Demande d'analyse HIJACKTHIS SVP !!!......

Résolu
Bonjour,

Voici le bilan réalisé par Hijackthis, ci-quelqu'un peut m'aider, merci !

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:18:08, on 15/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Contrôle parental\fssui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\winamp toolbar\WinampTbServer.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://side.search.ke.voila.fr/voilafr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.miely.free.fr/google_chti/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://side.search.ke.voila.fr/voilafr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb126\SearchSettings.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Contrôle parental\fssbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb126\SearchSettings.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S1317.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [ZNsoft Optimizer Xp] C:\Program Files\ZNsoft Corporation\ZNsoft Optimizer Xp\ZNsoft Xp.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Contrôle parental\fssui.exe" -autorun
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\DOCUME~1\Bat\LOCALS~1\Temp\E_SA5F.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [messengerskinner] C:\Program Files\MessengerSkinner\MessengerSkinner.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB5480] command /c del "C:\Program Files\MessengerSkinner\download\defaultPack.cab"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: PrintKey 2000 Fr.lnk = C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\microsoft office\office10\OSA.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Recherche sur eBay - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\VOILAFR_TOOLBAR\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O24 - Desktop Component 0: (no name) - http://srx.fr.ebayrtm.com/
Configuration: Windows XP
Internet Explorer 7.0

19 réponses

  1. Y a plein d infection dans ton rapport je te conseil de lancer ton antivirus
    1. G!rly ! voici le rapport Navilog1 : si tu peux continuer à m'aider merci !...

      Search Navipromo version 3.5.0 commencé le 16/03/2008 à 14:00:20,25

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Mise à jour le 04.03.2008 à 17h00 par IL-MAFIOSO

      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.11
      Système de fichiers : NTFS

      Executé en mode normal

      *** Recherche Programmes installés ***

      *** Recherche dossiers dans C:\WINDOWS ***

      *** Recherche dossiers dans C:\Program Files ***

      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

      *** Recherche dossiers dans "C:\Documents and Settings\Bat\applic~1" ***

      *** Recherche dossiers dans "C:\Documents and Settings\Bat\locals~1\applic~1" ***

      *** Recherche dossiers dans "C:\Documents and Settings\Bat\menudm~1\progra~1" ***

      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUD?~1\PROGRA~1 ***

      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      Aucun Fichier trouvé

      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans C:\WINDOWS\system32 *

      * Recherche dans "C:\Documents and Settings\Bat\locals~1\applic~1" *

      *** Recherche fichiers ***

      *** Recherche clés spécifiques dans le Registre ***

      HKEY_CURRENT_USER\Software\Lanconfig trouvé !

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :

      2)Recherche Heuristique :

      * Dans C:\WINDOWS\system32 :

      * Dans "C:\Documents and Settings\Bat\locals~1\applic~1" :

      venvdfn.da_ trouvé !
      venvdfn_nav.da_ trouvé !
      venvdfn_navps.da_ trouvé !

      3)Recherche Certificats :

      Certificat OOO-Favorit absent !

      4)Recherche fichiers connus :

      *** Analyse terminée le 16/03/2008 à 14:13:43,82 ***
      1. Contributeur
        salut bat

        la suite :

        Double clique sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
        Au menu principal, choisis 2 et valide.

        Le fix va t'informer qu'il va alors redémarrer ton PC
        Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
        Appuie sur une touche comme demandé.
        (si ton Pc ne redémarre pas automatiquement, fais le toi même)
        Au redémarrage de ton PC, choisis ta session habituelle.

        Patiente jusqu'au message :
        *** Nettoyage Termine le ..... ***
        Le blocnote va s'ouvrir.
        Sauvegarde le rapport de manière à le retrouver
        Referme le blocnote. Ton bureau va réapparaitre

        PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
        Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
        Tape explorer et valide. Celà te fera apparaitre ton bureau.

        puis repost un nouveau hijack this ainsi que le rapport de navilog option 2

        @+
        1. G!rly, comme convenu voici le nouveau rapport hijack this ainsi que le rapport navilog option 2 : MERCI BEAUCOUP !

          A) Le rapport hijack this :

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 17:17:09, on 16/03/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16608)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
          C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
          C:\WINDOWS\system32\slserv.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\WINDOWS\ALCWZRD.EXE
          C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
          C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
          C:\Apps\Powercinema\PCMService.exe
          C:\apps\ABoard\ABoard.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\DAEMON Tools\daemon.exe
          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
          C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
          C:\Program Files\Winamp\winampa.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
          C:\Program Files\Search Settings\SearchSettings.exe
          C:\Program Files\QuickTime\QTTask.exe
          C:\apps\ABoard\AOSD.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Windows Live\Contrôle parental\fssui.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
          C:\Program Files\Microsoft ActiveSync\wcescomm.exe
          C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
          C:\PROGRA~1\MICROS~4\rapimgr.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://side.search.ke.voila.fr/voilafr/
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.miely.free.fr/google_chti/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://side.search.ke.voila.fr/voilafr/
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb126\SearchSettings.dll
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
          O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
          O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Contrôle parental\fssbho.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb126\SearchSettings.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
          O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
          O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
          O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
          O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
          O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
          O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
          O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S1317.tmp" /EF "HKLM"
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
          O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
          O4 - HKLM\..\Run: [ZNsoft Optimizer Xp] C:\Program Files\ZNsoft Corporation\ZNsoft Optimizer Xp\ZNsoft Xp.exe
          O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Contrôle parental\fssui.exe" -autorun
          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
          O4 - HKCU\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\DOCUME~1\Bat\LOCALS~1\Temp\E_SA5F.tmp" /EF "HKCU"
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: PrintKey 2000 Fr.lnk = C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\microsoft office\office10\OSA.EXE
          O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O8 - Extra context menu item: Recherche sur eBay - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
          O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\VOILAFR_TOOLBAR\Cache\SelectedContextSearch.htm
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
          O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
          O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
          O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
          O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
          O24 - Desktop Component 0: (no name) - http://srx.fr.ebayrtm.com/...
      2. Contributeur
        ok

        pase ceci maintenant :

        Télécharge combofix.exe (par sUBs) sur ton Bureau.

        -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

        -> Double clique combofix.exe.
        -> Tape sur la touche 1 (Yes) pour démarrer le scan.
        -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

        NOTE : Le rapport se trouve également ici : C:\Combofix.txt

        Avant d'utiliser ComboFix :

        -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

        -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

        Une fois fait, sur ton bureau double-clic sur Combofix.exe.

        - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

        /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

        - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

        - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

        -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

        -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message ainsi qu´un nouveau rapport hijack this.

        -> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

        @+
        1. Voici donc la suite des rapports Combofix et Hijackthis

          A) Combofix :

          ComboFix 08-03-14.4 - Bat 2008-03-16 17:45:11.2 - NTFSx86
          Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.554 [GMT 1:00]
          Endroit: C:\Documents and Settings\Bat\Mes documents\ComboFix.exe
          .

          ((((((((((((((((((((((((((((( Fichiers créés 2008-02-16 to 2008-03-16 ))))))))))))))))))))))))))))))))))))
          .

          2008-03-15 23:14 . 2008-03-15 23:14 <REP> d-------- C:\Program Files\Trend Micro
          2008-03-14 12:03 . 2008-03-14 12:03 <REP> d-------- C:\Documents and Settings\Bat\DoctorWeb
          2008-03-14 08:52 . 2007-10-17 13:53 43,816 --a------ C:\WINDOWS\system32\drivers\fssfltr.sys
          2008-03-14 08:51 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
          2008-03-14 08:49 . 2008-03-14 08:49 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
          2008-03-14 08:44 . 2008-03-14 08:45 <REP> d-------- C:\Program Files\Windows Live Toolbar
          2008-03-14 08:44 . 2008-03-14 08:44 <REP> d-------- C:\Program Files\Windows Live Favorites
          2008-03-12 14:24 . 2008-03-12 14:24 <REP> d-------- C:\Program Files\iPod
          2008-03-12 14:24 . 2008-03-16 17:14 54,156 --ah----- C:\WINDOWS\QTFont.qfn
          2008-03-12 14:24 . 2008-03-12 14:24 1,409 --a------ C:\WINDOWS\QTFont.for
          2008-03-12 14:23 . 2008-03-12 14:24 <REP> d-------- C:\Program Files\iTunes
          2008-03-12 14:21 . 2008-03-12 14:22 <REP> d-------- C:\Program Files\QuickTime
          2008-03-12 01:20 . 2008-03-12 01:20 2,576 --a------ C:\WINDOWS\system32\settings.aaw
          2008-03-12 01:20 . 2008-03-12 01:20 1,152 --a------ C:\WINDOWS\system32\history.aaw
          2008-03-11 16:44 . 2008-03-11 16:44 <REP> d--hs---- C:\found.001
          2008-03-10 23:56 . 2008-03-10 23:56 <REP> d-------- C:\Program Files\Lavasoft
          2008-03-10 23:55 . 2008-03-10 23:55 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
          2008-03-10 16:30 . 2008-03-10 16:30 <REP> d--hs---- C:\found.000
          2008-03-08 12:07 . 2008-03-08 13:20 <REP> d-------- C:\Program Files\MP3Gain
          2008-03-05 23:37 . 2008-03-06 00:53 <REP> d-------- C:\Documents and Settings\Bat\Application Data\gtk-2.0
          2008-03-05 23:37 . 2008-03-05 23:37 <REP> d-------- C:\Documents and Settings\Bat\.thumbnails
          2008-03-05 23:35 . 2008-03-06 00:53 <REP> d-------- C:\Documents and Settings\Bat\.gimp-2.4
          2008-03-05 23:34 . 2008-03-05 23:34 <REP> d-------- C:\Program Files\GIMP-2.0
          2008-03-01 17:58 . 2003-01-26 11:41 40,960 --a------ C:\WINDOWS\system32\SSubTmr6.dll
          2008-03-01 17:57 . 2008-03-01 17:57 <REP> d-------- C:\Documents and Settings\Bat\Application Data\Search Settings
          2008-03-01 17:53 . 2008-03-01 18:30 <REP> d-------- C:\Program Files\Burrrn
          2008-03-01 17:30 . 2008-03-01 17:30 <REP> d-------- C:\Program Files\Search Settings
          2008-03-01 17:29 . 2008-03-01 17:29 <REP> d-------- C:\Program Files\Free Audio Pack
          2008-02-28 11:17 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
          2008-02-28 11:17 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
          2008-02-28 11:17 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
          2008-02-28 02:02 . 2008-03-15 19:08 <REP> d-------- C:\Program Files\Windows Live
          2008-02-28 02:02 . 2008-03-14 08:39 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
          2008-02-28 02:01 . 2008-03-14 08:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-03-16 16:13 --------- d-----w C:\Program Files\Navilog1
          2008-03-15 21:11 --------- d-----w C:\Program Files\voilafr_toolbar
          2008-03-15 18:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
          2008-03-10 22:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
          2008-03-10 22:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\WholeSecurity
          2008-03-08 12:14 --------- d-----w C:\Documents and Settings\Bat\Application Data\LimeWire
          2008-03-01 17:05 --------- d-----w C:\Program Files\Winamp
          2008-02-29 08:39 --------- d-----w C:\Program Files\Microsoft ActiveSync
          2008-02-28 01:03 --------- d-----w C:\Program Files\MSN Messenger
          2008-02-19 14:05 --------- d-----w C:\Documents and Settings\Bat\Application Data\Winamp
          2008-02-15 09:09 --------- d-----w C:\Program Files\Audacity
          2008-02-13 10:40 --------- d-----w C:\Program Files\Fichiers communs\Adobe
          2008-02-07 10:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
          2008-02-07 10:50 --------- d-----w C:\Program Files\Spybot - Search & Destroy
          2008-02-07 10:48 691,545 ----a-w C:\WINDOWS\unins000.exe
          2008-02-04 21:01 --------- d-----w C:\Documents and Settings\Bat\Application Data\Apple Computer
          2008-02-04 00:04 --------- d-----w C:\Program Files\Google
          2008-02-03 01:44 --------- d-----w C:\Program Files\Acoustica Mixcraft
          2008-02-03 01:36 --------- d-----w C:\Documents and Settings\Bat\Application Data\ESTsoft
          2008-02-03 01:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
          2008-02-03 01:15 --------- d-----w C:\Program Files\Acoustica Shared Effects
          2008-02-02 12:08 --------- d-----w C:\Program Files\Winamp Toolbar
          2008-02-02 12:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
          2008-02-01 10:35 --------- d-----w C:\Program Files\eMule
          2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
          2008-02-01 10:08 --------- d-----w C:\Program Files\LimeWire
          2008-01-30 22:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
          2008-01-30 21:59 --------- d-----w C:\Program Files\Apple Software Update
          2008-01-30 21:58 --------- d-----w C:\Program Files\Fichiers communs\Apple
          2008-01-30 21:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
          2008-01-24 09:40 --------- d-----w C:\Documents and Settings\Nanie.SN402710420008\Application Data\eBay
          2008-01-23 01:04 53,248 ----a-w C:\WINDOWS\fados.exe
          2008-01-23 00:54 --------- d-----w C:\Program Files\Fichiers communs\Atlence
          2008-01-23 00:44 --------- d-----w C:\Program Files\ScreenMates
          2008-01-21 08:52 --------- d-----w C:\Program Files\ZNsoft Corporation
          2008-01-11 05:36 44,544 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
          2007-12-19 22:53 347,136 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
          2007-12-18 09:51 179,584 ------w C:\WINDOWS\system32\dllcache\mrxdav.sys
          2007-12-02 22:58 48,352 ----a-w C:\Documents and Settings\Bat\Application Data\GDIPFONTCACHEV1.DAT
          .

          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          REGEDIT4
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
          2007-12-13 17:49 1185120 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll

          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
          2007-12-17 11:12 56360 --a------ C:\Program Files\Windows Live\Contrôle parental\fssbho.dll

          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
          2008-02-06 17:47 1160544 --a------ C:\Program Files\Search Settings\kb126\SearchSettings.dll

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
          "{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2007-12-13 17:49 1185120]

          [HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
          [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
          [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
          [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
          "{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-12-13 17:49 1185120]

          [HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
          [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
          [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
          [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]
          "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-08 22:18 68856]
          "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
          "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
          "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 21:45 1211176]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 13:00 208952]
          "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 13:00 455168]
          "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 13:00 455168]
          "Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 14:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
          "SoundMan"="SOUNDMAN.EXE" [2004-09-10 17:29 77824 C:\WINDOWS\SoundMan.exe]
          "AlcWzrd"="ALCWZRD.EXE" [2004-09-15 10:20 2557952 C:\WINDOWS\ALCWZRD.EXE]
          "ATIPTA"="C:\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 20:10 339968]
          "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
          "PCMService"="c:\Apps\Powercinema\PCMService.exe" [2004-09-15 21:17 81920]
          "ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 10:31 24576]
          "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
          "NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2003-07-13 01:49 155648]
          "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-09-08 10:34 180269]
          "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-11-08 23:00 128920]
          "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [2007-03-16 11:45 63712]
          "eBayToolbar"="C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe" [2008-01-20 13:03 623856]
          "ZNsoft Optimizer Xp"="C:\Program Files\ZNsoft Corporation\ZNsoft Optimizer Xp\ZNsoft Xp.exe" [2006-06-23 13:50 393216]
          "WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-15 23:54 37376]
          "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
          "SearchSettings"="C:\Program Files\Search Settings\SearchSettings.exe" [2008-02-06 17:47 1036640]
          "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
          "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
          "fssui"="C:\Program Files\Windows Live\Contrôle parental\fssui.exe" [2007-12-17 11:12 243240]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]

          C:\Documents and Settings\Bat\Menu D‚marrer\Programmes\D‚marrage\
          PrintKey 2000 Fr.lnk - C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe [2001-06-25 20:14:14 869888]

          C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
          Microsoft Office.lnk - C:\Program Files\microsoft office\office10\OSA.EXE [2001-02-13 08:01:04 83360]
          Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-09-08 22:18:28 126136]

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
          "NoSMBalloonTip"= 0 (0x0)

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
          "DisableMonitoring"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
          "DisableMonitoring"=dword:00000001

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%ProgramFiles%\\AOL 9.0\\aol.exe"=
          "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
          "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
          "%windir%\\system32\\sessmgr.exe"=
          "C:\\APPS\\Inventime\\my.exe"=
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
          "C:\\Program Files\\LimeWire\\LimeWire.exe"=
          "C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
          "C:\\Program Files\\Messenger\\msmsgs.exe"=
          "C:\\Program Files\\Internet Explorer\\iexplore.exe"=
          "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
          "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
          "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
          "C:\\Program Files\\iTunes\\iTunes.exe"=
          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
          "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
          "8302:TCP"= 8302:TCP:BitComet 8302 TCP
          "8302:UDP"= 8302:UDP:BitComet 8302 UDP
          "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

          R2 fssfltr;FssFltr;C:\WINDOWS\system32\DRIVERS\fssfltr.sys [2007-10-17 13:53]
          R2 fsssvc;Windows Live OneCare Contrôle parental;"C:\Program Files\Windows Live\Contrôle parental\fsssvc.exe" [2007-12-17 11:13]

          .
          Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
          "2008-03-12 12:32:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
          - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
          "2008-03-16 16:25:00 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
          - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
          .
          **************************************************************************

          catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-03-16 17:45:52
          Windows 5.1.2600 Service Pack 2 NTFS

          Balayage processus cachés ...

          Balayage caché autostart entries ...

          Balayage des fichiers cachés ...

          Scan terminé avec succès
          Les fichiers cachés: 0

          **************************************************************************

          [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MysqlInventime]
          "ImagePath"="c:\mysql\bin\mysqld-nt MysqlInventime"
          .
          Temps d'accomplissement: 2008-03-16 17:46:23
          ComboFix2.txt 2008-03-16 16:42:56
          .
          2008-03-15 18:09:12 --- E O F ---


          B) Hijackthis :

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 17:47:01, on 16/03/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16608)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\WINDOWS\ALCWZRD.EXE
          C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
          C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
          C:\Apps\Powercinema\PCMService.exe
          C:\apps\ABoard\ABoard.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\DAEMON Tools\daemon.exe
          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
          C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
          C:\Program Files\Winamp\winampa.exe
          C:\Program Files\Search Settings\SearchSettings.exe
          C:\Program Files\QuickTime\QTTask.exe
          C:\apps\ABoard\AOSD.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Windows Live\Contrôle parental\fssui.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Microsoft ActiveSync\wcescomm.exe
          C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
          C:\PROGRA~1\MICROS~4\rapimgr.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          c:\program files\winamp toolbar\WinampTbServer.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\WINDOWS\explorer.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\WINDOWS\system32\notepad.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.miely.free.fr/google_chti/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb126\SearchSettings.dll
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
          O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
          O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Contrôle parental\fssbho.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb126\SearchSettings.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
          O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
          O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
          O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
          O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
          O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
          O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
          O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
          O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
          O4 - HKLM\..\Run: [ZNsoft Optimizer Xp] C:\Program Files\ZNsoft Corporation\ZNsoft Optimizer Xp\ZNsoft Xp.exe
          O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Contrôle parental\fssui.exe" -autorun
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: PrintKey 2000 Fr.lnk = C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\microsoft office\office10\OSA.EXE
          O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
          O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
          O8 - Extra context menu item: Recherche sur eBay - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
          O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\VOILAFR_TOOLBAR\Cache\SelectedContextSearch.htm
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
          O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
          O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
          O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
          O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
          O24 - Desktop Component 0: (no name) - http://srx.fr.ebayrtm.com/...
          1. Contributeur
            bat,

            la suite :

            Copie le texte ci-dessous :

            File::
            C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
            C:\Program Files\VOILAFR_TOOLBAR\Cache\SelectedContextSearch.htm

            Folder::
            C:\Program Files\Search Settings

            Registry::
            [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "SearchSettings"=-
            [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
            [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

            Ouvre le Bloc-Notes puis colle le texte copié.
            (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
            Sauvegarde ce fichier sous le nom de CFScript.txt.

            Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

            http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif

            Cela va relancer Combofix,

            Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

            Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

            Ne touche à rien tant que le scan n'est pas terminé.

            Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

            S'il n'y a pas de rédémarrage, poste quand même les rapports.

            @+
            1. Salut G!rly ! Re-La suite : combofix et hijackthis :

              A) combofix :

              ComboFix 08-03-14.4 - Bat 2008-03-17 0:30:42.3 - NTFSx86
              Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.550 [GMT 1:00]
              Endroit: C:\Documents and Settings\Bat\Bureau\ComboFix.exe
              Command switches used :: C:\Documents and Settings\Bat\Bureau\CFScript.txt
              * Création d'un nouveau point de restauration

              FILE ::
              C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
              C:\Program Files\VOILAFR_TOOLBAR\Cache\SelectedContextSearch.htm
              .

              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
              .

              C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
              C:\Program Files\Search Settings
              C:\Program Files\Search Settings\kb126\SearchSettings.dll
              C:\Program Files\Search Settings\SearchSettings.exe
              C:\Program Files\VOILAFR_TOOLBAR\Cache\SelectedContextSearch.htm

              .
              ((((((((((((((((((((((((((((( Fichiers créés 2008-02-16 to 2008-03-16 ))))))))))))))))))))))))))))))))))))
              .

              2008-03-15 23:14 . 2008-03-15 23:14 <REP> d-------- C:\Program Files\Trend Micro
              2008-03-14 12:03 . 2008-03-14 12:03 <REP> d-------- C:\Documents and Settings\Bat\DoctorWeb
              2008-03-14 08:52 . 2007-10-17 13:53 43,816 --a------ C:\WINDOWS\system32\drivers\fssfltr.sys
              2008-03-14 08:51 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
              2008-03-14 08:49 . 2008-03-14 08:49 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
              2008-03-14 08:44 . 2008-03-14 08:45 <REP> d-------- C:\Program Files\Windows Live Toolbar
              2008-03-14 08:44 . 2008-03-14 08:44 <REP> d-------- C:\Program Files\Windows Live Favorites
              2008-03-12 14:24 . 2008-03-12 14:24 <REP> d-------- C:\Program Files\iPod
              2008-03-12 14:24 . 2008-03-16 17:14 54,156 --ah----- C:\WINDOWS\QTFont.qfn
              2008-03-12 14:24 . 2008-03-12 14:24 1,409 --a------ C:\WINDOWS\QTFont.for
              2008-03-12 14:23 . 2008-03-12 14:24 <REP> d-------- C:\Program Files\iTunes
              2008-03-12 14:21 . 2008-03-12 14:22 <REP> d-------- C:\Program Files\QuickTime
              2008-03-12 01:20 . 2008-03-12 01:20 2,576 --a------ C:\WINDOWS\system32\settings.aaw
              2008-03-12 01:20 . 2008-03-12 01:20 1,152 --a------ C:\WINDOWS\system32\history.aaw
              2008-03-11 16:44 . 2008-03-11 16:44 <REP> d--hs---- C:\found.001
              2008-03-10 23:56 . 2008-03-10 23:56 <REP> d-------- C:\Program Files\Lavasoft
              2008-03-10 23:55 . 2008-03-10 23:55 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
              2008-03-10 16:30 . 2008-03-10 16:30 <REP> d--hs---- C:\found.000
              2008-03-08 12:07 . 2008-03-08 13:20 <REP> d-------- C:\Program Files\MP3Gain
              2008-03-05 23:37 . 2008-03-06 00:53 <REP> d-------- C:\Documents and Settings\Bat\Application Data\gtk-2.0
              2008-03-05 23:37 . 2008-03-05 23:37 <REP> d-------- C:\Documents and Settings\Bat\.thumbnails
              2008-03-05 23:35 . 2008-03-06 00:53 <REP> d-------- C:\Documents and Settings\Bat\.gimp-2.4
              2008-03-05 23:34 . 2008-03-05 23:34 <REP> d-------- C:\Program Files\GIMP-2.0
              2008-03-01 17:58 . 2003-01-26 11:41 40,960 --a------ C:\WINDOWS\system32\SSubTmr6.dll
              2008-03-01 17:57 . 2008-03-01 17:57 <REP> d-------- C:\Documents and Settings\Bat\Application Data\Search Settings
              2008-03-01 17:53 . 2008-03-01 18:30 <REP> d-------- C:\Program Files\Burrrn
              2008-03-01 17:29 . 2008-03-01 17:29 <REP> d-------- C:\Program Files\Free Audio Pack
              2008-02-28 11:17 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
              2008-02-28 11:17 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
              2008-02-28 11:17 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
              2008-02-28 02:02 . 2008-03-15 19:08 <REP> d-------- C:\Program Files\Windows Live
              2008-02-28 02:02 . 2008-03-14 08:39 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
              2008-02-28 02:01 . 2008-03-14 08:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller

              .
              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
              .
              2008-03-16 19:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
              2008-03-16 16:13 --------- d-----w C:\Program Files\Navilog1
              2008-03-15 21:11 --------- d-----w C:\Program Files\voilafr_toolbar
              2008-03-10 22:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
              2008-03-10 22:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\WholeSecurity
              2008-03-08 12:14 --------- d-----w C:\Documents and Settings\Bat\Application Data\LimeWire
              2008-03-01 17:05 --------- d-----w C:\Program Files\Winamp
              2008-02-29 08:39 --------- d-----w C:\Program Files\Microsoft ActiveSync
              2008-02-28 01:03 --------- d-----w C:\Program Files\MSN Messenger
              2008-02-19 14:05 --------- d-----w C:\Documents and Settings\Bat\Application Data\Winamp
              2008-02-15 09:09 --------- d-----w C:\Program Files\Audacity
              2008-02-13 10:40 --------- d-----w C:\Program Files\Fichiers communs\Adobe
              2008-02-07 10:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
              2008-02-07 10:50 --------- d-----w C:\Program Files\Spybot - Search & Destroy
              2008-02-07 10:48 691,545 ----a-w C:\WINDOWS\unins000.exe
              2008-02-04 21:01 --------- d-----w C:\Documents and Settings\Bat\Application Data\Apple Computer
              2008-02-04 00:04 --------- d-----w C:\Program Files\Google
              2008-02-03 01:44 --------- d-----w C:\Program Files\Acoustica Mixcraft
              2008-02-03 01:36 --------- d-----w C:\Documents and Settings\Bat\Application Data\ESTsoft
              2008-02-03 01:31 --------- d--h--w C:\Program Files\InstallShield Installation Information
              2008-02-03 01:15 --------- d-----w C:\Program Files\Acoustica Shared Effects
              2008-02-02 12:08 --------- d-----w C:\Program Files\Winamp Toolbar
              2008-02-02 12:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
              2008-02-01 10:35 --------- d-----w C:\Program Files\eMule
              2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
              2008-02-01 10:08 --------- d-----w C:\Program Files\LimeWire
              2008-01-30 22:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
              2008-01-30 21:59 --------- d-----w C:\Program Files\Apple Software Update
              2008-01-30 21:58 --------- d-----w C:\Program Files\Fichiers communs\Apple
              2008-01-30 21:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
              2008-01-24 09:40 --------- d-----w C:\Documents and Settings\Nanie.SN402710420008\Application Data\eBay
              2008-01-23 01:04 53,248 ----a-w C:\WINDOWS\fados.exe
              2008-01-23 00:54 --------- d-----w C:\Program Files\Fichiers communs\Atlence
              2008-01-23 00:44 --------- d-----w C:\Program Files\ScreenMates
              2008-01-21 08:52 --------- d-----w C:\Program Files\ZNsoft Corporation
              2008-01-11 05:36 44,544 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
              2007-12-19 22:53 347,136 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
              2007-12-18 09:51 179,584 ------w C:\WINDOWS\system32\dllcache\mrxdav.sys
              2007-12-02 22:58 48,352 ----a-w C:\Documents and Settings\Bat\Application Data\GDIPFONTCACHEV1.DAT
              .

              ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
              .
              .
              REGEDIT4
              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}]
              2007-12-13 17:49 1185120 --a------ C:\Program Files\Winamp Toolbar\winamptb.dll

              [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
              2007-12-17 11:12 56360 --a------ C:\Program Files\Windows Live\Contrôle parental\fssbho.dll

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
              "{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= "C:\Program Files\Winamp Toolbar\winamptb.dll" [2007-12-13 17:49 1185120]

              [HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
              [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
              [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
              [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
              "{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}"= C:\Program Files\Winamp Toolbar\winamptb.dll [2007-12-13 17:49 1185120]

              [HKEY_CLASSES_ROOT\clsid\{ebf2ba02-9094-4c5a-858b-bb198f3d8de2}]
              [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand.1]
              [HKEY_CLASSES_ROOT\TypeLib\{538CD77C-BFDD-49b0-9562-77419CAB89D1}]
              [HKEY_CLASSES_ROOT\WINAMPTB.AOLToolBand]

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]
              "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-08 22:18 68856]
              "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
              "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
              "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 21:45 1211176]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 13:00 208952]
              "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 13:00 455168]
              "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 13:00 455168]
              "Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 14:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
              "SoundMan"="SOUNDMAN.EXE" [2004-09-10 17:29 77824 C:\WINDOWS\SoundMan.exe]
              "AlcWzrd"="ALCWZRD.EXE" [2004-09-15 10:20 2557952 C:\WINDOWS\ALCWZRD.EXE]
              "ATIPTA"="C:\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 20:10 339968]
              "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
              "PCMService"="c:\Apps\Powercinema\PCMService.exe" [2004-09-15 21:17 81920]
              "ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 10:31 24576]
              "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
              "NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2003-07-13 01:49 155648]
              "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-09-08 10:34 180269]
              "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-11-08 23:00 128920]
              "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [2007-03-16 11:45 63712]
              "eBayToolbar"="C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe" [2008-01-20 13:03 623856]
              "ZNsoft Optimizer Xp"="C:\Program Files\ZNsoft Corporation\ZNsoft Optimizer Xp\ZNsoft Xp.exe" [2006-06-23 13:50 393216]
              "WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-01-15 23:54 37376]
              "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
              "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
              "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
              "fssui"="C:\Program Files\Windows Live\Contrôle parental\fssui.exe" [2007-12-17 11:12 243240]

              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
              "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]

              C:\Documents and Settings\Bat\Menu D‚marrer\Programmes\D‚marrage\
              PrintKey 2000 Fr.lnk - C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe [2001-06-25 20:14:14 869888]

              C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
              Microsoft Office.lnk - C:\Program Files\microsoft office\office10\OSA.EXE [2001-02-13 08:01:04 83360]
              Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-09-08 22:18:28 126136]

              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
              "NoSMBalloonTip"= 0 (0x0)

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
              "%ProgramFiles%\\AOL 9.0\\aol.exe"=
              "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
              "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
              "%windir%\\system32\\sessmgr.exe"=
              "C:\\APPS\\Inventime\\my.exe"=
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
              "C:\\Program Files\\LimeWire\\LimeWire.exe"=
              "C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
              "C:\\Program Files\\Messenger\\msmsgs.exe"=
              "C:\\Program Files\\Internet Explorer\\iexplore.exe"=
              "C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
              "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
              "C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
              "C:\\Program Files\\iTunes\\iTunes.exe"=
              "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
              "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
              "8302:TCP"= 8302:TCP:BitComet 8302 TCP
              "8302:UDP"= 8302:UDP:BitComet 8302 UDP
              "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

              R2 fssfltr;FssFltr;C:\WINDOWS\system32\DRIVERS\fssfltr.sys [2007-10-17 13:53]
              R2 fsssvc;Windows Live OneCare Contrôle parental;"C:\Program Files\Windows Live\Contrôle parental\fsssvc.exe" [2007-12-17 11:13]

              .
              Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
              "2008-03-12 12:32:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
              - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
              "2008-03-16 20:25:00 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
              - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
              .
              **************************************************************************

              catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2008-03-17 00:32:12
              Windows 5.1.2600 Service Pack 2 NTFS

              Balayage processus cachés ...

              Balayage caché autostart entries ...

              Balayage des fichiers cachés ...

              Scan terminé avec succès
              Les fichiers cachés: 0

              **************************************************************************

              [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MysqlInventime]
              "ImagePath"="c:\mysql\bin\mysqld-nt MysqlInventime"
              .
              Temps d'accomplissement: 2008-03-17 0:32:46
              ComboFix-quarantined-files.txt 2008-03-16 23:32:38
              ComboFix2.txt 2008-03-16 16:46:24
              ComboFix3.txt 2008-03-16 16:42:56
              .
              2008-03-15 18:09:12 --- E O F ---

              B) Hijackthis :

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 00:33:31, on 17/03/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16608)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\SOUNDMAN.EXE
              C:\WINDOWS\ALCWZRD.EXE
              C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
              C:\Apps\Powercinema\PCMService.exe
              C:\apps\ABoard\ABoard.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\DAEMON Tools\daemon.exe
              C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
              C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
              C:\Program Files\Winamp\winampa.exe
              C:\Program Files\Search Settings\SearchSettings.exe
              C:\Program Files\QuickTime\QTTask.exe
              C:\apps\ABoard\AOSD.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\Windows Live\Contrôle parental\fssui.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Microsoft ActiveSync\wcescomm.exe
              C:\Program Files\Google\Google Updater\GoogleUpdater.exe
              C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
              C:\PROGRA~1\MICROS~4\rapimgr.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\Program Files\Windows Live\Messenger\usnsvc.exe
              c:\program files\winamp toolbar\WinampTbServer.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\WINDOWS\system32\notepad.exe
              C:\WINDOWS\explorer.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.miely.free.fr/google_chti/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
              O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
              O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
              O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Contrôle parental\fssbho.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
              O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
              O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
              O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
              O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
              O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
              O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
              O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
              O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
              O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
              O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
              O4 - HKLM\..\Run: [ZNsoft Optimizer Xp] C:\Program Files\ZNsoft Corporation\ZNsoft Optimizer Xp\ZNsoft Xp.exe
              O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Contrôle parental\fssui.exe" -autorun
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Startup: PrintKey 2000 Fr.lnk = C:\Program Files\PrintKey 2000 Fr\Printkey 2000 Fr.exe
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\microsoft office\office10\OSA.EXE
              O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
              O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
              O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
              O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
              O8 - Extra context menu item: Recherche sur eBay - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
              O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\VOILAFR_TOOLBAR\Cache\SelectedContextSearch.htm
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
              O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
              O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
              O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
              O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
              O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: MysqlInventime - Unknown owner - c:\mysql\bin\mysqld-nt.exe
              O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
              O24 - Desktop Component 0: (no name) - http://srx.fr.ebayrtm.com/...
              1. Contributeur
                Re,

                desinstale ce programme par le panneau de configuration > ajoue et suppression de programme

                C:\Program Files\Search Settings

                il aurait du etre supprimé par combofix mais il est toujours la...

                puis

                a l´aide de hijack this coche et fix les lignes suivantes :

                R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
                O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
                O8 - Extra context menu item: Rechercher avec Voila - file://C:\Program Files\VOILAFR_TOOLBAR\Cache\SelectedContextSearch.htm
                016- DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7}

                comment fixer :

                Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

                -> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

                puis :

                regarde ce tutorial pour mettre ta console java a jour :

                https://www.malekal.com/maintenir-java-adobe-reader-et-le-player-flash-a-jour/

                et instale un par feu :

                par feu : kerio

                Kerio (pare-feu) : reste gratuit après la période d'essai en français
                ----> https://www.zebulon.fr/telechargements/securite/firewalls/kerio.html

                Regarde ce tutoriel si tu as besoin d'aide pour l'installation et la configuration de Kerio
                --> https://kerio.probb.fr/t1-tuto-pour-kerio-4-2

                Plus d'info :
                ->https://kerio.probb.fr/

                par feu : kerio

                telechargement : http://sd-1.archive-host.com/membres/up/1366464061/kerio-kpf-422-911-win.rar

                tuto :

                http://www.malekal.com/kerio_firewall.php#mozTocId721480

                https://www.vulgarisation-informatique.com/kerio.php

                https://kerio.probb.fr/f2-sunbelt-kerio-personal-firewall

                Comodo 3 pro :

                http://www.commentcamarche.net/telecharger/telecharger 34055041 comodo firewall pro

                Online armor :

                http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall

                tuto : https://forum.pcastuces.com/sujet.asp?f=25&s=35606

                ou zone alarm plus facil a configurer mais moins performant

                https://www.malekal.com/tutoriel-zonealarm-firewall/

                anti spyware : bonus ;-)

                spywareblaster :

                http://www.brightfort.com/spywareblaster.html

                c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

                tuto : http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/question-spywareblaser-sujet_174747_1.htm

                puis en fin :

                regarde ceci concernant avast :

                antivir vs avast :

                -> http://forum.malekal.com/ftopic3528.php

                alors je te conseille de le desinstaller et d´installer antivir a la place

                Telecharge et instales l'antivirus Antivir Personal Edition Classic :

                ->https://www.malekal.com/avira-free-security-antivirus-gratuit/

                https://www.avira.com/en/prime

                http://mickael.barroux.free.fr/securite/antivir.php
                http://speedweb1.free.fr/frames2.php?page=tuto5
                <- tutoriel configuration du scanner...

                une fois antivir ouvert click surconfiguration et coche la case "expert mode" puis sur l´onglet scanner dans la fenetre du dessous tu va voir : rootkit search click sur le petit + pour deployer et coche la case a coté de ton disk dur
                puis click sur configuration en haut a droite; dans la nouvelle fenetre a gauche >scanner > coche "scan all files" et en dessous >scanner priority = High
                coche : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le desir.
                puis sur la droite coche les case suivantes :
                scan boot sectors of selected drives
                scan master boot sectors
                scan memory
                search foe rootkit before scan
                decoche :
                ignore off line files
                toujours a gauche > scan > deploie > heuristique > macrovirus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

                Je te dis tous ca car j´aimerais que tu performes un scan entier de ta machine a l´aide d´antivir avec les reglages stipulés ci dessus et que tu post le rapport généré ici stp

                @+
                1. A) g!rly, voici le dernier rapport d'Antivir (téléchargé en lieu et place d'Avast)

                  b) Par contre impossible de mettre à jour Spywareblaster ??? Que faire maintenant de Ad-Aware 2007 ???

                  Que dire : SINON MERCI ! @+ Bat

                  AntiVir PersonalEdition Classic
                  Report file date: lundi 17 mars 2008 09:19

                  Scanning for 1149639 virus strains and unwanted programs.

                  Licensed to: Avira AntiVir PersonalEdition Classic
                  Serial number: 0000149996-ADJIE-0001
                  Platform: Windows XP
                  Windows version: (Service Pack 2) [5.1.2600]
                  Username: SYSTEM
                  Computer name: SN402710420008

                  Version information:
                  BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
                  AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
                  AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
                  LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
                  LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
                  ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
                  ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 08:07:51
                  ANTIVIR2.VDF : 7.0.3.3 2048 Bytes 07/03/2008 08:07:51
                  ANTIVIR3.VDF : 7.0.3.34 182784 Bytes 17/03/2008 08:07:51
                  AVEWIN32.DLL : 7.6.0.73 3334656 Bytes 17/03/2008 08:07:52
                  AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
                  AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
                  AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
                  AVPACK32.DLL : 7.6.0.3 360488 Bytes 17/03/2008 08:07:52
                  AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
                  AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
                  AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
                  NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
                  RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
                  RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
                  SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

                  Configuration settings for the scan:
                  Jobname..........................: Complete system scan
                  Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                  Logging..........................: low
                  Primary action...................: interactive
                  Secondary action.................: ignore
                  Scan master boot sector..........: on
                  Scan boot sector.................: on
                  Boot sectors.....................: C:,
                  Scan memory......................: on
                  Process scan.....................: on
                  Scan registry....................: on
                  Search for rootkits..............: on
                  Scan all files...................: All files
                  Scan archives....................: on
                  Recursion depth..................: 20
                  Smart extensions.................: on
                  Macro heuristic..................: on
                  File heuristic...................: high

                  Start of the scan: lundi 17 mars 2008 09:19

                  Starting search for hidden objects.
                  '47126' objects were checked, '0' hidden objects were found.

                  The scan of running processes will be started
                  Scan process 'avscan.exe' - '1' Module(s) have been scanned
                  Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                  Scan process 'sched.exe' - '1' Module(s) have been scanned
                  Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                  Scan process 'avguard.exe' - '1' Module(s) have been scanned
                  Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
                  Scan process 'winampTbServer.exe' - '1' Module(s) have been scanned
                  Scan process 'iexplore.exe' - '1' Module(s) have been scanned
                  Scan process 'alg.exe' - '1' Module(s) have been scanned
                  Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
                  Scan process 'iPodService.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
                  Scan process 'slserv.exe' - '1' Module(s) have been scanned
                  Scan process 'mdm.exe' - '1' Module(s) have been scanned
                  Scan process 'kpf4ss.exe' - '1' Module(s) have been scanned
                  Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
                  Scan process 'fsssvc.exe' - '1' Module(s) have been scanned
                  Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
                  Scan process 'AOLacsd.exe' - '1' Module(s) have been scanned
                  Scan process 'rapimgr.exe' - '1' Module(s) have been scanned
                  Scan process 'Printkey 2000 Fr.exe' - '1' Module(s) have been scanned
                  Scan process 'GoogleUpdater.exe' - '1' Module(s) have been scanned
                  Scan process 'wcescomm.exe' - '1' Module(s) have been scanned
                  Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
                  Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                  Scan process 'fssui.exe' - '1' Module(s) have been scanned
                  Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
                  Scan process 'QTTask.exe' - '1' Module(s) have been scanned
                  Scan process 'AOSD.EXE' - '1' Module(s) have been scanned
                  Scan process 'winampa.exe' - '1' Module(s) have been scanned
                  Scan process 'eBayTBDaemon.exe' - '1' Module(s) have been scanned
                  Scan process 'apdproxy.exe' - '1' Module(s) have been scanned
                  Scan process 'daemon.exe' - '1' Module(s) have been scanned
                  Scan process 'realsched.exe' - '1' Module(s) have been scanned
                  Scan process 'ABOARD.EXE' - '1' Module(s) have been scanned
                  Scan process 'PCMService.exe' - '1' Module(s) have been scanned
                  Scan process 'jusched.exe' - '1' Module(s) have been scanned
                  Scan process 'atiptaxx.exe' - '1' Module(s) have been scanned
                  Scan process 'ALCWZRD.EXE' - '1' Module(s) have been scanned
                  Scan process 'SoundMan.exe' - '1' Module(s) have been scanned
                  Scan process 'explorer.exe' - '1' Module(s) have been scanned
                  Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                  Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                  Scan process 'aawservice.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                  Scan process 'lsass.exe' - '1' Module(s) have been scanned
                  Scan process 'services.exe' - '1' Module(s) have been scanned
                  Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                  Scan process 'csrss.exe' - '1' Module(s) have been scanned
                  Scan process 'smss.exe' - '1' Module(s) have been scanned
                  56 processes with 56 modules were scanned

                  Starting master boot sector scan:
                  Master boot sector HD0
                  [NOTE] No virus was found!
                  Master boot sector HD1
                  [NOTE] No virus was found!
                  [WARNING] The boot sector file could not be read!
                  [WARNING] Error code: 0x0015
                  Master boot sector HD2
                  [NOTE] No virus was found!
                  [WARNING] The boot sector file could not be read!
                  [WARNING] Error code: 0x0015
                  Master boot sector HD3
                  [NOTE] No virus was found!
                  [WARNING] The boot sector file could not be read!
                  [WARNING] Error code: 0x0015
                  Master boot sector HD4
                  [NOTE] No virus was found!
                  [WARNING] The boot sector file could not be read!
                  [WARNING] Error code: 0x0015

                  Start scanning boot sectors:
                  Boot sector 'C:\'
                  [NOTE] No virus was found!

                  Starting to scan the registry.
                  The registry was scanned ( '35' files ).

                  Starting the file scan:

                  Begin scan in 'C:\' <HDD>
                  C:\hiberfil.sys
                  [WARNING] The file could not be opened!
                  C:\pagefile.sys
                  [WARNING] The file could not be opened!
                  C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MessengerSkinnerrtk4.zip
                  [DETECTION] Contains suspicious code GEN/PwdZIP
                  [INFO] The file was moved to '48512adc.qua'!
                  C:\Documents and Settings\Bat\Mes documents\Navilog1.exe
                  [DETECTION] Contains detection pattern of the dropper DR/Tool.Reboot.F.59
                  [INFO] The file was moved to '48542f4d.qua'!
                  C:\Program Files\Navilog1\Backupnavi\thndqwkffs.exe
                  [DETECTION] Is the Trojan horse TR/Dropper.Gen
                  [INFO] The file was moved to '484c3266.qua'!
                  C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP183\A0032353.exe
                  [DETECTION] Is the Trojan horse TR/Dropper.Gen
                  [INFO] The file was moved to '480e3348.qua'!
                  C:\System Volume Information\_restore{751238CC-FEB5-4605-9EA9-B441EBD3D66D}\RP252\A0058666.exe
                  [DETECTION] Is the Trojan horse TR/Dropper.Gen
                  [INFO] The file was moved to '480e33f5.qua'!
                  C:\WINDOWS\system32\drivers\dtscsi.sys
                  [WARNING] The file could not be opened!
                  C:\WINDOWS\system32\drivers\sptd.sys
                  [WARNING] The file could not be opened!
                  C:\WINDOWS\system32\drivers\sptd1261.sys
                  [WARNING] The file could not be opened!

                  End of the scan: lundi 17 mars 2008 10:12
                  Used time: 53:14 min

                  The scan has been done completely.

                  7243 Scanning directories
                  332625 Files were scanned
                  4 viruses and/or unwanted programs were found
                  1 Files were classified as suspicious:
                  0 files were deleted
                  0 files were repaired
                  5 files were moved to quarantine
                  0 files were renamed
                  5 Files cannot be scanned
                  332621 Files not concerned
                  7484 Archives were scanned
                  5 Warnings
                  84 Notes
                  47126 Objects were scanned with rootkit scan
                  0 Hidden objects were found
                  1. Hello,

                    2 petites questions :

                    1) Impossible de mettre à jour Spywareblaster ???
                    2) Que faire maintenant de Ad-Aware 2007 ??? (qui tourne toujours au démarrage)


                    Merci pour tout et bravo pour la bonne conduite des opérations !

                    @ bientôt B@t
                    1. Contributeur
                      re,

                      tu as installé un par feu qui pourrait bloquer la mise a jour de spywareblaster ?...

                      tu as instalé quel par feu ?

                      garde adaware.

                      @+
                      1. Bonjour,
                        Pardon, en fait, je n'arrive pas à mettre à jour Kerio Personnal firewall... merci, B@t
                    2. Contributeur
                      salut bat,

                      oui c´est pus comprehenssible, kerio ne se met plus a jour, ils ont arreté le developpement...

                      en faite desinstale le

                      passe ccleaner pour corriger les erreures qu´il va laisser...

                      Ccleaner:

                      -> Télécharge Ccleaner (n'installe pas la barre d'outil Yahoo):

                      http://www.commentcamarche.net/telecharger/telechargement 168 ccleaner

                      -> L´installer.

                      -> Une fois installé et lancé :

                      Dans la colonne de gauche, click sur :

                      ->"erreurs" :

                      Coches toutes les cases sous"l´integrité du registre", puis click en bas sur "chercher des erreurs" une fois terminé, clic sur "reparer les erreurs", tu auras un message pour sauvegarder ta base de registre, tu click "oui" puis tu recommence jusqu'à ce qu'il ne trouve plus rien.

                      ps : les sauvegardes que tu auras faites, pourront etre supprimées ulterieurement si tout va bien.

                      ->"nettoyeur"

                      quitte ton navigateur avant de le lancer, dans les propriétés du nettoyeur de l´onglet "windows" et "applications"décoche la derniere case (Avancé si elle est cochée) puis click sur "lancer le nettoyage" qunand il aura terminé le scan click en bas a droite sur "lancer le nettoyage" et accepte par oui.

                      -> Tutoriel en image :

                      https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

                      -> Pour ceux qui voudraient aller plus loin en compagnie de jesses (fonctions avancés) :

                      http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

                      et prends celui ci qui est bien mieux ;-)

                      Online armor :

                      https://www.commentcamarche.net/telecharger/ 34055356 online armor personal firewall

                      tuto : https://forum.pcastuces.com/sujet.asp?f=25&s=35606

                      @+
                      1. Contributeur
                        de rien Bat ;-)

                        fais encore ceci :

                        Désactive ta restauration système:
                        pour cela :
                        Click droit sur poste de travail, dans l´arborescence sur propriétés;
                        dans la nouvelle fenettre click sur l´onglet restauration système;
                        coche la case désactiver la restauration systèm et applique.
                        puis redemarre le pc et click droit sur poste de travail, dans l´arborescence sur propriétés;
                        dans la nouvelle fenettre click sur l´onglet restauration systèm
                        décoche la case désactiver la restauration systèm et applique.

                        puis

                        Télécharge ToolsCleaner sur ton bureau.
                        --> http://www.commentcamarche.net/telecharger/telechargement 34055291 toolsclean(...)
                        # Clique sur Recherche et laisse le scan agir ...
                        # Clique sur Suppression pour finaliser.
                        # Tu peux, si tu le souhaites, te servir des Options facultatives.
                        # Clique sur Quitter pour obtenir le rapport.
                        # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                        @+
                        1. Salut !
                          Le rapport de Toolcleaner est vide !... @+ merci, Bat.
                      2. Contributeur
                        bat,

                        bon et bien tu va supprimer les outils manuellement...

                        supprime

                        hijack this
                        combofix + qoobox et les rapport qui sont a la racine de c
                        navilog par le panneau de configuration > ajoue et suppression de programme
                        toolcleaner

                        Voila ;-)

                        Nos chemins se separent ici ...

                        bonne continuation a toi`

                        Bye

                        g!rly`
                        1. UN GRAND MERCI POUR TOUT, FELICITATIONS¨POUR LES COMPETENCES EN INFORMATIQUE, LE GUIDAGE ET LA SUPPRESSION DES VILAINES BESTIOLES !!!
                          @+ B@t
                      3. Contributeur
                        De rien bat, c´etait un plaisir ;-)

                        Bonne continuation`

                        Bye´

                        g!rly`