Spyware a répetition. - Page 2

  1. Voici le rapport :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 13:07:13, on 10/04/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16643)
    Boot mode: Normal

    Running processes:
    C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\McAfee\MPS\mpsevh.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcvsshld.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\notepad.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Java\jre1.6.0\bin\jusched.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
    C:\Program Files\McAfee\MSK\mskagent.exe
    C:\Program Files\Dell\MediaDirect\PCMService.exe
    C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam\Quickcam.exe
    C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Windows\System32\p2phost.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Windows Mail\WinMail.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
    O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
    O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Spyware-Secure] C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe -s
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
    O4 - Global Startup: QuickSet.lnk = ?
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C1574CE9-52AD-49F2-88DA-FED605F09682}: NameServer = 192.168.0.1
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: EBP Pervasive.SQL - Unknown owner - C:\PVSW\Bin\WGE_SRV.exe
    O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
    O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
    O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
    0
    1. Voici le rapport :

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 13:07:13, on 10/04/2008
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16643)
      Boot mode: Normal

      Running processes:
      C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\McAfee\MPS\mpsevh.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcvsshld.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\notepad.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\Java\jre1.6.0\bin\jusched.exe
      C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
      C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
      C:\Program Files\McAfee\MSK\mskagent.exe
      C:\Program Files\Dell\MediaDirect\PCMService.exe
      C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
      C:\Program Files\Logitech\QuickCam\Quickcam.exe
      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\DellSupport\DSAgnt.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Windows\System32\p2phost.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\Program Files\Digital Line Detect\DLG.exe
      C:\Program Files\Dell\QuickSet\quickset.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\Windows Mail\WinMail.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
      C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
      O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
      O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Spyware-Secure] C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe -s
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
      O4 - Global Startup: QuickSet.lnk = ?
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
      O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{C1574CE9-52AD-49F2-88DA-FED605F09682}: NameServer = 192.168.0.1
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
      O23 - Service: EBP Pervasive.SQL - Unknown owner - C:\PVSW\Bin\WGE_SRV.exe
      O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
      O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
      O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
      O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
      O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
      O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
      O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
      O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
      O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
      O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
      O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
      O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      0
      1. Contributeur
        ok

        tu passeras ceci en rentrant :

        Télécharge combofix.exe (par sUBs) sur ton Bureau.

        -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

        -> Double clique combofix.exe.
        -> Tape sur la touche 1 (Yes) pour démarrer le scan.
        -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

        NOTE : Le rapport se trouve également ici : C:\Combofix.txt

        Avant d'utiliser ComboFix :

        -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

        -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

        Une fois fait, sur ton bureau double-clic sur Combofix.exe.

        - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

        /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

        - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

        - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

        -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

        -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

        -> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

        + post un nouveau rapport hijack this stp

        @+
        0
        1. Tien rapport hijack
          this :

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 15:48:06, on 10/04/2008
          Platform: Windows Vista (WinNT 6.00.1904)
          MSIE: Internet Explorer v7.00 (7.00.6000.16643)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\taskeng.exe
          C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
          C:\Program Files\McAfee\MPS\mpsevh.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\Java\jre1.6.0\bin\jusched.exe
          C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
          C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
          C:\Program Files\McAfee\MSK\mskagent.exe
          C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
          C:\Program Files\Dell\MediaDirect\PCMService.exe
          C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
          C:\Program Files\Logitech\QuickCam\Quickcam.exe
          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\DellSupport\DSAgnt.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Windows\System32\p2phost.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Program Files\Digital Line Detect\DLG.exe
          C:\Program Files\Dell\QuickSet\quickset.exe
          C:\Program Files\Windows Mail\WinMail.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
          C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
          C:\Windows\system32\ctfmon.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O1 - Hosts: ::1 localhost
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
          O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
          O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
          O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
          O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
          O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
          O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
          O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [Spyware-Secure] C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe -s
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
          O4 - Global Startup: QuickSet.lnk = ?
          O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O13 - Gopher Prefix:
          O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
          O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
          O17 - HKLM\System\CCS\Services\Tcpip\..\{C1574CE9-52AD-49F2-88DA-FED605F09682}: NameServer = 192.168.0.1
          O23 - Service: McAfee Application Installer Cleanup (0295601207835010) (0295601207835010mcinstcleanup) - McAfee, Inc. - C:\Windows\TEMP\029560~1.EXE
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
          O23 - Service: EBP Pervasive.SQL - Unknown owner - C:\PVSW\Bin\WGE_SRV.exe
          O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
          O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
          O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
          O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
          O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
          O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
          O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
          O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
          O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
          O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
          O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
          O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
          O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
          O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
          O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
          O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
          O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
          O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
          O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
          O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
          0
          1. Rappord combofix :
            ComboFix 08-04-09.9 - Muriel 2008-04-10 15:52:46.1 - NTFSx86
            Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1194 [GMT 2:00]
            Endroit: C:\Users\Muriel\Desktop\ComboFix.exe
            * Création d'un nouveau point de restauration
            * Resident AV is active

            .

            ((((((((((((((((((((((((((((( Fichiers créés 2008-03-10 to 2008-04-10 ))))))))))))))))))))))))))))))))))))
            .

            Pas de nouveau fichier créé dans cet espace de temps

            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2008-04-10 13:43 --------- d-----w C:\Program Files\Spyware-Secure
            2008-04-10 13:43 --------- d-----w C:\Program Files\McAfee
            2008-04-10 10:55 --------- d-----w C:\Program Files\Trend Micro
            2008-04-10 10:45 --------- d-----w C:\Program Files\Navilog1
            2008-04-10 09:29 --------- d-----w C:\Program Files\Google
            2008-04-10 08:31 --------- d-----w C:\Program Files\Alwil Software
            2008-04-10 07:34 --------- d-----w C:\Program Files\Windows Mail
            2008-04-10 07:33 --------- d-----w C:\ProgramData\Microsoft Help
            2008-04-07 17:23 --------- d--h--r C:\Users\Muriel\AppData\Roaming\SecuROM
            2008-04-07 17:11 --------- d-----w C:\Program Files\EA GAMES
            2008-04-07 07:21 --------- d-----w C:\Program Files\MobeeSoft
            2008-04-07 07:19 4,761,682 ----a-w C:\Users\Muriel\FROTV.1.0-inst.zip
            2008-03-18 18:16 540 ----a-w C:\Users\Muriel\neverwinter.zip
            2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
            2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
            2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
            2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
            2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
            2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
            2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
            2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
            2008-02-28 02:02 --------- d-----w C:\Program Files\Windows Live
            2008-02-24 21:07 --------- d-----w C:\Users\Muriel\AppData\Roaming\Apple Computer
            2008-02-22 14:39 --------- d-----w C:\Program Files\Common Files\Adobe
            2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
            2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
            2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
            2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
            2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
            2008-02-20 10:29 194,560 ----a-w C:\Windows\System32\WebClnt.dll
            2008-02-20 10:29 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
            2008-02-20 10:23 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
            2008-02-20 10:23 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
            2008-02-20 10:23 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
            2008-02-20 10:23 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
            2008-02-20 10:23 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys
            2008-02-20 10:23 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
            2008-02-20 10:23 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
            2008-02-20 10:22 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
            2008-02-20 10:22 24,064 ----a-w C:\Windows\System32\netcfg.exe
            2008-02-20 10:22 22,016 ----a-w C:\Windows\System32\netiougc.exe
            2008-02-20 10:22 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
            2008-02-20 10:22 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
            2008-02-20 10:21 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
            2008-02-20 10:21 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
            2008-02-20 10:21 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
            2008-02-20 10:21 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
            2008-02-20 10:21 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
            2008-02-20 10:21 1,686,528 ----a-w C:\Windows\System32\gameux.dll
            2008-02-20 10:17 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
            2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
            2008-02-18 10:48 --------- d-----w C:\Program Files\iTunes
            2008-02-18 10:48 --------- d-----w C:\Program Files\iPod
            2008-02-18 10:47 --------- d-----w C:\Program Files\Bonjour
            2008-02-18 10:46 --------- d-----w C:\Program Files\QuickTime
            2008-02-18 10:39 --------- d-----w C:\ProgramData\Apple Computer
            2008-02-15 21:44 --------- d-----w C:\Users\Muriel\AppData\Roaming\PeerNetworking
            2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe
            2008-02-01 10:17 587,264 ----a-w C:\Windows\WLXPGSS.SCR
            2008-01-10 18:24 11,776 ----a-w C:\Windows\System32\sbunattend.exe
            2007-09-01 13:25 174 --sha-w C:\Program Files\desktop.ini
            2007-05-05 14:56 241,287 ----a-w C:\Users\Muriel\Mes comptes.zip
            .

            ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            REGEDIT4
            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 20:24 1232896]
            "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2006-11-12 03:19 446976]
            "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
            "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36 201728]
            "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-08-16 16:19 5728112]
            "CollaborationHost"="C:\Windows\system32\p2phost.exe" [2006-11-02 14:35 191488]
            "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-04-10 09:50 171448]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-04-18 00:34 1006264]
            "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-18 01:52 815104]
            "SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-04-11 05:25 77824]
            "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 18:12 90112]
            "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920]
            "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 12:22 221184]
            "MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 16:30 152144]
            "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2006-11-17 23:13 17920]
            "PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2006-10-13 12:31 184320]
            "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 12:35 221184]
            "LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 17:33 563984]
            "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 17:37 2178832]
            "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [2007-03-16 12:45 63712]
            "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
            "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 15:18 267048]
            "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
            "Spyware-Secure"="C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe" [2007-12-21 12:38 598528]

            C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
            Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-04-11 05:29:07 50688]
            QuickSet.lnk - C:\Windows\Installer\{53A01CC6-14B0-4512-A2E7-10D39BF83DC4}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-04-11 05:30:19 45056]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
            "EnableLUA"= 0 (0x0)

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
            "DisableMonitoring"=dword:00000001

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
            "DisableMonitoring"=dword:00000001

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
            "DisableMonitoring"=dword:00000001

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
            "EnableFirewall"= 0 (0x0)

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
            "{51BB28C0-AF88-45E2-91BB-50BE6382192E}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
            "{5F440360-839B-4C38-A380-0DEFB0811791}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
            "{F829845D-9D43-4AF5-9B36-98ACDACA2E29}"= TCP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
            "{E1A4D40B-1A22-426C-AF37-D858A8E10BD1}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
            "{1050EA20-1DAD-4DF1-A847-02D54991B786}"= UDP:C:\PVSW\Bin\w3dbsmgr.exe:Database Service Manager
            "{35444289-44C3-4645-9D9C-6A833C717E62}"= TCP:C:\PVSW\Bin\w3dbsmgr.exe:Database Service Manager
            "{DF98D3A7-E143-4FAA-AABE-A9DE5E1FFF91}"= UDP:C:\PVSW\Bin\w3dbsmgr.exe:Database Service Manager
            "{A3192F3E-E0F6-4F6B-83A8-5B8809310396}"= TCP:C:\PVSW\Bin\w3dbsmgr.exe:Database Service Manager
            "{62304269-AEB4-4D77-883D-DE075977994A}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
            "{6502C0A9-DADA-4D5B-B31E-00F50F3F0F4A}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
            "{3D370D68-E28A-440B-859D-5885459533ED}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
            "{2B9242BD-D458-45E2-B4BD-9A84CFED162F}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
            "EnableFirewall"= 0 (0x0)

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
            "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
            "EnableFirewall"= 0 (0x0)

            R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05]
            R2 EBP Pervasive.SQL;EBP Pervasive.SQL;C:\PVSW\Bin\WGE_SRV.exe [2006-12-07 17:08]
            R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-12 01:10]
            R3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-10-25 06:53]
            S2 0295601207835010mcinstcleanup;McAfee Application Installer Cleanup (0295601207835010);C:\Windows\TEMP\[u]0/u29560~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1789b191-e7da-11db-94b2-806e6f6e6963}]
            \shell\AutoRun\command - E:\Autorun.exe

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0a96b29-a63d-11dc-86ed-00188bc6045e}]
            \shell\Auto\command - bittorrent.exe e
            \shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

            .
            Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
            "2008-04-10 13:42:01 C:\Windows\Tasks\User_Feed_Synchronization-{E9B1139D-0DC9-4BA3-BBD1-C1C32BF445DE}.job"
            - C:\Windows\system32\msfeedssync.exe
            .
            **************************************************************************

            catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2008-04-10 15:56:55
            Windows 6.0.6000 NTFS

            Balayage processus cachés ...

            Balayage caché autostart entries ...

            Balayage des fichiers cachés ...

            Scan terminé avec succès
            Les fichiers cachés: 0

            **************************************************************************
            .
            --------------------- DLLs a chargé sous des processus courants ---------------------

            PROCESS: C:\Windows\Explorer.exe
            -> C:\Windows\system32\DLAAPI_W.DLL
            .
            Temps d'accomplissement: 2008-04-10 15:57:55
            ComboFix-quarantined-files.txt 2008-04-10 13:57:44
            Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
            Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
            .
            2008-04-10 07:33:49 --- E O F ---
            __________________________________________________________________________
            0
            1. Contributeur
              fais analyser

              C:\Windows\system32\p2phost.exe

              sur ce site :

              http://virusscan.jotti.org/de/

              post le reusltat ici stp

              @+
              0
              1. J'ai un autre virus : RemAdm-ProcLaunch!171

                Et mon ordi n'a pas redémarer .
                0
                1. Et comment on scanne avec le site ?
                  0
                  1. Contributeur
                    tu appuie sur parcourir tu recherche le fichier et l´envoie

                    a la fin tu copie le resultat

                    il est ce virus : RemAdm-ProcLaunch!171

                    le chemin ?

                    exemple C:\windows\
                    0
                    1. Un autre virus : EICAR test file
                      Et le rapport :
                      Datei: p2phost.exe_
                      Auslastung: 0% 100%

                      Status: OK (Anmerkung: diese Datei wurde bereits vorher gescannt. Die Scanergebnisse werden daher nicht in der Datenbank gespeichert.)
                      Entdeckte Packprogramme: -
                      Bit9 rapportiert: No threat detected (more info)

                      A-Squared Keine Viren gefunden
                      AntiVir Keine Viren gefunden
                      ArcaVir Keine Viren gefunden
                      Avast Keine Viren gefunden
                      AVG Antivirus Keine Viren gefunden
                      BitDefender Keine Viren gefunden
                      ClamAV Keine Viren gefunden
                      CPsecure Keine Viren gefunden
                      Dr.Web Keine Viren gefunden
                      F-Prot Antivirus Keine Viren gefunden
                      F-Secure Anti-Virus Keine Viren gefunden
                      Fortinet Keine Viren gefunden
                      Ikarus Keine Viren gefunden
                      Kaspersky Anti-Virus Keine Viren gefunden
                      NOD32 Keine Viren gefunden
                      Norman Virus Control Keine Viren gefunden
                      Panda Antivirus Keine Viren gefunden
                      Rising Antivirus Keine Viren gefunden
                      Sophos Antivirus Keine Viren gefunden
                      VirusBuster Keine Viren gefunden
                      VBA32 Keine Viren gefunden

                      0
                      1. Contributeur
                        ok

                        fais ceci :

                        Copie le texte ci-dessous :

                        Folder::
                        C:\Program Files\Spyware-Secure

                        Registry::
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "Spyware-Secure"=-

                        Ouvre le Bloc-Notes puis colle le texte copié.
                        (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
                        Sauvegarde ce fichier sous le nom de CFScript.txt.

                        Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

                        http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif

                        Cela va relancer Combofix,

                        Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

                        Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

                        Ne touche à rien tant que le scan n'est pas terminé.

                        Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

                        S'il n'y a pas de rédémarrage, poste quand même les rapports.

                        @+
                        0
                        1. Rapport COMBOFIX :

                          ComboFix 08-04-09.9 - Muriel 2008-04-10 20:54:35.2 - NTFSx86
                          Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.906 [GMT 2:00]
                          Endroit: C:\Users\Muriel\Desktop\ComboFix.exe
                          Command switches used :: c:\Users\Muriel\AppData\Roaming\Microsoft\Windows\Recent\CFScript.lnk
                          * Création d'un nouveau point de restauration
                          * Resident AV is active

                          .

                          ((((((((((((((((((((((((((((( Fichiers créés 2008-03-10 to 2008-04-10 ))))))))))))))))))))))))))))))))))))
                          .

                          Pas de nouveau fichier créé dans cet espace de temps

                          .
                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          2008-04-10 13:43 --------- d-----w C:\Program Files\Spyware-Secure
                          2008-04-10 13:43 --------- d-----w C:\Program Files\McAfee
                          2008-04-10 10:55 --------- d-----w C:\Program Files\Trend Micro
                          2008-04-10 10:45 --------- d-----w C:\Program Files\Navilog1
                          2008-04-10 09:29 --------- d-----w C:\Program Files\Google
                          2008-04-10 08:31 --------- d-----w C:\Program Files\Alwil Software
                          2008-04-10 07:34 --------- d-----w C:\Program Files\Windows Mail
                          2008-04-10 07:33 --------- d-----w C:\ProgramData\Microsoft Help
                          2008-04-07 17:23 --------- d--h--r C:\Users\Muriel\AppData\Roaming\SecuROM
                          2008-04-07 17:11 --------- d-----w C:\Program Files\EA GAMES
                          2008-04-07 07:21 --------- d-----w C:\Program Files\MobeeSoft
                          2008-04-07 07:19 4,761,682 ----a-w C:\Users\Muriel\FROTV.1.0-inst.zip
                          2008-03-18 18:16 540 ----a-w C:\Users\Muriel\neverwinter.zip
                          2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
                          2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
                          2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
                          2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
                          2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
                          2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
                          2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
                          2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
                          2008-02-28 02:02 --------- d-----w C:\Program Files\Windows Live
                          2008-02-24 21:07 --------- d-----w C:\Users\Muriel\AppData\Roaming\Apple Computer
                          2008-02-22 14:39 --------- d-----w C:\Program Files\Common Files\Adobe
                          2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
                          2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
                          2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
                          2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
                          2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
                          2008-02-20 10:29 194,560 ----a-w C:\Windows\System32\WebClnt.dll
                          2008-02-20 10:29 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
                          2008-02-20 10:23 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
                          2008-02-20 10:23 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
                          2008-02-20 10:23 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
                          2008-02-20 10:23 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
                          2008-02-20 10:23 17,464 ----a-w C:\Windows\system32\drivers\intelide.sys
                          2008-02-20 10:23 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
                          2008-02-20 10:23 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
                          2008-02-20 10:22 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
                          2008-02-20 10:22 24,064 ----a-w C:\Windows\System32\netcfg.exe
                          2008-02-20 10:22 22,016 ----a-w C:\Windows\System32\netiougc.exe
                          2008-02-20 10:22 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
                          2008-02-20 10:22 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
                          2008-02-20 10:21 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
                          2008-02-20 10:21 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
                          2008-02-20 10:21 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
                          2008-02-20 10:21 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
                          2008-02-20 10:21 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
                          2008-02-20 10:21 1,686,528 ----a-w C:\Windows\System32\gameux.dll
                          2008-02-20 10:17 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
                          2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
                          2008-02-18 10:48 --------- d-----w C:\Program Files\iTunes
                          2008-02-18 10:48 --------- d-----w C:\Program Files\iPod
                          2008-02-18 10:47 --------- d-----w C:\Program Files\Bonjour
                          2008-02-18 10:46 --------- d-----w C:\Program Files\QuickTime
                          2008-02-18 10:39 --------- d-----w C:\ProgramData\Apple Computer
                          2008-02-15 21:44 --------- d-----w C:\Users\Muriel\AppData\Roaming\PeerNetworking
                          2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe
                          2008-02-01 10:17 587,264 ----a-w C:\Windows\WLXPGSS.SCR
                          2008-01-10 18:24 11,776 ----a-w C:\Windows\System32\sbunattend.exe
                          2007-09-01 13:25 174 --sha-w C:\Program Files\desktop.ini
                          2007-05-05 14:56 241,287 ----a-w C:\Users\Muriel\Mes comptes.zip
                          .

                          ((((((((((((((((((((((((((((( snapshot@2008-04-10_15.57.19,46 )))))))))))))))))))))))))))))))))))))))))
                          .
                          - 2008-04-10 13:40:34 67,584 --s-a-w C:\Windows\bootstat.dat
                          + 2008-04-10 15:43:37 67,584 --s-a-w C:\Windows\bootstat.dat
                          + 2008-04-10 18:58:32 53,248 ----a-w C:\Windows\PSEXESVC.EXE
                          - 2008-04-10 13:44:03 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                          + 2008-04-10 18:47:53 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                          - 2008-04-10 13:44:03 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                          + 2008-04-10 18:47:53 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                          - 2008-04-10 13:44:03 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                          + 2008-04-10 18:47:53 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                          - 2008-04-10 07:39:57 200,560 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
                          + 2008-04-10 15:43:45 203,392 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S4.bin
                          .
                          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          REGEDIT4
                          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 20:24 1232896]
                          "DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2006-11-12 03:19 446976]
                          "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
                          "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36 201728]
                          "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-08-16 16:19 5728112]
                          "CollaborationHost"="C:\Windows\system32\p2phost.exe" [2006-11-02 14:35 191488]
                          "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-04-10 09:50 171448]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-04-18 00:34 1006264]
                          "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-18 01:52 815104]
                          "SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-04-11 05:25 77824]
                          "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 18:12 90112]
                          "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 12:37 81920]
                          "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 12:22 221184]
                          "MskAgentexe"="C:\Program Files\McAfee\MSK\MskAgent.exe" [2007-01-17 16:30 152144]
                          "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2006-11-17 23:13 17920]
                          "PCMService"="C:\Program Files\Dell\MediaDirect\PCMService.exe" [2006-10-13 12:31 184320]
                          "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 12:35 221184]
                          "LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 17:33 563984]
                          "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 17:37 2178832]
                          "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [2007-03-16 12:45 63712]
                          "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
                          "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 15:18 267048]
                          "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
                          "Spyware-Secure"="C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe" [2007-12-21 12:38 598528]

                          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
                          Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-04-11 05:29:07 50688]
                          QuickSet.lnk - C:\Windows\Installer\{53A01CC6-14B0-4512-A2E7-10D39BF83DC4}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-04-11 05:30:19 45056]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                          "EnableLUA"= 0 (0x0)

                          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
                          "DisableMonitoring"=dword:00000001

                          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
                          "DisableMonitoring"=dword:00000001

                          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
                          "DisableMonitoring"=dword:00000001

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
                          "EnableFirewall"= 0 (0x0)

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                          "{51BB28C0-AF88-45E2-91BB-50BE6382192E}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
                          "{5F440360-839B-4C38-A380-0DEFB0811791}"= UDP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
                          "{F829845D-9D43-4AF5-9B36-98ACDACA2E29}"= TCP:C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
                          "{E1A4D40B-1A22-426C-AF37-D858A8E10BD1}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
                          "{1050EA20-1DAD-4DF1-A847-02D54991B786}"= UDP:C:\PVSW\Bin\w3dbsmgr.exe:Database Service Manager
                          "{35444289-44C3-4645-9D9C-6A833C717E62}"= TCP:C:\PVSW\Bin\w3dbsmgr.exe:Database Service Manager
                          "{DF98D3A7-E143-4FAA-AABE-A9DE5E1FFF91}"= UDP:C:\PVSW\Bin\w3dbsmgr.exe:Database Service Manager
                          "{A3192F3E-E0F6-4F6B-83A8-5B8809310396}"= TCP:C:\PVSW\Bin\w3dbsmgr.exe:Database Service Manager
                          "{62304269-AEB4-4D77-883D-DE075977994A}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
                          "{6502C0A9-DADA-4D5B-B31E-00F50F3F0F4A}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
                          "{3D370D68-E28A-440B-859D-5885459533ED}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
                          "{2B9242BD-D458-45E2-B4BD-9A84CFED162F}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
                          "EnableFirewall"= 0 (0x0)

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
                          "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
                          "EnableFirewall"= 0 (0x0)

                          R1 DLARTL_M;DLARTL_M;C:\Windows\system32\Drivers\DLARTL_M.SYS [2007-02-08 20:05]
                          R2 EBP Pervasive.SQL;EBP Pervasive.SQL;C:\PVSW\Bin\WGE_SRV.exe [2006-12-07 17:08]
                          R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-11-12 01:10]
                          R3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-10-25 06:53]
                          S2 0295601207835010mcinstcleanup;McAfee Application Installer Cleanup (0295601207835010);C:\Windows\TEMP\[u]0/u29560~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1789b191-e7da-11db-94b2-806e6f6e6963}]
                          \shell\AutoRun\command - E:\Autorun.exe

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b0a96b29-a63d-11dc-86ed-00188bc6045e}]
                          \shell\Auto\command - bittorrent.exe e
                          \shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL bittorrent.exe e

                          .
                          Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
                          "2008-04-10 13:42:01 C:\Windows\Tasks\User_Feed_Synchronization-{E9B1139D-0DC9-4BA3-BBD1-C1C32BF445DE}.job"
                          - C:\Windows\system32\msfeedssync.exe
                          .
                          **************************************************************************

                          catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2008-04-10 20:58:44
                          Windows 6.0.6000 NTFS

                          Balayage processus cachés ...

                          Balayage caché autostart entries ...

                          Balayage des fichiers cachés ...

                          Scan terminé avec succès
                          Les fichiers cachés: 0

                          **************************************************************************
                          .
                          --------------------- DLLs a chargé sous des processus courants ---------------------

                          PROCESS: C:\Windows\Explorer.exe
                          -> C:\Windows\system32\DLAAPI_W.DLL
                          .
                          Temps d'accomplissement: 2008-04-10 20:59:58
                          ComboFix-quarantined-files.txt 2008-04-10 18:59:45
                          ComboFix2.txt 2008-04-10 13:57:56
                          Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
                          Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
                          .
                          2008-04-10 07:33:49 --- E O F ---

                          ___________________________________________________________________________
                          Rapport HITJAKTHIS :

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 21:05:59, on 10/04/2008
                          Platform: Windows Vista (WinNT 6.00.1904)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16643)
                          Boot mode: Normal

                          Running processes:
                          C:\Windows\system32\taskeng.exe
                          C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                          C:\Windows\system32\Dwm.exe
                          C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
                          C:\Program Files\McAfee\MPS\mpsevh.exe
                          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                          C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
                          C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                          C:\Program Files\McAfee\MSK\mskagent.exe
                          C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
                          C:\Program Files\Dell\MediaDirect\PCMService.exe
                          C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
                          C:\Program Files\Logitech\QuickCam\Quickcam.exe
                          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\DellSupport\DSAgnt.exe
                          C:\Windows\ehome\ehtray.exe
                          C:\Program Files\Windows Media Player\wmpnscfg.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Windows\System32\p2phost.exe
                          C:\Windows\ehome\ehmsas.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                          C:\Windows\system32\wbem\unsecapp.exe
                          C:\Program Files\Digital Line Detect\DLG.exe
                          C:\Program Files\Dell\QuickSet\quickset.exe
                          C:\Program Files\Windows Mail\WinMail.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                          C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
                          C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
                          C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
                          C:\Windows\system32\ctfmon.exe
                          C:\Windows\system32\notepad.exe
                          C:\Windows\System32\notepad.exe
                          C:\Windows\system32\conime.exe
                          C:\Windows\Explorer.exe
                          C:\Windows\system32\notepad.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          O1 - Hosts: ::1 localhost
                          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
                          O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                          O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
                          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                          O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                          O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
                          O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
                          O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
                          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                          O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
                          O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
                          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [Spyware-Secure] C:\Program Files\Spyware-Secure\Spyware-Secure_trial.exe
                          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                          O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
                          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe -s
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                          O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                          O4 - Global Startup: QuickSet.lnk = ?
                          O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                          O13 - Gopher Prefix:
                          O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
                          O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
                          O17 - HKLM\System\CCS\Services\Tcpip\..\{C1574CE9-52AD-49F2-88DA-FED605F09682}: NameServer = 192.168.0.1
                          O23 - Service: McAfee Application Installer Cleanup (0295601207835010) (0295601207835010mcinstcleanup) - Unknown owner - C:\Windows\TEMP\029560~1.EXE (file missing)
                          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
                          O23 - Service: EBP Pervasive.SQL - Unknown owner - C:\PVSW\Bin\WGE_SRV.exe
                          O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                          O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                          O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                          O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
                          O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
                          O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                          O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
                          O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                          O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
                          O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
                          O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
                          O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                          O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                          O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
                          O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
                          O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
                          O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                          O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                          O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                          O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
                          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                          0
                          1. Contributeur
                            j´arrete
                            merci de trouver un autre helper
                            0
                            Précédent
                            • 1
                            • 2