Télécharge SmitfraudFix
            Utilitaire de S!Ri: Moe et balltrap34
            http://siri.urz.free.fr/Fix/SmitfraudFix.php
            et télécharge SmitfraudFix.exe.

            Regarde le tuto

            Exécute le en choisissant l’option 1,
            il va générer un rapport
            Copie/colle le sur le poste stp.

            Bon courage
            A++

            0
            1. J'ai remarqué un truc, c'est qu'il y a plein de "RUNDLL32.EXE" qui sont en tâche en arrière-plan.
              C'est un peu louche, et c'est rarement utilisé par le système.
              Essaye de tuer ces trois processus.
              0
              1. Un peu de lecture
                http://www.commentcamarche.net/processus/rundll32 exe.php3
                0
            2. Re salut , voila le rapport clean :

              02/12/2007 a 23:51:48,22

              *** Recherche C:

              *** Recherche C:\Windows\
              C:\Windows\UnGins.exe FOUND

              *** Recherche C:\Windows\system32
              C:\Windows\system32\wininit.exe FOUND
              C:\Windows\system32\wininit.exe FOUND

              *** Recherche C:\Program Files
              *** End of the report !

              et celui de smidfraudfix :

              SmitFraudFix v2.257

              Scan done at 0:03:17,38, 03/12/2007
              Run from C:\Windows\System32\SmitfraudFix
              OS: Microsoft Windows [version 6.0.6000] - Windows_NT
              The filesystem type is NTFS
              Fix run in normal mode

              »»»»»»»»»»»»»»»»»»»»»»»» Process

              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              C:\Windows\System32\spoolsv.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\Program Files\DellTPad\Apoint.exe
              C:\Windows\OEM02Mon.exe
              C:\Program Files\Java\jre1.6.0\bin\jusched.exe
              C:\Program Files\DellTPad\ApMsgFwd.exe
              C:\Program Files\DellTPad\HidFind.exe
              C:\Windows\System32\rundll32.exe
              C:\Windows\System32\rundll32.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\Windows\System32\rundll32.exe
              C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
              C:\Windows\ehome\ehtray.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Program Files\Digital Line Detect\DLG.exe
              C:\Program Files\DellTPad\Apntex.exe
              C:\Windows\ehome\ehmsas.exe
              C:\Program Files\Dell\QuickSet\quickset.exe
              C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
              C:\Windows\system32\aestsrv.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\Program Files\Microsoft LifeCam\MSCamS32.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\STacSV.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Windows\system32\DRIVERS\xaudio.exe
              C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Windows Media Player\wmpnetwk.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Windows\System32\mobsync.exe
              C:\Windows\system32\wbem\unsecapp.exe
              C:\Program Files\Windows Live\Messenger\usnsvc.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Windows\system32\conime.exe
              C:\Windows\system32\taskeng.exe
              C:\Windows\servicing\TrustedInstaller.exe
              C:\Windows\system32\NOTEPAD.EXE
              C:\Windows\system32\cmd.exe
              C:\Windows\system32\SearchProtocolHost.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Windows\system32\SearchFilterHost.exe

              »»»»»»»»»»»»»»»»»»»»»»»» hosts

              »»»»»»»»»»»»»»»»»»»»»»»» C:\

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Kam

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Kam\Application Data

              »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Kam\FAVORI~1

              »»»»»»»»»»»»»»»»»»»»»»»» Desktop

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

              »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

              »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

              »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
              !!!Attention, following keys are not inevitably infected!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
              !!!Attention, following keys are not inevitably infected!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
              "AppInit_DLLs"="C:\\PROGRA~1\\KASPER~1\\KASPER~1.0\\r3hook.dll,C:\\PROGRA~1\\KASPER~1\\KASPER~1.0\\adialhk.dll"
              "LoadAppInit_DLLs"=dword:00000001

              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
              !!!Attention, following keys are not inevitably infected!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

              »»»»»»»»»»»»»»»»»»»»»»»» Rustock

              »»»»»»»»»»»»»»»»»»»»»»»» DNS

              Description: Intel(R) Wireless WiFi Link 4965AGN
              DNS Server Search Order: 192.168.1.1
              DNS Server Search Order: 0.0.0.0

              HKLM\SYSTEM\CCS\Services\Tcpip\..\{41EFE59C-E81A-415C-9692-EF14BD714CBE}: DhcpNameServer=192.168.1.1 0.0.0.0
              HKLM\SYSTEM\CS1\Services\Tcpip\..\{41EFE59C-E81A-415C-9692-EF14BD714CBE}: DhcpNameServer=192.168.1.1 0.0.0.0
              HKLM\SYSTEM\CS2\Services\Tcpip\..\{41EFE59C-E81A-415C-9692-EF14BD714CBE}: DhcpNameServer=192.168.1.1 0.0.0.0
              HKLM\SYSTEM\CS3\Services\Tcpip\..\{41EFE59C-E81A-415C-9692-EF14BD714CBE}: DhcpNameServer=192.168.1.1 0.0.0.0
              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
              HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
              HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

              »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

              »»»»»»»»»»»»»»»»»»»»»»»» End

              Merçi je vais voir ce que je peux faire avec ces rundll....bonne nuit :))
              0
              1. Ok

                On continue

                Redémarre ton PC en mode sans échec :
                Redémarre en mode sans échec (Pour cela : démarrer le PC en tapotant sur la touche F8 du clavier jusqu'à ce que le menu des options avancées de Windows apparaisse puis avec les touches fléchées du clavier, sélectionner Mode sans échec puis appuyer sur la touche Entrée...)
                Double-clic sur clean. Cela va ouvrir une fenêtre noire.
                Un menu va apparaître, choisis l'option 2 en appuyant sur la touche 2 de ton clavier.
                Clean va travailler.
                Un rapport Va etre généré, envoie le moi dans ta prochaine réponse !

                Démarre en mode sans échec :
                Pour cela, tu tapotes la touche F8 ((Si F8 ne marche pas utilise la touche F5)).
                dès le début de l’allumage du pc sans t’arrêter.
                Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                ----------------------------------------------------------------------------
                Relance le programme Smitfraud,
                Cette fois choisit l’option 2,
                répond oui à tous ;
                Sauvegarde le rapport,
                Redémarre en mode normal,
                Copie/colle le rapport sauvegardé sur le forum

                Un log Hijackthis dans la foulée
                0
                1. Salut marie merçi pour ta réponse (y en a qui se lèvent tot) , voila les rapports :

                  Script executed in Safe Mode
                  Rapport clean par Malekal_morte - http://www.malekal.com
                  Script executed in Safe Mode 03/12/2007 a 12:22:04,95

                  Microsoft Windows [version 6.0.6000]

                  *** Suppression C:

                  *** Suppression C:\Windows\
                  tentative de suppression de C:\Windows\UnGins.exe

                  *** Suppression C:\Windows\system32
                  tentative de suppression de C:\Windows\system32\wininit.exe
                  Impossible de supprimer C:\Windows\system32\wininit.exe
                  tentative de suppression de C:\Windows\system32\wininit.exe
                  Impossible de supprimer C:\Windows\system32\wininit.exe

                  *** Suppression C:\Program Files

                  *** Deletion of the registry keys successful..
                  *** End of the report !

                  SmitFraudFix v2.257

                  Scan done at 12:30:18,83, 03/12/2007
                  Run from C:\Users\Kam\Desktop\SmitfraudFix
                  OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                  The filesystem type is NTFS
                  Fix run in safe mode

                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                  !!!Attention, following keys are not inevitably infected!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                  127.0.0.1 localhost
                  ::1 localhost

                  »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                  S!Ri's WS2Fix: LSP not Found.

                  »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                  GenericRenosFix by S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{41EFE59C-E81A-415C-9692-EF14BD714CBE}: DhcpNameServer=192.168.1.1 0.0.0.0
                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{41EFE59C-E81A-415C-9692-EF14BD714CBE}: DhcpNameServer=192.168.1.1 0.0.0.0
                  HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                  HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

                  »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                  !!!Attention, following keys are not inevitably infected!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                  »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                  Registry Cleaning done.

                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                  !!!Attention, following keys are not inevitably infected!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» End

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 12:33:59, on 03/12/2007
                  Platform: Windows Vista (WinNT 6.00.1904)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16546)
                  Boot mode: Safe mode

                  Running processes:
                  C:\Windows\explorer.exe
                  C:\Windows\notepad.exe
                  C:\Windows\System32\mobsync.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\Windows\system32\NOTEPAD.EXE
                  C:\Windows\system32\NOTEPAD.EXE
                  C:\Users\Kam\Desktop\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: IeMonitorBho Class - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
                  O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                  O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
                  O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                  O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                  O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
                  O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
                  O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                  O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O4 - Global Startup: QuickSet.lnk = ?
                  O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                  O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                  O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
                  O9 - Extra button: Casino-On-Net - {3015DB92-158E-4b77-9020-85C8E311FBB5} - C:\PROGRA~1\CASINO~1\casino.exe
                  O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                  O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
                  O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll (file missing)
                  O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                  O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
                  O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
                  O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                  O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                  O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
                  O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                  0
                  1. re , ne trouvant pas de solution j'ai effectué une restauration systeme ce qui a résolu le problème , mais s'il s'agissait d'un malware ou autre il est toujours sur le pc n'est ce pas? merçi pour votre aide
                    0
                    1. Slt

                      Rends toi sur http://www.virustotal.com/flash/index_en.html
                      Clique sur "Parcourir..." et cherche EXACTEMENT le fichier en gras :

                      C:\Windows\OEM02Mon.exe

                      Attends que le rectangle soit vert (à droite) et clique sur "Send".

                      Une fois le scan terminé, copie/colle le rapport sur le forum.

                      0
                      1. Salut , voila le rapport ! :

                        Antivirus Version Dernière mise à jour Résultat
                        AhnLab-V3 2007.12.4.1 2007.12.04 -
                        AntiVir 7.6.0.34 2007.12.04 -
                        Authentium 4.93.8 2007.12.04 -
                        Avast 4.7.1074.0 2007.12.03 -
                        AVG 7.5.0.503 2007.12.04 -
                        BitDefender 7.2 2007.12.04 -
                        CAT-QuickHeal 9.00 2007.12.03 -
                        ClamAV 0.91.2 2007.12.04 -
                        DrWeb 4.44.0.09170 2007.12.04 -
                        eSafe 7.0.15.0 2007.12.03 -
                        eTrust-Vet 31.3.5349 2007.12.04 -
                        Ewido 4.0 2007.12.03 -
                        FileAdvisor 1 2007.12.04 -
                        Fortinet 3.14.0.0 2007.12.04 -
                        F-Prot 4.4.2.54 2007.12.04 -
                        F-Secure 6.70.13030.0 2007.12.04 -
                        Ikarus T3.1.1.12 2007.12.04 -
                        Kaspersky 7.0.0.125 2007.12.04 -
                        McAfee 5176 2007.12.03 -
                        Microsoft 1.3007 2007.12.03 -
                        NOD32v2 2699 2007.12.03 -
                        Norman 5.80.02 2007.12.03 -
                        Panda 9.0.0.4 2007.12.03 -
                        Prevx1 V2 2007.12.04 Heuristic: Suspicious Hijacker
                        Rising 20.21.10.00 2007.12.04 -
                        Sophos 4.24.0 2007.12.04 -
                        Sunbelt 2.2.907.0 2007.12.01 -
                        Symantec 10 2007.12.04 -
                        TheHacker 6.2.9.148 2007.12.03 -
                        VBA32 3.12.2.5 2007.12.03 -
                        VirusBuster 4.3.26:9 2007.12.03 -
                        Webwasher-Gateway 6.0.1 2007.12.04 -
                        Information additionnelle
                        File size: 36864 bytes
                        MD5: 23242fd6c7d4c61807e84fd3a79248c4
                        SHA1: 3214ff50dc3f98ba8fcebcdc8854f770e8ea0bbe
                        PEiD: -
                        Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PX5=FD17F7CC0030E108906400A182BC7F00DB9CE8D1
                        0
                        1. Refais un log Hijackthis
                          Stp

                          Quels sont les symptômes de ton pc?
                          0
                          1. Hé bin c'est assez bizarre , mon pc était ralentit uniquement pour le streaming ! je devais attendre quasiment 1 a 2minute pour n'importe quelle video ou musique..l'affichage des pages était toujours rapide , les tests de bande passante aussi , j'ai fait une restauration systeme et c'est rentré dans l'orde! mais je ne sais vraiment pas a cause de quoi mon pc était ralentit..et surtout uniquement pour le streaming..
                            voici le log :
                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 13:07:19, on 04/12/2007
                            Platform: Windows Vista (WinNT 6.00.1904)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16546)
                            Boot mode: Normal

                            Running processes:
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\Explorer.EXE
                            C:\Windows\system32\taskeng.exe
                            C:\Program Files\Windows Defender\MSASCui.exe
                            C:\Program Files\DellTPad\Apoint.exe
                            C:\Windows\OEM02Mon.exe
                            C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                            C:\Windows\System32\rundll32.exe
                            C:\Program Files\DellTPad\ApMsgFwd.exe
                            C:\Windows\System32\rundll32.exe
                            C:\Windows\System32\rundll32.exe
                            C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                            C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
                            C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                            C:\Windows\ehome\ehtray.exe
                            C:\Program Files\DellTPad\HidFind.exe
                            C:\Program Files\Windows Media Player\wmpnscfg.exe
                            C:\Program Files\DellTPad\Apntex.exe
                            C:\Windows\ehome\ehmsas.exe
                            C:\Program Files\Digital Line Detect\DLG.exe
                            C:\Program Files\Dell\QuickSet\quickset.exe
                            C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                            C:\Windows\System32\mobsync.exe
                            C:\Program Files\Mozilla Firefox\firefox.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                            O1 - Hosts: ::1 localhost
                            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                            O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
                            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                            O2 - BHO: IeMonitorBho Class - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
                            O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                            O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
                            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                            O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
                            O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                            O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                            O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
                            O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                            O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
                            O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
                            O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
                            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                            O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                            O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                            O4 - Global Startup: QuickSet.lnk = ?
                            O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                            O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                            O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
                            O9 - Extra button: Casino-On-Net - {3015DB92-158E-4b77-9020-85C8E311FBB5} - C:\PROGRA~1\CASINO~1\casino.exe
                            O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                            O13 - Gopher Prefix:
                            O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.euro.dell.com/systemprofiler/SysPro.CAB
                            O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
                            O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                            O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
                            O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll (file missing)
                            O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
                            O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
                            O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                            O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                            O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                            O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                            O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
                            O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                            O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                            0
                            1. Mets ta console Java à jour en cliquant sur ce lien
                              N'oublie pas de supprimer les versions obsolètes (ajout/supp)
                              https://www.java.com/fr/download/manual.jsp

                              Casino-On-Net ► tu joues en ligne ???

                              Fais tout ce qui suit dans l' ordre ...

                              (si ce n’ est déjà fait) Télécharge et installe CCleaner :
                              https://forums.cnetfrance.fr
                              Sur le site, clique sur > Download latest version et laisse-toi guider.
                              Ne coche pas "Ajouter la barre d' outils Yahoo".
                              Laisse-le s’ installer tel que …

                              Télécharge OTMoveIt (de Old_Timer) sur ton bureau...
                              http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

                              Redémarre le PC en mode sans échec :
                              http://forum.telecharger.01net.com/forum/
                              (méthode F8 de préférence)

                              --------------------------------------------
                              Tu n' auras pas accès à Internet pendant le "mode sans échec".
                              Aussi, copie/colle la procédure dans un fichier texte (word) et mets-la sur le
                              "bureau" pour l' avoir à ta disposition.
                              --------------------------------------------

                              Ferme toutes les fenêtres et applications.
                              Relance HijackThis et clique sur > Do a system scan only puis, coche les
                              cases devant les lignes qui suivent (et uniquement ces lignes), si tjrs présentes :

                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                              O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" –start
                              O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                              O4 - Global Startup: QuickSet.lnk = ?
                              O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                              O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll (file missing)

                              Puis, clique sur > Fix checked et valide par « Yes ». Referme HijackThis.

                              Double-clique sur OTMoveIt.exe pour le lancer.
                              Assure toi que la case "Unregister Dll's and Ocx's" soit bien cochée !!!
                              Copie le texte qui se trouve dans l'encadré ci-dessous et colle-le dans le cadre
                              de gauche de OTMoveIt nommé Paste List of Files/Folders to be moved.

                              C:\Windows\OEM02Mon.exe


                              Clique sur MoveIt! pour lancer la suppression.
                              Lorsque un résultat apparaît dans le cadre Results, clique sur Exit.
                              Redémarre ton PC.
                              Copie-colle le rapport dans ta réponse :
                              Il est situé sur --> C:\_OTMoveIt\MovedFiles.

                              Lance CCleaner ...
                              Clique sur > Analyse > Lancer le nettoyage, puis sur OK dans la fenêtre qui s' affiche.
                              (re)Lance le nettoyage et (re)confirme par OK.

                              A++
                              0
                              1. Voila le rapport : C:\Windows\OEM02Mon.exe moved successfully.

                                Created on 12/04/2007 15:26:59

                                si il est possible d'avoir ton avis sur ce qui a pu se passer ce serait cool ! :))
                                en tout cas merçi pour ton aide c'est tres gentil !!
                                (et oui le casino c'est normal)
                                0
                                1. Suppression des véroles que tu avais avec les Fix que je t'ai fait passer

                                  Comment se comporte ton PC ??

                                  0
                                  1. Tout est rentré dans l'ordre c'est nickel !! merçi beaucoup :))
                                    0
                                    1. Supprime TOUT les logiciels que je t'ai fait installer
                                      Pour compléter leur suppression
                                      · Télécharge ToolsCleaner de A.Roshtein sur ton Bureau.
                                      http://pagesperso-orange.fr/AceRothstein/ToolsCleaner2.exe
                                      · Clique sur Recherche et laisse le scan se terminer.
                                      · Clique, sur Suppression pour finaliser.
                                      · Tu peux, si tu le souhaites, te servir des Options facultatives.
                                      · Clique sur Quitter, pour que le rapport puisse se créer.
                                      · Poste moi le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur( C:\).
                                      0
                                      1. merçi encore

                                        C:\_OtMoveIt: trouvé !
                                        C:\Program Files\Navilog1: trouvé !
                                        C:\Program Files\Trend Micro\HijackThis: trouvé !
                                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
                                        C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
                                        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
                                        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
                                        C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
                                        C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
                                        C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
                                        C:\Users\Kam\AppData\Roaming\Microsoft\Windows\Recent\HijackThis.lnk: trouvé !
                                        C:\Users\Kam\Desktop\HijackThis.lnk: trouvé !
                                        C:\Users\Kam\Desktop\OtMoveIt.exe: trouvé !
                                        C:\Users\Kam\Desktop\HJTInstall.exe: trouvé !
                                        C:\Users\Kam\Desktop\Clean: trouvé !
                                        C:\Users\Kam\Desktop\clean\Clean: trouvé !

                                        ---------------------------------
                                        -->- Suppression:

                                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
                                        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
                                        C:\Users\Kam\AppData\Roaming\Microsoft\Windows\Recent\HijackThis.lnk: supprimé !
                                        C:\Users\Kam\Desktop\HijackThis.lnk: supprimé !
                                        C:\Users\Kam\Desktop\OtMoveIt.exe: supprimé !
                                        C:\Users\Kam\Desktop\HJTInstall.exe: supprimé !
                                        C:\_OtMoveIt: supprimé !
                                        C:\Program Files\Navilog1: supprimé !
                                        C:\Program Files\Trend Micro\HijackThis: supprimé !
                                        C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: Erreur de suppression !
                                        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !
                                        C:\Users\Kam\Desktop\Clean: supprimé !
                                        0
                                        • 1
                                        • 2