Win32

Bonjour,
Sur l'ordi d'un ami, après avoir reçu sur MSN un lien disant : Pk y a ta tof sur ce site".
Il a cliqué dessus, et maintenant, quand il allume son PC, avast! détecte un logiciel malveillant (Win32....)
Quand il éteint son PC, un écran bleu dis qu'il y a un problème sur son ordinateur.

Après l'avoir mis en quarantaine, et supprimer plusieurs fois, le message d' avast! persiste...

Comment faire pour se débarrasser complètement de win32... ?
Configuration: Windows XP
Firefox 2.0.0.13

16 réponses

  1. dans 45 minutes je l'ai

    merci a tout a l'heure
    0
    1. voila, je suis devant l'ordinateur en question...

      que dois-je faire ?
      0

      1. Bonjour/Bonsoir
        • Ne pas surfer ailleurs que sur le site
        • Couper MSN ou tout autre connexion hormis celle sur le site
        • Appliquer exactement et dans l'ordre les procédures indiquées.
        • Au cas ou plusieurs intervenants se manifestent, en choisir un et un seul.

        • Rester devant la machine en rafraichissant souvent le forum pour voir les nouvelles réponses.
        • Répondre sans attendre à toutes les questions posées dans l'ordre ou elles ont étés posées
        • Etre précis dans les réponses. Ne s'en tenir qu'au sujet et rien qu'au sujet.
        • A proscrire : le language SMS.

        • Ne pas quitter tant qu'il n'est pas dit explicitement que le problème est résolu ou qu'il dépasse les compétences de celui ou ceux qui vous aident.
        • Ne pas ouvrir plusieurs discussions sur le même sujet sauf si on vous le demande (Problème non résolu. Ca arrive)

        • Ne pas s'impatienter. L'analyse d'un rapport et la recherche de solutions appropriées prends un certain temps. Inutile donc de reposter le même message. Nous ne vous oublions pas, nous vous cherchons une solution

        • Ne pas oublier : nous sommes bénévoles. Nous mangeons, nous dormons, nous travaillons, nous avons une vie de famille aussi.

        • Les procédures qui vont suivre, bien que largement éprouvées, sont mises en oeuvre aux risques et périls du possesseur de la machine.


        Préparation de la machine
        • Vider la corbeille
        • Fermer toutes les applications

        ================ PareFeu XP - Vista ===================
        • Si un autre pare-feu que celui de windows est installé, vérifier qu'il est actif et passer à l'étape CCleaner

        • Sinon

        pour activer/désactiver le Pare-feu Vista
        pour activer/désactiver le Pare-feu Xp le Pare-feu Vista

        • Activer le pare-Feu si ce n'est déjà fait

        ===================== CCLEANER ========================
        Pour le petit coup de polish.
        • Appliquer la procédure ci-dessous.
        • l'outil pourra être conservé pour faire le ménage de temps en temps en appliquant la même procédure.

        • Télécharger CCLeaner et l'installer sur le bureau en refusant l'installation de la barre Yahoo.
        • Fermer toutes les applications
        • Lancer CCLeaner
        S'il n'est pas en Français cliquer sur Options, Setting, Language et sélectionner Français
        • cocher dans le menu Nettoyeur - onglet Windows :
        Internet Explorer: Fichiers Internet Temporaires, Cookies
        • Système: Vider la Poubelle, Fichiers Temporaires, Presse-papiers
        • Avancé: Vieilles données du Prefetch
        • Décocher dans le menu Options - sous-menu Avancé :
        Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures
        • Cocher dans le menu Nettoyeur - onglet Applications : Internet: Sun Java
        • Cocher , si cela est possible, dans le menu Nettoyeur - onglet Applications :
        Firefox/Mozilla: Cache Internet, Cookies
        • Click sur Analyse
        • Click sur le bouton Lancer le nettoyage dans le menu Nettoyeur.
        • Click sur Registre
        • Sélectionner tout
        • Click sur Chercher des erreurs (En bas)

        Une fois le scan terminé sélectionner tout
        • Click sur Réparer les erreurs sélectionnées

        ==================== HIJACKTHIS ======================

        HijackThis

        • Télécharger HijackThis
        • Installer HijackThis en se laissant guider (Accepter le répertoire proposé sans rien changer)
        • Fermer HijackThis
        • Télécharger sur le bureau HJTNew (Si le Pare-Feu ou l'Anti-virus se manifeste, Ignorer)
        • Fermer toutes les applications
        • Se débrancher d'Internet (Enlever le cable, c'est encore la meilleure solution)
        • Lancer HJTNew.exe (Si le Pare-Feu ou l'Anti-virus se manifeste, Ignorer)
        Ne pas s'étonner pour HJTNew, rien ne s'affiche, juste une fenêtre qui s'ouvre et se ferme aussitôt. C'est normal.
        • Click sur Do a system scan and save a logfile
        • Copier/Coller le rapport dans le prochain message
        • Supprimer HJTNew.exe (sinon l'Anti-virus risque de se manifester souvent) puis
        • Attendre les instructions
        _
        0
        1. Voici le rapport :

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 16:14:32, on 06/04/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16608)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\LEXBCES.EXE
          C:\WINDOWS\system32\LEXPPS.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
          C:\WINDOWS\System32\FTRTSVC.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\RunDLL32.exe
          C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\PROGRA~1\INCRED~1\bin\IMApp.exe
          C:\Program Files\MSN Messenger\usnsvc.exe
          C:\Program Files\Trend Micro\HijackThis\MonJack.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
          F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\Huguette\LOCALS~1\Temp\winlogon.exe
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
          O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
          O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
          O4 - HKLM\..\Run: [VF0060 STISvc] RunDLL32.exe V0060Pin.dll,RunDLL32EP 513
          O4 - HKLM\..\Run: [EPSON Stylus DX5000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\WINDOWS\TEMP\E_S10E.tmp" /EF "HKLM"
          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
          O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\GestMaj.exe GestionnaireInternet.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
          O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
          O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
          O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
          O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
          O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
          O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
          O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
          O24 - Desktop Component 0: (no name) - http://www.jeuxvideo.com/articles/0000/images/pc/f/fi21pc0b.jpg
          0
          1. ======================== SDFIX ========================

            • Télécharger SDFix sur le bureau
            • Double-Click sur le fichier SDFix.EXE et se laisser guider pour l'installation
            • Le programme s'installe dans le répertoire C:\SDFix

            Il est indispensable d'effectuer le nettoyage avec SDFix en mode sans échec.
            ------
            • Redémarrer en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
            • Attention, pas d’accès à internet dans ce mode. Enregistrer ou imprimer les consignes.

            • Relancer le Pc et tapoter la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
            • Avec les touches « flèches », sélectionner Mode sans échec ==> entrée ==>nom utilisateur habituel
            -------
            • Une fois en mode sans échec, cliquer sur le menu Démarrer puis Exécuter et coller la commande suivant : C:\SDFix\RunThis.bat
            • Taper Y puis appuyer sur la touche Entrée du clavier, afin de lancer le nettoyage !
            • SDFix va procéder au nettoyage, patience...cela peut durer une trentaine de minutes
            • Une fenêtre indique que SDFix doit redémarrer l'ordinateur afin de terminer le nettoyage.
            -------
            • Appuyer sur une touche du clavier pour redémarrer le PC.
            • Au redémarrage du PC, SDFix indique que le nettoyage est terminé.
            • Appuyer sur une touche du clavier afin d'ouvrir le rapport créé par SDFix.
            • Il peut être enregistré si besoin, par exemple si on demande de le poster sur un forum (menu Edition / Enregistrer sous).
            • Sans quoi le rapport sera quand même sauvegardé dans le fichier suivant : Report.txt
            dans le dossier SDFix (ex : C:\SDFix\Report.txt) + un nouveaur rapport HiJackThis
            0
            1. [b]SDFix: Version 1.167 [/b]
              Run by Huguette on 06/04/2008 at 16:52

              Microsoft Windows XP [version 5.1.2600]
              Running From: C:\DOCUME~1\Huguette\Bureau\SDFix

              [b]Checking Services [/b]:

              Restoring Windows Registry Values
              Restoring Windows Default Hosts File

              Rebooting

              [b]Checking Files [/b]:

              Trojan Files Found:

              C:\WINDOWS\system32\real.txt - Deleted

              Removing Temp Files

              [b]ADS Check [/b]:

              [b]Final Check [/b]:

              catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2008-04-06 17:01:36
              Windows 5.1.2600 Service Pack 2 NTFS

              scanning hidden processes ...

              scanning hidden services & system hive ...

              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001060eb3bcf]
              "001b9865ed0c"=hex:7a,56,16,31,0a,10,11,d5,a4,bb,73,84,e0,5d,51,b1
              "001d254d2466"=hex:16,87,70,53,8c,b3,4d,6c,9d,9c,8d,b2,8a,4c,dd,a3
              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001060eb3bcf]
              "001b9865ed0c"=hex:7a,56,16,31,0a,10,11,d5,a4,bb,73,84,e0,5d,51,b1
              "001d254d2466"=hex:16,87,70,53,8c,b3,4d,6c,9d,9c,8d,b2,8a,4c,dd,a3

              scanning hidden registry entries ...

              scanning hidden files ...

              scan completed successfully
              hidden processes: 0
              hidden services: 0
              hidden files: 0

              [b]Remaining Services [/b]:

              Authorized Application Key Export:

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
              "C:\\Program Files\\Securitoo\\av_fw\\backweb\\1044199\\Program\\backWeb-1044199.exe"="C:\\Program Files\\Securitoo\\av_fw\\backweb\\1044199\\Program\\backWeb-1044199.exe:*:Disabled:backWeb-1044199"
              "C:\\Program Files\\Securitoo\\av_fw\\backweb\\8520111\\Program\\fspex.exe"="C:\\Program Files\\Securitoo\\av_fw\\backweb\\8520111\\Program\\fspex.exe:*:Enabled:Securitoo Antivirus Firewall"
              "C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"="C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD:*:Disabled:Age of Empires II"
              "C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"="C:\\Program Files\\IncrediMail\\bin\\IMApp.exe:*:Enabled:IncrediMail"
              "C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
              "C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"
              "C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"="C:\\Program Files\\IncrediMail\\bin\\ImLc.exe:*:Enabled:IncrediMail"
              "C:\\Program Files\\UBISOFT\\SCRABBLE© 2005 EDITION\\Scrabble2005.exe"="C:\\Program Files\\UBISOFT\\SCRABBLE© 2005 EDITION\\Scrabble2005.exe:*:Enabled:Scrabble dition 2005"
              "C:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"="C:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE:*:Disabled:LEXPPS.EXE"
              "C:\\Program Files\\Wanadoo\\WOOBrowser\\WOOBrowser.exe"="C:\\Program Files\\Wanadoo\\WOOBrowser\\WOOBrowser.exe:*:Enabled:Navigateur Internet"
              "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
              "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
              "C:\\Documents and Settings\\Huguette\\Mes documents\\t‚l‚chargements\\incredimail_install.exe"="C:\\Documents and Settings\\Huguette\\Mes documents\\t‚l‚chargements\\incredimail_install.exe:*:Enabled:IncrediMail Installer"
              "C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
              "C:\\DOCUME~1\\Huguette\\LOCALS~1\\Temp\\winlogon.exe"="C:\\DOCUME~1\\Huguette\\LOCALS~1\\Temp\\winlogon.exe:*:Enabled:Flash Driver"

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
              "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
              "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

              [b]Remaining Files [/b]:

              File Backups: - C:\DOCUME~1\Huguette\Bureau\SDFix\backups\backups.zip

              [b]Files with Hidden Attributes [/b]:

              Fri 12 Mar 2004 54,384 A..H. --- "C:\Program Files\AOL 9.0\aolphx.exe"
              Fri 12 Mar 2004 156,784 A..H. --- "C:\Program Files\AOL 9.0\aoltray.exe"
              Fri 12 Mar 2004 31,344 A..H. --- "C:\Program Files\AOL 9.0\RBM.exe"
              Tue 12 Dec 2006 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
              Wed 19 Apr 2006 10,198 A..H. --- "C:\Program Files\Microsoft Office\Office\Gestionnaire Office\Off44.tmp"

              [b]Finished![/b]
              0
              1. Comme dit dans l'aide, il me faudrait un rapport Hijackthis
                0
                1. excuse moi, j'ai complètement oublier... le voici :

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 17:46:30, on 06/04/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16608)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\LEXBCES.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\system32\LEXPPS.EXE
                  C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                  C:\WINDOWS\System32\FTRTSVC.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINDOWS\system32\RunDLL32.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                  C:\Program Files\Wanadoo\GestionnaireInternet.exe
                  C:\Program Files\Wanadoo\ComComp.exe
                  C:\PROGRA~1\Wanadoo\Toaster.exe
                  C:\PROGRA~1\Wanadoo\Inactivity.exe
                  C:\PROGRA~1\Wanadoo\PollingModule.exe
                  C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                  C:\Program Files\Wanadoo\Watch.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\MSN Messenger\msnmsgr.exe
                  C:\Program Files\MSN Messenger\usnsvc.exe
                  C:\Program Files\Trend Micro\HijackThis\MonJack.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                  F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\Huguette\LOCALS~1\Temp\winlogon.exe
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
                  O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O4 - HKLM\..\Run: [VF0060 STISvc] RunDLL32.exe V0060Pin.dll,RunDLL32EP 513
                  O4 - HKLM\..\Run: [EPSON Stylus DX5000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\WINDOWS\TEMP\E_S10E.tmp" /EF "HKLM"
                  O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                  O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                  O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\GestMaj.exe GestionnaireInternet.exe
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                  O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
                  O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
                  O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                  O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
                  O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
                  O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                  O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{CF4EAF0B-E038-46AE-AD45-AB2F76D9107D}: NameServer = 80.10.246.130 81.253.149.10
                  O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
                  O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                  O24 - Desktop Component 0: (no name) - http://www.jeuxvideo.com/articles/0000/images/pc/f/fi21pc0b.jpg
                  0
                  1. +CCl
                    +HJT
                    +SDFix
                    MalwaresBytes
                    ---------------------------------- ne pas tenir compte des lignes ci-dessus


                    OK, Il en reste.

                    ================== MalwareBytes =====================

                    Telecharger MalwareBytes

                    Le Tutorial

                    Attention à ce que l'option Perform Full Scan soit cochée

                    Ne pas oublier de supprimer tout ce que MalwaresByte trouve. Bouton Remove Selected après avoir tout sélectionné

                    Poster le rapport et un nouveau rapport HiJackThis
                    0
                    1. Voici le rapport de MalwaresByte :

                      Malwarebytes' Anti-Malware 1.10
                      Version de la base de données: 581

                      Type de recherche: Examen complet (A:\|C:\|E:\|F:\|G:\|H:\|I:\|)
                      Eléments examinés: 129126
                      Temps écoulé: 1 hour(s), 13 minute(s), 52 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 22
                      Valeur(s) du Registre infectée(s): 3
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 10
                      Fichier(s) infecté(s): 8

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      HKEY_CLASSES_ROOT\CLSID\{460ac4db-b0de-4626-a0f0-175dd84dcb9b} (Adware.Hotbar) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{90b5a95a-afd5-4d11-b9bd-a69d53d22226} (Adware.Hotbar) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\shoppingreport.iebutton (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\shoppingreport.iebutton.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\shoppingreport.hbinfoband (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\shoppingreport.hbinfoband.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\shoppingreport.iebuttona (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\shoppingreport.iebuttona.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\shoppingreport.hbax (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\shoppingreport.hbax.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\shoppingreport.rprtctrl (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\shoppingreport.rprtctrl.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Interface\{8ad9ad05-36be-4e40-ba62-5422eb0d02fb} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Interface\{aebf09e2-0c15-43c8-99bf-928c645d98a0} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Interface\{d8560ac2-21b5-4c1a-bdd4-bd12bc83b082} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Typelib\{cdca70d8-c6a6-49ee-9bed-7429d6c477a2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Typelib\{d136987f-e1c4-4ccc-a220-893df03ec5df} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Typelib\{e343edfc-1e6c-4cb5-aa29-e9c922641c80} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\shoppingreport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\Software\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.

                      Valeur(s) du Registre infectée(s):
                      HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07aa283a-43d7-4cbe-a064-32a21112d94d} (Adware.Zango) -> Quarantined and deleted successfully.

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      C:\Program Files\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Program Files\ShoppingReport\Bin (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Program Files\ShoppingReport\cs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Program Files\ShoppingReport\Bin\2.0.26 (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Huguette\Application Data\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Huguette\Application Data\ShoppingReport\cs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Huguette\Application Data\ShoppingReport\cs\db (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Huguette\Application Data\ShoppingReport\cs\dwld (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Huguette\Application Data\ShoppingReport\cs\report (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Huguette\Application Data\ShoppingReport\cs\res2 (Adware.Shopping.Report) -> Quarantined and deleted successfully.

                      Fichier(s) infecté(s):
                      C:\Program Files\ShoppingReport\Uninst.exe (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Huguette\Application Data\ShoppingReport\cs\Config.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Huguette\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Huguette\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Huguette\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Huguette\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Huguette\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Huguette\Application Data\ShoppingReport\cs\res2\WhiteList.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully.

                      voici le rapport de HiJackThis

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 19:12:25, on 06/04/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\LEXBCES.EXE
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\system32\LEXPPS.EXE
                      C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                      C:\WINDOWS\System32\FTRTSVC.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\WINDOWS\system32\RunDLL32.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                      C:\Program Files\Wanadoo\GestionnaireInternet.exe
                      C:\Program Files\Wanadoo\ComComp.exe
                      C:\PROGRA~1\Wanadoo\Toaster.exe
                      C:\PROGRA~1\Wanadoo\Inactivity.exe
                      C:\PROGRA~1\Wanadoo\PollingModule.exe
                      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                      C:\Program Files\Wanadoo\Watch.exe
                      C:\Program Files\MSN Messenger\usnsvc.exe
                      C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                      C:\WINDOWS\system32\RunDLL32.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Program Files\MSN Messenger\msnmsgr.exe
                      C:\Program Files\Trend Micro\HijackThis\MonJack.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/fr/fra/gen/default.htm
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                      F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\Huguette\LOCALS~1\Temp\winlogon.exe,
                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                      O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
                      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                      O4 - HKLM\..\Run: [VF0060 STISvc] RunDLL32.exe V0060Pin.dll,RunDLL32EP 513
                      O4 - HKLM\..\Run: [EPSON Stylus DX5000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\WINDOWS\TEMP\E_S10E.tmp" /EF "HKLM"
                      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                      O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\GestMaj.exe GestionnaireInternet.exe
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                      O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
                      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
                      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                      O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
                      O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
                      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                      O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{CF4EAF0B-E038-46AE-AD45-AB2F76D9107D}: NameServer = 80.10.246.130 81.253.149.10
                      O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
                      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                      O24 - Desktop Component 0: (no name) - http://www.jeuxvideo.com/articles/0000/images/pc/f/fi21pc0b.jpg
                      0
                      1. +CCl
                        +HJT
                        +SDFix
                        +MalwaresBytes
                        ComboFix
                        ---------------------------------- ne pas tenir compte des lignes ci-dessus

                        OK, Il en reste encore.

                        ===================== COMBOFIX =======================
                        </gras>
                        • Imprimer ou sauvegarder avec le bloc-note cette procédure car la suite va se dérouler sans accès à Internet.
                        • Installer ComboFix sur le bureau
                        Note :
                        Le serveur de téléchargement peut être en surcharge et renvoyer une page d'erreur. Il faut insister.

                        • Renommer COMBOFIX.EXE en COMBO-FIX.EXE
                        ------
                        • Redémarrer en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
                        • Attention, pas d’accès à internet dans ce mode. Enregistrer ou imprimer les consignes.

                        • Relancer le Pc et tapoter la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
                        • Avec les touches « flèches », sélectionner Mode sans échec ==> entrée ==>nom utilisateur habituel
                        -------
                        • Désactiver seulement pendant l'utilisation de ComboFix, la protection de l'antivirus et de l'antispyware ceux-ci pouvant entraver le bon fonctionnement de combofix
                        • Fermer toutes les applications en cours
                        • Double-click sur l'icône qui s'est installé sur le bureau
                        • Appuyer sur la touche 1 puis sur entrée:
                        • Laisser Combofix travailler sans se servir de la machine.
                        • Si ComboFix a besoin de redémarrer la machine, laisser faire sinon redémarrer en mode normal.
                        • Copier/Coller le rapport généré dans le bloc-note dans le prochain message
                        (Ce fichier est automatiquement généré et enregistré sous C:\Combofix.txt)
                        0
                        1. J'ai ce rapport... est-ce le bon ?

                          ComboFix 08-04-10.9 - Huguette 2008-04-11 17:12:21.1 - NTFSx86
                          Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.68 [GMT 2:00]
                          Endroit: C:\Documents and Settings\Huguette\Bureau\ComboFix.exe
                          * Création d'un nouveau point de restauration

                          [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                          .

                          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                          .

                          C:\Documents and Settings\Huguette\Application Data\HbTools
                          C:\Documents and Settings\Huguette\Application Data\HbTools\HbTools.log
                          C:\Documents and Settings\Huguette\Application Data\HbTools\v3.0\HbTools\dynamic\3893245.sdf
                          C:\Documents and Settings\Huguette\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\27503
                          C:\Documents and Settings\Huguette\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\34123
                          C:\Documents and Settings\Huguette\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\34186
                          C:\Documents and Settings\Huguette\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\427075
                          C:\Documents and Settings\Huguette\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\52335
                          C:\Documents and Settings\Huguette\Application Data\HbTools\v3.0\HbTools\dynamic\TooltipXML\61779
                          C:\Documents and Settings\Huguette\Application Data\HbTools\v3.0\HbTools\dynamic\ustat\35ec.dat
                          C:\Documents and Settings\Huguette\real.txt
                          C:\WINDOWS\system32\drivers\fad.sys

                          .
                          ((((((((((((((((((((((((((((( Fichiers créés 2008-03-11 to 2008-04-11 ))))))))))))))))))))))))))))))))))))
                          .

                          2008-04-08 15:55 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aswSP.sys
                          2008-04-08 15:55 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\aswFsBlk.sys
                          2008-04-07 20:11 . 2008-04-07 20:11 <REP> d-------- C:\Program Files\Jette7
                          2008-04-07 18:37 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\SYSTEM32\mucltui.dll
                          2008-04-07 18:37 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\SYSTEM32\muweb.dll
                          2008-04-07 18:37 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\SYSTEM32\mucltui.dll.mui
                          2008-04-06 18:30 . 2008-04-06 18:30 1,158 --a------ C:\WINDOWS\mozver.dat
                          2008-04-06 17:54 . 2008-04-06 17:54 <REP> d-------- C:\Documents and Settings\Huguette\Application Data\Malwarebytes
                          2008-04-06 17:53 . 2008-04-06 17:53 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                          2008-04-06 17:53 . 2008-04-06 17:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                          2008-04-06 17:48 . 2008-04-06 17:48 <REP> d-------- C:\Program Files\Windows Live
                          2008-04-06 17:48 . 2008-04-06 17:53 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
                          2008-04-06 17:48 . 2008-04-06 17:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
                          2008-04-06 16:32 . 2008-04-06 16:32 <REP> d-------- C:\WINDOWS\ERUNT
                          2008-04-06 16:10 . 2008-04-06 16:10 <REP> d-------- C:\Program Files\Trend Micro

                          .
                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          2008-04-11 15:10 --------- d-----w C:\Program Files\Wanadoo
                          2008-03-29 17:45 1,146,232 ----a-w C:\WINDOWS\SYSTEM32\aswBoot.exe
                          2008-03-29 17:35 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
                          2008-03-29 17:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
                          2008-03-29 17:27 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
                          2008-03-29 17:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
                          2008-03-29 17:23 95,608 ----a-w C:\WINDOWS\SYSTEM32\AVASTSS.scr
                          2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\SYSTEM32\win32k.sys
                          2008-03-20 08:09 1,845,376 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\win32k.sys
                          2008-03-01 16:28 3,591,680 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
                          2008-02-29 08:57 625,664 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
                          2008-02-29 08:56 70,656 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
                          2008-02-22 10:00 13,824 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
                          2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\SYSTEM32\gdi32.dll
                          2008-02-20 06:51 282,624 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\gdi32.dll
                          2008-02-20 05:35 45,568 ----a-w C:\WINDOWS\SYSTEM32\dnsrslvr.dll
                          2008-02-20 05:35 45,568 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\dnsrslvr.dll
                          2008-02-20 05:35 148,992 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\dnsapi.dll
                          2008-02-15 05:44 161,792 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
                          .

                          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          REGEDIT4
                          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
                          "WOOKIT"="C:\Program Files\Wanadoo\GestMaj.exe" [2004-10-14 16:55 32768]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "VF0060 STISvc"="V0060Pin.dll" [2004-11-01 03:00 36864 C:\WINDOWS\SYSTEM32\V0060Pin.dll]
                          "WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49 20480]
                          "WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55 32768]
                          "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-19 16:10 110592 C:\WINDOWS\SYSTEM32\bthprops.cpl]
                          "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]

                          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                          "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 16:09 15360]
                          "WOOKIT"="C:\Program Files\Wanadoo\GestMaj.exe" [2004-10-14 16:55 32768]
                          "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]

                          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
                          "^SetupICWDesktop"="" []

                          C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                          Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]

                          [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^DSLMON.lnk]
                          path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\DSLMON.lnk
                          backup=C:\WINDOWS\pss\DSLMON.lnkCommon Startup

                          [HKLM\~\startupfolder\C:^Documents and Settings^Huguette^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 1.1.3.lnk]
                          path=C:\Documents and Settings\Huguette\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 1.1.3.lnk
                          backup=C:\WINDOWS\pss\OpenOffice.org 1.1.3.lnkStartup

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
                          --a------ 2004-04-08 06:25 496752 C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative WebCam Tray]
                          --------- 2004-11-18 04:50 258048 C:\Program Files\Creative\Shared Files\CamTray.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
                          --a------ 2004-08-19 16:09 15360 C:\WINDOWS\system32\ctfmon.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
                          --a------ 2004-03-15 02:04 122933 C:\WINDOWS\system32\dla\tfswctrl.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
                          --------- 2004-04-11 12:43 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure Manager]
                          --a------ 2004-12-22 10:28 118832 C:\Program Files\Securitoo\av_fw\Common\FSM32.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure Startup Wizard]
                          --a------ 2005-03-16 15:45 208896 C:\Program Files\Securitoo\av_fw\FSGUI\FSSW.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure TNB]
                          --a------ 2005-01-25 17:13 684032 C:\Program Files\Securitoo\av_fw\TNB\TNBUtil.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flash Driver]
                          C:\DOCUME~1\Huguette\LOCALS~1\Temp\winlogon.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
                          --a------ 2005-10-19 08:59 126976 C:\WINDOWS\system32\hkcmd.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
                          --a------ 2005-10-19 08:59 155648 C:\WINDOWS\system32\igfxtray.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ImInstaller_IncrediMail]
                          C:\DOCUME~1\Huguette\LOCALS~1\Temp\ImInstaller\IncrediMail\incredimail_install.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
                          --a------ 2006-12-07 16:11 204843 C:\Program Files\IncrediMail\bin\IncMail.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaDicoAnglais]
                          --------- 2001-04-26 15:49 221184 C:\Program Files\Micro Application\MediaDICO Anglais\MediaDICOAnglais.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
                          --a------ 2004-10-13 18:24 1694208 C:\Program Files\Messenger\MSMSGS.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\News Service]
                          --a------ 2004-05-06 14:21 372736 C:\Program Files\Securitoo\av_fw\FSGUI\ispnews.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
                          --------- 2004-04-11 21:15 290816 C:\Program Files\Dell\Media Experience\PCMService.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                          --a------ 2004-09-29 03:25 98304 C:\Program Files\QuickTime\qttask.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
                          --a------ 2004-09-29 03:25 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
                          --a------ 2003-11-19 18:48 32881 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
                          --a------ 2003-08-19 02:01 110592 C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
                          -ra------ 2006-03-30 17:45 313472 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
                          C:\WINDOWS\system32\dumprep 0 -u

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan]
                          c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wanadoo Messager.exe]
                          --a------ 2005-02-07 10:30 2342912 C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WooCnxMon]

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOKIT]
                          --------- 2004-10-14 16:55 32768 C:\PROGRA~1\Wanadoo\GestMaj.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]
                          --------- 2004-10-14 16:55 32768 C:\PROGRA~1\Wanadoo\GestMaj.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
                          --------- 2004-08-23 14:49 20480 C:\PROGRA~1\Wanadoo\Watch.exe

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                          "%windir%\\system32\\sessmgr.exe"=
                          "C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
                          "C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
                          "C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
                          "C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
                          "C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
                          "C:\\Program Files\\UBISOFT\\SCRABBLE® 2005 EDITION\\Scrabble2005.exe"=
                          "C:\\WINDOWS\\SYSTEM32\\LEXPPS.EXE"=
                          "C:\\Program Files\\Wanadoo\\WOOBrowser\\WOOBrowser.exe"=
                          "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
                          "C:\\Program Files\\MSN Messenger\\livecall.exe"=
                          "C:\\Documents and Settings\\Huguette\\Mes documents\\téléchargements\\incredimail_install.exe"=
                          "C:\\Program Files\\Internet Explorer\\iexplore.exe"=

                          R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2005-10-24 14:01]
                          R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
                          R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
                          R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2006-05-04 18:50]
                          S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2006-03-02 19:25]
                          S3 jatmlano;jatmlano;C:\DOCUME~1\Huguette\LOCALS~1\Temp\jatmlano.sys []
                          S3 V0060VID;Creative WebCam Live! Ultra;C:\WINDOWS\system32\DRIVERS\V0060Vid.sys [2005-02-02 10:15]

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{18b630ee-cf53-11d9-a5d2-00038a000015}]
                          \Shell\AutoRun\command - E:\loader.exe /no hidden

                          .
                          Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
                          "2004-10-17 21:00:00 C:\WINDOWS\Tasks\Rappel d'abonnement 1 auprès de l'ISP.job"
                          - C:\WINDOWS\System32\OOBE\OOBEBALN.EXE
                          .
                          **************************************************************************

                          catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2008-04-11 17:18:49
                          Windows 5.1.2600 Service Pack 2 NTFS

                          Balayage processus cachés ...

                          Balayage caché autostart entries ...

                          Balayage des fichiers cachés ...

                          Scan terminé avec succès
                          Les fichiers cachés: 0

                          **************************************************************************
                          .
                          Temps d'accomplissement: 2008-04-11 17:21:32
                          ComboFix-quarantined-files.txt 2008-04-11 15:21:25
                          Pre-Run: 53,992,984,576 octets libres
                          Post-Run: 53,988,139,008 octets libres
                          .
                          2008-04-09 14:51:55 --- E O F ---
                          0
                          1. +CCl
                            +HJT
                            +SDFix
                            +MalwaresBytes
                            +ComboFix
                            ---------------------------------- ne pas tenir compte des lignes ci-dessus

                            Oui, remet un rapport HiJackThis STP
                            0
                            1. Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 11:40:02, on 19/04/2008
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              C:\WINDOWS\system32\LEXBCES.EXE
                              C:\WINDOWS\system32\LEXPPS.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                              C:\WINDOWS\System32\FTRTSVC.exe
                              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\RunDLL32.exe
                              C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Wanadoo\GestionnaireInternet.exe
                              C:\Program Files\Wanadoo\ComComp.exe
                              C:\PROGRA~1\Wanadoo\Toaster.exe
                              C:\PROGRA~1\Wanadoo\Inactivity.exe
                              C:\PROGRA~1\Wanadoo\PollingModule.exe
                              C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                              C:\Program Files\Wanadoo\Watch.exe
                              C:\Program Files\IncrediMail\bin\IncMail.exe
                              C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                              C:\Program Files\MSN Messenger\msnmsgr.exe
                              C:\Program Files\MSN Messenger\usnsvc.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Trend Micro\HijackThis\MonJack.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                              O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
                              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                              O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
                              O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                              O4 - HKLM\..\Run: [VF0060 STISvc] RunDLL32.exe V0060Pin.dll,RunDLL32EP 513
                              O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                              O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                              O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\GestMaj.exe GestionnaireInternet.exe
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                              O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
                              O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
                              O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
                              O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
                              O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe
                              O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                              O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                              O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab
                              O17 - HKLM\System\CCS\Services\Tcpip\..\{CF4EAF0B-E038-46AE-AD45-AB2F76D9107D}: NameServer = 80.10.246.130 81.253.149.10
                              O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
                              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
                              O24 - Desktop Component 0: (no name) - http://www.jeuxvideo.com/articles/0000/images/pc/f/fi21pc0b.jpg
                              0
                              1. +CCl
                                +HJT
                                +SDFix
                                +MalwaresBytes
                                +ComboFix
                                ---------------------------------- ne pas tenir compte des lignes ci-dessus


                                ----------------------- Fixer des lignes HitjackThis -------------------

                                Relancer Hitjackthis

                                • Fixer cette/ces lignes


                                O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

                                O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)



                                • Pour fixer cette/ces lignes.
                                • Cliquer sur la petite case à gauche de chaque ligne à fixer.

                                • Une fois cette/ces lignes cochées,
                                • fermer toutes tes fenêtres y compris internet
                                • click sur le bouton en bas FIX CHECKED
                                • Fermer et relancer HitJackThis
                                • Copier/Coller le nouveau rapport sur le forum.

                                -
                                0