Troyan probable! Unclassified.ActiveX.Trojan.

Résolu
Bonjour,
Afin de visionner une vidéo en ligne j'ai voulu installer un codec activ X. Seulement le fichier (setup.exe) etait un virus ou un trojan, enfin je sais pas trop.

Quelques recherches sur internet (pas facile en raison de ce probleme) me laisse suposer qu'il s'agit de Unclassified.ActiveX.Trojan.A, mais c loin d'etre sur.

Les symptomes: A chaque action que je fais sur mon pc une fenetre d'erreur s'ouvre:
System error!
your computer was infected by unknown troyan.
It's dangerous for your system (critical files can be lost)!
Click OK to download the antispyware program to clean your systm! (Recommended)

En cliquant plusieur fois sur annuler elle se ferme, en cliquant sur ok il me repropose de telecharger un fichier "setup.exe"

Bref, avast ne detecte rien, spybot non plus, spy doctor detecte 250 trucs avant de me demander de payer, et je suis sur le point d'essayer counterspy.

Pouvez-vous m'aider?
Je vous remercie d'avance
Ambre
Configuration: Windows XP
Internet Explorer 7.0

16 réponses

  1. Spy doctor est héllas payant
    0
    1. salut

      Télécharge ceci: (merci a S!RI pour ce programme).
      http://siri.urz.free.fr/Fix/SmitfraudFix.zip
      ou
      http://siri.urz.free.fr/Fix/SmitfraudFix.php
      Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1, il va générer un rapport
      Copie/colle le sur le poste stp.
      ----------------------------------------------------------------------------
      Démarre en mode sans échec :
      Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
      Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
      Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
      (Si F8 ne marche pas utilise la touche F5).
      ----------------------------------------------------------------------------
      Relance le programme Smitfraud,
      Cette fois choisit l’option 2, répond oui a tous ;
      Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

      et fait cela aussi

      Clique sur ce lien
      http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
      pour télécharger le fichier d'installation d'HijackThis.

      Enregistre HJTInstall.exe sur ton bureau.

      Double-clique sur HJTInstall.exe pour lancer le programme

      Par défaut, il s'installera là :
      C:\Program Files\Trend Micro\HijackThis

      Accepte la license en cliquant sur le bouton "I Accept"

      Choisis l'option "Do a system scan and save a log file"

      Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note

      Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

      Colle le rapport que tu viens de copier sur ce forum

      Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement

      Tutoriaux : http://pageperso.aol.fr/balltrap34/demohijack.htm (ne fixe rien pour le moment !!)
      http://cybersecurite.xooit.com/t138-HijackThis-2-0-2.htm

      a+
      0
      1. smitfraud 1er rapport:

        SmitFraudFix v2.287

        Rapport fait à 5:48:28,31, 11/02/2008
        Executé à partir de C:\Documents and

        Settings\Amber\Bureau\SmitfraudFix\SmitfraudFix
        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
        Le type du système de fichiers est NTFS
        Fix executé en mode normal

        »»»»»»»»»»»»»»»»»»»»»»»» Process

        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\WLTRYSVC.EXE
        C:\WINDOWS\System32\bcmwltry.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Fichiers communs\Apple\Mobile Device

        Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\hkcmd.exe
        C:\WINDOWS\system32\igfxpers.exe
        C:\WINDOWS\system32\igfxsrvc.exe
        C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
        C:\WINDOWS\stsystra.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Dell\QuickSet\quickset.exe
        C:\Program Files\Creative\Mixer\CTSVolFE.exe
        C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
        C:\Program Files\Fichiers communs\Roxio

        Shared\9.0\SharedCOM\RoxWatchTray9.exe
        C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
        C:\Program Files\Dell\MediaDirect\PCMService.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\NetWaiting\netWaiting.exe
        C:\Program Files\DellSupport\DSAgnt.exe
        C:\WINDOWS\WebCam\M1000\M1000Mnt.exe
        C:\WINDOWS\System32\alg.exe
        C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
        C:\Program Files\Digital Line Detect\DLG.exe
        C:\Program Files\SetPoint\SetPoint.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe
        C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
        C:\Program Files\iPod\bin\iPodService.exe
        C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
        C:\Program Files\Fichiers communs\Roxio

        Shared\9.0\SharedCOM\CPSHelpRunner.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\Program Files\MSN Messenger\usnsvc.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\Spyware Doctor\pctsAuxs.exe
        C:\Program Files\Spyware Doctor\pctsSvc.exe
        C:\Program Files\Spyware Doctor\pctsTray.exe
        C:\Program Files\Sunbelt Software\CounterSpy\CounterSpy.exe
        C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
        C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Program Files\WinRAR\WinRAR.exe
        C:\WINDOWS\system32\cmd.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe

        »»»»»»»»»»»»»»»»»»»»»»»» hosts

        »»»»»»»»»»»»»»»»»»»»»»»» C:\

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Amber

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Amber\Application Data

        »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

        »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Amber\Favoris

        »»»»»»»»»»»»»»»»»»»»»»»» Bureau

        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

        »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

        »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

        [HKEY_CURRENT_USER\Software\Microsoft\Internet

        Explorer\Desktop\Components\0]
        "Source"="About:Home"
        "SubscribedURL"="About:Home"
        "FriendlyName"="Ma page d'accueil"

        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        IEDFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri
        +--------------------------------------------------+
        [!] Suspicious: sysvol32.dll
        BHO: Sysem Player - {D70E28A7-AA79-4D62-A59F-87024840BB62}
        CLSID: {D70E28A7-AA79-4D62-A59F-87024840BB62}
        AppID: {D70E28A7-AA79-4D62-A59F-87024840BB62}
        AppID: sysvol32.dll
        Classes: sysvol32.Video
        TypeLib: {74D46BBA-5638-473A-83B6-97E7804A7411}
        Interface: {48D78BE5-CFB9-4B66-9AC4-96D4CF21DE06}

        »»»»»»»»»»»»»»»»»»»»»»»» VACFix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        VACFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
        "AppInit_DLLs"=""
        "LoadAppInit_DLLs"=dword:00000001

        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
        "System"=""

        »»»»»»»»»»»»»»»»»»»»»»»» Rustock

        pe386 détecté, utilisez un scanner de Rootkit
        lzx32 détecté, utilisez un scanner de Rootkit

        »»»»»»»»»»»»»»»»»»»»»»»» DNS

        Description: Carte Mini Dell Wireless 1390 - Miniport d'ordonnancement de

        paquets
        DNS Server Search Order: 192.168.1.1

        HKLM\SYSTEM\CCS\Services\Tcpip\..\{3D6F5600-A36B-4787-AFF6-FD733CD2DD72}:

        NameServer=192.168.1.1
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{3D6F5600-A36B-4787-AFF6-FD733CD2DD72}:

        NameServer=192.168.1.1
        HKLM\SYSTEM\CS3\Services\Tcpip\..\{3D6F5600-A36B-4787-AFF6-FD733CD2DD72}:

        NameServer=192.168.1.1

        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

        »»»»»»»»»»»»»»»»»»»»»»»» Fin

        smitfraud 2eme rapport (mode sans echec):

        SmitFraudFix v2.287

        Rapport fait à 5:58:55,15, 11/02/2008
        Executé à partir de C:\Documents and

        Settings\Amber\Bureau\SmitfraudFix\SmitfraudFix
        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
        Le type du système de fichiers est NTFS
        Fix executé en mode sans echec

        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

        »»»»»»»»»»»»»»»»»»»»»»»» hosts

        127.0.0.1 localhost

        »»»»»»»»»»»»»»»»»»»»»»»» VACFix

        VACFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

        S!Ri's WS2Fix: LSP not Found.
        »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

        GenericRenosFix by S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

        IEDFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri
        C:\WINDOWS\sysvol32.dll deleted.

        »»»»»»»»»»»»»»»»»»»»»»»» DNS

        HKLM\SYSTEM\CCS\Services\Tcpip\..\{3D6F5600-A36B-4787-AFF6-FD733CD2DD72}:

        NameServer=192.168.1.1
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{3D6F5600-A36B-4787-AFF6-FD733CD2DD72}:

        NameServer=192.168.1.1
        HKLM\SYSTEM\CS3\Services\Tcpip\..\{3D6F5600-A36B-4787-AFF6-FD733CD2DD72}:

        NameServer=192.168.1.1

        »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
        "System"=""

        »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

        »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

        Nettoyage terminé.

        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» Fin

        hijackthis rapport:

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 06:14:37, on 11/02/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16574)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\WLTRYSVC.EXE
        C:\WINDOWS\System32\bcmwltry.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Fichiers communs\Apple\Mobile Device

        Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
        C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
        C:\WINDOWS\system32\igfxsrvc.exe
        C:\WINDOWS\system32\hkcmd.exe
        C:\WINDOWS\system32\igfxpers.exe
        C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
        C:\WINDOWS\stsystra.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Dell\QuickSet\quickset.exe
        C:\WINDOWS\system32\WLTRAY.exe
        C:\Program Files\Creative\Mixer\CTSVolFE.exe
        C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
        C:\Program Files\Fichiers communs\Roxio

        Shared\9.0\SharedCOM\RoxWatchTray9.exe
        C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
        C:\Program Files\Dell\MediaDirect\PCMService.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\WINDOWS\WebCam\M1000\M1000Mnt.exe
        C:\Program Files\Spyware Doctor\pctsTray.exe
        C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\NetWaiting\netWaiting.exe
        C:\Program Files\DellSupport\DSAgnt.exe
        C:\Program Files\Spyware Doctor\pctsAuxs.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
        C:\Program Files\Digital Line Detect\DLG.exe
        C:\Program Files\Spyware Doctor\pctsSvc.exe
        C:\Program Files\SetPoint\SetPoint.exe
        C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
        C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe
        C:\WINDOWS\System32\alg.exe
        C:\Program Files\Fichiers communs\Roxio

        Shared\9.0\SharedCOM\CPSHelpRunner.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\MSN Messenger\msnmsgr.exe
        C:\Program Files\MSN Messenger\usnsvc.exe
        C:\WINDOWS\system32\NOTEPAD.EXE
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe

        R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL =

        www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=4070921
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

        Liens
        O2 - BHO: Adobe PDF Reader Link Helper -

        {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat

        7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} -

        C:\WINDOWS\system32\gigagetbho_v10.dll
        O2 - BHO: Search Assistant - {1648E328-3E5A-4EA5-A9C6-E5F09EE272DA} -

        C:\WINDOWS\system32\adssite_sidebar.dll
        O2 - BHO: Adobe PDF Reader Link Helper -

        {445A3D12-EBA3-4054-AB54-587BF3FF40EA} - C:\WINDOWS\AcroIEHelper.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F}

        - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -

        C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -

        c:\program files\google\googletoolbar2.dll
        O2 - BHO: Browser Address Error Redirector -

        {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
        O2 - BHO: EpsonToolBandKicker Class -

        {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON

        Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

        files\google\googletoolbar2.dll
        O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} -

        C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no

        file)
        O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
        O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program

        Files\Java\jre1.6.0_03\bin\jusched.exe"
        O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [Dell QuickSet] C:\Program

        Files\Dell\QuickSet\quickset.exe
        O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program

        Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE"
        O4 - HKLM\..\Run: [Broadcom Wireless Manager UI]

        C:\WINDOWS\system32\WLTRAY.exe
        O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program

        Files\Creative\Mixer\CTSVolFE.exe" /r
        O4 - HKLM\..\Run: [ISUSPM Startup]

        C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers

        communs\InstallShield\UpdateService\issch.exe" -start
        O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Fichiers communs\Roxio

        Shared\9.0\SharedCOM\RoxWatchTray9.exe"
        O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program

        Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
        O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
        O4 - HKLM\..\Run: [PCMService] "C:\Program

        Files\Dell\MediaDirect\PCMService.exe"
        O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series]

        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus

        Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"

        -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKLM\..\Run: [M1000Mnt] M1000Rmv.exe /StartStillMnt
        O4 - HKLM\..\Run: [postSetupCheck] C:\WINDOWS\System32\Rundll32.exe

        "C:\WINDOWS\system32\gzmrt.dll" DllStart
        O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
        O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt

        Software\CounterSpy\SBCSTray.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
        O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe"

        /startup
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &

        Destroy\TeaTimer.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE

        (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE

        (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE

        (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE

        (User 'Default user')
        O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers

        communs\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Global Startup: BTTray.lnk = ?
        O4 - Global Startup: Digital Line Detect.lnk = ?
        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program

        Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O4 - Global Startup: SetPoint.lnk = ?
        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions

        present
        O8 - Extra context menu item: &Download All by Gigaget - C:\Program

        Files\Giganology\Gigaget\getallurl.htm
        O8 - Extra context menu item: &Download by Gigaget - C:\Program

        Files\Giganology\Gigaget\geturl.htm
        O8 - Extra context menu item: E&xporter vers Microsoft Excel -

        res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... -

        C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

        C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) -

        {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

        Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

        C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

        C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration -

        {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

        C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger -

        {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

        Files\Messenger\msmsgs.exe
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -

        http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin

        Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
        O16 - DPF: {7DA181BB-EF8D-4A7E-8C53-7BFC718EF71D} (Upload Class) -

        http://photoservice.photos.orange.fr/migrationorange/index.cfm
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient

        Class) -

        http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O17 -

        HKLM\System\CCS\Services\Tcpip\..\{3D6F5600-A36B-4787-AFF6-FD733CD2DD72}:

        NameServer = 192.168.1.1
        O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers

        communs\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program

        Files\Fichiers communs\Apple\Mobile Device

        Support\bin\AppleMobileDeviceService.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software -

        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil

        Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program

        Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil

        Software\Avast4\ashWebSv.exe
        O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. -

        C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
        O23 - Service: DSBrokerService - Unknown owner - C:\Program

        Files\DellSupport\brkrsvc.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program

        Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision

        Corporation - C:\Program Files\Fichiers

        communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program

        Files\iPod\bin\iPodService.exe
        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Fichiers

        communs\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
        O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions -

        C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
        O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software

        - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
        O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools -

        C:\Program Files\Spyware Doctor\pctsAuxs.exe
        O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools -

        C:\Program Files\Spyware Doctor\pctsSvc.exe
        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program

        Files\Fichiers communs\SureThing Shared\stllssvr.exe
        O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner -

        C:\WINDOWS\System32\WLTRYSVC.EXE
        0
        1. ok,

          fais ce qui suis et je te retrouve demain, , je vais me coucher , il est bientot 7h ;)

          télécharge AVG anti-rootkit ici https://www.commentcamarche.net/telecharger/ 34055015 avg anti rootkit
          tutoriel ici:http://forum.malekal.com/ftopic2546.php

          poste moi le rapport STP .
          a+
          0
          1. Apparemment il n'y a pas de "rootkit", il n'a pas emit de rapport mais m'a dit que j'avais pa de rootkit.

            Je vais me coucher aussi

            A bientot
            Ambre
            0
            1. salut

              Commence par télécharger ComboFix ici:
              http://download.bleepingcomputer.com/sUBs/ComboFix.exe
              Et enregistre le sur le bureau.
              Regardes ici, si tu souhaites te familiariser avec son utilisation:
              https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

              Sur ton bureau double clic sur Combofix.exe.
              Appuies sur la touche 1, pour que le programme commence à s'exécuter et suis les instructions à l'écran.
              En cours de nettoyage il est possible, que tu reçoives un avertissement te disant que le pc va redémarrer, laisse faire.

              Après le redemarrage du pc, un rapport s'ouvrira dans le Bloc notes en fin d'analyse, copie et colle tout son contenu dans ton prochain message.
              (Le fichier rapport Combofix.txt , est ensuite automatiquement sauvegardé dans C:\Combofix.txt)

              /!\ Pendant toute la durée (ça peut être assez long si le pc est très infecté) du scan de ComboFix, n'ouvres aucun programme et ne surfe pas sur le net.

              a+
              0
              1. Alors voila le rapport de combofix:

                ComboFix 08-02-11.2 - Amber 2008-02-11 17:14:00.1 - NTFSx86
                Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.396 [GMT 1:00]
                Endroit: C:\Documents and Settings\Amber\Bureau\ComboFix.exe
                * Création d'un nouveau point de restauration

                [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                .

                ((((((((((((((((((((((((((((( Fichiers créés 2008-01-11 to 2008-02-11 ))))))))))))))))))))))))))))))))))))
                .

                2008-02-11 15:41 . 2008-02-11 15:41 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
                2008-02-11 06:49 . 2007-01-18 13:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
                2008-02-11 06:13 . 2008-02-11 06:13 <REP> d-------- C:\Program Files\Trend Micro
                2008-02-11 05:34 . 2008-02-11 05:34 15,544 --a------ C:\WINDOWS\system32\drivers\sbhr.sys
                2008-02-11 05:33 . 2008-02-11 05:33 <REP> d-------- C:\Documents and Settings\Amber\Application Data\Sunbelt Software
                2008-02-11 05:33 . 2008-02-11 05:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sunbelt Software
                2008-02-11 05:30 . 2008-02-11 05:30 <REP> d-------- C:\Program Files\Sunbelt Software
                2008-02-11 04:59 . 2008-02-11 06:31 <REP> d-------- C:\Program Files\Spyware Doctor
                2008-02-11 04:59 . 2008-02-11 04:59 <REP> d-------- C:\Documents and Settings\Amber\Application Data\PC Tools
                2008-02-11 04:59 . 2008-02-11 17:06 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
                2008-02-11 04:59 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
                2008-02-11 04:59 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
                2008-02-11 04:59 . 2007-12-10 14:53 41,864 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
                2008-02-11 04:59 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
                2008-02-11 04:31 . 2008-02-11 04:31 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
                2008-02-11 04:31 . 2008-02-11 04:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                2008-02-11 03:55 . 2008-02-11 03:55 235,008 --a------ C:\WINDOWS\AcroIEHelper.dll
                2008-02-11 03:55 . 2008-02-11 03:56 47 --a------ C:\tmp.bat
                2008-02-09 19:31 . 2008-02-09 19:32 <REP> d-------- C:\Program Files\FileZilla
                2008-01-26 22:22 . 2008-01-26 22:22 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
                2008-01-24 17:07 . 2008-01-24 17:07 <REP> d-------- C:\WINDOWS\system32\windows media
                2008-01-24 17:07 . 2008-01-24 17:07 <REP> d-------- C:\Program Files\Windows Media Components
                2008-01-24 17:04 . 2008-02-09 19:49 <REP> d-------- C:\Program Files\NRJ

                .
                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2008-02-11 04:59 4,838 ----a-w C:\WINDOWS\system32\tmp.reg
                2008-02-11 03:09 --------- d-----w C:\Program Files\Emule
                2008-02-09 18:32 --------- d-----w C:\Program Files\DivX
                2008-02-08 22:55 85,504 ----a-w C:\WINDOWS\system32\VACFix.exe
                2008-02-08 09:37 82,432 ----a-w C:\WINDOWS\system32\IEDFix.exe
                2008-01-29 00:40 --------- d-----w C:\Documents and Settings\Amber\Application Data\LimeWire
                2008-01-08 14:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
                2007-12-23 21:31 77,353 ----a-w C:\WINDOWS\system32\adssite_sidebar_uninstall.exe
                2007-12-19 13:42 2,936 ----a-w C:\Documents and Settings\Amber\Application Data\wklnhst.dat
                2007-12-19 12:51 --------- d-----w C:\Program Files\SecureW2
                2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
                2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
                2007-12-03 18:15 79,868 ----a-w C:\WINDOWS\system32\adssite-remove.exe
                2007-12-03 18:15 40,737 ----a-w C:\WINDOWS\system32\rightonadz-uninst.exe
                2007-12-03 17:12 282,624 ----a-w C:\WINDOWS\system32\adssite_sidebar.dll
                .

                ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                REGEDIT4
                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1648E328-3E5A-4EA5-A9C6-E5F09EE272DA}]
                2007-12-03 18:12 282624 --a------ C:\WINDOWS\system32\adssite_sidebar.dll

                [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{445A3D12-EBA3-4054-AB54-587BF3FF40EA}]
                2008-02-11 03:55 235008 --a------ C:\WINDOWS\AcroIEHelper.dll

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 12:00 15360]
                "ModemOnHold"="C:\Program Files\NetWaiting\netWaiting.exe" [2003-09-10 02:24 20480]
                "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 12:09 460784]
                "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-13 16:44 98304]
                "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 16:41 77824]
                "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 16:45 118784]
                "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
                "SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 16:30 282624 C:\WINDOWS\stsystra.exe]
                "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 11:48 761947]
                "Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2007-02-20 12:29 1191936]
                "Logitech Hardware Abstraction Layer"="C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE" [2007-01-11 19:15 101136]
                "Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-10-31 21:48 1392640]
                "CTSVolFE.exe"="C:\Program Files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 15:57 57344]
                "ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184]
                "ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920]
                "RoxWatchTray"="C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 11:22 221184]
                "RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 09:00 1116920]
                "dscactivate"="c:\dell\dsca.exe" [2007-07-30 04:40 16384]
                "PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-05-02 18:16 184320]
                "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-11 19:15 101136 C:\WINDOWS\KHALMNPR.Exe]
                "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
                "EPSON Stylus Photo RX420 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" [2004-04-09 04:00 98304]
                "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24 286720]
                "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42 267064]
                "M1000Mnt"="M1000Rmv.exe" []
                "postSetupCheck"="C:\WINDOWS\system32\gzmrt.dll" [ ]
                "ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2007-12-10 14:53 1103752]
                "SBCSTray"="C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe" [2007-12-21 15:30 698864]

                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 12:00 15360]

                C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-24 18:28:28 622653]
                Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-09-20 18:27:22 24576]
                Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
                SetPoint.lnk - C:\Program Files\SetPoint\SetPoint.exe [2007-09-26 18:34:36 679936]

                R0 SBHR;SBHR;C:\WINDOWS\system32\drivers\sbhr.sys [2008-02-11 05:34]
                R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 10:35]
                R2 BCMWLNPF;Broadcom Netgroup Packet Filter;C:\WINDOWS\system32\drivers\bcmwlnpf.sys [2006-10-31 21:48]
                R3 SBAPIFS;SBAPIFS;C:\WINDOWS\system32\drivers\sbapifs.sys []
                S3 M1000Srv;M5603C USB2.0 Camera Driver;C:\WINDOWS\system32\Drivers\M1000KNT.sys [2005-07-20 13:28]
                S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 21:58]
                S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 22:08]

                *Newly Created Service* - SBAPIFS
                .
                **************************************************************************

                catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-02-11 17:17:08
                Windows 5.1.2600 Service Pack 2 NTFS

                detected NTDLL code modification:
                ZwClose

                Balayage processus cachés ...

                Balayage caché autostart entries ...

                Balayage des fichiers cachés ...

                Scan terminé avec succès
                Les fichiers cachés: 0

                **************************************************************************
                .
                --------------------- DLLs a chargé sous des processus courants ---------------------

                PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
                -> C:\Program Files\ArcSoft\PhotoImpression 5\share\pihook.dll
                -> C:\WINDOWS\system32\DLAAPI_W.DLL
                .
                Temps d'accomplissement: 2008-02-11 17:18:06
                .
                2008-01-10 09:27:28 --- E O F ---
                0
                1. salut

                  sauvegarde ta base de registre avant de faire les manips ci dessous.

                  * télécharge ERUNT

                  https://www.zebulon.fr/telechargements/utilitaires/systeme-utilitaires/erunt.html
                  tuto
                  http://pageperso.aol.fr/loraline60/tuto_erunt.htm

                  puis

                  Sélectionne le texte suivant :

                  file::

                  C:\WINDOWS\system32\adssite-remove.exe
                  C:\WINDOWS\system32\rightonadz-uninst.exe
                  C:\WINDOWS\system32\adssite_sidebar.dll

                  registry::

                  [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1648E328-3E5A-4EA5-A9C6-E5F09EE272DA}]
                  2007-12-03 18:12 282624 --a------ C:\WINDOWS\system32\adssite_sidebar.dll


                  * Copie le texte sélectionné (CTRL+C).
                  * Ouvre le bloc-note (programme>Accessoire>bloc-note).
                  * Colle le texte copié dans ce bloc-note (CTRL+V).
                  * Sauvegarde ce fichier sous le nom de CFScript.txt
                  * Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe
                  * Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
                  * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal!
                  Ne touche à rien tant que le scan n'est pas terminé.
                  * Une fois le scan achevé, un rapport va s'afficher: Poste son contenu.
                  * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

                  et un nouvel hijackthis
                  0
                  1. Voila les rapports

                    RAPPORT COMBOFIX

                    ComboFix 08-02-11.2 - Amber 2008-02-11 19:30:19.2 - NTFSx86
                    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.437 [GMT 1:00]
                    Endroit: C:\Documents and Settings\Amber\Bureau\ComboFix.exe
                    Command switches used :: C:\Documents and Settings\Amber\Bureau\CFScript.txt
                    * Création d'un nouveau point de restauration

                    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

                    FILE
                    C:\WINDOWS\system32\adssite-remove.exe
                    C:\WINDOWS\system32\adssite_sidebar.dll
                    C:\WINDOWS\system32\rightonadz-uninst.exe
                    .

                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    C:\WINDOWS\system32\adssite-remove.exe
                    C:\WINDOWS\system32\adssite_sidebar.dll
                    C:\WINDOWS\system32\rightonadz-uninst.exe

                    .
                    ((((((((((((((((((((((((((((( Fichiers créés 2008-01-11 to 2008-02-11 ))))))))))))))))))))))))))))))))))))
                    .

                    2008-02-11 19:24 . 2008-02-11 19:24 <REP> d-------- C:\Program Files\ERUNT
                    2008-02-11 15:41 . 2008-02-11 15:41 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
                    2008-02-11 06:49 . 2007-01-18 13:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
                    2008-02-11 06:13 . 2008-02-11 06:13 <REP> d-------- C:\Program Files\Trend Micro
                    2008-02-11 05:34 . 2008-02-11 05:34 15,544 --a------ C:\WINDOWS\system32\drivers\sbhr.sys
                    2008-02-11 05:33 . 2008-02-11 05:33 <REP> d-------- C:\Documents and Settings\Amber\Application Data\Sunbelt Software
                    2008-02-11 05:33 . 2008-02-11 05:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sunbelt Software
                    2008-02-11 05:30 . 2008-02-11 05:30 <REP> d-------- C:\Program Files\Sunbelt Software
                    2008-02-11 04:59 . 2008-02-11 06:31 <REP> d-------- C:\Program Files\Spyware Doctor
                    2008-02-11 04:59 . 2008-02-11 04:59 <REP> d-------- C:\Documents and Settings\Amber\Application Data\PC Tools
                    2008-02-11 04:59 . 2008-02-11 17:43 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
                    2008-02-11 04:59 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
                    2008-02-11 04:59 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
                    2008-02-11 04:59 . 2007-12-10 14:53 41,864 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
                    2008-02-11 04:59 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
                    2008-02-11 04:31 . 2008-02-11 04:31 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
                    2008-02-11 04:31 . 2008-02-11 04:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                    2008-02-11 03:55 . 2008-02-11 03:55 235,008 --a------ C:\WINDOWS\AcroIEHelper.dll
                    2008-02-11 03:55 . 2008-02-11 03:56 47 --a------ C:\tmp.bat
                    2008-02-09 19:31 . 2008-02-09 19:32 <REP> d-------- C:\Program Files\FileZilla
                    2008-01-26 22:22 . 2008-01-26 22:22 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
                    2008-01-24 17:07 . 2008-01-24 17:07 <REP> d-------- C:\WINDOWS\system32\windows media
                    2008-01-24 17:07 . 2008-01-24 17:07 <REP> d-------- C:\Program Files\Windows Media Components
                    2008-01-24 17:04 . 2008-02-09 19:49 <REP> d-------- C:\Program Files\NRJ

                    .
                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2008-02-11 04:59 4,838 ----a-w C:\WINDOWS\system32\tmp.reg
                    2008-02-11 03:09 --------- d-----w C:\Program Files\Emule
                    2008-02-09 18:32 --------- d-----w C:\Program Files\DivX
                    2008-02-08 22:55 85,504 ----a-w C:\WINDOWS\system32\VACFix.exe
                    2008-02-08 09:37 82,432 ----a-w C:\WINDOWS\system32\IEDFix.exe
                    2008-01-29 00:40 --------- d-----w C:\Documents and Settings\Amber\Application Data\LimeWire
                    2008-01-08 14:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
                    2007-12-23 21:31 77,353 ----a-w C:\WINDOWS\system32\adssite_sidebar_uninstall.exe
                    2007-12-19 13:42 2,936 ----a-w C:\Documents and Settings\Amber\Application Data\wklnhst.dat
                    2007-12-19 12:51 --------- d-----w C:\Program Files\SecureW2
                    2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
                    2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
                    .

                    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    .
                    REGEDIT4
                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{445A3D12-EBA3-4054-AB54-587BF3FF40EA}]
                    2008-02-11 03:55 235008 --a------ C:\WINDOWS\AcroIEHelper.dll

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 12:00 15360]
                    "ModemOnHold"="C:\Program Files\NetWaiting\netWaiting.exe" [2003-09-10 02:24 20480]
                    "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 12:09 460784]
                    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-13 16:44 98304]
                    "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 16:41 77824]
                    "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 16:45 118784]
                    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
                    "SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 16:30 282624 C:\WINDOWS\stsystra.exe]
                    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 11:48 761947]
                    "Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2007-02-20 12:29 1191936]
                    "Logitech Hardware Abstraction Layer"="C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE" [2007-01-11 19:15 101136]
                    "Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [2006-10-31 21:48 1392640]
                    "CTSVolFE.exe"="C:\Program Files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 15:57 57344]
                    "ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184]
                    "ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920]
                    "RoxWatchTray"="C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 11:22 221184]
                    "RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 09:00 1116920]
                    "dscactivate"="c:\dell\dsca.exe" [2007-07-30 04:40 16384]
                    "PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2007-05-02 18:16 184320]
                    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-11 19:15 101136 C:\WINDOWS\KHALMNPR.Exe]
                    "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
                    "EPSON Stylus Photo RX420 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" [2004-04-09 04:00 98304]
                    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24 286720]
                    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42 267064]
                    "M1000Mnt"="M1000Rmv.exe" []
                    "postSetupCheck"="C:\WINDOWS\system32\gzmrt.dll" [ ]
                    "ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2007-12-10 14:53 1103752]
                    "SBCSTray"="C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe" [2007-12-21 15:30 698864]

                    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 12:00 15360]

                    C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                    BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-05-24 18:28:28 622653]
                    Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-09-20 18:27:22 24576]
                    Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
                    SetPoint.lnk - C:\Program Files\SetPoint\SetPoint.exe [2007-09-26 18:34:36 679936]

                    R0 SBHR;SBHR;C:\WINDOWS\system32\drivers\sbhr.sys [2008-02-11 05:34]
                    R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 10:35]
                    R2 BCMWLNPF;Broadcom Netgroup Packet Filter;C:\WINDOWS\system32\drivers\bcmwlnpf.sys [2006-10-31 21:48]
                    R3 SBAPIFS;SBAPIFS;C:\WINDOWS\system32\drivers\sbapifs.sys []
                    S3 M1000Srv;M5603C USB2.0 Camera Driver;C:\WINDOWS\system32\Drivers\M1000KNT.sys [2005-07-20 13:28]
                    S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 21:58]
                    S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 22:08]

                    *Newly Created Service* - SBAPIFS
                    .
                    **************************************************************************

                    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2008-02-11 19:33:47
                    Windows 5.1.2600 Service Pack 2 NTFS

                    detected NTDLL code modification:
                    ZwClose

                    Balayage processus cachés ...

                    Balayage caché autostart entries ...

                    Balayage des fichiers cachés ...

                    Scan terminé avec succès
                    Les fichiers cachés: 0

                    **************************************************************************
                    .
                    Temps d'accomplissement: 2008-02-11 19:34:56
                    ComboFix-quarantined-files.txt 2008-02-11 18:34:52
                    ComboFix2.txt 2008-02-11 16:18:08
                    .
                    2008-01-10 09:27:28 --- E O F ---

                    RAPPORT HIJACKTHIS

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 19:36:34, on 11/02/2008
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\csrss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\WLTRYSVC.EXE
                    C:\WINDOWS\System32\bcmwltry.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                    C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
                    C:\Program Files\Spyware Doctor\pctsAuxs.exe
                    C:\WINDOWS\system32\hkcmd.exe
                    C:\WINDOWS\system32\igfxpers.exe
                    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                    C:\WINDOWS\system32\igfxsrvc.exe
                    C:\WINDOWS\stsystra.exe
                    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    C:\Program Files\Dell\QuickSet\quickset.exe
                    C:\WINDOWS\system32\WLTRAY.exe
                    C:\Program Files\Creative\Mixer\CTSVolFE.exe
                    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                    C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                    C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
                    C:\Program Files\Dell\MediaDirect\PCMService.exe
                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\Program Files\Spyware Doctor\pctsTray.exe
                    C:\WINDOWS\WebCam\M1000\M1000Mnt.exe
                    C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\NetWaiting\netWaiting.exe
                    C:\Program Files\DellSupport\DSAgnt.exe
                    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                    C:\Program Files\Spyware Doctor\pctsSvc.exe
                    C:\Program Files\Digital Line Detect\DLG.exe
                    C:\Program Files\SetPoint\SetPoint.exe
                    C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
                    C:\WINDOWS\system32\svchost.exe
                    C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
                    C:\WINDOWS\system32\wbem\wmiprvse.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\Program Files\iPod\bin\iPodService.exe
                    C:\WINDOWS\System32\alg.exe
                    C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\MSN Messenger\usnsvc.exe
                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                    C:\WINDOWS\explorer.exe
                    C:\WINDOWS\system32\NOTEPAD.EXE
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                    C:\WINDOWS\system32\wbem\wmiprvse.exe

                    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=4070921
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
                    O2 - BHO: Adobe PDF Reader Link Helper - {445A3D12-EBA3-4054-AB54-587BF3FF40EA} - C:\WINDOWS\AcroIEHelper.dll
                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
                    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
                    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
                    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE"
                    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
                    O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
                    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                    O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
                    O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
                    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
                    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    O4 - HKLM\..\Run: [M1000Mnt] M1000Rmv.exe /StartStillMnt
                    O4 - HKLM\..\Run: [postSetupCheck] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\gzmrt.dll" DllStart
                    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                    O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
                    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
                    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                    O4 - Global Startup: BTTray.lnk = ?
                    O4 - Global Startup: Digital Line Detect.lnk = ?
                    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                    O4 - Global Startup: SetPoint.lnk = ?
                    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                    O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
                    O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                    O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
                    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                    O16 - DPF: {7DA181BB-EF8D-4A7E-8C53-7BFC718EF71D} (Upload Class) - http://photoservice.photos.orange.fr/migrationorange/index.cfm
                    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{3D6F5600-A36B-4787-AFF6-FD733CD2DD72}: NameServer = 192.168.1.1
                    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                    O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
                    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe
                    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
                    0
                    1. ok, ça avance

                      relance kijackthis

                      fait "do a system scan only"

                      coche les ligne suivantes et clic sur fix cheked

                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O4 - HKLM\..\Run: [postSetupCheck] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\gzmrt.dll" DllStart

                      --------------------------------
                      Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
                      http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
                      Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
                      • Redémarre ton ordinateur
                      • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
                      • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
                      • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
                      • Choisis ton compte.
                      Déroule la liste des instructions ci-dessous :
                      • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.cmd pour lancer le scrïpt.
                      • Appuie sur Y pour commencer le processus de nettoyage.
                      • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                      • Appuie sur une touche pour redémarrer le PC.
                      • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                      • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                      • Appuie sur une touche pour finir l'exécution du scrïpt et charger les icônes de ton Bureau.
                      • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                      • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !

                      a+
                      0
                      1. RAPPORT SDFix

                        SDFix: Version 1.141

                        Run by Amber on 11/02/2008 at 20:24

                        Microsoft Windows XP [version 5.1.2600]

                        Running From: C:\DOCUME~1\Amber\Bureau\SDFix\SDFix

                        Safe Mode:
                        Checking Services:

                        Restoring Windows Registry Values
                        Restoring Windows Default Hosts File

                        Rebooting...

                        Normal Mode:
                        Checking Files:

                        Trojan Files Found:

                        C:\WINDOWS\AcroIEHelper.dll - Deleted

                        Removing Temp Files...

                        ADS Check:

                        Final Check:

                        catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,

                        http://www.gmer.net
                        Rootkit scan 2008-02-11 20:30:36
                        Windows 5.1.2600 Service Pack 2 NTFS

                        detected NTDLL code modification:
                        ZwClose

                        scanning hidden processes ...

                        scanning hidden services & system hive ...

                        scanning hidden registry entries ...

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows

                        NT\CurrentVersion\Prefetcher]
                        "TracesProcessed"=dword:0000003b
                        "TracesSuccessful"=dword:00000003
                        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell

                        Extensions\Approved\{11DAD237-1A5D-3AE6-ABED-EEEEB75921AD}]
                        "eapdnnbjmi"=hex:66,61,62,6b,67,6f,68,6e,69,66,69,62,00,fc
                        "daeemnoe"=hex:64,62,64,6b,6f,69,64,69,67,68,69,62,6b,67,62,61,65,61,6e,68,

                        69,..
                        "iahjnnlmpcapakjnoi"=hex:6b,61,6c,65,6a,67,61,6a,61,63,62,6b,6b,6f,6d,63,6d

                        ,63,6c,66,62,..
                        "hajjohclokoacekl"=hex:6b,61,6c,65,6a,67,61,6a,61,63,62,6b,6b,6f,6d,63,6d,6

                        3,6c,66,62,..

                        scanning hidden files ...

                        scan completed successfully
                        hidden processes: 0
                        hidden services: 0
                        hidden files: 224

                        Remaining Services:
                        ------------------

                        Authorized Application Key Export:

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\paramete

                        rs\firewallpolicy\standardprofile\authorizedapplications\list]
                        "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN

                        Messenger\\msnmsgr.exe:*:Enabled:Messenger"

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\paramete

                        rs\firewallpolicy\domainprofile\authorizedapplications\list]

                        Remaining Files:
                        ---------------

                        File Backups: - C:\DOCUME~1\Amber\Bureau\SDFix\SDFix\backups\backups.zip

                        Files with Hidden Attributes:

                        Mon 10 Dec 2007 4,348 A.SH. --- "C:\Documents and Settings\All

                        Users\DRM\DRMv1.bak"
                        Tue 13 Nov 2007 0 A.SH. --- "C:\Documents and Settings\All

                        Users\DRM\Cache\Indiv01.tmp"
                        Wed 19 Dec 2007 39,424 ...H. --- "C:\Documents and

                        Settings\Amber\Mes documents\Fac\Fiches de lecture\~WRL0004.tmp"
                        Sun 16 Dec 2007 26,624 ...H. --- "C:\Documents and

                        Settings\Amber\Mes documents\Fac\Fiches de lecture\~WRL0907.tmp"
                        Wed 26 Sep 2007 8 A..H. --- "C:\Documents and

                        Settings\Amber\Application

                        Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\lock.tmp"
                        Tue 2 Oct 2007 8 A..H. --- "C:\Documents and

                        Settings\Amber\Application

                        Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\lock.tmp"
                        Tue 2 Oct 2007 8 A..H. --- "C:\Documents and

                        Settings\Amber\Application

                        Data\GTek\GTUpdate\AUpdate\Channels\ch_u3\lock.tmp"
                        Wed 2 Jan 2008 8 A..H. --- "C:\Documents and

                        Settings\Amber\Application

                        Data\GTek\GTUpdate\AUpdate\Channels\ch_u4\lock.tmp"

                        Finished!

                        RAPPORT HIJACKTHIS

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 20:36:14, on 11/02/2008
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\csrss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\WLTRYSVC.EXE
                        C:\WINDOWS\System32\bcmwltry.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Fichiers communs\Apple\Mobile Device

                        Support\bin\AppleMobileDeviceService.exe
                        C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                        C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
                        C:\Program Files\Spyware Doctor\pctsAuxs.exe
                        C:\Program Files\Spyware Doctor\pctsSvc.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Spyware Doctor\pctsTray.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\WINDOWS\System32\alg.exe
                        C:\WINDOWS\system32\notepad.exe
                        C:\WINDOWS\system32\hkcmd.exe
                        C:\WINDOWS\system32\igfxpers.exe
                        C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                        C:\WINDOWS\stsystra.exe
                        C:\WINDOWS\system32\igfxsrvc.exe
                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        C:\Program Files\Dell\QuickSet\quickset.exe
                        C:\WINDOWS\system32\WLTRAY.exe
                        C:\Program Files\Creative\Mixer\CTSVolFE.exe
                        C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                        C:\Program Files\Fichiers communs\Roxio

                        Shared\9.0\SharedCOM\RoxWatchTray9.exe
                        C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
                        C:\Program Files\Dell\MediaDirect\PCMService.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\WINDOWS\WebCam\M1000\M1000Mnt.exe
                        C:\WINDOWS\system32\wbem\wmiprvse.exe
                        C:\Program Files\NetWaiting\netWaiting.exe
                        C:\Program Files\DellSupport\DSAgnt.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\WINDOWS\system32\wbem\wmiprvse.exe
                        C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                        C:\Program Files\Digital Line Detect\DLG.exe
                        C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                        C:\Program Files\SetPoint\SetPoint.exe
                        C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
                        C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
                        C:\Program Files\Fichiers communs\Roxio

                        Shared\9.0\SharedCOM\CPSHelpRunner.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\WINDOWS\system32\NOTEPAD.EXE
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL =

                        www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=4070921
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

                        Liens
                        O2 - BHO: Adobe PDF Reader Link Helper -

                        {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat

                        7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} -

                        C:\WINDOWS\system32\gigagetbho_v10.dll
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F}

                        - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -

                        C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -

                        c:\program files\google\googletoolbar2.dll
                        O2 - BHO: Browser Address Error Redirector -

                        {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                        O2 - BHO: EpsonToolBandKicker Class -

                        {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON

                        Web-To-Page\EPSON Web-To-Page.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

                        files\google\googletoolbar2.dll
                        O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} -

                        C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                        O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no

                        file)
                        O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                        O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                        O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program

                        Files\Java\jre1.6.0_03\bin\jusched.exe"
                        O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
                        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        O4 - HKLM\..\Run: [Dell QuickSet] C:\Program

                        Files\Dell\QuickSet\quickset.exe
                        O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program

                        Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE"
                        O4 - HKLM\..\Run: [Broadcom Wireless Manager UI]

                        C:\WINDOWS\system32\WLTRAY.exe
                        O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program

                        Files\Creative\Mixer\CTSVolFE.exe" /r
                        O4 - HKLM\..\Run: [ISUSPM Startup]

                        C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers

                        communs\InstallShield\UpdateService\issch.exe" -start
                        O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Fichiers communs\Roxio

                        Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                        O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program

                        Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
                        O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
                        O4 - HKLM\..\Run: [PCMService] "C:\Program

                        Files\Dell\MediaDirect\PCMService.exe"
                        O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series]

                        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus

                        Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"

                        -atboottime
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKLM\..\Run: [M1000Mnt] M1000Rmv.exe /StartStillMnt
                        O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                        O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt

                        Software\CounterSpy\SBCSTray.exe
                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
                        O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe"

                        /startup
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search &

                        Destroy\TeaTimer.exe
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE

                        (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE

                        (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE

                        (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE

                        (User 'Default user')
                        O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers

                        communs\Adobe\Calibration\Adobe Gamma Loader.exe
                        O4 - Global Startup: BTTray.lnk = ?
                        O4 - Global Startup: Digital Line Detect.lnk = ?
                        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program

                        Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                        O4 - Global Startup: SetPoint.lnk = ?
                        O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions

                        present
                        O8 - Extra context menu item: &Download All by Gigaget - C:\Program

                        Files\Giganology\Gigaget\getallurl.htm
                        O8 - Extra context menu item: &Download by Gigaget - C:\Program

                        Files\Giganology\Gigaget\geturl.htm
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel -

                        res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                        O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... -

                        C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

                        C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) -

                        {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

                        Files\Java\jre1.6.0_03\bin\ssv.dll
                        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

                        C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

                        C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration -

                        {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

                        C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger -

                        {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

                        Files\Messenger\msmsgs.exe
                        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -

                        https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -

                        http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
                        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin

                        Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                        O16 - DPF: {7DA181BB-EF8D-4A7E-8C53-7BFC718EF71D} (Upload Class) -

                        http://photoservice.photos.orange.fr/migrationorange/index.cfm
                        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient

                        Class) -

                        http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                        O17 -

                        HKLM\System\CCS\Services\Tcpip\..\{3D6F5600-A36B-4787-AFF6-FD733CD2DD72}:

                        NameServer = 192.168.1.1
                        O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers

                        communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program

                        Files\Fichiers communs\Apple\Mobile Device

                        Support\bin\AppleMobileDeviceService.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software -

                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil

                        Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program

                        Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil

                        Software\Avast4\ashWebSv.exe
                        O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. -

                        C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                        O23 - Service: DSBrokerService - Unknown owner - C:\Program

                        Files\DellSupport\brkrsvc.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program

                        Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision

                        Corporation - C:\Program Files\Fichiers

                        communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program

                        Files\iPod\bin\iPodService.exe
                        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Fichiers

                        communs\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                        O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions -

                        C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                        O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software

                        - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
                        O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools -

                        C:\Program Files\Spyware Doctor\pctsAuxs.exe
                        O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools -

                        C:\Program Files\Spyware Doctor\pctsSvc.exe
                        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program

                        Files\Fichiers communs\SureThing Shared\stllssvr.exe
                        O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner -

                        C:\WINDOWS\System32\WLTRYSVC.EXE
                        0
                        1. bien, ça à l'air d'avancer tranquille

                          je te donne quelques consigne de nettoyage et/afin de verifier que rien n'est passé à coté
                          consigne que tu peux appliquer regulierement, ça ne feras pas de mal à ton pc

                          coté conseil:
                          personnellement, je prefèrerais que tu es antivir , plutot qu'avast
                          un tuto pour antivir
                          https://www.malekal.com/avira-free-security-antivirus-gratuit/

                          donc si tu veux changer d'antivirus;
                          tu dois utiliser le désinstalleur d Avast: https://www.avast.com/fr-fr/uninstall-utility
                          -------------------------------------
                          voila les consignes (valable pour le futurt aussi)

                          Lis bien et exécute cette manip dans l’ordre.

                          #Télécharge et installe ces logiciels (si tu ne les as pas) pour les 3 premiers
                          mets les à jour, comme indiqué dans les démos ou tutos.

                          Ne les utilise pas tout de suite.

                          Antispywares et autres :

                          *Ad-Aware (gratuit)
                          Téléchargement :
                          http://www.commentcamarche.net/telecharger/telecharger 83 ad aware 2007 free

                          Tuto :
                          http://perso.orange.fr/rginformatique/section%20virus/adawrevid.asf

                          *Spybot (gratuit) :
                          Téléchargement :
                          http://telecharger.01net.com/windows/Internet/internet_utlitaire/fiches/26157.html
                          voir demo d utilisation (merci Balltrap)
                          http://perso.orange.fr/rginformatique/section%20virus/demo%20spybot.htm

                          * AVG AS

                          AVG anti spyware
                          https://www.01net.com/telecharger/
                          Mets le a jour avant de lancer le scan.
                          Tuto :
                          http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html

                          Nettoyeurs (de fichiers inutiles) et autres :

                          *Ccleaner (gratuit)
                          Téléchargement :
                          https://www.01net.com/
                          Tuto :
                          https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

                          Lors de l’installation, [décoche] l’option qui t’installerait la barre Yahoo !

                          ========================================
                          ->Affiche tous les fichiers et dossiers :
                          clique sur démarrer/panneau de configuration (en affichage classique)/option des dossiers/affichage

                          [Coche] « afficher les dossiers et fichiers cachés »

                          [Décoche] la case « Masquer les fichiers protégés du système d'exploitation (recommandé) »

                          [Décoche] « masquer les extensions dont le type est connu »

                          Puis fais [appliquer] pour valider les changements.

                          Et [Ok]
                          =

                          =======================================

                          ->Démarre en mode sans échec :
                          Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                          Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec
                          puis tape « entrée ».
                          Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                          (Si F8 ne marche pas utilise la touche F5).
                          =========================
                          ->Lance CCleaner.

                          Suppression des fichiers temporaires

                          Va dans la section "Options" situé dans la marge gauche.
                          Décoche "Avancé"
                          Retourne ensuite dans la section "Nettoyeur"
                          Fais bien attention de cocher toutes ces cases dans la marge gauche (Internet Explorer/Windows Explorer/Système)
                          • Clique sur [Analyse]
                          • Patiente le temps du scan, qui peut prendre un peu de temps si c'est la première fois.
                          • Une fois le scan terminé, clique sur [Lancer le Nettoyage]

                          ========================================
                          ->Lance AVG pour un scan complet "Analyse" ->"Paramètres"

                          Sous la question "Comment réagir ?" :

                          -> clique sur "Actions recommandées" et choisis "Quarantaines"
                          -> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"

                          Si un fichier est infecté en fin d'analyse

                          ->Clique sur "Appliquer toutes les actions "

                          ->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".

                          ->Enregistre ce fichier texte sur ton bureau et [copie/colle le rapport en forum]
                          ========================================
                          ->Passe Ad-Aware et supprime tout ce qu’il trouve + supprime les quarantaines…
                          ========================================
                          ->Passe Spybot et corrige tout ce qu’il trouve + vaccine + supprime les quarantaines…
                          ========================================
                          ->Relance CCleaner.
                          Suppression des incohérences du registre

                          • Clique sur l'icône [Erreurs] situés dans la marge à gauche
                          • Puis clique sur [Analyser les erreurs]
                          • Patiente pendant que CCleaner scan ton registre.
                          • Une fois le scan terminé, coche toutes les entrèes qu'il t'aura trouvée.
                          • Tu peux cliquer ensuite sur [Corriger les erreurs].

                          Si tu n'est pas sur de ce que tu fais, tu peux choisir de sauvegarder les entrées cochées pour les restaurer ultérieurement.
                          ========================================
                          ->Vide ta Corbeille.
                          ========================================
                          ->Redémarre en mode normal,

                          - > Ouvre ce lien pour scanner ton PC avec un BitDefender en ligne (uniquement sous Internet Explorer) :

                          https://www.bitdefender.com/toolbox/

                          Utilisation :
                          Cliquer sur "J'accepte" puis accepter également l'ActiveX bloqué par la barre anti-popup du SP2 qui clignotera en haut et l'installer.
                          Ensuite, cliquer sur "Cliquez ici pour scanner".
                          Patienter jusqu'à la fin du scan qui peut durer assez longtemps...

                          Copier/coller le rapport entier sur le forum.

                          Tutoriel en images ici : http://pageperso.aol.fr/rginformatique/mapage/defender.htm (merci à Balltrap34 pour cette réalisation)
                          [Recoche] la case « Masquer les fichiers protégés du système d'exploitation (recommandé) »

                          Relance Hijackthis et copie/colle un nouveau rapport sur le forum.

                          normalement apres cela ton systeme est propre, et protegé, Ambre.
                          Assez rare comme prénom....

                          je regarderais tes rapports dès qu'il seront fait, mais ça a l'air deja mieux

                          bonne soirée

                          0
                          1. Bonsoir!

                            Rapport AVG:

                            ---------------------------------------------------------
                            AVG Anti-Spyware - Rapport d'analyse
                            ---------------------------------------------------------

                            + Créé à: 01:23:04 12/02/2008

                            + Résultat de l'analyse:

                            C:\Program Files\Emule\patch\EvID4226Patch.exe -> Not-A-Virus.Hacktool.EvID : Nettoyé et sauvegardé (mise en quarantaine).

                            Fin du rapport

                            Rapport bit defender:

                            BitDefender Online Scanner

                            Scan report generated at: Tue, Feb 12, 2008 - 02:43:31

                            Scan path: C:\;D:\;

                            Statistics

                            Time
                            01:03:38

                            Files
                            199799

                            Folders
                            6187

                            Boot Sectors
                            5

                            Archives
                            3852

                            Packed Files
                            13899

                            Results

                            Identified Viruses
                            2

                            Infected Files
                            3

                            Suspect Files
                            5

                            Warnings
                            0

                            Disinfected
                            0

                            Deleted Files
                            8

                            Engines Info

                            Virus Definitions
                            980385

                            Engine build
                            AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

                            Scan plugins
                            16

                            Archive plugins
                            41

                            Unpack plugins
                            7

                            E-mail plugins
                            6

                            System plugins
                            5

                            Scan Settings

                            First Action
                            Disinfect

                            Second Action
                            Delete

                            Heuristics
                            Yes

                            Enable Warnings
                            Yes

                            Scanned Extensions
                            *;

                            Exclude Extensions

                            Scan Emails
                            Yes

                            Scan Archives
                            Yes

                            Scan Packed
                            Yes

                            Scan Files
                            Yes

                            Scan Boot
                            Yes

                            Scanned File
                            Status

                            C:\Program Files\Trend Micro\HijackThis\backups\backup-20080211-201438-847.dll
                            Suspected of: Trojan.Downloader.Codec.E

                            C:\Program Files\Trend Micro\HijackThis\backups\backup-20080211-201438-847.dll
                            Disinfection failed

                            C:\Program Files\Trend Micro\HijackThis\backups\backup-20080211-201438-847.dll
                            Deleted

                            C:\QooBox\Quarantine\C\WINDOWS\system32\rightonadz-uninst.exe.vir=>(NSIS o)
                            Detected with: Adware.AdRotator.G

                            C:\QooBox\Quarantine\C\WINDOWS\system32\rightonadz-uninst.exe.vir=>(NSIS o)
                            Deleted

                            C:\QooBox\Quarantine\C\WINDOWS\system32\rightonadz-uninst.exe.vir
                            Update failed

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP132\A0028444.exe
                            Suspected of: Trojan.Downloader.Codec.C

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP132\A0028444.exe
                            Disinfection failed

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP132\A0028444.exe
                            Deleted

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP133\A0028631.dll
                            Infected with: Trojan.Downloader.Codec.G

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP133\A0028631.dll
                            Disinfection failed

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP133\A0028631.dll
                            Deleted

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP135\A0028791.exe=>(NSIS o)
                            Detected with: Adware.AdRotator.G

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP135\A0028791.exe=>(NSIS o)
                            Deleted

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP135\A0028791.exe
                            Update failed

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP135\A0028858.dll
                            Suspected of: Trojan.Downloader.Codec.E

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP135\A0028858.dll
                            Disinfection failed

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP135\A0028858.dll
                            Deleted

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP135\A0028865.dll
                            Suspected of: Trojan.Downloader.Codec.E

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP135\A0028865.dll
                            Disinfection failed

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP135\A0028865.dll
                            Deleted

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP136\A0029797.dll
                            Suspected of: Trojan.Downloader.Codec.E

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP136\A0029797.dll
                            Disinfection failed

                            C:\System Volume Information\_restore{340C3340-2EBB-4324-859A-C37E85627171}\RP136\A0029797.dll
                            Deleted

                            Rapport Hijackthis:

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 04:13:02, on 12/02/2008
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\System32\WLTRYSVC.EXE
                            C:\WINDOWS\System32\bcmwltry.exe
                            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\system32\hkcmd.exe
                            C:\WINDOWS\system32\igfxpers.exe
                            C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                            C:\WINDOWS\stsystra.exe
                            C:\WINDOWS\system32\igfxsrvc.exe
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            C:\Program Files\Dell\QuickSet\quickset.exe
                            C:\WINDOWS\system32\WLTRAY.exe
                            C:\Program Files\Creative\Mixer\CTSVolFE.exe
                            C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                            C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                            C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
                            C:\Program Files\Dell\MediaDirect\PCMService.exe
                            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\NetWaiting\netWaiting.exe
                            C:\Program Files\DellSupport\DSAgnt.exe
                            C:\WINDOWS\WebCam\M1000\M1000Mnt.exe
                            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                            C:\Program Files\Digital Line Detect\DLG.exe
                            C:\Program Files\SetPoint\SetPoint.exe
                            C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
                            C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\MSN Messenger\msnmsgr.exe
                            C:\Program Files\MSN Messenger\usnsvc.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=4070921
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                            O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                            O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                            O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                            O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                            O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
                            O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                            O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                            O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                            O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
                            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
                            O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE"
                            O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
                            O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
                            O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                            O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                            O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                            O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
                            O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
                            O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
                            O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                            O4 - HKLM\..\Run: [M1000Mnt] M1000Rmv.exe /StartStillMnt
                            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
                            O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                            O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                            O4 - Global Startup: BTTray.lnk = ?
                            O4 - Global Startup: Digital Line Detect.lnk = ?
                            O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                            O4 - Global Startup: SetPoint.lnk = ?
                            O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                            O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
                            O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                            O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
                            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                            O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                            O16 - DPF: {7DA181BB-EF8D-4A7E-8C53-7BFC718EF71D} (Upload Class) - http://photoservice.photos.orange.fr/migrationorange/index.cfm
                            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                            O17 - HKLM\System\CCS\Services\Tcpip\..\{3D6F5600-A36B-4787-AFF6-FD733CD2DD72}: NameServer = 192.168.1.1
                            O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
                            O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                            O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                            O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe
                            O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
                            0
                            1. ok.
                              c'est propre, ce qu'à trouver bitdefender est dand la restauration et la quarantaine de combofix

                              relance hijackthis , fait "do a system scan only"

                              coche cette ligne et fixcheked
                              O16 - DPF: {7DA181BB-EF8D-4A7E-8C53-7BFC718EF71D} (Upload Class) - http://photoservice.photos.orange.fr/migrationorange/index.cfm
                              ----------------------

                              desactive les restauaration du systeme

                              demarrer->clic droit sur poste de travail puis propriété

                              dans l'onglet restauration du system coche desactiver la restauration du systeme, puis appliquer(en bas à droite)

                              puis decoche, desactiver la restauratiton du systeme, et appliquer

                              -----

                              pour nettoyer les programmes que je t' ai fait installer

                              · Télécharge ToolsCleaner de A.Roshtein sur ton Bureau.

                              http://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe

                              · Clique sur Recherche et laisse le scan se terminer.
                              · Clique, sur Suppression pour finaliser.
                              · Tu peux, si tu le souhaites, te servir des Options facultatives.
                              · Clique sur Quitter, pour que le rapport puisse se créer.
                              · Poste moi le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur( C:\).

                              ----------------------------------------------------------
                              pour finaliser le nettoyage

                              Nettoyeurs (de fichiers inutiles) et autres :

                              *Ccleaner (gratuit)
                              Téléchargement :

                              Tuto :
                              http://www.commentcamarche.net/telecharger/telecharger 168 ccleaner
                              https://kerio.probb.fr/
                              https://www.malekal.com/tutoriel-ccleaner/
                              ET
                              http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm
                              https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
                              * Supprime regulierement les fichiers inutiles (fichiers temporaire , cookies .. ect) a l'aide de CCleaner

                              Lors de l’installation, [décoche] l’option qui t’installerait la barre Yahoo !

                              ---------------------------------
                              *un autre logiciel pour nettoyer, windows se salissant tres vite :/
                              regseeker
                              https://www.commentcamarche.net/telecharger/ 34055142 regseeker

                              un tuto
                              http://www.kachouri.com/
                              ------------
                              a+
                              0
                              1. -->- Recherche:

                                C:\Qoobox: trouvé !
                                C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
                                C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
                                C:\Documents and Settings\Amber\Bureau\HijackThis.lnk: trouvé !
                                C:\Documents and Settings\Amber\Bureau\HJTInstall.exe: trouvé !
                                C:\Program Files\Trend Micro\HijackThis: trouvé !
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
                                C:\Program Files\WIDCOMM\Bluetooth Software\gzip.exe: trouvé !
                                C:\QooBox\Quarantine\C\Combofix: trouvé !

                                ---------------------------------
                                -->- Suppression:

                                C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
                                C:\Documents and Settings\Amber\Bureau\HijackThis.lnk: supprimé !
                                C:\Documents and Settings\Amber\Bureau\HJTInstall.exe: supprimé !
                                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
                                C:\Program Files\WIDCOMM\Bluetooth Software\gzip.exe: supprimé !
                                C:\Qoobox: supprimé !
                                C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
                                C:\Program Files\Trend Micro\HijackThis: supprimé !

                                Corbeille vidée!
                                Fichiers temporaires nettoyés !

                                Merci encore pour l'aide! Passe une bonne journée (bonne nuit?)
                                Ambre
                                0
                                1. salut

                                  bon surf,
                                  je mets ton sujet en resolu
                                  0