Probleme d'infection publicitaire.

Bonjour,
voilà depuis 1 semaine j'ai un probleme avec internet explorer. J'ai plein de fenetre qui s'ouvre s'en mon accord et se sont des publicités. De plus, il y a des publicité qui s'introduisent sur n'importe qu'elle page. Ces pub disent " votre ordi est infecté, effectué un test ..."
J'ai donc fait la Méthode préliminaire de désinfection - Version Fr de Kristopher est donc voici les rapports.
J'ai windows vista, voici les differents rapports.
Merci Beaucoup
Gilles.

Ccleaner :
ANALYSE COMPLETE - (28.404 secs)
------------------------------------------------------------------------------------------
12,1MB ont été supprimés. (Taille approximative)
------------------------------------------------------------------------------------------

Détails des fichiers à supprimer (Note: AUCUN fichier n'a pour l'instant été supprimé)
------------------------------------------------------------------------------------------
Fichiers Temporaires d'Internet Explorer (fichiers 1166) 8,80MB
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\gilles@ads.pointroll[2].txt 769 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\gilles@bluestreak[2].txt 140 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\gilles@c.msn[1].txt 68 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\gilles@live[1].txt 351 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\gilles@messenger.msn[1].txt 96 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\gilles@msn[1].txt 433 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\gilles@rad.msn[2].txt 690 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\gilles@t.msn[1].txt 323 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@2.gmodules[1].txt 388 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@2.gmodules[3].txt 417 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@5.gmodules[1].txt 387 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@5.gmodules[3].txt 417 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@8.gmodules[1].txt 417 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@85.12.43[1].txt 175 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@85.17.166[1].txt 173 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@89.188.16[2].txt 76 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@89.188.16[3].txt 75 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@89.188.16[4].txt 75 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@ad.yieldmanager[2].txt 693 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@adnetserver[2].txt 266 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@adtrgt[2].txt 485 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@advertising[1].txt 417 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@antiver2008[2].txt 1,24KB
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@atdmt[1].txt 104 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@auctionads[1].txt 97 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@bluestreak[2].txt 183 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@bs.serving-sys[1].txt 111 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@doubleclick[1].txt 89 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@edt02[1].txt 300 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@em.gad-network[1].txt 186 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@google[1].txt 130 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@google[2].txt 137 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@hopelessromantic[1].txt 97 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@iapref.orange[1].txt 95 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@mediaplex[1].txt 85 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@orange[1].txt 250 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@primecasino[2].txt 207 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@programme[2].txt 374 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@reparateurdesysteme[1].txt 1,24KB
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@safe.reparateurdesysteme[1].txt 610 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@sdv[1].txt 326 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@server.iad.liveperson[2].txt 217 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@serving-sys[1].txt 554 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@smartadserver[1].txt 298 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@storageprotector[1].txt 321 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@wanadoo[1].txt 87 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@weborama[1].txt 91 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@www.admedia365[2].txt 103 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@www.google[2].txt 512 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@www.google[3].txt 835 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@www.jackpotmadness[1].txt 122 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@www.orange[1].txt 78 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@www.primecasino[1].txt 79 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@www.web-mediaplayer[1].txt 115 bytes
C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Cookies\low\gilles@xiti[1].txt 106 bytes
C:\Users\Gilles\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008021320080214\index.dat 32,00KB
C:\Users\Gilles\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012008021220080213\index.dat 32,00KB
Marqué pour l'effacement: C:\Users\Gilles\Local Settings\Temporary Internet Files\Content.IE5\index.dat
C:\Users\Gilles\AppData\Local\Temp\LastScan.txt 1,73KB
C:\Users\Gilles\AppData\Local\Temp\tmp0000a17c 39,50KB
C:\Users\Gilles\AppData\Local\Temp\ycomp_setup.exe 1,56MB
C:\Windows\system32\wbem\Logs\wmiprov.log 1,41KB
C:\Windows\Debug\mrt.log 1,19KB
C:\Windows\Debug\mrteng.log 586 bytes
C:\Windows\Debug\UserMode\ChkAcc.log 0 bytes
C:\Windows\Debug\UserMode\ChkAcc.bak 0 bytes
C:\Windows\system32\LogFiles\HTTPERR\httperr1.log 1,65KB
C:\Windows\system32\LogFiles\Scm\SCM.EVM.1 0,28MB
C:\Windows\system32\LogFiles\Scm\SCM.EVM.2 0,41MB
C:\Windows\system32\LogFiles\Scm\SCM.EVM.3 0,47MB
C:\Windows\system32\LogFiles\Scm\SCM.EVM.4 0,41MB
C:\Users\Gilles\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol 405 bytes
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\logfile.txt 288 bytes
C:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\{8083E289-2DF6-472B-804A-8BDFE921B4B2} 5,89KB
------------------------------------------------------------------------------------------

AVG Anti spyware :
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------

+ Créé à: 20:25:03 13/02/2008

+ Résultat de l'analyse:

Rien à signaler.

Fin du rapport

Bitdefender : le scan ne marche pas en ligne pour moi
J ai testé avec AVAST est aucun virus

HijackThis V2.02 :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:03:13, on 11/02/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe
C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\Windows\System32\rundll32.exe
C:\Windows\DvzCommon\DvzMsgr.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Windows\System32\mobsync.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\DllHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MaxBlastMonitor.exe] C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [Windows Audio Control] ppnsvc.exe
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\Gilles\AppData\Local\Temp\ddabb.dll,#1
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\Gilles\AppData\Local\Temp\gebab.dll,c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - Startup: CCC.lnk = ?
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Dataviz Messenger.lnk = C:\Windows\DvzCommon\DvzMsgr.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C4001682-89C7-48F8-B1E2-3896BF36CCD0}: NameServer = 80.10.246.130 81.253.149.10
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Program Files\Reverso\Reverso Translation Server\LogoMedia TranslateDotNet Server.exe

--
End of file - 9467 bytes
Configuration: Windows Vista
Internet Explorer 7.0

23 réponses

Résumé de la discussion

Le récit concerne un problème persistant avec Internet Explorer, où des fenêtres publicitaires s’ouvrent sans consentement et des messages trompeurs indiquent que l’ordinateur est infecté, requérant un diagnostic. Des nettoyages ont été effectués avec divers outils (Ccleaner, AVG, Avast, HijackThis), révélant surtout des cookies suspects et des entrées de démarrage, sans menace avérée confirmée. Les rapports évoquent Windows Vista et Internet Explorer 7, avec des modules publicitaires et des barres d’outils susceptibles d'altérer les pages, ainsi que des démarrages inhabituels et des processus actifs. Certaines suites indiquent que la meilleure réponse proposait une aide extérieure et une approche fondée sur les rapports, sans garantie de résolution et nécessitant de poursuivre les nettoyages.

Bobot (l’IA à votre service)
  1. Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"lp.exe"
    O4 - HKLM\..\Run: [Windows Audio Control] ppnsvc.exe
    O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\Gilles\AppData\Local\Temp\ddabb.dll,#1
    O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\Gilles\AppData\Local\Temp\gebab.dll,c

    _________________

    télécharge OTMoveIt
    http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau. Ou sur https://www.luanagames.com/index.fr.html
    double-clique sur OTMoveIt.exe pour le lancer.
    copie la liste qui se trouve en citation ci-dessous,
    et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

    Citation :
    C:\Users\Gilles\AppData\Local\Temp\gebab.dll
    C:\Users\Gilles\AppData\Local\Temp\ddabb.dll

    clique sur MoveIt! pour lancer la suppression.
    le résultat apparaitra dans le cadre "Results".
    clique sur Exit pour fermer.
    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

    ______________________

    Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

    - Va dans démarrer puis panneau de configuration
    - Double Clique sur l'icône "Comptes d'utilisateurs"
    - Clique ensuite sur désactiver et valide.

    Télécharge maintenant Navilog1 depuis-ce lien :

    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, Fais un Clic-droit sur le raccourci Navilog1 présent sur ton bureau et choisis "Exécuter

    en tant qu'administrateur".

    Au menu principal, Fais le choix 1
    Laisse toi guider et patiente.
    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche le blocnote va s'ouvrir.
    Copie-colle l'intégralité du rapport dans une réponse.
    Referme le blocnote
    Le rapport fixnavi.txt est en outre sauvegardé dans %systemdrive%.
    0
    1. d'accord je le fais de suite
      Merci pour ta rapidité.
      Je te tiens au courant
      Gilles
      0
      1. Rapport Of Moveit :

        File/Folder C:\Users\Gilles\AppData\Local\Temp\gebab.dll not found.
        File/Folder C:\Users\Gilles\AppData\Local\Temp\ddabb.dll not found.

        OTMoveIt2 v1.0.20 log created on 02132008_224347
        Rapport Navilog :

        Search Navipromo version 3.4.5 commencé le 13/02/2008 à 22:52:57,05

        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
        !!! Postez ce rapport sur le forum pour le faire analyser !!!
        !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

        Outil exécuté depuis C:\Program Files\navilog1
        Mise à jour le 11.02.2008 à 20h00 par IL-MAFIOSO

        Microsoft Windows Vista 6.0.6000
        Internet Explorer : 7.0.6000.16575
        Système de fichiers : NTFS

        Executé en mode normal

        *** Recherche Programmes installés ***

        *** Recherche dossiers dans C:\Windows ***

        *** Recherche dossiers dans C:\Program Files ***

        *** Recherche dossiers dans C:\ProgramData ***

        *** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***

        *** Recherche dossiers dans C:\Users\Gilles\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs ***

        *** Recherche dossiers dans C:\Users\Gilles\AppData\Local\virtualstore\Program Files ***

        *** Recherche dossiers dans C:\Users\Gilles\AppData\Roaming ***

        *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
        pour + d'infos : http://www.gmer.net

        Aucun Fichier trouvé

        *** Recherche avec GenericNaviSearch ***
        !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
        !!! A vérifier impérativement avant toute suppression manuelle !!!

        * Recherche dans C:\Windows\system32 *

        * Recherche dans C:\Users\Gilles\AppData\Local\Microsoft *

        * Recherche dans C:\Users\Gilles\AppData\Local\virtualstore\windows\system32 *

        * Recherche dans C:\Users\Gilles\AppData\Local *

        *** Recherche fichiers ***

        *** Recherche clés spécifiques dans le Registre ***

        *** Module de Recherche complémentaire ***
        (Recherche fichiers spécifiques)

        1)Recherche nouveaux fichiers Instant Access :

        2)Recherche Heuristique :

        * Dans C:\Windows\system32 :

        * Dans C:\Users\Gilles\AppData\Local\Microsoft :

        * Dans C:\Users\Gilles\AppData\Local\virtualstore\windows\system32 :

        * Dans C:\Users\Gilles\AppData\Local :

        3)Recherche Certificats :

        Certificat Egroup absent !

        4)Recherche fichiers connus :

        *** Analyse terminée le 13/02/2008 à 22:59:33,30 ***
        0
        1. Que dois je faire à present s'il vous plait
          Merci
          0
          1. salut g le meme probleme que toi il fat faire koi alors?
            0
            1. Contributeur sécurité
              slt, tu fais ton propre post , tu explique tes soucis et tu colle un rapport hijakchits

              a plus
              0
          2. oui exact. Lis déjà çà : http://www.commentcamarche.net/faq/sujet 3174 virus methode preliminaire de desinfection version fr
            ça m'a beaucoup aidé.
            Gilles.
            0
            1. bon g relancé hijackthis sa ma donner sa

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 21:12:16, on 14/02/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16608)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\WINDOWS\SOUNDMAN.EXE
              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              C:\Launch Manager\LaunchAp.exe
              C:\Launch Manager\HotkeyApp.exe
              C:\Launch Manager\OSD.exe
              C:\Launch Manager\OSDCtrl.exe
              C:\Launch Manager\Wbutton.exe
              C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
              C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
              C:\WINDOWS\system32\rundll32.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\Program Files\Windows Live\Messenger\usnsvc.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer optimisé pour MSN
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
              O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
              O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              O4 - HKLM\..\Run: [LaunchAp] C:\Launch Manager\LaunchAp.exe
              O4 - HKLM\..\Run: [HotkeyApp] C:\Launch Manager\HotkeyApp.exe
              O4 - HKLM\..\Run: [LMgrVolOSD] C:\Launch Manager\OSD.exe
              O4 - HKLM\..\Run: [LMgrOSD] C:\Launch Manager\OSDCtrl.exe
              O4 - HKLM\..\Run: [Wbutton] "C:\Launch Manager\Wbutton.exe"
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [CtrlVol] C:\Launch Manager\CtrlVol.exe
              O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
              O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
              O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [fsc-reminder.exe] C:\WINDOWS\reminder\fsc-reminder.exe 2453871 14
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
              O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Startup: Pense-bête.lnk = C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE
              O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
              O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
              O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
              O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
              O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
              O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
              O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
              O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
              O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game08.zylom.com/activex/zylomgamesplayer.cab
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{3E9DADC2-7A62-43EB-8313-5E2A008A16AD}: NameServer = 192.168.1.1,86.64.145.140
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              0
              1. bon g relancé hijackthis sa ma donner sa

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 21:12:16, on 14/02/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16608)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                C:\WINDOWS\SOUNDMAN.EXE
                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                C:\Launch Manager\LaunchAp.exe
                C:\Launch Manager\HotkeyApp.exe
                C:\Launch Manager\OSD.exe
                C:\Launch Manager\OSDCtrl.exe
                C:\Launch Manager\Wbutton.exe
                C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
                C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
                C:\WINDOWS\system32\rundll32.exe
                C:\Program Files\QuickTime\qttask.exe
                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                C:\Program Files\iPod\bin\iPodService.exe
                C:\Program Files\Windows Live\Messenger\usnsvc.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer optimisé pour MSN
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                O4 - HKLM\..\Run: [LaunchAp] C:\Launch Manager\LaunchAp.exe
                O4 - HKLM\..\Run: [HotkeyApp] C:\Launch Manager\HotkeyApp.exe
                O4 - HKLM\..\Run: [LMgrVolOSD] C:\Launch Manager\OSD.exe
                O4 - HKLM\..\Run: [LMgrOSD] C:\Launch Manager\OSDCtrl.exe
                O4 - HKLM\..\Run: [Wbutton] "C:\Launch Manager\Wbutton.exe"
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [CtrlVol] C:\Launch Manager\CtrlVol.exe
                O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
                O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
                O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [fsc-reminder.exe] C:\WINDOWS\reminder\fsc-reminder.exe 2453871 14
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                O4 - Startup: Pense-bête.lnk = C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE
                O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
                O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
                O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
                O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
                O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game08.zylom.com/activex/zylomgamesplayer.cab
                O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
                O17 - HKLM\System\CCS\Services\Tcpip\..\{3E9DADC2-7A62-43EB-8313-5E2A008A16AD}: NameServer = 192.168.1.1,86.64.145.140
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                0
                1. Contributeur sécurité
                  n'encombre pas ce post!!!!!!!!!!!!!!!!!!!! cré ton propre post , explique tes soucis et colle un rapport hijackthis et navilog
                  0
              2. RAPPORT COMBOFIX

                ComboFix 08-02-15.1 - Gilles 2008-02-14 21:12:54.1 - NTFSx86
                Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1239 [GMT 1:00]
                Endroit: C:\Users\Gilles\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DW1CRMEN\ComboFix[1].exe
                * Création d'un nouveau point de restauration
                .

                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                .

                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\moviebox
                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\moviebox\Uninstall.lnk
                C:\Windows\system32\Cfx32.lic
                C:\Windows\system32\cfx32.ocx

                .
                ((((((((((((((((((((((((((((( Fichiers créés 2008-01-15 to 2008-02-15 ))))))))))))))))))))))))))))))))))))
                .

                Pas de nouveau fichier créé dans cet espace de temps

                .
                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2008-02-14 20:07 --------- d-----w C:\Program Files\Navilog1
                2008-02-14 16:04 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
                2008-02-14 16:03 54,784 ----a-w C:\Windows\system32\drivers\i8042prt.sys
                2008-02-14 16:03 495,160 ----a-w C:\Windows\system32\drivers\Wdf01000.sys
                2008-02-14 16:03 35,384 ----a-w C:\Windows\system32\drivers\WdfLdr.sys
                2008-02-14 16:03 35,384 ----a-w C:\Windows\system32\drivers\kbdclass.sys
                2008-02-14 16:03 34,360 ----a-w C:\Windows\system32\drivers\mouclass.sys
                2008-02-14 16:03 19,968 ----a-w C:\Windows\system32\drivers\sermouse.sys
                2008-02-14 16:00 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
                2008-02-14 16:00 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
                2008-02-14 16:00 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
                2008-02-14 16:00 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
                2008-02-14 16:00 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
                2008-02-14 16:00 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
                2008-02-14 16:00 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
                2008-02-14 16:00 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
                2008-02-14 16:00 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys
                2008-02-14 16:00 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
                2008-02-14 16:00 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
                2008-02-14 16:00 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
                2008-02-14 15:58 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
                2008-02-11 20:02 --------- d-----w C:\Program Files\Trend Micro
                2008-02-10 21:40 --------- d-----w C:\Users\Gilles\AppData\Roaming\Grisoft
                2008-02-10 21:34 --------- d-----w C:\ProgramData\Yahoo! Companion
                2008-02-10 21:22 --------- d-----w C:\Program Files\Yahoo!
                2008-02-10 21:22 --------- d-----w C:\Program Files\CCleaner
                2008-02-10 19:47 --------- d-----w C:\Program Files\a-squared Anti-Malware
                2008-02-10 09:59 --------- d-----w C:\ProgramData\Lavasoft
                2008-02-10 09:56 --------- d-----w C:\Program Files\Lavasoft
                2008-01-18 20:57 --------- d-----w C:\Program Files\Picasa2
                2008-01-18 18:06 --------- d-----w C:\Program Files\iCarbon
                2008-01-18 17:49 --------- d-----w C:\Program Files\Rapidos!
                2008-01-10 20:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
                2008-01-10 20:53 --------- d-----w C:\Program Files\PowerQuest
                2008-01-10 17:29 400,864 ----a-w C:\Windows\system32\drivers\timntr.sys
                2008-01-10 17:29 32,768 ----a-w C:\Windows\system32\drivers\tifsfilt.sys
                2008-01-10 17:29 120,992 ----a-w C:\Windows\system32\drivers\snapman.sys
                2008-01-10 17:29 --------- d-----w C:\Program Files\Maxtor
                2008-01-10 17:29 --------- d-----w C:\Program Files\Common Files\Maxtor
                2008-01-09 20:08 --------- d-----w C:\Program Files\Windows Sidebar
                2008-01-09 20:08 --------- d-----w C:\Program Files\Windows Mail
                2008-01-09 19:00 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
                2008-01-09 19:00 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
                2007-12-28 15:16 --------- d-----w C:\ProgramData\Elaborate Bytes
                2007-12-28 15:14 --------- d-----w C:\Program Files\Elaborate Bytes
                2007-11-26 15:39 2,923,520 ----a-w C:\Windows\explorer.exe
                2007-08-30 10:37 174 --sha-w C:\Program Files\desktop.ini
                2007-10-14 20:56 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                2007-10-14 20:56 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                2007-10-14 20:56 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                .

                ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                REGEDIT4
                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 19:59 1232896]
                "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
                "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:55 5674352]
                "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
                "AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2007-05-26 17:19 407724]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-04-13 17:00 1006264]
                "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
                "NeroFilterCheck"="C:\Windows\system32\NeroCheck.exe" [2001-07-09 09:50 155648]
                "MSConfig"="C:\Windows\system32\msconfig.exe" [2006-11-02 10:45 222208]
                "MaxBlastMonitor.exe"="C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe" [2007-08-08 17:26 1169440]
                "AcronisTimounterMonitor"="C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe" [2007-08-08 17:39 1945448]
                "Acronis Scheduler2 Service"="C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe" [2007-08-08 17:31 148760]

                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 22:18 443968]

                C:\Users\Gilles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                CCC.lnk - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe [2006-09-29 09:57:36 49152]
                HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE [2003-03-19 17:08:14 299008]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                "EnableLUA"= 0 (0x0)

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
                "System"="kddst.exe"

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                Authentication Packages REG_MULTI_SZ msv1_0 relog_ap

                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
                --a------ 2005-05-19 14:47 57344 C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe

                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
                --a------ 2007-10-23 22:18 443968 C:\Program Files\Picasa2\PicasaMediaDetector.exe

                R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-12-04 15:52]
                R3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-02-02 21:09]
                R3 yukonwlh;Pilote miniport NDIS6.0 pour contrôleur Ethernet Marvell Yukon;C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 08:30]

                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\ccc-core-static]
                msiexec /fums {395787D8-AB35-3BCE-772B-1C50144B1CDC} /qb
                .
                Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
                "2008-02-15 20:20:00 C:\Windows\Tasks\User_Feed_Synchronization-{C2AC7880-B428-4E20-A15C-5A2F935F76F7}.job"
                - C:\Windows\system32\msfeedssync.exe
                .
                **************************************************************************

                catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-02-15 21:17:27
                Windows 6.0.6000 NTFS

                Balayage processus cachés ...

                Balayage caché autostart entries ...

                Balayage des fichiers cachés ...

                Scan terminé avec succès
                Les fichiers cachés: 0

                **************************************************************************
                .
                ------------------------ Other Running Processes ------------------------
                .
                C:\Windows\system32\Ati2evxx.exe
                C:\Windows\system32\Ati2evxx.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                C:\Windows\ehome\ehmsas.exe
                C:\Windows\DvzCommon\DvzMsgr.exe
                C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe
                C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\Program Files\Reverso\Reverso Translation Server\LogoMedia TranslateDotNet Server.exe
                C:\Program Files\Windows Media Player\wmpnscfg.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Windows\system32\wbem\unsecapp.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\Program Files\Windows Media Player\wmpnetwk.exe
                .
                **************************************************************************
                .
                Temps d'accomplissement: 2008-02-15 21:20:35 - machine was rebooted
                ComboFix-quarantined-files.txt 2008-02-15 20:20:29
                .
                2008-02-14 16:30:40 --- E O F ---

                RAPPORT ANTIVIR

                AntiVir PersonalEdition Classic
                Report file date: vendredi 15 février 2008 21:56

                Scanning for 1109375 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows Vista
                Windows version: (plain) [6.0.6000]
                Username: Gilles
                Computer name: PC-DE-GILLES

                Version information:
                BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 20:47:29
                ANTIVIR2.VDF : 7.0.2.113 1673728 Bytes 08/02/2008 20:47:29
                ANTIVIR3.VDF : 7.0.2.140 184320 Bytes 14/02/2008 20:47:29
                AVEWIN32.DLL : 7.6.0.65 3240448 Bytes 15/02/2008 20:47:29
                AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                AVPACK32.DLL : 7.6.0.3 360488 Bytes 15/02/2008 20:47:29
                AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                Configuration settings for the scan:
                Jobname..........................: Local Hard Disks
                Configuration file...............: c:\program files\avira\antivir personaledition classic\alldiscs.avp
                Logging..........................: low
                Primary action...................: interactive
                Secondary action.................: ignore
                Scan master boot sector..........: off
                Scan boot sector.................: on
                Boot sectors.....................: C:,
                Scan memory......................: on
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: off
                Scan all files...................: Intelligent file selection
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: medium

                Start of the scan: vendredi 15 février 2008 21:56

                The scan of running processes will be started
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
                Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
                Scan process 'HelpPane.exe' - '1' Module(s) have been scanned
                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'lsm.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'wininit.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                20 processes with 20 modules were scanned

                Start scanning boot sectors:
                Boot sector 'C:\'
                [NOTE] No virus was found!

                Starting to scan the registry.
                The registry was scanned ( '26' files ).

                Starting the file scan:

                Begin scan in 'C:\'
                C:\pagefile.sys
                [WARNING] The file could not be opened!
                C:\Users\Gilles\Downloads\Cute FTP Pro 8.0.08.09.2006 + crack + serial - FR powered by Anakin_-.rar
                [0] Archive type: RAR
                --> CuteFTP.Pro.v8.0.08.09.2006\cuteftp.professional.v8.0.08.09.2006.1-patch.exe
                [DETECTION] Is the Trojan horse TR/Patch.F.1
                [INFO] The file was moved to '482a0b42.qua'!
                C:\Users\Gilles\Downloads\Macromedia Studio 8 Fr (dreamweaver 8 - Fireworks 8 - Flash 8) + Kegen.ace
                [0] Archive type: ACE
                --> Video … voir en premier.avi
                [WARNING] Error creating the file
                --> Le concept.doc
                [WARNING] No further files can be extracted from this archive. The archive will be closed
                [WARNING] No further files can be extracted from this archive. The archive will be closed
                C:\Windows\System32\kddst.exe
                [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
                [INFO] The file was moved to '481a13e7.qua'!

                End of the scan: vendredi 15 février 2008 23:42
                Used time: 1:45:55 min

                The scan has been done completely.

                15921 Scanning directories
                409596 Files were scanned
                2 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                0 files were deleted
                0 files were repaired
                2 files were moved to quarantine
                0 files were renamed
                1 Files cannot be scanned
                409594 Files not concerned
                1378 Archives were scanned
                4 Warnings
                6 Notes
                0
                1. Bonsoir jlpjlp,
                  Que dois-je faire à present.
                  S'il te plait. Merci pour ton aide.
                  Gilles.
                  0
                  1. Que dois je faire à present, s'il vous plait
                    Merci.
                    0
                    1. Bonsoir,
                      est ce que quelqu'un peut me dire ce que je dois faire à present.
                      S'il vous plait Merci
                      Gilles.
                      0
                      1. Bonsoir,
                        est ce que quelqu'un peut me dire ce que je dois faire à present.
                        S'il vous plait Merci
                        Gilles.
                        0
                        1. Contributeur sécurité
                          désolé absent....

                          ____________

                          vire ces deux crack en allant dans poste de travail puis C...

                          C:\Users\Gilles\Downloads\Cute FTP Pro 8.0.08.09.2006 + crack + serial - FR powered by Anakin_-.rar

                          C:\Users\Gilles\Downloads\Macromedia Studio 8 Fr (dreamweaver 8 - Fireworks 8 - Flash 8) + Kegen.ace

                          _______________

                          vire ce qui est en quarantaine dans antivir

                          ________________

                          performes un scan a l´aide d´antivir avec les regalges ci dessous et post le rapport ici stp

                          une fois antivir ouvert click surconfiguration et coche la case "expert mode" puis sur l´onglet scanner dans la fenetre du dessous tu va voir : rootkit search click sur le petit + pour deployer et coche la case a coté de ton disk dur
                          puis click sur configuration en haut a droite; dans la nouvelle fenetre a gauche >scanner > coche "scan all files" et en dessous >scanner priority = High
                          coche : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le desir.
                          puis sur la droite coche les case suivantes :
                          scan boot sectors of selected drives
                          scan master boot sectors
                          scan memory
                          search foe rootkit before scan
                          decoche :
                          ignore off line files
                          toujours a gauche > scan > deploie > heuristique > macrovirus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

                          _________________

                          recolle un rapport hiajckhtis et dis tes soucis
                          0
                          1. MErci à toi jlpjlp pour ton aide, j'espere que ton week end était bon.
                            gilles.

                            RAPPORT ANTIVIR

                            AntiVir PersonalEdition Classic
                            Report file date: mardi 19 février 2008 20:26

                            Scanning for 1117323 virus strains and unwanted programs.

                            Licensed to: Avira AntiVir PersonalEdition Classic
                            Serial number: 0000149996-ADJIE-0001
                            Platform: Windows Vista
                            Windows version: (plain) [6.0.6000]
                            Username: SYSTEM
                            Computer name: PC-DE-GILLES

                            Version information:
                            BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                            AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                            AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                            LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                            LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                            ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                            ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 20:47:29
                            ANTIVIR2.VDF : 7.0.2.113 1673728 Bytes 08/02/2008 20:47:29
                            ANTIVIR3.VDF : 7.0.2.162 292864 Bytes 19/02/2008 18:56:01
                            AVEWIN32.DLL : 7.6.0.67 3293696 Bytes 16/02/2008 22:36:58
                            AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                            AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                            AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                            AVPACK32.DLL : 7.6.0.3 360488 Bytes 15/02/2008 20:47:29
                            AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                            AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                            AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                            NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                            RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                            RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                            SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                            Configuration settings for the scan:
                            Jobname..........................: Complete system scan
                            Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                            Logging..........................: low
                            Primary action...................: interactive
                            Secondary action.................: ignore
                            Scan master boot sector..........: on
                            Scan boot sector.................: on
                            Boot sectors.....................: C:,
                            Scan memory......................: on
                            Process scan.....................: on
                            Scan registry....................: on
                            Search for rootkits..............: on
                            Scan all files...................: All files
                            Scan archives....................: on
                            Recursion depth..................: 20
                            Smart extensions.................: on
                            Macro heuristic..................: on
                            File heuristic...................: high

                            Start of the scan: mardi 19 février 2008 20:26

                            Starting search for hidden objects.
                            '80813' objects were checked, '0' hidden objects were found.

                            The scan of running processes will be started
                            Scan process 'avscan.exe' - '1' Module(s) have been scanned
                            Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                            Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
                            Scan process 'iexplore.exe' - '1' Module(s) have been scanned
                            Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
                            Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
                            Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
                            Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
                            Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                            Scan process 'alg.exe' - '1' Module(s) have been scanned
                            Scan process 'CCC.exe' - '1' Module(s) have been scanned
                            Scan process 'FxSvr2.exe' - '1' Module(s) have been scanned
                            Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
                            Scan process 'svchost.exe' - '1' Module(s) have been scanned
                            Scan process 'svchost.exe' - '1' Module(s) have been scanned
                            Scan process 'svchost.exe' - '1' Module(s) have been scanned
                            Scan process 'HOTSYNC.EXE' - '1' Module(s) have been scanned
                            Scan process 'LogoMedia TranslateDotNet Server.exe' - '1' Module(s) have been scanned
                            Scan process 'DvzMsgr.exe' - '1' Module(s) have been scanned
                            Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
                            Scan process 'sched.exe' - '1' Module(s) have been scanned
                            Scan process 'schedul2.exe' - '1' Module(s) have been scanned
                            Scan process 'AnyDVD.exe' - '1' Module(s) have been scanned
                            Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
                            Scan process 'MOM.exe' - '1' Module(s) have been scanned
                            Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                            Scan process 'ehtray.exe' - '1' Module(s) have been scanned
                            Scan process 'sidebar.exe' - '1' Module(s) have been scanned
                            Scan process 'LogiTray.exe' - '1' Module(s) have been scanned
                            Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                            Scan process 'schedhlp.exe' - '1' Module(s) have been scanned
                            Scan process 'TimounterMonitor.exe' - '1' Module(s) have been scanned
                            Scan process 'MaxBlastMonitor.exe' - '1' Module(s) have been scanned
                            Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
                            Scan process 'explorer.exe' - '1' Module(s) have been scanned
                            Scan process 'dwm.exe' - '1' Module(s) have been scanned
                            Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                            Scan process 'svchost.exe' - '1' Module(s) have been scanned
                            Scan process 'avguard.exe' - '1' Module(s) have been scanned
                            Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                            Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
                            Scan process 'svchost.exe' - '1' Module(s) have been scanned
                            Scan process 'svchost.exe' - '1' Module(s) have been scanned
                            Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
                            Scan process 'audiodg.exe' - '0' Module(s) have been scanned
                            Scan process 'svchost.exe' - '1' Module(s) have been scanned
                            Scan process 'svchost.exe' - '1' Module(s) have been scanned
                            Scan process 'svchost.exe' - '1' Module(s) have been scanned
                            Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
                            Scan process 'svchost.exe' - '1' Module(s) have been scanned
                            Scan process 'svchost.exe' - '1' Module(s) have been scanned
                            Scan process 'svchost.exe' - '1' Module(s) have been scanned
                            Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                            Scan process 'lsm.exe' - '1' Module(s) have been scanned
                            Scan process 'lsass.exe' - '1' Module(s) have been scanned
                            Scan process 'services.exe' - '1' Module(s) have been scanned
                            Scan process 'csrss.exe' - '1' Module(s) have been scanned
                            Scan process 'wininit.exe' - '1' Module(s) have been scanned
                            Scan process 'csrss.exe' - '1' Module(s) have been scanned
                            Scan process 'smss.exe' - '1' Module(s) have been scanned
                            59 processes with 59 modules were scanned

                            Starting master boot sector scan:
                            Master boot sector HD0
                            [NOTE] No virus was found!

                            Start scanning boot sectors:
                            Boot sector 'C:\'
                            [NOTE] No virus was found!

                            Starting to scan the registry.
                            The registry was scanned ( '18' files ).

                            Starting the file scan:

                            Begin scan in 'C:\'
                            C:\pagefile.sys
                            [WARNING] The file could not be opened!
                            C:\$Recycle.Bin\S-1-5-21-1421052672-4129886406-887425490-1000\$RBDQWSU.ace
                            [0] Archive type: ACE
                            --> Video … voir en premier.avi
                            [WARNING] Error creating the file
                            --> Le concept.doc
                            [WARNING] No further files can be extracted from this archive. The archive will be closed
                            [WARNING] No further files can be extracted from this archive. The archive will be closed
                            C:\Users\Gilles\Documents\Adobe Premiere Elements v2.0 Retail Winxp Incl Keymaker-Core.rar
                            [0] Archive type: RAR
                            --> keygen.exe
                            [DETECTION] Contains suspicious code HEUR/Crypted
                            [INFO] The file was moved to '482a36db.qua'!

                            End of the scan: mardi 19 février 2008 21:31
                            Used time: 1:04:30 min

                            The scan has been done completely.

                            16763 Scanning directories
                            412744 Files were scanned
                            0 viruses and/or unwanted programs were found
                            1 Files were classified as suspicious:
                            0 files were deleted
                            0 files were repaired
                            1 files were moved to quarantine
                            0 files were renamed
                            1 Files cannot be scanned
                            412744 Files not concerned
                            1382 Archives were scanned
                            4 Warnings
                            6 Notes
                            80813 Objects were scanned with rootkit scan
                            0 Hidden objects were found

                            RAPPORT HIJACKTHIS

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 21:32:48, on 19/02/2008
                            Platform: Windows Vista (WinNT 6.00.1904)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16609)
                            Boot mode: Normal

                            Running processes:
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\Explorer.EXE
                            C:\Program Files\Windows Defender\MSASCui.exe
                            C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
                            C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
                            C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                            C:\Program Files\Logitech\Video\LogiTray.exe
                            C:\Program Files\Windows Sidebar\sidebar.exe
                            C:\Windows\ehome\ehtray.exe
                            C:\Program Files\MSN Messenger\msnmsgr.exe
                            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                            C:\Windows\ehome\ehmsas.exe
                            C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
                            C:\Windows\DvzCommon\DvzMsgr.exe
                            C:\Program Files\Palm\HOTSYNC.EXE
                            C:\Program Files\Logitech\Video\FxSvr2.exe
                            C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                            C:\Program Files\Windows Media Player\wmpnscfg.exe
                            C:\Windows\system32\wbem\unsecapp.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.exe
                            O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
                            O4 - HKLM\..\Run: [MaxBlastMonitor.exe] C:\Program Files\Maxtor\MaxBlast\MaxBlastMonitor.exe
                            O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Maxtor\MaxBlast\TimounterMonitor.exe
                            O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Maxtor\Schedule2\schedhlp.exe"
                            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                            O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                            O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                            O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
                            O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
                            O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
                            O4 - Startup: CCC.lnk = ?
                            O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
                            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                            O4 - Global Startup: Dataviz Messenger.lnk = C:\Windows\DvzCommon\DvzMsgr.exe
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                            O13 - Gopher Prefix:
                            O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.fr/s/v/26.26/uploader2.cab
                            O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
                            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
                            O17 - HKLM\System\CCS\Services\Tcpip\..\{C4001682-89C7-48F8-B1E2-3896BF36CCD0}: NameServer = 80.10.246.1 81.253.149.2
                            O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe
                            O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
                            O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                            O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            O23 - Service: LEC TranslateDotNet Server - Language Engineering Corporation, LLC - C:\Program Files\Reverso\Reverso Translation Server\LogoMedia TranslateDotNet Server.exe
                            0
                            1. Contributeur sécurité
                              analyse ce fichier sur virus total et colle le rapport: https://www.virustotal.com/gui/

                              C:\$Recycle.Bin\S-1-5-21-1421052672-4129886406-887425490-1000\$RBDQWSU.ace

                              ___________________

                              quels problemes as tu?

                              rq:

                              pour protéger gratos ton ordi

                              http://www.commentcamarche.net/telecharger/logiciel 4 securite

                              mettre un antivirus

                              AVAST en français ou ANTIVIR (en anglais mais très efficace)
                              https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
                              -------------
                              des anti-espions :
                              AD AWARE + SPYBOT +/- si tea timer non active de spybot: WINDOWS DEFENDER ou SPYWARE TERMINATOR

                              +/-
                              SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

                              Rq : spybot et ad-aware on sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
                              --------
                              un pare feu :
                              celui de Windows ou mieux KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)

                              https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
                              https://manuelsdaide.com/contact/
                              http://www.open-files.com/forum/index.php?showtopic=29277
                              http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm

                              -----------

                              CCLEANER pour effacer les traces de surf
                              0
                              1. Salut jlpjlp,
                                Concernant le test virus total cela me marque que le dossier et trop volumineux.

                                Maintenat depuis ce week end, je n'ai eu aucun probleme. Aucune publicité n'est apparu.
                                L'ordi à l'air de tourner correctement.

                                Merci pour les infos de protections.
                                Gilles.
                                0
                                1. Contributeur sécurité
                                  ok
                                  essaye de refaire un scan antivir et colle le rapport
                                  0
                                  1. RAPPORT ANTIVIR

                                    AntiVir PersonalEdition Classic
                                    Report file date: mercredi 20 février 2008 20:43

                                    Scanning for 1118450 virus strains and unwanted programs.

                                    Licensed to: Avira AntiVir PersonalEdition Classic
                                    Serial number: 0000149996-ADJIE-0001
                                    Platform: Windows Vista
                                    Windows version: (plain) [6.0.6000]
                                    Username: SYSTEM
                                    Computer name: PC-DE-GILLES

                                    Version information:
                                    BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                                    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                                    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                                    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                                    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                                    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                                    ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 20:47:29
                                    ANTIVIR2.VDF : 7.0.2.113 1673728 Bytes 08/02/2008 20:47:29
                                    ANTIVIR3.VDF : 7.0.2.169 308736 Bytes 20/02/2008 19:13:59
                                    AVEWIN32.DLL : 7.6.0.67 3293696 Bytes 16/02/2008 22:36:58
                                    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                                    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                                    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                                    AVPACK32.DLL : 7.6.0.3 360488 Bytes 15/02/2008 20:47:29
                                    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                                    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                                    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                                    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                                    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                                    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                                    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                                    Configuration settings for the scan:
                                    Jobname..........................: Complete system scan
                                    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                                    Logging..........................: low
                                    Primary action...................: interactive
                                    Secondary action.................: ignore
                                    Scan master boot sector..........: on
                                    Scan boot sector.................: on
                                    Boot sectors.....................: C:,
                                    Scan memory......................: on
                                    Process scan.....................: on
                                    Scan registry....................: on
                                    Search for rootkits..............: on
                                    Scan all files...................: All files
                                    Scan archives....................: on
                                    Recursion depth..................: 20
                                    Smart extensions.................: on
                                    Macro heuristic..................: on
                                    File heuristic...................: high

                                    Start of the scan: mercredi 20 février 2008 20:43

                                    Starting search for hidden objects.
                                    '81379' objects were checked, '0' hidden objects were found.

                                    The scan of running processes will be started
                                    Scan process 'avscan.exe' - '1' Module(s) have been scanned
                                    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                                    Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
                                    Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
                                    Scan process 'iexplore.exe' - '1' Module(s) have been scanned
                                    Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
                                    Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
                                    Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
                                    Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
                                    Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                                    Scan process 'alg.exe' - '1' Module(s) have been scanned
                                    Scan process 'CCC.exe' - '1' Module(s) have been scanned
                                    Scan process 'FxSvr2.exe' - '1' Module(s) have been scanned
                                    Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'LogoMedia TranslateDotNet Server.exe' - '1' Module(s) have been scanned
                                    Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
                                    Scan process 'sched.exe' - '1' Module(s) have been scanned
                                    Scan process 'schedul2.exe' - '1' Module(s) have been scanned
                                    Scan process 'HOTSYNC.EXE' - '1' Module(s) have been scanned
                                    Scan process 'DvzMsgr.exe' - '1' Module(s) have been scanned
                                    Scan process 'AnyDVD.exe' - '1' Module(s) have been scanned
                                    Scan process 'MOM.exe' - '1' Module(s) have been scanned
                                    Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
                                    Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                                    Scan process 'ehtray.exe' - '1' Module(s) have been scanned
                                    Scan process 'sidebar.exe' - '1' Module(s) have been scanned
                                    Scan process 'LogiTray.exe' - '1' Module(s) have been scanned
                                    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                                    Scan process 'schedhlp.exe' - '1' Module(s) have been scanned
                                    Scan process 'TimounterMonitor.exe' - '1' Module(s) have been scanned
                                    Scan process 'MaxBlastMonitor.exe' - '1' Module(s) have been scanned
                                    Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
                                    Scan process 'explorer.exe' - '1' Module(s) have been scanned
                                    Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                                    Scan process 'dwm.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'avguard.exe' - '1' Module(s) have been scanned
                                    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
                                    Scan process 'audiodg.exe' - '0' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                                    Scan process 'lsm.exe' - '1' Module(s) have been scanned
                                    Scan process 'lsass.exe' - '1' Module(s) have been scanned
                                    Scan process 'services.exe' - '1' Module(s) have been scanned
                                    Scan process 'csrss.exe' - '1' Module(s) have been scanned
                                    Scan process 'wininit.exe' - '1' Module(s) have been scanned
                                    Scan process 'csrss.exe' - '1' Module(s) have been scanned
                                    Scan process 'smss.exe' - '1' Module(s) have been scanned
                                    60 processes with 60 modules were scanned

                                    Starting master boot sector scan:
                                    Master boot sector HD0
                                    [NOTE] No virus was found!

                                    Start scanning boot sectors:
                                    Boot sector 'C:\'
                                    [NOTE] No virus was found!

                                    Starting to scan the registry.
                                    The registry was scanned ( '18' files ).

                                    Starting the file scan:

                                    Begin scan in 'C:\'
                                    C:\pagefile.sys
                                    [WARNING] The file could not be opened!

                                    End of the scan: mercredi 20 février 2008 21:42
                                    Used time: 59:44 min

                                    The scan has been done completely.

                                    16766 Scanning directories
                                    391377 Files were scanned
                                    0 viruses and/or unwanted programs were found
                                    0 Files were classified as suspicious:
                                    0 files were deleted
                                    0 files were repaired
                                    0 files were moved to quarantine
                                    0 files were renamed
                                    1 Files cannot be scanned
                                    391377 Files not concerned
                                    1230 Archives were scanned
                                    1 Warnings
                                    0 Notes
                                    81379 Objects were scanned with rootkit scan
                                    0 Hidden objects were found
                                    0
                                    • 1
                                    • 2