Erreur sur un RUNDLL

Résolu
Bonjour,
Je suis pas spécialement à l'aise en informatique mais j'ai quand même un anti-virus.
Il y a peu,il m'a découvert un virus dans les fichiers systèmes.Je l'ai donc supprimé mais au démarrage de mon ordinateur ce message apparaît.
RUNDLL
erreur de chargement de C:\WINDOWS\SYSTEM32\GZMRT.DLL
le module spécifié est introuvable.

Donc je voudrais savoir comment régler ce problème j'attends avec impatience votre aide et vos réponses.
Configuration: Windows XP
Internet Explorer 6.0

17 réponses

Résumé de la discussion

Un message d'erreur au démarrage signale le chargement du module C:\WINDOWS\SYSTEM32\GZMRT.DLL introuvable après qu'un antivirus a détecté un virus dans les fichiers système sous Windows XP. Les échanges portent principalement sur l'utilisation d'outils comme HijackThis pour identifier et supprimer les entrées dangereuses, et sur les risques liés à des manipulations manuelles sans guidance. Le fil met en évidence des éléments persistant dans le démarrage et des extensions de navigateur ou BHO associés à gzmrt.dll, et conseille une désinfection guidée par l'analyse des logs avant toute suppression. En cas de contamination avérée, plusieurs messages évoquent aussi des mesures complémentaires, notamment la désactivation puis la réactivation de la restauration système afin de créer un point de restauration sain.

Bobot (l’IA à votre service)
  1. J'ai lu un peu le forum sur ce qui concerne ce problème et je vois que je ne suis pas le seul je vous post mon logfile pour savoir quoi faire,j'attends impatiemment votre aide et vos réponses.Merci d'avance,crodialement Alex1809.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 07:32:31, on 30/05/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Acer\eManager\anbmServ.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\acer\epm\epm-dm.exe
    C:\Program Files\Launch Manager\QtZgAcer.EXE
    C:\Program Files\Acer\eRecovery\Monitor.exe
    C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Alexis Damant\Bureau\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.acer.com/worldwide/selection.html
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: (no name) - {ED19E184-266B-769A-1DF6-74E29B032696} - (no file)
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    R3 - URLSearchHook: (no name) - {E04FB6D1-766B-219F-1DF6-74E29B0473C7} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: rightonads optimizer - {10F3E8BD-257A-4702-A2F5-DC02055B068C} - C:\WINDOWS\system32\gzmrt.dll (file missing)
    O2 - BHO: (no name) - {41DC786B-BC87-B87A-A04D-EF2B57BD8798} - (no file)
    O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-DCF7-F96DA086B434} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: (no name) - {E04FB6D1-766B-219F-1DF6-74E29B0473C7} - (no file)
    O2 - BHO: (no name) - {ED19E184-266B-769A-1DF6-74E29B032696} - (no file)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Adssite Toolbar - {41C29B07-6F91-4966-91BE-2E2841643C83} - C:\Program Files\Adssite Advanced Toolbar\toolbar.dll
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
    O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
    O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
    O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [webHancer Agent] C:\Program Files\webHancer\Programs\whagent.exe
    O4 - HKLM\..\Run: [postSetupCheck] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\gzmrt.dll" DllStart
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{1A9ACC37-30D1-493B-A02E-B3492DE89A50}: NameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C2290D1F-69C8-4A3A-A411-42B684B2A6B7}: NameServer = 192.168.1.1
    O20 - AppInit_DLLs: ,
    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    0
    1. Bonjour,,,

      Tu as essayé ceci ?
      0
      1. Bonjour à toi fahd_zboot ben d'après ce que j'ai lu il faut utiliser hijackthis mais j'ai peur de faire quelque chose de mauvais donc je voudrais des renseignement avant de faire une manipulation.Mais merci de ton conseil mais je comprends pas trop.
        0
    2. Salut ,

      /!\ Manip crée spécialement pour cet utilisateur , ne pas reproduire chez soi ... /!\

      1)Télécharge OTMoveIt2 ( de Old Timer )

      2)Une fois téléchargé double-clique sur OTMoveIt2.exe pour le lancer.

      Assure toi que la case Unregister Dll's and Ocx's soit bien cochée

      3)puis copie les lignes en gras qui se trouvent en dessous :

      C:\WINDOWS\system32\gzmrt.dll
      Emptytemp


      et colle-les dans le cadre de gauche de OTMoveIt : "Paste List Of Files/Folders to Move."
      clique sur MoveIt! pour lancer la suppression.
      le résultat apparaitra dans le cadre Results.
      clique sur Exit pour fermer.
      4) Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

      (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

      5) Il te sera peut-être demander de redémarrer le pc pour achever la suppression -> Accepte ( si il ne fait pas automatiquement , fait-le toi même )

      /!\ Note : Au démarrage ton bureau RISQUE de ne plus apparaître , dans ce cas fait --> CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
      Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

      Tape explorer.exe et valide. Cela fera re-apparaître le Bureau.

      **********************************


      Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

      → Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton Bureau.

      → A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

      → Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

      → Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

      → MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :

      → Dans l'onglet analyse, vérifie que "Exécuter un examen complet" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

      → MBAM analyse ton ordinateur. L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.

      → A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

      → Si des malwares ont été détectés, leur liste s'affiche.
      En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

      → MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Ferme le Bloc-notes. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

      → Ferme MBAM en cliquant sur Quitter.

      → Poste le rapport dans ta réponse

      A++
      0
      1. Merci à toi c'est long par contre et c'est sûr que sa marche au moins?^^
        0
    3. Re ,

      Les discours sont longs , je te l'accorde . Mais c'est parce qu'ils sont détaillés.

      Sinon , oui , "sa marche" ( suffit de suivre à la lettre ce que je te demande )

      Bonne chance
      A++
      0
      1. Voilà le rapport de Move It:

        File/Folder C:\WINDOWS\system32\gzmrt.dll not found.
        < Emptytemp >
        File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_90.dat scheduled to be deleted on reboot.
        File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
        Temp folders emptied.
        IE temp folders emptied.

        OTMoveIt2 by OldTimer - Version 1.0.4.2 log created on 05302008_104938

        Files moved on Reboot...
        File C:\WINDOWS\temp\Perflib_Perfdata_90.dat not found!
        File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!

        pour ça c'est bon?
        0
    4. Re ,

      Parfait , passe à la suite.

      A++
      0
      1. Voila le rapport de l'analyse complète

        Type de recherche: Examen complet (C:\|D:\|)
        Eléments examinés: 68366
        Temps écoulé: 9 minute(s), 52 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 33
        Valeur(s) du Registre infectée(s): 2
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 3
        Fichier(s) infecté(s): 16

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        HKEY_CLASSES_ROOT\Interface\{1037b06c-84b7-4240-8d80-485810a0497d} (Adware.Mirar) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{54b287f9-fd90-4457-b65e-cb91560c021d} (Adware.Mirar) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{6e4c7afc-9915-4036-b7f9-8b3f1710788f} (Adware.Mirar) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{566dede9-9ed8-45da-9be6-9b2eeab17f49} (Adware.Mirar) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{9a9c9b68-f908-4aab-8d0c-10ea8997f37e} (Adware.Mirar) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\whiehelperobj.whiehelperobj.1 (Adware.WebHancer) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{c900b400-cdfe-11d3-976a-00e02913a9e0} (Adware.WebHancer) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{c89435b0-cdfe-11d3-976a-00e02913a9e0} (Adware.WebHancer) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{c8cb3870-cdfe-11d3-976a-00e02913a9e0} (Adware.WebHancer) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e7bd74f-2b8d-469e-dcf7-f96da086b434} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\AppID\{127df9b4-d75d-44a6-af78-8c3a8ceb03db} (Adware.WhenUSave) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\acm.acmfactory (Adware.WhenUSave) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\acm.acmfactory.1 (Adware.WhenUSave) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{a9aae1ab-9688-42c5-86f5-c12f6b9015ad} (Adware.WhenUSave) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{43382522-a846-46f4-ac57-1f71ae6e1086} (Adware.WhenUSave) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{572fb162-c0ba-4edf-8cff-e3846153b9b0} (Adware.WhenUSave) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Interface\{72a836d1-bc00-43c0-a941-17960e4fb842} (Adware.WhenUSave) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{df901432-1b9f-4f5b-9e56-301c553f9095} (Adware.WhenUSave) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\pornpro.pornpro_bho (Adware.PlayaZ) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\pornpro.pornpro_bho.1 (Adware.PlayaZ) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{0d39a900-0f3a-4c29-a254-3e65244fdc34} (Adware.PlayaZ) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\contexttool (Adware.PlayaZ) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\Software\MediaHoldings (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\Software\Mirar (AdWare.Mirar) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\Software\PlayMP3 (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\Software\Microsoft\HID_Layer (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Think-Adz Search Assistant (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Enhanced Ads by Think-Adz (Trojan.BHO) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\whiehelperobj.whiehelperobj (Adware.WebHancer) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webHancer Agent (Adware.WebHancer) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\webHancer (Adware.WebHancer) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\AppID\ACM.DLL (Adware.WhenUSave) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\WUSN.1 (Adware.WhenUSave) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\webHancer Agent (Adware.Webhancer) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\POSTSETUPCHECK (Adware.Agent) -> Quarantined and deleted successfully.

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        C:\Program Files\contexttool (Adware.PlayaZ) -> Quarantined and deleted successfully.
        C:\Program Files\webHancer (Adware.Webhancer) -> Quarantined and deleted successfully.
        C:\Program Files\webHancer\Programs (Adware.Webhancer) -> Quarantined and deleted successfully.

        Fichier(s) infecté(s):
        C:\WINDOWS\system32\wpcap.dll (Spyware.Agent) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\packet.dll (Spyware.Agent) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{188E40F0-ED0E-4229-A9C6-C6CA03F40F1B}\RP436\A0054709.EXE (Adware.Mirar) -> Quarantined and deleted successfully.
        C:\Program Files\contexttool\pcre3.dll (Adware.PlayaZ) -> Quarantined and deleted successfully.
        C:\Program Files\contexttool\uninstall.exe (Adware.PlayaZ) -> Quarantined and deleted successfully.
        C:\Program Files\contexttool\ContextHelper.dat (Adware.PlayaZ) -> Quarantined and deleted successfully.
        C:\Program Files\webHancer\Programs\whagent.ini (Adware.Webhancer) -> Quarantined and deleted successfully.
        C:\Program Files\webHancer\Programs\license.txt (Adware.Webhancer) -> Quarantined and deleted successfully.
        C:\Program Files\webHancer\Programs\readme.txt (Adware.Webhancer) -> Quarantined and deleted successfully.
        C:\Program Files\webHancer\Programs\sporder.dll (Adware.Webhancer) -> Quarantined and deleted successfully.
        C:\Program Files\webHancer\Programs\whagent.exe (Adware.Webhancer) -> Quarantined and deleted successfully.
        C:\Program Files\webHancer\Programs\whinstaller.exe (Adware.Webhancer) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\rundll32.exe (Adware.Agent) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\msnav32.ax (Malware.Trace) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\zxdnt3d.cfg (Malware.Trace) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\nvs2.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.

        la c'est bon normalement?^^
        0
    5. Re ,

      Nickel pour ça.

      Tu me repostes un rapport Hijackthis stp ?

      A++
      0
      1. voila le rapport Highjackthis:

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 11:19:48, on 30/05/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16640)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\Acer\eManager\anbmServ.exe
        C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\acer\epm\epm-dm.exe
        C:\Program Files\Launch Manager\QtZgAcer.EXE
        C:\Program Files\Acer\eRecovery\Monitor.exe
        C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Documents and Settings\Alexis Damant\Bureau\HiJackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.acer.com/worldwide/selection.html
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: (no name) - {ED19E184-266B-769A-1DF6-74E29B032696} - (no file)
        R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
        R3 - URLSearchHook: (no name) - {E04FB6D1-766B-219F-1DF6-74E29B0473C7} - (no file)
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
        O2 - BHO: rightonads optimizer - {10F3E8BD-257A-4702-A2F5-DC02055B068C} - C:\WINDOWS\system32\gzmrt.dll (file missing)
        O2 - BHO: (no name) - {41DC786B-BC87-B87A-A04D-EF2B57BD8798} - (no file)
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
        O2 - BHO: (no name) - {E04FB6D1-766B-219F-1DF6-74E29B0473C7} - (no file)
        O2 - BHO: (no name) - {ED19E184-266B-769A-1DF6-74E29B032696} - (no file)
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: Adssite Toolbar - {41C29B07-6F91-4966-91BE-2E2841643C83} - C:\Program Files\Adssite Advanced Toolbar\toolbar.dll
        O4 - HKLM\..\Run: [LaunchApp] Alaunch
        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
        O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
        O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
        O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
        O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
        O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
        O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
        O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{1A9ACC37-30D1-493B-A02E-B3492DE89A50}: NameServer = 192.168.1.1
        O17 - HKLM\System\CCS\Services\Tcpip\..\{C2290D1F-69C8-4A3A-A411-42B684B2A6B7}: NameServer = 192.168.1.1
        O20 - AppInit_DLLs: ,
        O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
        O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        0
    6. Re ,

      → Relance hijackthis , en menu principal choisis ' Do a system scan only' Et fixe ces/cette ligne(s) : ( coche la case à leurs gauches )


      R3 - URLSearchHook: (no name) - {ED19E184-266B-769A-1DF6-74E29B032696} - (no file)
      R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
      R3 - URLSearchHook: (no name) - {E04FB6D1-766B-219F-1DF6-74E29B0473C7} - (no file)
      O2 - BHO: rightonads optimizer - {10F3E8BD-257A-4702-A2F5-DC02055B068C} - C:\WINDOWS\system32\gzmrt.dll (file missing)
      O2 - BHO: (no name) - {41DC786B-BC87-B87A-A04D-EF2B57BD8798} - (no file)
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: (no name) - {E04FB6D1-766B-219F-1DF6-74E29B0473C7} - (no file)
      O2 - BHO: (no name) - {ED19E184-266B-769A-1DF6-74E29B032696} - (no file)
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O20 - AppInit_DLLs: ,


      Ferme toutes les fenêtres (hormis Hijackthis), y compris ton navigateur web.

      → clique sur ' fixchecked '

      ***********************************************


      Pour vérif ,

      **************************************************

      → Télécharge Navilog1

      et enregistre-le sur ton bureau.

      → Ensuite double clique sur navilog1.exe pour lancer l'installation.
      Une fois l'installation terminée, le fix s'exécutera automatiquement.
      (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

      Laisse-toi guider. Au menu principal, choisis l'option 1

      Pendant le scan ton anti-virus risque de gueuler , ne t'inquiete pas c'est normal ;)

      Patiente jusqu'au message

      *** Analyse Termine le ..... ***

      Puis poste moi le rapport.

      ( rapport situé a la racine du disque -> C:\Fixnavi.txt )
      (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

      Tutorial :
      http://mickael.barroux.free.fr/securite/navilog.php

      **************************************************

      Ferme Internet Explorer puis fait :
      Démarrer > panneau de configuration > options internet
      Onglet "Contenu" puis onglet "Certificats" et si tu trouves ceci, en particulier dans "éditeurs approuvés", mais regarde ailleurs :

      _electronic-group
      _egroup
      _Montorgueil
      _VIP
      _Sunny Day Design Ltd


      Tu les supprimes.

      **************************************************

      A++
      0
      1. Quand je suis dans navilog faut mettre quelle désinfection lol je comprend pas la
        0
    7. C'est marqué.

      tu choisis l'option 1.

      ++
      0
      1. Voila le rapport de l'analyse navilog

        Search Navipromo version 3.5.7 commencé le 30/05/2008 à 11:36:24,89

        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
        !!! Postez ce rapport sur le forum pour le faire analyser !!!
        !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

        Outil exécuté depuis C:\Program Files\navilog1
        Session actuelle : "Alexis Damant"

        Mise à jour le 11.05.2008 à 18h00 par IL-MAFIOSO

        Microsoft Windows XP [version 5.1.2600]
        Internet Explorer : 7.0.5730.13
        Système de fichiers : FAT32

        Recherche executé en mode normal

        *** Recherche Programmes installés ***

        *** Recherche dossiers dans "C:\WINDOWS" ***

        *** Recherche dossiers dans "C:\Program Files" ***

        *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

        *** Recherche dossiers dans "c:\docume~1\alluse~1\menudÉ~1\progra~1" ***

        *** Recherche dossiers dans "C:\Documents and Settings\Alexis Damant\applic~1" ***

        *** Recherche dossiers dans "C:\Documents and Settings\Alexis Damant\locals~1\applic~1" ***

        *** Recherche dossiers dans "C:\Documents and Settings\Alexis Damant\menud+~1\progra~1" ***

        *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
        pour + d'infos : http://www.gmer.net

        Fichier(s) caché(s) :

        C:\Documents and Settings\Alexis Damant\Local Settings\Application Data\ilczea.exe 327680 bytes
        C:\Documents and Settings\Alexis Damant\Local Settings\Application Data\ilczea.dat 32768 bytes
        C:\Documents and Settings\Alexis Damant\Local Settings\Application Data\ilczea_nav.dat 393216 bytes
        C:\Documents and Settings\Alexis Damant\Local Settings\Application Data\ilczea_navps.dat 32768 bytes
        C:\Documents and Settings\Alexis Damant\Local Settings\Application Data\ilczea_navup.dat 458752 bytes

        *** Recherche avec GenericNaviSearch ***
        !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
        !!! A vérifier impérativement avant toute suppression manuelle !!!

        * Recherche dans "C:\WINDOWS\system32" *

        * Recherche dans "C:\Documents and Settings\Alexis Damant\locals~1\applic~1" *

        *** Recherche fichiers ***

        *** Recherche clés spécifiques dans le Registre ***

        HKEY_CURRENT_USER\Software\Lanconfig trouvé !

        *** Module de Recherche complémentaire ***
        (Recherche fichiers spécifiques)

        1)Recherche nouveaux fichiers Instant Access :

        2)Recherche Heuristique :

        * Dans "C:\WINDOWS\system32" :

        * Dans "C:\Documents and Settings\Alexis Damant\locals~1\applic~1" :

        ilczea.dat trouvé !

        3)Recherche Certificats :

        Certificat Egroup trouvé !
        Certificat Electronic-Group trouvé !
        Certificat OOO-Favorit trouvé !
        Certificat Sunny-Day-Design-Ltd absent !

        4)Recherche fichiers connus :

        *** Analyse terminée le 30/05/2008 à 11:37:16,70 ***
        0
    8. Re ,

      ça confirme mes doutes ;))

      **************************************************

      -> Relance Navilog1 ,

      Choisi l'option 2 cette fois-ci.

      Navilog va travailler , patiente jusqu'a ce message :

      *** Nettoyage terminé le ... ***

      -> Poste moi le rapport qui va apparaitre. ( situé aussi dans C:\ )

      (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

      **************************************************

      Fais Démarrer et Exécuter.

      Dans la fenêtre qui s'ouvre, tu copies/colles :

      regedit /a C:\run.txt HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

      puis OK.

      Copie dans ta réponse C:\run.txt (en l'ouvrant avec le Bloc-notes).

      **************************************************

      + un nouveau rapport Hijackthis.
      A+++
      0
      1. Dans les options internet,contenu et tout ça j'ai que electronic-groupe j'enlève quand meme?
        0
      2. Il me demande rédemarrer le pc je l'ai fait?^^
        0
      3. Donc voila le machin run:

        REGEDIT4

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
        "LaunchApp"="Alaunch"
        "IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
        "HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
        "SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
        "SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
        "IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
        "MSPY2002"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
        "PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
        "PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
        "ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
        "EPM-DM"="c:\\acer\\epm\\epm-dm.exe"
        "ePowerManagement"="C:\\Acer\\ePM\\ePM.exe boot"
        "LManager"="C:\\Program Files\\Launch Manager\\QtZgAcer.EXE"
        "eRecoveryService"="C:\\Program Files\\Acer\\eRecovery\\Monitor.exe"
        "SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_03\\bin\\jusched.exe"
        "avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"

        Et le nouveau rapport highjackthis:

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 11:54:19, on 30/05/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16640)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\Acer\eManager\anbmServ.exe
        C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\NOTEPAD.EXE
        C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Acer\eRecovery\Monitor.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\acer\epm\epm-dm.exe
        C:\Program Files\Launch Manager\QtZgAcer.EXE
        C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Documents and Settings\Alexis Damant\Bureau\HiJackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.acer.com/worldwide/selection.html
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: Adssite Toolbar - {41C29B07-6F91-4966-91BE-2E2841643C83} - C:\Program Files\Adssite Advanced Toolbar\toolbar.dll
        O4 - HKLM\..\Run: [LaunchApp] Alaunch
        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
        O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
        O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
        O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
        O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
        O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
        O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
        O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{1A9ACC37-30D1-493B-A02E-B3492DE89A50}: NameServer = 192.168.1.1
        O17 - HKLM\System\CCS\Services\Tcpip\..\{C2290D1F-69C8-4A3A-A411-42B684B2A6B7}: NameServer = 192.168.1.1
        O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
        O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        0
    9. Oui tu l'enlèves ;)
      Puis tu fait le reste.
      A++

      EDIT : Vii redémarre =)
      0
      1. Et le rapport Navilog ?
        0
        1. Le voici:

          Clean Navipromo version 3.5.7 commencé le 30/05/2008 à 11:45:41,79

          Outil exécuté depuis C:\Program Files\navilog1
          Session actuelle : "Alexis Damant"

          Mise à jour le 11.05.2008 à 18h00 par IL-MAFIOSO

          Microsoft Windows XP [version 5.1.2600]
          Internet Explorer : 7.0.5730.13
          Système de fichiers : FAT32

          Mode suppression automatique
          avec prise en charge résultats Catchme et GNS

          Nettoyage exécuté au redémarrage de l'ordinateur

          *** Creation backups fichiers trouvés par Catchme ***

          Copie vers "C:\Program Files\navilog1\Backupnavi"

          *** Suppression des fichiers trouvés avec Catchme ***

          ** 2ème passage avec résultats Catchme **

          * Dans "C:\WINDOWS\system32" *

          C:\WINDOWS\prefetch\ilczea*.pf trouvé !
          Copie C:\WINDOWS\prefetch\ilczea*.pf réalisée avec succès !
          C:\WINDOWS\prefetch\ilczea*.pf supprimé !

          * Dans "C:\Documents and Settings\Alexis Damant\locals~1\applic~1" *

          ilczea.exe trouvé !
          Copie ilczea.exe réalisée avec succès !
          ilczea.exe supprimé !

          ilczea.dat trouvé !
          Copie ilczea.dat réalisée avec succès !
          ilczea.dat supprimé !

          ilczea_nav.dat trouvé !
          Copie ilczea_nav.dat réalisée avec succès !
          ilczea_nav.dat supprimé !

          ilczea_navps.dat trouvé !
          Copie ilczea_navps.dat réalisée avec succès !
          ilczea_navps.dat supprimé !

          ilczea_navup.dat trouvé !
          Copie ilczea_navup.dat réalisée avec succès !
          ilczea_navup.dat supprimé !

          *** Suppression avec sauvegardes résultats GenericNaviSearch ***

          * Suppression dans "C:\WINDOWS\System32" *

          * Suppression dans "C:\Documents and Settings\Alexis Damant\locals~1\applic~1" *

          *** Suppression dossiers dans "C:\WINDOWS" ***

          *** Suppression dossiers dans "C:\Program Files" ***

          *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***

          *** Suppression dossiers dans "c:\docume~1\alluse~1\menudÉ~1\progra~1" ***

          *** Suppression dossiers dans "C:\Documents and Settings\Alexis Damant\applic~1" ***

          *** Suppression dossiers dans "C:\Documents and Settings\Alexis Damant\locals~1\applic~1" ***

          *** Suppression dossiers dans "C:\Documents and Settings\Alexis Damant\menud+~1\progra~1" ***

          *** Suppression fichiers ***

          *** Suppression fichiers temporaires ***

          Nettoyage contenu C:\WINDOWS\Temp effectué !
          Nettoyage contenu C:\Documents and Settings\Alexis Damant\locals~1\Temp effectué !

          *** Traitement Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

          2)Recherche, création sauvegardes et suppression Heuristique :

          * Dans "C:\WINDOWS\system32" *

          * Dans "C:\Documents and Settings\Alexis Damant\locals~1\applic~1" *

          *** Sauvegarde du Registre vers dossier Safebackup ***

          sauvegarde du Registre réalisée avec succès !

          *** Nettoyage Registre ***

          Nettoyage Registre Ok

          *** Certificats ***

          Certificat Egroup absent !
          Certificat Electronic-Group absent !
          Certificat OOO-Favorit supprimé !
          Certificat Sunny-Day-Design-Ltdt absent !

          *** Nettoyage terminé le 30/05/2008 à 11:52:10,17 ***
          0
      2. Re !

        Parfait.

        -> Supprime C:\Run.txt

        **********************************************

        1) Télécharge Ncleaner sur ton bureau , double clique sur le fichier d'installation et installe le logiciel.

        2) Double clique sur l'icône crée sur le bureau et choisi ' cleansystem '

        3) A gauche de l'écran , sous ' clean system and applications ' vérifie que seulement les 4 premières cases soit cochées , puis clique sur ' clean now ' > ' analyze '

        --- Le programme va rechercher les fichier inutiles ---

        Une fois l'analyse terminée , clique sur ' Clean ' et repond ' Yes ' a la demande de confirmation.

        Cela terminé , clique sur ' Done '

        4) Reprend l'étape 2 et choisi cette fois ci ' Registry clean and repair ' vérifie que toute les cases soient cochées et clique sur ' Clean now ' ( dans la colonne de droite cette fois-ci ) > ' Scan '

        --- Le programme va rechercher les clées de registre invalides ---

        Une fois le scan terminé , clique sur ' Remove ' et repond ' Yes ' a la demande de confirmation.

        Cela terminé , clique sur ' Done '

        ****************************************************

        → Télécharge clean : http://www.malekal.com/download/clean.zip

        → Dézippe-le ( clique droit , extraire tout)

        → Lance clean.cmd ( ou clean ), Choisi l'option 1 et poste moi le rapport.

        (- Où est le rapport clean ? : « Poste de travail » / double clic sur disque « C / » double-clic sur « rapport_clean.txt » et « copier/coller le contenu » sur le forum. )

        Note : Tu auras peut-être un message qui t'invitera a uploader un fichier , fait-le dès que tu pourras.

        Tutorial : http://bibou0007.com/outils-specifiques-f78/tuto-clean-t1007.htm

        ****************************************************

        A++
        0
        1. Re sa y est sa à l'air de bien marché merci beaucoup pour l'aide.
          0
        2. Re sa y est sa à l'air de bien marché merci beaucoup pour l'aide.
          0
      3. Re ,

        Ce n'est pas fini.
        Le rapport Clean stp.

        ++
        0
        1. Re bon ben voila le rapport de clean:

          30/05/2008 a 14:03:16,29

          *** Recherche des fichiers dans C:

          *** Recherche des fichiers dans C:\WINDOWS\

          *** Recherche des fichiers dans C:\WINDOWS\system32
          C:\WINDOWS\system32\wnsapisv.exe FOUND
          "C:\Documents and Settings\Alexis Damant\Application Data\ezpinst.exe" FOUND

          *** Recherche des fichiers dans C:\Program Files
          "C:\Program Files\Fichiers communs\Y1220OU.exe" FOUND
          C:\PROGRA~1\RACLE~1\ FOUND
          "C:\Program Files\Adssite Advanced Toolbar\" FOUND
          "C:\Program Files\Adssite Games Collection\" FOUND
          "C:\Program Files\DivX\Google\Firefox\ffinstaller.exe" FOUND
          "C:\Program Files\TheSearchAccelerator\" FOUND
          0
      4. Re ,,

        Tu vois il y avais encore des infections ;)

        *********************************************


        → Redémarre en MSE

        Autre tutorials pour MSE:

        https://www.micro-astuce.com/depannage/demarrer-mode-sans-echec.php
        http://www.coupdepoucepc.com/modules/news/article.php?storyid=253

        → Re-lance clean -> Choisis l'option 2

        ---Clean va travailler.---

        → Un rapport Va etre généré , poste le moi ;)

        ( Le rapport est aussi sauvegardé dans C:\Rapport_clean.txt )


        *********************************************


        _Maintenant , nous allons supprimer les logiciels de désinfection que je t'ai fait téléchargé.
        En effet , s'en servir est dangereux pour le pc si l'on ne s'y connais pas.
        De plus ils sont mis régulièrement à jours.

        → Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.

        → Double clique sur ToolsCleaner2.exe >
        → Clique sur .Recherche
        → puis sur Suppression quand la liste est trouvée.
        → Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

        (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        Note : ton bureau RISQUE de disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

        CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
        Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

        Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

        Tuto : http://www.commentcamarche.net/faq/sujet 8341 toolscleaner suppression des fix de force brute ( merci espion3004 )

        A+
        0
        1. Bon ben je crois que c'est bon par contre ya rien marqué sur le rapport juste ça:

          -->- Recherche:

          Est ce normal?
          0
      5. Re ,
        Non pas normal.

        tu veux bien recommencer stp ?

        +A+
        0
        1. OK
          0
        2. @Alex1809Sa me met juste recherche et apres quand je fais suppresion me marques ben suppresion mais dans le rapport il ya rien comme les autres rapports que je t'ai envoyé.
          0
      6. Re ,

        Tu as encore Hijackthis ?
        0
        1. Non il a été enlévé avec ToolsCleaner et MoveIT aussi s'est supprimé.
          0
      7. Re ,
        voila c'est ce que je voulais savoir.

        ->Supprime Toolscleaner
        ->Supprime Tcleaner.txt


        Garde Ncleaner , tu t'en servira de temps en temps pour faire le ménage dans ton pc. ( par exemple toute les semaines ) .

        Garde également MBAM au cas où.

        ************************************************

        Ta version d'Adobe n'est pas à jour , désinstalle ta version actuelle en passant par ' ajout et supréssion de programmes '

        Puis télécharge la dernière , via ce site --> https://get2.adobe.com/reader/otherversions/

        Bulletin de sécurité sur les versions Adobe 7.0.8 et antérieures :

        https://www.adobe.com/support/security/bulletins/apsb07-01.html

        ************************************************

        Désinstalle ta version actuelle de JAVA via ,

        Sous XP :

        Ajout et suppression de programmes

        Sous Vista:

        Programmes et fonctionnalités

        Puis met à jour JAVA --> https://www.java.com/fr/download/windows_manual.jsp?locale=fr&host=www.java.com:80 [ Version 6 update 6 ]

        ************************************************

        Désactive le pare-feu Windows en t'aidant de ce lien :

        http://www.libellules.ch/firewall_xpsp2.php

        ************************************************

        Télécharge le pare-feu Kerio

        Tutorial en cas de problèmes : https://kerio.probb.fr/f2-sunbelt-kerio-personal-firewall

        ************************************************

        Maintenant que ton PC n'est plus infecté, désactive ta "Restauration du système" puis réactive la, ce qui créer un point de restauration sain...

        Désactivation :
        Clique droit sur le "Poste de travail" > Propriétés > onglet "Restauration du système" > coche la case "Désactiver la Restauration du système sur tous les lecteurs"
        > Applique patiente jusqu’à ce que cela soit marqué "désactivé" puis Ok.

        Activation :
        Suivre le même chemin ; décoche la case "Désactiver la Restauration du système sur tous les lecteurs"
        > Applique attends que cela soit à nouveau sur "surveillance" puis Ok. Redémarre l'ordinateur.

        Tutorial :
        http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20020830101856924

        ______________________________________________________________________

        A Lire

        -> http://www.commentcamarche.net/faq/sujet 8201 pirates attaquent

        -> https://sebsauvage.net/safehex.html#r_pourquoisecuriser

        -> http://www.commentcamarche.net/faq/sujet 9289 trojan comment ca marche

        -> https://forum.pcastuces.com/default.asp

        -> http://assiste.com.free.fr/p/abc/a/safe_cex.html

        ______________________________________________________________________

        Navigation sécurisée Avec Mozilla Firefox :

        -> Comparatif IE contre FF → http://www.infos-du-net.com/actualite/dossiers/11-firefox-internet-explorer.html

        -> Pourquoi utiliser FF ? → https://sebsauvage.net/logiciels/firefox.html

        > Téléchargement <


        -> https://forum.zebulon.fr/topic/69628-s%C3%A9curiser-un-peu-plus-firefox/ [ sécuriser FireFox ]

        Note :

        Il est important de garder IE car nombreux sont les logiciels qui ne fonctionnent qu'avec lui.

        ______________________________________________________________________

        Pour sécuriser ( si tu ne les as pas encore ):
        ______________________________________________________________________

        ************ 1 ***********

        -> Spybot S&D (-> Scan passif + Résident )

        ____________> Téléchargement <


        -> Tutorial : https://forums.cnetfrance.fr

        ************ 2 ***********

        -> Spyware blaster

        ____________> Téléchargement <


        -> Tutorial : https://www.malekal.com/tutorial-spywareblaster/

        ************ 3 ***********

        -> SpywareGuard ( Ce logiciel complète très bien Spybot)

        ____________> Téléchargement <


        -> Tutorial : https://www.zebulon.fr/dossiers/securite/47-spywareguard.html

        ______________________________________________________________________

        Voila !
        Mon aide s'arrête la ;)
        Bonne lecture :)

        Et continuation.

        Si tu as des questions ...

        A++

        0
        1. Merci énormément pour ton conseil et tkt le message quand j'allume mon pc ne se met plus donc vrement un grand merci.
          0