Google me détecte unn virus!

jonjon -  
don-diego Messages postés 11 Statut Membre -
Bonjour, voila ça fais quelque semaine que cela se produit, a chaque fois que je fais une recherche sur google, google m'indique que j ai un virus ou un spyware et me demande donnai le code d'un cryptogramme.
j ai avast home a jour (plusieurs scan minutieux effectué), spybot searh and destroy a jour et en protection résidente.
j ai effectué plusieurs scan en ligne anti-virus et spyware de tout le fournisseur connu.
se proble se produit avec internet explorer et mozilla firefox.

je vous remet mon rapport HijackThis.

Logfile of HijackThis v1.99.1
Scan saved at 17:57:43, on 14/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Multimedia Combo Set\MouseDrv.exe
C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\EPSON\ESM2\eEBSVC.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
E:\z johnny\logiciel\anti virus\Nouveau dossier\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=212.241.180.239:81
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WireLessMouse ] C:\Program Files\Multimedia Combo Set\MouseDrv.exe
O4 - HKLM\..\Run: [WireLessKeyboard ] C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_SAD.tmp" /EF "HKCU"
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\EPSON\ESM2\STMS.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\fichiers communs\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\fichiers communs\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\fichiers communs\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\fichiers communs\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner371420.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: dimsntfy - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\EPSON\ESM2\eEBSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Moon Secure Antivirus Core (msav) - Unknown owner - C:\Program Files\Moon Secure Antivirus\msavcore.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Configuration: Windows XP
Firefox 2.0.0.14

18 réponses

  1. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bonsoir

    Télécharge malwarebytes
    http://www.malwarebytes.org/mbam/program/mbam-setup.exe
    Une aide pour l'installation
    http://www.swl1f.net/viewtopic.php?f=14&t=68

    => Installe le
    => Ensuite va en mode sans echec

    Relance le Pc et tapote la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
    Avec les touches « flèches », sélectionne Mode sans échec ==> entrée ==>nom utilisateur habituel

    => Lance malwarebytes
    => Coche "Executer un examen complet"
    => Si tu es en présence d'une infection à la fin de l'examen clique sur "ok"
    => Clique sur Supprimer la sélection
    => Pour poster le rapport Clique sur l'onglet Rapports/Logs, sélectionne celui t'intéresse et clique sur Ouvrir
    => Fait copier coller et poste le rapport

    --------------------------

    ensuite

    * Télécharge CCleaner
    https://filehippo.com/download_ccleaner/
    => Aide toi de ce tuto pour l'utiliser
    http://www.swl1f.net/viewtopic.php?f=14&t=69

    --------------------------

    Ensuite

    Refais un nouveau hijack mais avec cette version

    ftp://ftp.commentcamarche.com/download/HJTInstall.exe

    désinstalle l'ancienne et installe la nouvelle
    => Si problème voir l'aide
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
    @+
    0
    1. jonjon
       
      bonsoir et merci de de m aidé.

      alors j ai fais comme tu me l'a indiqué, et arés 2h de scan de malwarebytes en mode sans echec rien a signalé comme infection, et j ai quand meme lancé ccleaner mais le proble y est toujours.

      et comme tu me l avais demandé viola le scan d' HijackThis.

      si tu trouve des élément a fixé préviens moi. merci d'avance.

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 22:36:56, on 14/06/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\netdde.exe
      C:\Program Files\EPSON\ESM2\eEBSVC.exe
      C:\WINDOWS\system32\acs.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\VTTimer.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Multimedia Combo Set\MouseDrv.exe
      C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\Program Files\Mozilla Firefox\firefox.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=212.241.180.239:81
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
      O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
      O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
      O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [WireLessMouse ] C:\Program Files\Multimedia Combo Set\MouseDrv.exe
      O4 - HKLM\..\Run: [WireLessKeyboard ] C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
      O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_SAD.tmp" /EF "HKCU"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
      O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\EPSON\ESM2\STMS.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
      O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
      O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner371420.cab
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} -
      O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
      O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -
      O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
      O20 - AppInit_DLLs: avgrsstx.dll
      O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\EPSON\ESM2\eEBSVC.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Moon Secure Antivirus Core (msav) - Unknown owner - C:\Program Files\Moon Secure Antivirus\msavcore.exe (file missing)
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
      O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      0
  2. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Relance hijack et clique sur "Do a system scan only"
    Ensuite recherche ces lignes et coches les cases

    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file)
    O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
    O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} -

    Ensuite clique sur "Fix checked"

    pour vérif

    fait un scan en ligne

    avec bitdefender et colle le rapport

    https://www.bitdefender.com/toolbox/

    Scan à faire sous Internet Explorer

    un tuto
    http://pageperso.aol.fr/rginformatique/mapage/defender.htm

    ensuite un nouveau rapport hijack stp
    @+
    0
    1. jonjon
       
      bonjour, bon rien ne va.

      j ai effectué les fixs que tu ma dit, cela c'est passé sans problème, après j ai voulu faire le scan en ligne avec bitdefender mais la impossible de pouvoir tout télécharger correctement quand se n est pas les anti virus engine qui fait défaut c'est les signatures de virus qui ne se charge pas. donc désolé mais impossible de faire un scan avec bitdefender

      de mon coté j ai l'impression que ma connection est ralenti, les page mettent un certain temp a se chargé alors que je suis avec numéricable en cable eternet. bref certe site site comme battles arenas (un jeu en ligne) mais beaucou de temp a se charger se qui n'était pas le cas avant, pour etre sur que ça ne venais pas de ma connection j ai débrangé ma box et rebranger j ai aussi fait un reset de celle ci. mais rien n y change, est ce que c'est du a un meme et seul probleme?

      j ai vérifié les port ouvert, il y en avait un inconnu je l ai bloqué depuis il ne revien pas mais mon probleme perciste.

      je te remet le rapport hijack

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:29:20, on 15/06/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16674)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\netdde.exe
      C:\Program Files\EPSON\ESM2\eEBSVC.exe
      C:\WINDOWS\system32\acs.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\VTTimer.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Multimedia Combo Set\MouseDrv.exe
      C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=212.241.180.239:81
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: BHO Barre de Confiance - {988B07F5-7392-455A-8A1F-64935CB8B6ED} - C:\Program Files\BarreConfCMCIC\TAPBar.dll
      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [WireLessMouse ] C:\Program Files\Multimedia Combo Set\MouseDrv.exe
      O4 - HKLM\..\Run: [WireLessKeyboard ] C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
      O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_SAD.tmp" /EF "HKCU"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
      O4 - Global Startup: EPSON Background Monitor.lnk = C:\Program Files\EPSON\ESM2\STMS.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
      O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner371420.cab
      O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
      O20 - AppInit_DLLs: avgrsstx.dll
      O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\EPSON\ESM2\eEBSVC.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Moon Secure Antivirus Core (msav) - Unknown owner - C:\Program Files\Moon Secure Antivirus\msavcore.exe (file missing)
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
      O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      0
  3. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Très bien on pousse un peu la recherche

    Télécharge DiagHelp.zip sur ton bureau http://www.malekal.com/download/DiagHelp.zip
    ==> Ne double-clic pas dessus !! Fais un clic droit sur le fichier et extraire tout
    ==> Un nouveau dossier chercher va être créé DiagHelp
    ==> Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)
    ==> Une fenêtre va s'ouvrir, choisis l'option 1
    ==> L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande
    ==> Copie/colle le contenu du bloc-note qui s'ouvre, pour cela :
    ==> Dans le bloc-note, cliquez sur le menu Edition / Selectionner tout
    ==> A nouveau menu Edition / copier
    ==> Dans un nouveau message ici, faire un clic droit / coller
    @+

    0
    1. jonjon
       
      voila le rapport

      j'espère franchement que cela va s arranger

      DiagHelp version v1.4 - http://www.malekal.com
      excute le 15/06/2008 à 12:06:48,71


      Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
      C:\WINDOWS\prefetch\CMD.EXE-087B4001.pf -->15/06/2008 12:06:43
      C:\WINDOWS\prefetch\CHCP.COM-18156052.pf -->15/06/2008 12:06:38
      C:\WINDOWS\prefetch\WINRAR.EXE-39C6DAD9.pf -->15/06/2008 12:05:53
      C:\WINDOWS\prefetch\WLLOGINPROXY.EXE-2D4B6027.pf -->15/06/2008 12:02:45
      C:\WINDOWS\prefetch\IEXPLORE.EXE-27122324.pf -->15/06/2008 12:02:36
      C:\WINDOWS\prefetch\MSNMSGR.EXE-030AB647.pf -->15/06/2008 12:01:18
      C:\WINDOWS\prefetch\BDOSCANDEL.EXE-1059F64B.pf -->15/06/2008 11:46:48
      C:\WINDOWS\prefetch\REGSVR32.EXE-25EEFE2F.pf -->15/06/2008 11:46:45
      C:\WINDOWS\prefetch\NOTEPAD.EXE-336351A9.pf -->15/06/2008 11:43:24
      C:\WINDOWS\prefetch\CPORTS.EXE-0A1BDED8.pf -->15/06/2008 11:42:31

      C:\WINDOWS\System32\drivers\fidbox.dat -->15/06/2008 12:05:10
      C:\WINDOWS\System32\drivers\fidbox.idx -->15/06/2008 10:54:23
      C:\WINDOWS\System32\drivers\iksyssec.sys -->12/06/2008 21:09:15
      C:\WINDOWS\System32\drivers\iksysflt.sys -->12/06/2008 21:09:13
      C:\WINDOWS\System32\drivers\kcom.sys -->12/06/2008 21:08:40
      C:\WINDOWS\System32\drivers\ikfilesec.sys -->12/06/2008 21:08:27
      C:\WINDOWS\System32\drivers\ikfileflt.sys -->12/06/2008 21:08:27

      C:\WINDOWS\System32\PerfStringBackup.INI -->15/06/2008 10:59:54
      C:\WINDOWS\System32\perfh00C.dat -->15/06/2008 10:59:54
      C:\WINDOWS\System32\perfh009.dat -->15/06/2008 10:59:54
      C:\WINDOWS\System32\perfc00C.dat -->15/06/2008 10:59:54
      C:\WINDOWS\System32\perfc009.dat -->15/06/2008 10:59:54
      C:\WINDOWS\System32\nvapps.xml -->15/06/2008 10:56:23
      C:\WINDOWS\System32\vsconfig.xml -->15/06/2008 10:56:09
      C:\WINDOWS\System32\wpa.dbl -->15/06/2008 10:56:07
      C:\WINDOWS\System32\iklog.log -->12/06/2008 22:26:47
      C:\WINDOWS\System32\client.sid -->08/06/2008 12:16:20
      C:\WINDOWS\System32\zllictbl.dat -->31/05/2008 15:46:59
      C:\WINDOWS\System32\CONFIG.NT -->31/05/2008 15:20:49
      C:\WINDOWS\System32\118290.54 -->31/05/2008 12:57:09
      C:\WINDOWS\System32\wpa.bak -->31/05/2008 01:31:05
      C:\WINDOWS\System32\nscompat.tlb -->31/05/2008 01:29:14
      C:\WINDOWS\System32\amcompat.tlb -->31/05/2008 01:29:14
      C:\WINDOWS\System32\FNTCACHE.DAT -->31/05/2008 01:28:32
      C:\WINDOWS\System32\spdwnwxp.log -->31/05/2008 01:25:12
      C:\WINDOWS\System32\MRT.exe -->30/05/2008 01:35:11
      C:\WINDOWS\System32\spupdwxp.log -->16/05/2008 22:27:32
      C:\WINDOWS\System32\aswBoot.exe -->16/05/2008 01:24:43
      C:\WINDOWS\System32\AvastSS.scr -->16/05/2008 01:12:36
      C:\WINDOWS\System32\jupdate-1.6.0_05-b13.log -->09/05/2008 11:14:52
      C:\WINDOWS\System32\quartz.dll -->07/05/2008 07:15:36
      C:\WINDOWS\System32\jupdate-1.6.0_04-b12.log -->01/05/2008 21:59:04

      C:\WINDOWS\setupapi.log -->15/06/2008 11:50:52
      C:\WINDOWS\wiadebug.log -->15/06/2008 10:55:48
      C:\WINDOWS\wiaservc.log -->15/06/2008 10:55:47
      C:\WINDOWS\WindowsUpdate.log -->15/06/2008 10:55:46
      C:\WINDOWS\bootstat.dat -->15/06/2008 10:55:05
      C:\WINDOWS\SchedLgU.Txt -->15/06/2008 10:54:02
      C:\WINDOWS\Sti_Trace.log -->14/06/2008 22:12:23
      C:\WINDOWS\mozver.dat -->14/06/2008 17:20:38
      C:\WINDOWS\nsreg.dat -->14/06/2008 16:32:04
      C:\WINDOWS\118294.78 -->31/05/2008 12:57:09
      C:\WINDOWS\win.ini -->29/05/2008 22:47:56
      C:\WINDOWS\LTDLG13N.INI -->22/05/2008 23:50:53
      C:\WINDOWS\_MSRSTRT.EXE -->12/05/2008 11:34:45
      C:\WINDOWS\etel1.ini -->10/05/2008 14:02:07
      C:\WINDOWS\err.txt -->10/05/2008 13:17:18

      winlogon.exe
      Verified: Signed
      svchost.exe
      Verified: Signed
      ws2_32.dll
      Verified: Signed
      user32.dll
      Verified: Signed
      tcpip.sys
      Verified: Signed
      ndis.sys
      Verified: Signed
      null.sys
      Verified: Signed


      ListDLLs v2.25 - DLL lister for Win9x/NT
      Copyright (C) 1997-2004 Mark Russinovich
      Sysinternals - www.sysinternals.com

      ------------------------------------------------------------------------------
      explorer.exe pid: 1768
      Command line: C:\WINDOWS\Explorer.EXE

      Base Size Version Path
      0x44080000 0xd0000 7.00.6000.16674 C:\WINDOWS\system32\WININET.dll
      0x00400000 0x9000 6.00.5441.0000 C:\WINDOWS\system32\Normaliz.dll
      0x43e00000 0x45000 7.00.6000.16674 C:\WINDOWS\system32\iertutil.dll
      0x58b50000 0x9a000 5.82.2900.2982 C:\WINDOWS\system32\comctl32.dll
      0x76f80000 0x7f000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL
      0x77000000 0xd4000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
      0x60560000 0x33000 17.00.0054.0000 C:\WINDOWS\system32\AcSignIcon.dll
      0x76ac0000 0x11000 3.05.2284.0000 C:\WINDOWS\system32\ATL.DLL
      0x60610000 0x61000 17.00.0054.0110 C:\Program Files\Fichiers communs\Autodesk Shared\AcSignCore16.dll
      0x7d200000 0x2be000 3.01.4000.4039 C:\WINDOWS\system32\msi.dll
      0x44360000 0x5cd000 7.00.6000.16674 C:\WINDOWS\system32\ieframe.dll
      0x44160000 0x127000 7.00.6000.16674 C:\WINDOWS\system32\urlmon.dll
      0x442b0000 0x3c000 7.00.6000.16674 C:\WINDOWS\system32\webcheck.dll
      0x164a0000 0x23000 5.02.5721.5145 C:\WINDOWS\system32\WPDShServiceObj.dll
      0x109c0000 0x2c000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceTypes.dll
      0x01930000 0x1a000 1.00.0002.0000 C:\Program Files\Spyware Doctor\FilterLSP.dll
      0x019d0000 0x25000 1.00.0084.0000 C:\Program Files\Fichiers communs\PC Tools\LSP\PCTLsp.dll
      0x7c3a0000 0x7b000 7.10.3077.0000 C:\WINDOWS\system32\MSVCP71.dll
      0x7c340000 0x56000 7.10.3052.0004 C:\WINDOWS\system32\MSVCR71.dll
      0x10930000 0x49000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceApi.dll
      0x023e0000 0x185000 1.05.0000.0011 C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      0x43ff0000 0xa000 7.00.6000.16674 C:\WINDOWS\system32\jsproxy.dll
      0x10000000 0x13000 7.05.0001.0036 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll
      0x01d20000 0x2b000 C:\Program Files\WinRAR\rarext.dll
      0x01e30000 0x13000 1.02.0000.0000 C:\Program Files\EPSON\Creativity Suite\Easy Photo Print\EPPShell.dll
      0x73d20000 0xfe000 6.02.4131.0000 C:\WINDOWS\system32\MFC42.DLL
      0x61d70000 0xe000 6.00.8665.0000 C:\WINDOWS\system32\MFC42LOC.DLL
      0x01e50000 0x2a000 7.05.0001.0036 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
      0x02df0000 0x1bc000 1.01.0000.0278 C:\Program Files\Fichiers communs\Autodesk shared\dwf common\DWFShellExtension.dll
      0x018d0000 0xb000 7.00.0473.0000 C:\Program Files\Zone Labs\ZoneAlarm\zlavscan.dll
      0x01920000 0x4000 5.03.0017.0000 C:\Program Files\Zone Labs\ZoneAlarm\zlavscan_Loc040c.dll
      0x01e80000 0x8000 1.00.0000.0000 C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
      0x64f00000 0x12000 4.08.1201.0000 C:\Program Files\Alwil Software\Avast4\ashShell.dll
      0x61310000 0x54000 2.00.0500.0000 C:\Program Files\OpenOffice.org 2.4\program\shlxthdl.dll
      0x60e20000 0x8e000 4.05.2003.0120 C:\Program Files\OpenOffice.org 2.4\program\stlport_vc7145.dll
      0x031c0000 0x1c000 7.00.0000.0000 C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll

      ListDLLs v2.25 - DLL lister for Win9x/NT
      Copyright (C) 1997-2004 Mark Russinovich
      Sysinternals - www.sysinternals.com

      ------------------------------------------------------------------------------
      winlogon.exe pid: 736
      Command line: winlogon.exe

      Base Size Version Path
      0x01000000 0x81000 \??\C:\WINDOWS\system32\winlogon.exe
      0x58b50000 0x9a000 5.82.2900.2982 C:\WINDOWS\system32\COMCTL32.dll
      0x74730000 0x3d000 3.525.1117.0000 C:\WINDOWS\system32\ODBC32.dll
      0x20000000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
      0x01260000 0x3b000 1.07.0018.0005 C:\WINDOWS\system32\WgaLogon.dll
      0x76f80000 0x7f000 2001.12.4414.0308 C:\WINDOWS\system32\CLBCATQ.DLL
      0x77000000 0xd4000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
      0x76ac0000 0x11000 3.05.2284.0000 C:\WINDOWS\system32\ATL.DLL


      Le volume dans le lecteur C n'a pas de nom.
      Le numéro de série du volume est F831-BD8D

      Répertoire de C:\WINDOWS\system32

      05/08/2004 14:00 6 144 csrss.exe
      1 fichier(s) 6 144 octets
      0 Rép(s) 6 275 694 592 octets libres

      Contenu de Downloaded Program Files
      Le volume dans le lecteur C n'a pas de nom.
      Le numéro de série du volume est F831-BD8D

      Répertoire de C:\WINDOWS\Downloaded Program Files

      15/06/2008 11:50 <REP> .
      15/06/2008 11:50 <REP> ..
      20/01/2005 14:53 171 ampx.inf
      07/12/2004 17:07 32 bdcore.dll
      25/05/2006 01:21 118 784 bdupd.dll
      15/06/2008 01:51 <REP> CONFLICT.1
      15/06/2008 01:51 <REP> CONFLICT.2
      15/06/2008 11:50 <REP> CONFLICT.3
      18/06/2007 02:23 65 desktop.ini
      23/02/2007 20:43 2 639 608 ICSScan.dll
      23/02/2007 14:05 403 ICSScanner.inf
      25/05/2006 01:21 53 248 ipsupd.dll
      08/08/2006 11:45 576 kavwebscan.inf
      16/03/2005 12:34 7 407 lang.ini
      07/12/2004 17:07 32 libfn.dll
      13/02/2008 17:55 130 live.ini
      09/01/2007 08:30 110 592 PURfr-fr.dll
      14/03/2005 14:58 7 073 scanoptions.tsi
      13 fichier(s) 2 938 121 octets

      Répertoire de C:\WINDOWS\Downloaded Program Files\CONFLICT.1

      15/06/2008 01:51 <REP> .
      15/06/2008 01:51 <REP> ..
      09/01/2008 15:01 32 bdcore.dll
      09/01/2008 15:01 118 784 bdupd.dll
      09/01/2008 15:01 53 248 ipsupd.dll
      26/02/2008 15:42 7 724 lang.ini
      09/01/2008 15:01 32 libfn.dll
      21/01/2008 17:43 130 live.ini
      26/02/2008 15:59 487 424 oscan82.ocx
      09/01/2008 15:01 6 828 scanoptions.tsi
      8 fichier(s) 674 202 octets

      Répertoire de C:\WINDOWS\Downloaded Program Files\CONFLICT.2

      15/06/2008 11:50 <REP> .
      15/06/2008 11:50 <REP> ..
      09/01/2008 15:01 32 bdcore.dll
      09/01/2008 15:01 118 784 bdupd.dll
      09/01/2008 15:01 53 248 ipsupd.dll
      26/02/2008 15:42 7 724 lang.ini
      09/01/2008 15:01 32 libfn.dll
      21/01/2008 17:43 130 live.ini
      26/02/2008 15:59 487 424 oscan82.ocx
      09/01/2008 15:01 6 828 scanoptions.tsi
      8 fichier(s) 674 202 octets

      Répertoire de C:\WINDOWS\Downloaded Program Files\CONFLICT.3

      15/06/2008 11:50 <REP> .
      15/06/2008 11:50 <REP> ..
      09/01/2008 15:01 32 bdcore.dll
      09/01/2008 15:01 118 784 bdupd.dll
      09/01/2008 15:01 53 248 ipsupd.dll
      26/02/2008 15:42 7 724 lang.ini
      09/01/2008 15:01 32 libfn.dll
      21/01/2008 17:43 130 live.ini
      07/02/2008 14:06 1 248 oscan8.inf
      26/02/2008 15:59 487 424 oscan82.ocx
      09/01/2008 15:01 6 828 scanoptions.tsi
      9 fichier(s) 675 450 octets

      Total des fichiers listés :
      38 fichier(s) 4 961 975 octets
      11 Rép(s) 6 275 686 400 octets libres

      Recherche de rootkit! (Merci S!Ri)

      Recherche d'infections connues

      Export des clefs sensibles..


      Liste des fichiers en exception sur le pare-feu XP SP2

      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "D:\\eMule\\emule.exe"="D:\\eMule\\emule.exe:*:Enabled:eMule"
      "D:\\Program Files\\TmNationsForever\\TmForever.exe"="D:\\Program Files\\TmNationsForever\\TmForever.exe:*:Enabled:TmForever"
      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

      Export de la clef SharedTaskScheduler

      [SharedTaskScheduler]
      "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
      "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"



      exports des policies
      REGEDIT4

      [system]
      "dontdisplaylastusername"=dword:00000000
      "legalnoticecaption"=""
      "legalnoticetext"=""
      "shutdownwithoutlogon"=dword:00000001
      "undockwithoutlogon"=dword:00000001



      Export des clefs sensibles..
      Rechercher adresses sensibles dans le fichier HOSTS...
      127.0.0.1 www.activexupdate.com
      127.0.0.1 activexupdate.com
      127.0.0.1 www.antispywareupdates.net
      127.0.0.1 antispywareupdates.net
      127.0.0.1 www.avpcheckupdate.com
      127.0.0.1 avpcheckupdate.com
      127.0.0.1 client.exeupdate.com
      127.0.0.1 www.eupdatepage.com
      127.0.0.1 eupdatepage.com
      127.0.0.1 www.exeupdate.com
      127.0.0.1 exeupdate.com
      127.0.0.1 www.hotwinupdates.com
      127.0.0.1 hotwinupdates.com
      127.0.0.1 www.lavasoftupdate.com
      127.0.0.1 lavasoftupdate.com
      127.0.0.1 www.malwarewipeupdate.com
      127.0.0.1 malwarewipeupdate.com
      127.0.0.1 www.msupdate.net
      127.0.0.1 msupdate.net
      127.0.0.1 www.msupdater.net
      127.0.0.1 msupdater.net
      127.0.0.1 www.necessaryupdates.com
      127.0.0.1 necessaryupdates.com
      127.0.0.1 newupdates.lzio.com
      127.0.0.1 redirect.msupdate.net
      127.0.0.1 search.keyword.exeupdate.com
      127.0.0.1 www.securityupdatesite.com
      127.0.0.1 securityupdatesite.com
      127.0.0.1 settings.updatemysettings.com
      127.0.0.1 www.spyaxeupdate.com
      127.0.0.1 spyaxeupdate.com
      127.0.0.1 www.spyfalconupdate.com
      127.0.0.1 spyfalconupdate.com
      127.0.0.1 www.systemupdates.net
      127.0.0.1 systemupdates.net
      127.0.0.1 trial.updates.winsoftware.com
      127.0.0.1 update.680180.net
      127.0.0.1 update.shareaza.com
      127.0.0.1 www.updatemysettings.com
      127.0.0.1 updatemysettings.com
      127.0.0.1 updates.spywarequake.com
      127.0.0.1 www.urgentsystemupdate.biz
      127.0.0.1 urgentsystemupdate.biz
      127.0.0.1 www.urgentsystemupdate.com
      127.0.0.1 urgentsystemupdate.com
      127.0.0.1 windupdates.com
      127.0.0.1 www.flwupdate.com
      127.0.0.1 flwupdate.com
      127.0.0.1 www.pandaantivirus-2007.com
      127.0.0.1 pandaantivirus-2007.com
      127.0.0.1 www.pandadownload-now.com
      127.0.0.1 pandadownload-now.com
      127.0.0.1 www.panda-hq.com
      127.0.0.1 panda-hq.com
      catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-06-15 12:08:58
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden services & system hive ...

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
      "s1"=dword:48db5cf1
      "s2"=dword:664aad8c
      "h0"=dword:00000001

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
      "h0"=dword:00000000
      "khjeh"=hex:bf,f4,e0,09,90,01,26,35,7a,fc,ec,f5,10,f0,63,fd,c3,64,f0,45,84,..
      "p0"="d:\Program Files\DAEMON Tools\"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
      "a0"=hex:20,01,00,00,a7,db,a3,44,bc,56,6e,6b,bb,46,7a,71,f9,cc,01,d6,b9,..
      "khjeh"=hex:5d,d4,a8,d5,75,72,fc,b4,7c,c7,09,4d,31,f1,35,3f,1d,2b,6a,53,05,..

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
      "khjeh"=hex:96,a6,8e,50,2b,5d,50,a5,3b,24,d9,cc,2c,f2,66,8c,6a,dc,10,4b,4b,..
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
      "h0"=dword:00000000
      "khjeh"=hex:bf,f4,e0,09,90,01,26,35,7a,fc,ec,f5,10,f0,63,fd,c3,64,f0,45,84,..
      "p0"="d:\Program Files\DAEMON Tools\"

      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
      "a0"=hex:20,01,00,00,a7,db,a3,44,bc,56,6e,6b,bb,46,7a,71,f9,cc,01,d6,b9,..
      "khjeh"=hex:5d,d4,a8,d5,75,72,fc,b4,7c,c7,09,4d,31,f1,35,3f,1d,2b,6a,53,05,..

      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
      "khjeh"=hex:71,45,8e,17,f1,8f,49,04,f6,ae,f2,a6,c7,84,87,f2,33,4a,90,34,9b,..
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
      "h0"=dword:00000000
      "khjeh"=hex:bf,f4,e0,09,90,01,26,35,7a,fc,ec,f5,10,f0,63,fd,c3,64,f0,45,84,..
      "p0"="d:\Program Files\DAEMON Tools\"

      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
      "a0"=hex:20,01,00,00,a7,db,a3,44,bc,56,6e,6b,bb,46,7a,71,f9,cc,01,d6,b9,..
      "khjeh"=hex:5d,d4,a8,d5,75,72,fc,b4,7c,c7,09,4d,31,f1,35,3f,1d,2b,6a,53,05,..

      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
      "khjeh"=hex:96,a6,8e,50,2b,5d,50,a5,3b,24,d9,cc,2c,f2,66,8c,6a,dc,10,4b,4b,..
      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
      "h0"=dword:00000000
      "khjeh"=hex:bf,f4,e0,09,90,01,26,35,7a,fc,ec,f5,10,f0,63,fd,c3,64,f0,45,84,..
      "p0"="d:\Program Files\DAEMON Tools\"

      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
      "a0"=hex:20,01,00,00,a7,db,a3,44,bc,56,6e,6b,bb,46,7a,71,f9,cc,01,d6,b9,..
      "khjeh"=hex:5d,d4,a8,d5,75,72,fc,b4,7c,c7,09,4d,31,f1,35,3f,1d,2b,6a,53,05,..

      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
      "khjeh"=hex:96,a6,8e,50,2b,5d,50,a5,3b,24,d9,cc,2c,f2,66,8c,6a,dc,10,4b,4b,..

      scanning hidden registry entries ...

      scanning hidden files ...

      scan completed successfully
      hidden services: 0
      hidden files: 0


      KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)

      Process list by traversal of KiWaitListHead

      4 - System
      216 - ashServ.exe
      712 - csrss.exe
      736 - winlogon.exe
      780 - services.exe
      792 - lsass.exe
      948 - svchost.exe
      1028 - svchost.exe
      1136 - svchost.exe
      1260 - eEBSvc.exe
      1264 - svchost.exe
      1288 - nvsvc32.exe
      1332 - svchost.exe
      1452 - vsmon.exe
      1524 - acs.exe
      1580 - guard.exe
      1768 - explorer.exe
      2368 - cmd.exe
      2652 - ashMaiSv.exe
      2720 - ashWebSv.exe
      2944 - alg.exe
      3384 - VTTimer.exe
      3440 - firefox.exe
      3616 - iexplore.exe
      3860 - ashDisp.exe
      3872 - zlclient.exe
      3888 - usnsvc.exe
      3952 - avgas.exe
      3960 - ctfmon.exe
      4028 - msnmsgr.exe

      Total number of processes = 30
      NOTE: Under WinXP, this will not show all processes.

      KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)

      Driver/Module list by traversal of PsLoadedModuleList

      804D7000 - \WINDOWS\system32\ntoskrnl.exe
      806EC000 - \WINDOWS\system32\hal.dll
      F7987000 - \WINDOWS\system32\KDCOM.DLL
      F7897000 - \WINDOWS\system32\BOOTVID.dll
      F74FF000 - sptd.sys
      F7989000 - \WINDOWS\System32\Drivers\WMILIB.SYS
      F74E7000 - \WINDOWS\System32\Drivers\SCSIPORT.SYS
      F74B8000 - ACPI.sys
      F74A7000 - pci.sys
      F75F7000 - isapnp.sys
      F798B000 - viaide.sys
      F7707000 - \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
      F7607000 - MountMgr.sys
      F7878000 - ftdisk.sys
      F770F000 - PartMgr.sys
      F7617000 - VolSnap.sys
      F7860000 - atapi.sys
      F7627000 - disk.sys
      F7637000 - \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
      F7840000 - fltMgr.sys
      F782E000 - sr.sys
      F7647000 - PxHelp20.sys
      F7970000 - KSecDD.sys
      F7B52000 - Ntfs.sys
      F7A22000 - NDIS.sys
      F7657000 - uagp35.sys
      F795C000 - srescan.sys
      F7A0F000 - sfvfs02.sys
      F7717000 - sfhlp02.sys
      F7B40000 - sfdrv01.sys
      F7B25000 - Mup.sys
      BAF98000 - \SystemRoot\system32\DRIVERS\amdk7.sys
      BA6A4000 - \SystemRoot\system32\DRIVERS\nv4_mini.sys
      BA690000 - \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
      BAF88000 - \SystemRoot\system32\DRIVERS\cdrom.sys
      BAF78000 - \SystemRoot\system32\DRIVERS\redbook.sys
      BA66D000 - \SystemRoot\system32\DRIVERS\ks.sys
      BAF68000 - \SystemRoot\system32\DRIVERS\imapi.sys
      F77BF000 - \SystemRoot\system32\DRIVERS\usbuhci.sys
      BA64A000 - \SystemRoot\system32\DRIVERS\USBPORT.SYS
      F77C7000 - \SystemRoot\system32\DRIVERS\usbehci.sys
      BA622000 - \SystemRoot\system32\drivers\vinyl97.sys
      BA5FE000 - \SystemRoot\system32\drivers\portcls.sys
      BAF58000 - \SystemRoot\system32\drivers\drmk.sys
      F77CF000 - \SystemRoot\system32\DRIVERS\fetnd5.sys
      BA5B4000 - \SystemRoot\System32\Drivers\afzidbmi.SYS
      F7737000 - \SystemRoot\system32\DRIVERS\fdc.sys
      BA5A3000 - \SystemRoot\system32\DRIVERS\serial.sys
      BAEF4000 - \SystemRoot\system32\DRIVERS\serenum.sys
      BA58F000 - \SystemRoot\system32\DRIVERS\parport.sys
      BAF48000 - \SystemRoot\system32\DRIVERS\i8042prt.sys
      F773F000 - \SystemRoot\system32\DRIVERS\mouclass.sys
      BAAC2000 - \SystemRoot\system32\DRIVERS\audstub.sys
      F7747000 - \SystemRoot\system32\DRIVERS\rasirda.sys
      F774F000 - \SystemRoot\system32\DRIVERS\TDI.SYS
      BAF38000 - \SystemRoot\system32\DRIVERS\rasl2tp.sys
      BAEEC000 - \SystemRoot\system32\DRIVERS\ndistapi.sys
      BA578000 - \SystemRoot\system32\DRIVERS\ndiswan.sys
      F7687000 - \SystemRoot\system32\DRIVERS\raspppoe.sys
      F7697000 - \SystemRoot\system32\DRIVERS\raspptp.sys
      BA4C7000 - \SystemRoot\system32\DRIVERS\psched.sys
      F76A7000 - \SystemRoot\system32\DRIVERS\msgpc.sys
      F7757000 - \SystemRoot\system32\DRIVERS\ptilink.sys
      F775F000 - \SystemRoot\system32\DRIVERS\raspti.sys
      F76B7000 - \SystemRoot\system32\DRIVERS\termdd.sys
      F7767000 - \SystemRoot\system32\DRIVERS\kbdclass.sys
      F79BB000 - \SystemRoot\system32\DRIVERS\swenum.sys
      BA493000 - \SystemRoot\system32\DRIVERS\update.sys
      BAEE8000 - \SystemRoot\system32\DRIVERS\mssmbios.sys
      F76C7000 - \SystemRoot\System32\Drivers\NDProxy.SYS
      F76D7000 - \SystemRoot\system32\DRIVERS\usbhub.sys
      F79BF000 - \SystemRoot\system32\DRIVERS\USBD.SYS
      F7777000 - \SystemRoot\system32\DRIVERS\flpydisk.sys
      B82F8000 - \SystemRoot\system32\DRIVERS\klif.sys
      F79C3000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
      F7A76000 - \SystemRoot\System32\Drivers\Null.SYS
      F79C5000 - \SystemRoot\System32\Drivers\Beep.SYS
      F7A61000 - \SystemRoot\System32\DRIVERS\AvgAsCln.sys
      F7787000 - \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
      F778F000 - \SystemRoot\System32\drivers\vga.sys
      F79C9000 - \SystemRoot\System32\Drivers\mnmdd.SYS
      F79CB000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
      F7797000 - \SystemRoot\System32\Drivers\Msfs.SYS
      F779F000 - \SystemRoot\System32\Drivers\Npfs.SYS
      BAFE8000 - \SystemRoot\system32\DRIVERS\rasacd.sys
      B82C5000 - \SystemRoot\system32\DRIVERS\ipsec.sys
      B826D000 - \SystemRoot\system32\DRIVERS\tcpip.sys
      F76F7000 - \SystemRoot\System32\Drivers\aswTdi.SYS
      B8245000 - \SystemRoot\system32\DRIVERS\netbt.sys
      B81E5000 - \SystemRoot\System32\vsdatant.sys
      B819C000 - \SystemRoot\system32\DRIVERS\ipnat.sys
      F7497000 - \SystemRoot\system32\DRIVERS\wanarp.sys
      BAF2C000 - \SystemRoot\System32\drivers\ws2ifsl.sys
      B817A000 - \SystemRoot\System32\drivers\afd.sys
      F7487000 - \SystemRoot\system32\DRIVERS\netbios.sys
      B814F000 - \SystemRoot\system32\DRIVERS\rdbss.sys
      B80E0000 - \SystemRoot\system32\DRIVERS\mrxsmb.sys
      F7477000 - \SystemRoot\System32\Drivers\Fips.SYS
      F7AB8000 - \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
      B80C9000 - \SystemRoot\System32\Drivers\aswSP.SYS
      F77AF000 - \SystemRoot\System32\Drivers\Aavmker4.SYS
      B7F8F000 - \SystemRoot\system32\DRIVERS\Ltn_stk7070P.sys
      BAEFC000 - \SystemRoot\system32\DRIVERS\BdaSup.SYS
      BA48B000 - \SystemRoot\system32\DRIVERS\Ltn_stkrc.sys
      F7457000 - \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
      BA487000 - \SystemRoot\system32\DRIVERS\kbdhid.sys
      F7447000 - \SystemRoot\System32\Drivers\Cdfs.SYS
      F77E7000 - \SystemRoot\system32\DRIVERS\usbccgp.sys
      BA483000 - \SystemRoot\system32\DRIVERS\hidusb.sys
      BA47F000 - \SystemRoot\system32\DRIVERS\mouhid.sys
      B7F77000 - \SystemRoot\System32\Drivers\dump_atapi.sys
      F79FB000 - \SystemRoot\System32\Drivers\dump_WMILIB.SYS
      BF800000 - \SystemRoot\System32\win32k.sys
      BAE80000 - \SystemRoot\System32\drivers\Dxapi.sys
      F77F7000 - \SystemRoot\System32\watchdog.sys
      BF9C3000 - \SystemRoot\System32\drivers\dxg.sys
      BAADA000 - \SystemRoot\System32\drivers\dxgthk.sys
      BF9D5000 - \SystemRoot\System32\nv4_disp.dll
      F77B7000 - \SystemRoot\system32\DRIVERS\aswFsBlk.sys
      B78BE000 - \SystemRoot\system32\DRIVERS\AegisP.sys
      B77E0000 - \SystemRoot\system32\DRIVERS\irda.sys
      B78B2000 - \SystemRoot\system32\DRIVERS\ndisuio.sys
      B6DB5000 - \SystemRoot\System32\Drivers\Fastfat.SYS
      B6C0F000 - \SystemRoot\System32\Drivers\aswMon2.SYS
      B6A6A000 - \SystemRoot\system32\drivers\wdmaud.sys
      B6C55000 - \SystemRoot\system32\drivers\sysaudio.sys
      B6830000 - \SystemRoot\system32\DRIVERS\mrxdav.sys
      F799D000 - \SystemRoot\System32\Drivers\ParVdm.SYS
      B66FF000 - \SystemRoot\System32\Drivers\HTTP.sys
      B69D4000 - \SystemRoot\system32\DRIVERS\secdrv.sys
      B656D000 - \SystemRoot\system32\DRIVERS\srv.sys
      B6565000 - \SystemRoot\System32\Drivers\aswRdr.SYS
      B36A3000 - \SystemRoot\system32\drivers\kmixer.sys
      F7AB6000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys

      Total number of drivers = 134

      Liste des programmes installes

      Adaptateur USB-IrDA
      Adobe Bridge 1.0
      Adobe Common File Installer
      Adobe Help Center 1.0
      Adobe Photoshop CS2
      Adobe Photoshop CS2
      Adobe Reader 7.1.0 - Français
      Adobe Shockwave Player
      Adobe Stock Photos 1.0
      Archiveur WinRAR
      Assistant de connexion Windows Live
      ATI Display Driver
      AutoCAD 2007 - Français
      Autodesk DWF Viewer
      avast! Antivirus
      AVG Anti-Spyware 7.5
      Barre de confiance CM-CIC
      Budget Plus
      Camera RAW Plug-In for EPSON Creativity Suite
      CCleaner (remove only)
      eMule
      EPSON Attach To Email
      EPSON Attach To Email
      EPSON Copy Utility 3
      EPSON Easy Photo Print
      EPSON File Manager
      EPSON Logiciel imprimante
      EPSON Logiciel imprimante
      EPSON Scan
      EPSON Scan Assistant
      EPSON Status Monitor 2
      EPSON Status Monitor 2
      EPSON Stylus CX7300_CX8300_DX7400_DX8400 Manuel
      EPSON Web-To-Page
      Google Earth
      GPL Ghostscript 8.50
      GPL Ghostscript Fonts
      HijackThis 2.0.2
      Java(TM) 6 Update 4
      Java(TM) 6 Update 5
      Java(TM) SE Runtime Environment 6
      Java(TM) SE Runtime Environment 6 Update 1
      Kaspersky Online Scanner
      Lecteur Windows Media 11
      Macromedia Flash Player 8
      Malwarebytes' Anti-Malware
      Managed DirectX (0901)
      Microsoft .NET Framework 2.0 Language Pack - FRA
      Microsoft .NET Framework 2.0 Service Pack 1
      Microsoft Compression Client Pack 1.0 for Windows XP
      Microsoft Internationalized Domain Names Mitigation APIs
      Microsoft National Language Support Downlevel APIs
      Microsoft User-Mode Driver Framework Feature Pack 1.0
      Microsoft Visual C++ 2005 Redistributable
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)
      Mise à jour de sécurité pour Windows XP (KB923789)
      Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA
      Mozilla Firefox (2.0.0.14)
      MSXML 4.0 SP2 (KB927978)
      MSXML 4.0 SP2 (KB936181)
      MSXML 4.0 SP2 Parser and SDK
      Multimedia Combo Set Driver
      Nero
      NETGEAR WPN311 Wireless Adapter
      NETGEAR WPN311 Wireless Adapter
      NVIDIA Drivers
      OpenOffice.org 2.4
      Pinnacle TVCenter Pro
      PSP ISO Compressor
      PSP WIFI Max
      Room Arranger (remove only)
      S3 S3Display
      S3 S3Gamma2
      S3 S3Info2
      S3 S3Overlay
      Sony Ericsson PC Suite
      Spybot - Search & Destroy
      Spybot - Search & Destroy 1.5.2.20
      Spyware Doctor 5.0
      TeLL me More
      TerraExplorer
      TmNationsForever
      VaryView (remove only)
      VideoLAN VLC media player 0.8.6c
      Winamp
      Windows Genuine Advantage Notifications (KB905474)
      Windows Genuine Advantage Validation Tool (KB892130)
      Windows Genuine Advantage Validation Tool (KB892130)
      Windows Internet Explorer 7
      Windows Live installer
      Windows Live Messenger
      Windows Live OneCare safety scanner
      Windows Media Format 11 runtime
      Windows Media Format 11 runtime
      Windows Media Player 11
      ZoneAlarm
      ZyDAS IEEE 802.11 b+g Wireless LAN - USB



      Le volume dans le lecteur C n'a pas de nom.
      Le numéro de série du volume est F831-BD8D

      Répertoire de C:\Program Files

      14/06/2008 19:25 <REP> .
      14/06/2008 19:25 <REP> ..
      19/06/2007 17:42 <REP> Adobe
      12/07/2007 09:51 <REP> ahead
      31/05/2008 15:20 <REP> Alwil Software
      19/06/2007 14:42 <REP> AnswerWorks 4.0
      28/12/2007 01:20 <REP> Apache Group
      22/12/2007 02:38 <REP> Apache Software Foundation
      19/06/2007 14:35 <REP> Autodesk
      28/05/2008 19:31 <REP> BarreConfCMCIC
      22/06/2007 15:48 <REP> BitTorrent
      18/06/2007 02:49 <REP> CCleaner
      22/05/2008 23:47 <REP> Cheewoo
      18/06/2007 02:22 <REP> ComPlus Applications
      10/05/2008 13:42 <REP> DaemonTools_WhenUSave_Installer
      11/01/2008 19:10 <REP> Datel
      26/05/2008 14:31 <REP> DivX
      04/01/2008 13:36 <REP> Elaborate Bytes
      29/04/2008 22:57 <REP> EPSON
      08/06/2008 14:01 <REP> Fichiers communs
      12/05/2008 21:29 <REP> FlashGet
      31/05/2008 00:11 <REP> Google
      10/06/2008 23:27 <REP> Grisoft
      15/06/2008 10:54 <REP> Internet Explorer
      31/05/2008 18:04 <REP> iSafer
      09/05/2008 11:14 <REP> Java
      14/06/2008 19:22 <REP> Malwarebytes' Anti-Malware
      18/11/2007 21:47 <REP> Managed DirectX (0901)
      31/05/2008 01:28 <REP> Messenger
      18/06/2007 02:25 <REP> microsoft frontpage
      19/06/2007 14:43 <REP> Microsoft Office
      31/05/2008 01:20 <REP> Movie Maker
      15/06/2008 11:27 <REP> Mozilla Firefox
      18/06/2007 02:20 <REP> MSN
      18/06/2007 02:21 <REP> MSN Gaming Zone
      19/06/2007 16:45 <REP> MSXML 4.0
      05/05/2008 19:51 <REP> Multimedia Combo Set
      31/05/2008 00:04 <REP> NCH Swift Sound
      20/10/2007 18:48 <REP> NETGEAR
      31/05/2008 01:20 <REP> NetMeeting
      18/06/2007 02:21 <REP> Online Services
      01/05/2008 22:05 <REP> OpenOffice.org 2.2
      01/05/2008 22:07 <REP> OpenOffice.org 2.4
      31/05/2008 01:20 <REP> Outlook Express
      20/10/2007 20:50 <REP> Pinnacle
      18/06/2007 02:23 <REP> Services en ligne
      02/06/2008 00:10 <REP> Skyline
      09/11/2007 21:21 <REP> Sony Ericsson
      27/04/2008 20:01 <REP> Spybot - Search & Destroy
      12/06/2008 22:26 <REP> Spyware Doctor
      14/06/2008 19:25 <REP> Trend Micro
      04/01/2008 14:58 <REP> TRUST SPYC@M 100
      31/05/2008 00:05 <REP> Uniblue
      20/10/2007 22:38 <REP> Wanadoo
      26/05/2008 14:24 <REP> Winamp
      05/05/2008 20:11 <REP> Windows Live
      14/06/2008 12:08 <REP> Windows Live Safety Center
      27/06/2007 16:27 <REP> Windows Media Connect 2
      31/05/2008 01:20 <REP> Windows Media Player
      31/05/2008 01:20 <REP> Windows NT
      31/05/2008 01:51 <REP> Winpooch
      18/06/2007 03:05 <REP> WinRAR
      18/06/2007 02:25 <REP> xerox
      31/05/2008 15:43 <REP> Zone Labs
      11/01/2008 19:10 <REP> ZyDAS Technology Corporation
      0 fichier(s) 0 octets
      65 Rép(s) 6 264 455 168 octets libres
      Le volume dans le lecteur C n'a pas de nom.
      Le numéro de série du volume est F831-BD8D

      Répertoire de C:\Program Files\fichiers communs

      08/06/2008 14:01 <REP> .
      08/06/2008 14:01 <REP> ..
      20/05/2008 23:03 <REP> Adobe
      19/06/2007 01:33 <REP> Adobe Systems Shared
      19/06/2007 14:44 <REP> Autodesk Shared
      22/05/2008 23:47 <REP> Cheewoo
      19/06/2007 14:43 <REP> Designer
      29/04/2008 23:02 <REP> InstallShield
      19/06/2007 16:07 <REP> Java
      05/05/2008 20:10 <REP> Microsoft Shared
      18/06/2007 02:22 <REP> MSSoap
      05/07/2007 10:27 <REP> NSV
      08/06/2008 14:01 <REP> Nullsoft
      18/06/2007 04:14 <REP> ODBC
      18/06/2007 03:49 <REP> PC Tools
      18/06/2007 02:22 <REP> Services
      09/11/2007 21:21 <REP> Sony Ericsson Shared
      18/06/2007 04:14 <REP> SpeechEngines
      31/05/2008 01:20 <REP> System
      09/11/2007 21:21 <REP> Teleca Shared
      0 fichier(s) 0 octets
      20 Rép(s) 6 264 451 072 octets libres




      c:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
      c:\Documents and Settings\All Users\Bureau\nailfix\Process.exe
      c:\Documents and Settings\johnny\Application Data\Adobe\Acrobat\7.0\Updater\AdbeRdr709_fr_FR.exe
      c:\Documents and Settings\johnny\Application Data\Adobe\Acrobat\7.0\Updater\AdbeRdr710_fr_FR.exe
      c:\Documents and Settings\johnny\Bureau\nailfix.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\catchme.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\diff.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\dumphive.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\FilesInfoCmd.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\find2.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\Fport.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\grep.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\gzip.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\KProcCheck.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\LFiles.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\LISTDLLS.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\md5sums.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\pslist.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\sigcheck.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\streams.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\swreg.exe
      c:\Documents and Settings\johnny\Bureau\DiagHelp\DiagHelp\tar.exe
      c:\Documents and Settings\johnny\Bureau\Nouveau dossier (2)\cports.exe
      c:\Documents and Settings\johnny\Local Settings\Temp\Rar$EX00.391\cports.exe
      c:\Documents and Settings\johnny\Mes documents\dwg2pdfmx.exe
      c:\Documents and Settings\All Users\Application Data\Grisoft\AVG Anti-Spyware 7.5\Downloads\help.dll
      c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll
      c:\Documents and Settings\All Users\Application Data\Skyline\TEDetect.dll
      c:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll

      ****** Fin du rapport DiagHelp
      Veuillez svp envoyer le fichier C:\upload_moi_PC.tar.gz a l'adresse http://upload.malekal.com
      0
  4. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bon et bien je ne vois pas grand chose dans ce rapport

    recherche et supprime ceci
    C:\WINDOWS\118294.78
    C:\WINDOWS\etel1.ini

    ensuite

    Télécharge ATF Cleaner par Atribune.
    http://www.atribune.org/ccount/click.php?id=1

    Double-clique ATF-Cleaner.exe afin de lancer le programme.
    Sous l'onglet Main, choisis : Select All
    Clique sur le bouton Empty Selected

    Si tu utilises le navigateur Firefox :

    Clique Firefox au haut et choisis : Select All
    Clique le bouton Empty Selected
    NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

    Si tu utilises le navigateur Opera :

    Clique Opera au haut et choisis : Select All
    Clique le bouton Empty Selected
    NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

    Clique Exit, du menu prinicipal, afin de fermer le programme.
    Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.
    C’est généralement lorsque le disque dur plante qu’on se rend compte qu’on a oublié de le sauvegarder.

    repasse Spybot

    ensuite suit les étapes de ce lien http://www.commentcamarche.net/faq/sujet 3446 windows xp mon pc rame que faire

    rédémarre ton pc et tient moi au courant

    @+
    0
    1. don-diego Messages postés 11 Statut Membre
       
      c'est toujours moi mais sous mon pseudo de mon compte

      bon le probleme persiste je te mets le message de google ainsi que l'adresse de la page en espérant que ça te guide sur quelque chose.

      http://sorry.google.com/sorry/?continue=http://www.google.com/search%3Fclient%3Dfirefox-a%26rls%3Dorg.mozilla%253Afr%253Aofficial%26channel%3Ds%26hl%3Dfr%26q%3Dbanque%26lr%3D%26btnG%3DRecherche%2BGoogle

      Nous sommes désolés...

      ... Votre requête ressemble étrangement à des requêtes automatisées provenant d'un virus informatique ou d'une application de type spyware. Nous devons protéger avant tout nos utilisateurs et ne pouvons traiter votre requête pour l'instant.

      Nous rétablirons votre accès le plus rapidement possible. Essayez de nouveau prochainement. Si vous pensez que votre ordinateur ou votre réseau fait l'objet d'une attaque, vous pouvez lancer un utilitaire de détection de virus ou encore un utilitaire de suppression de spyware pour garantir l'intégrité de votre système.

      Si cette erreur s'affiche en permanence, vous pouvez résoudre le problème en supprimant votre cookie Google et en vous rendant de nouveau sur le site de Google. Pour obtenir les instructions correspondant à votre navigateur, consultez le centre d'assistance en ligne de votre navigateur.

      Si l'ensemble du réseau est affecté, vous trouverez d'autres informations dans le Centre d'aide du service de recherche sur le Web Google.

      Nous vous prions de bien vouloir nous excuser pour les désagréments occasionnés et espérons vous revoir sur Google très prochainement
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Quel navigateur utilise tu
    Essaye le navigateur Firefox plus sur/securisé qu IE
    Firefox n'utilise pas le dangereux protocole ActiveX
    Téléchargement: => http://www.mozilla-europe.org/fr/products/firefox/][b]Firefox
    Tutorial pour le sécuriser: => https://forum.zebulon.fr/topic/69628-s%C3%A9curiser-un-peu-plus-firefox/

    0
    1. don-diego Messages postés 11 Statut Membre
       
      je suis déja passé sur mozilla firefox pour palier a se probleme mais cela n a était sans succés
      0
  7. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    as tu essayé avec un autre moteur de recherche
    style yahoo, free, lycos ?
    0
  8. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bonsoir

    on vérifie une chose

    Télécharge sur le Bureau http://siri.urz.free.fr/Fix/SmitfraudFix.exe
    => Double clic sur SmitfraudFix.zip
    => Extraire tout
    => Double clic sur SmitfraudFix
    => Double Clic sur SmitfraudFix.cmd
    => Choisir Option 1
    => poste le rapport
    @+
    0
    1. don-diego Messages postés 11 Statut Membre
       
      voila le rapport, eut être un espoir...

      SmitFraudFix v2.325

      Rapport fait à 21:08:26,70, 16/06/2008
      Executé à partir de C:\Program Files\Mozilla Firefox\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\ZoneLabs\vsmon.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\netdde.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\VTTimer.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Program Files\Multimedia Combo Set\MouseDrv.exe
      C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\WINDOWS\system32\rsvp.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\cmd.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      Fichier hosts corrompu !

      127.0.0.1 www.legal-at-spybot.info
      127.0.0.1 legal-at-spybot.info

      »»»»»»»»»»»»»»»»»»»»»»»» C:\


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\johnny


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\johnny\Application Data


      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer


      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\johnny\Favoris


      »»»»»»»»»»»»»»»»»»»»»»»» Bureau


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues


      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="Ma page d'accueil"


      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri



      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri


      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri


      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll


      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"="avgrsstx.dll"
      "LoadAppInit_DLLs"=dword:00000001


      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      "System"=""


      »»»»»»»»»»»»»»»»»»»»»»»» Rustock



      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: Carte Fast Ethernet compatible VIA - Miniport d'ordonnancement de paquets
      DNS Server Search Order: 82.216.111.123
      DNS Server Search Order: 82.216.111.124
      DNS Server Search Order: 82.216.111.125
      DNS Server Search Order: 82.216.111.121
      DNS Server Search Order: 82.216.111.122

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{C2E7B846-06B6-4B6C-B0BD-A7AA3E2C8586}: DhcpNameServer=82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121 82.216.111.122
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{C2E7B846-06B6-4B6C-B0BD-A7AA3E2C8586}: DhcpNameServer=82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121 82.216.111.122
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121 82.216.111.122
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=82.216.111.123 82.216.111.124 82.216.111.125 82.216.111.121 82.216.111.122


      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll


      »»»»»»»»»»»»»»»»»»»»»»»» Fin
      0
  9. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Redémarre l'ordinateur en mode sans échec
    (tapoter F8 au boot pour obtenir le menu de démarrage ou http://service1.symantec.com/

    * Double clique sur smitfraudfix.cmd

    * Sélectionne 2 pour supprimer les fichiers responsables de l'infection.

    A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran et supprimer les clés de démarrage automatique de l'infection.

    A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

    * Redémarre en mode normal et poste le rapport ici

    N.B.: Cette étape élimine les fichiers infectieux détectés à l'étape #1
    Attention que l'option 2 de l'outil supprime le fond d'écran !

    reposte un nouveau rapport hijackthis à l'issu stp
    0
  10. don-diego Messages postés 11 Statut Membre
     
    bon je ne sais pas ce que c'est truc provoqué mais le problème est toujours la.

    voila le rapport HijackThis.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:54:16, on 16/06/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\netdde.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\Multimedia Combo Set\MouseDrv.exe
    C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=212.241.180.239:81
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (disabled by BHODemon)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (disabled by BHODemon)
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [WireLessMouse ] C:\Program Files\Multimedia Combo Set\MouseDrv.exe
    O4 - HKLM\..\Run: [WireLessKeyboard ] C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    0
  11. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    ok on essaye ceci

    Télécharge sur ton bureau RHosts (Merci à S!ri) disponible ici,
    http://siri.urz.free.fr/Softs/RHosts.exe
    Double-clique sur Rhosts.exe et clique sur "restaurer".

    0
  12. don-diego Messages postés 11 Statut Membre
     
    nan, rien y change, j avais restaurai la liste hosts avec spybot.

    pppppfffffff......... qu'est ce qui peut bien causé ceci!

    merci pour ton aide quand meme
    0
  13. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bonjour

    Pour vérif on va faire un nouveau scan
    si je ne vois rien il me faudra demander de l'aide

    Télécharge sur ton bureau DSS (ex Comboscan) de Deckard:

    (choisis enregistrer, puis Bureau comme emplacement)

    http://deckard.geekstogo.com/dss.exe

    Ferme toutes les applications en cours.

    Double-clic sur comboscan.exe pour lancer l'outil.

    Une fenêtre s'ouvre, invitant à fermer toutes les applications, clique sur OK.

    A la fin de l'analyse, une fenêtre s'ouvre, clique sur OK.

    Le rapport Comboscan.txt va s'afficher, copie le dans ta prochaine réponse.
    Si un rapport complémentaire a été créé, poste le aussi dans ta rép

    0
  14. don-diego Messages postés 11 Statut Membre
     
    bonsoir, bon il ma sorti deux rapport.

    pour info je suis passé sur XP sp3 ..... ça n a rien changé.... l'esoir fait vivre.
    j ai toujours du mal a ouvrir mes pages internet (Délai d'attente dépassé) alors que quand je télécharge un fichier je suis a 500, 800ko/s. et c'est plutot lourd car je suis obligé de relancé la page 3 a 5 fois pour obtenir quelque chose.

    alors voila le premier.

    Deckard's System Scanner v20071014.68
    Run by johnny on 2008-06-17 23:25:31
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------

    -- System Restore --------------------------------------------------------------

    Successfully created a Deckard's System Scanner Restore Point.

    -- Last 5 Restore Point(s) --
    12: 2008-06-17 21:25:39 UTC - RP76 - Deckard's System Scanner Restore Point
    11: 2008-06-17 19:55:00 UTC - RP75 - Software Distribution Service 3.0
    10: 2008-06-17 19:41:15 UTC - RP74 - Installed Windows Defender
    9: 2008-06-17 19:18:18 UTC - RP73 - Software Distribution Service 3.0
    8: 2008-06-17 19:03:52 UTC - RP72 - Le KB950762 pour Windows XP a été installé.

    -- First Restore Point --
    1: 2008-06-15 15:01:15 UTC - RP65 - Opération de restauration

    Backed up registry hives.
    Performed disk cleanup.

    -- HijackThis (run as johnny.exe) ----------------------------------------------

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 23:26:51, on 17/06/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\Multimedia Combo Set\MouseDrv.exe
    C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\johnny\Bureau\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\johnny.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=212.241.180.239:81
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (disabled by BHODemon)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (disabled by BHODemon)
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [WireLessMouse ] C:\Program Files\Multimedia Combo Set\MouseDrv.exe
    O4 - HKLM\..\Run: [WireLessKeyboard ] C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -masquer
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\spyware doctor\filterlsp.dll
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner371420.cab
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: NetLimiter (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 2 Pro\nlsvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    0
  15. don-diego Messages postés 11 Statut Membre
     
    bon mon probleme de vitesse internet est résolu mais le probleme GOOGLE est toujours la!

    voila un nouveau rapport.... on c'est jamais.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:37:48, on 18/06/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\Multimedia Combo Set\MouseDrv.exe
    C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=212.241.180.239:81
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (disabled by BHODemon)
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [WireLessMouse ] C:\Program Files\Multimedia Combo Set\MouseDrv.exe
    O4 - HKLM\..\Run: [WireLessKeyboard ] C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -masquer
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O20 - AppInit_DLLs: avgrsstx.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    0
  16. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Essaye ceci

    http://telechargement.zebulon.fr/zeb-restore.html

    ensuite clique sur
    * Réparation IE
    * Sites de confiance et sensibles
    * Préfixes et Protocoles Internet

    et fait restaurer
    redémarrer ton PC et tient moi au courant
    0
  17. don-diego Messages postés 11 Statut Membre
     
    bon cela na rien changé, dit moi, sais tu comment changer d'adresse IP?
    0
  18. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Je ne pense pas que ce soit la meilleure chose à faire
    mais bon http://noos.free.fr/faq/7b.html

    désolé mais je ne vois plus rien pour ce soucis
    fait ceci (IMPORTANT)

    =démarrer
    =panneau de configuration
    =système
    =onglet Restauration système
    =coche la case (Désactiver la restauration système)
    =redémarre l'ordinateur
    =réactive la ensuite

    @+
    0
    1. don-diego Messages postés 11 Statut Membre
       
      bon rien y fait.... snif

      bon merci quand meme pour ton aide.
      0