Virus win 32

Bonjour, je vous renvoi mon message car avec firefox ca marche pas du tout .j ai un probleme de virus win32 qui me bogue et je sait pas comment fsire pour m en debaraaser je connait absolument rien au ordi a part pitonner dessus
pouvez vous m aider je vous envoiemon rapport hijaLogfile of HijackThis v1.99.1
Scan saved at 09:52:17, on 2008-05-24
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
C:\Program Files\Bell\Gestionnaire de securite\RPS.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Accélérateur du service de base Sympatico\slipaccel.exe
C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Bell\Sympatico Security Advisor\SSAComHandler.exe
C:\Users\guy richard\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fsympatico.msn.ca%2fdefaultf.aspx%2f%3f
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sympatico.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Bell\Gestionnaire de securite\pkR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Media Player Classic - {D2A8552D-4340-413E-B94E-245827FBC269} - C:\Windows\ausctv32a.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [mpeg wma] "C:\ProgramData\popcompcomp.680kc"
O4 - HKLM\..\Run: [vc log bows face] "C:\ProgramData\meal real draw.k5co81"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
O4 - HKLM\..\Run: [Gestionnaire de sécurité Sympatico] "C:\Program Files\Bell\Gestionnaire de securite\Rps.exe"
O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Bell\Gestionnaire de securite\ZkRunOnceR.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [BTBFirstRun] C:\Program Files\Hewlett-Packard\SDP\hprun.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - Global Startup: Accélérateur du service de base.lnk = ?
O4 - Global Startup: Connexions HP.lnk = C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-ca.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} (HPDDClientExec Class) - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxdev.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - (no file)
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Service de mise-à-jour pour le Gestionnaire de sécurité Sympatico (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Bell\Gestionnaire de securite\rpsupdaterR.exe
O23 - Service: Gestionnaire de sécurité Sympatico Coupe-feu (RP_FWS) - Bell Sympatico - C:\Program Files\Bell\Gestionnaire de securite\Fws.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30003 (W3SVC) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30001 (WAS) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-20001 (WMSvc) - Unknown owner - %windir%\system32\inetsrv\wmsvc.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

kthis je crois que vouis demander a tous as lors le voici
Configuration: Windows Vista
Internet Explorer 7.0

19 réponses

  1. O4 - HKLM\..\Run: [mpeg wma] "C:\ProgramData\popcompcomp.680kc"

    O4 - HKLM\..\Run: [vc log bows face] "C:\ProgramData\meal real draw.k5co81"

    O4 - HKLM\..\Run: [vc log bows face] "C:\ProgramData\meal real draw.k5co81"

    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe

    coche ces lignes et clic sur fixcheket

    ensuite tu desinstal cette vertion de hitjacthis et instal celle la:
    https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/29061.html

    ensuite tu sup le fichier de hitjacthis qui as sur ton bureau et tu refait un scan avec le nouveau hitjakthis
    1. Salut

      Les fichiers infectés tu les supprimes comment ??

      Ça sert à rien de faire supprimer les lignes..........

  2. Salut,

    c'est une catastrophe ton ordi

    1) Tu n'as pas téléchargé la version à jour de Hijackthis

    2) Tu n'as pas de pare-feu ni d'antivirus

    Résous d'abord ces problèmes avant d'envisager une désinfection.

    ciao

    Zor
    1. Comme l'a si bien dit Amd64, télécharge la nouvelle version d'Hijackthis.

      puis

      installe un anti-virus https://www.malekal.com/avira-free-security-antivirus-gratuit/

      installe un pare-feu http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm

      et Malwarebytes antimalware (MBAM)

      Télécharge Malwarebytes' Anti-Malware (MBAM) https://www.01net.com/telecharger/windows/Securite/anti-spam/fiches/44096.html

      Sauvegarde ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

      Clic droit sur le bureau => nouveau doccument => doccument texte et copi/colle ces instructions pour faire la manip' correctement !

      * Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton Bureau.

      A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

      * Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

      Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware soient cochées.

      MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :

      * Dans l'onglet analyse, vérifie que "Exécuter un examen complet" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

      MBAM analyse ton ordinateur. L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.

      A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

      * Si des malwares ont été détectés, leur liste s'affiche.
      En cliquant sur Suppression <== (a faire impérativement sous peine de recommencer le scan) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

      MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Ferme le Bloc-notes. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

      Ferme MBAM en cliquant sur Quitter.

      Poste le rapport dans ta réponse

      EN RESUME,
      fais un scan en mode sans échec avec Antivir, MBAM et Hijackthis
      Copie les 3 rapports ici

      Bonne chance

      Zor
      1. Bonsoir, Copie colle ton rapport HijackThis à cette adresse http://www.hijackthis.de/fr et clic sur analyser.Cela t'expliquera un peu.Surtout ne fait rien sans l'accord de celui qui suit ton pbs, c'est juste pour un peu plus d'infos.

        Cordialement.
        1. voici j ai fait le menage en telechargant cccleaner ainsi que antivir il a trouver 3 trojan qu il a mit en quarantaine
          ensuite j ai telecharger la version de hijakthis recommender et voici le rapport.a premiere vue mon virus a disparu et la vitesse de mon systeme a grandement evoluer Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 18:54:50, on 2008-06-24
          Platform: Windows Vista (WinNT 6.00.1904)
          MSIE: Internet Explorer v7.00 (7.00.6000.16681)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Windows\system32\taskeng.exe
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Windows\System32\hkcmd.exe
          C:\Windows\System32\igfxpers.exe
          C:\Program Files\HP\QuickPlay\QPService.exe
          C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
          C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
          C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
          C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
          C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
          C:\Program Files\Bell\Gestionnaire de securite\RPS.exe
          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
          C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
          C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\Bell\Sympatico Security Advisor\SSAComHandler.exe
          C:\Program Files\Internet Explorer\IEUser.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
          C:\Users\guy richard\Desktop\HiJackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fsympatico.msn.ca%2fdefaultf.aspx%2f%3f
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sympatico.ca/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.ca/
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O1 - Hosts: ::1 localhost
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
          O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Bell\Gestionnaire de securite\pkR.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: Media Player Classic - {D2A8552D-4340-413E-B94E-245827FBC269} - C:\Windows\ausctv32a.dll (file missing)
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
          O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
          O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
          O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
          O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
          O4 - HKLM\..\Run: [mpeg wma] "C:\ProgramData\popcompcomp.680kc"
          O4 - HKLM\..\Run: [vc log bows face] "C:\ProgramData\meal real draw.k5co81"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
          O4 - HKLM\..\Run: [Gestionnaire de sécurité Sympatico] "C:\Program Files\Bell\Gestionnaire de securite\Rps.exe"
          O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Bell\Gestionnaire de securite\ZkRunOnceR.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [BTBFirstRun] C:\Program Files\Hewlett-Packard\SDP\hprun.exe
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
          O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Gestionnaire de securite\IdxClnR.exe"
          O4 - Global Startup: Connexions HP.lnk = C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
          O13 - Gopher Prefix:
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-ca.cab
          O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
          O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
          O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} (HPDDClientExec Class) - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
          O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5302/mcfscan.cab
          O17 - HKLM\System\CCS\Services\Tcpip\..\{32C4204B-14E6-4E84-984C-5922428C69C9}: NameServer = 207.164.234.129 207.164.234.193
          O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
          O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
          O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
          O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - (no file)
          O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
          O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
          O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
          O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
          O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
          O23 - Service: Service de mise-à-jour pour le Gestionnaire de sécurité Sympatico (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Bell\Gestionnaire de securite\rpsupdaterR.exe
          O23 - Service: Gestionnaire de sécurité Sympatico Coupe-feu (RP_FWS) - Bell Sympatico - C:\Program Files\Bell\Gestionnaire de securite\Fws.exe
          O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
          1. Salut,
            Fais un scan en ligne Kaspersky avec Internet Explorer :
            https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
            -> Click sur Démarrer Online-Scanner
            -> Click maintenant sur J'accepte.
            -> Valide l'installation d'un ou de plusieurs ActiveX si c'est nécessaire.
            -> Patiente pendant l'installation des Mises à jour.
            -> Choisis par la suite l'analyse du Poste de travail.
            -> Sauvegarde puis colle le rapport généré en fin d'analyse comme réponse .
            @+
            1. j ai essayé de faire le scan avec kaspersky mais il n est pas compatible avec vista
              je fait quoi pour remedier a ca
              merci a l avance
              1. Salut,

                Puisque tu as installé antivir, pourquoi ne ferais-tu pas un scan avec cet antivirus.

                Il n'est pas nécessaire d'aller chercher ailleurs ce que l'on a à portée de main.

                Pourquoi n'appliques-tu pas ce que je t'ai conseillé au point 4???

                A plus

                Zor
                1. voici les rapports demandes

                  Avira AntiVir Personal
                  Report file date: 24 juin 2008 11:28

                  Scanning for 1165085 virus strains and unwanted programs.

                  Licensed to: Avira AntiVir PersonalEdition Classic
                  Serial number: 0000149996-ADJIE-0001
                  Platform: Windows Vista
                  Windows version: (plain) [6.0.6000]
                  Boot mode: Normally booted
                  Username: SYSTEM
                  Computer name: MAISON

                  Version information:
                  BUILD.DAT : 8.1.00.295 16479 Bytes 2008-04-09 16:24:00
                  AVSCAN.EXE : 8.1.2.12 311553 Bytes 2008-03-18 18:02:56
                  AVSCAN.DLL : 8.1.1.0 53505 Bytes 2008-02-07 17:43:37
                  LUKE.DLL : 8.1.2.9 151809 Bytes 2008-02-28 17:41:23
                  LUKERES.DLL : 8.1.2.1 12033 Bytes 2008-02-21 17:28:40
                  ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 2007-07-18 19:33:34
                  ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 2008-03-07 22:08:58
                  ANTIVIR2.VDF : 7.0.3.62 337408 Bytes 2008-03-21 04:12:34
                  ANTIVIR3.VDF : 7.0.3.68 57856 Bytes 2008-03-25 17:27:50
                  Engineversion : 8.1.0.28
                  AEVDF.DLL : 8.1.0.5 102772 Bytes 2008-02-25 18:58:21
                  AESCRIPT.DLL : 8.1.0.19 229754 Bytes 2008-04-08 00:34:44
                  AESCN.DLL : 8.1.0.12 115060 Bytes 2008-04-08 00:34:44
                  AERDL.DLL : 8.1.0.19 418164 Bytes 2008-04-08 00:34:44
                  AEPACK.DLL : 8.1.1.0 364918 Bytes 2008-03-18 20:20:42
                  AEOFFICE.DLL : 8.1.0.15 192889 Bytes 2008-04-08 00:34:44
                  AEHEUR.DLL : 8.1.0.15 1147253 Bytes 2008-04-08 00:34:44
                  AEHELP.DLL : 8.1.0.11 115061 Bytes 2008-04-08 00:34:43
                  AEGEN.DLL : 8.1.0.15 299379 Bytes 2008-04-08 00:34:43
                  AEEMU.DLL : 8.1.0.5 430450 Bytes 2008-04-08 00:34:43
                  AECORE.DLL : 8.1.0.25 168309 Bytes 2008-04-08 18:58:32
                  AVWINLL.DLL : 1.0.0.7 14593 Bytes 2008-01-24 02:07:53
                  AVPREF.DLL : 8.0.0.1 25857 Bytes 2008-02-18 19:37:50
                  AVREP.DLL : 7.0.0.1 155688 Bytes 2007-04-16 22:26:47
                  AVREG.DLL : 8.0.0.0 30977 Bytes 2008-01-24 02:07:49
                  AVARKT.DLL : 1.0.0.23 307457 Bytes 2008-02-12 17:29:23
                  AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 2008-02-28 17:31:31
                  SQLITE3.DLL : 3.3.17.1 339968 Bytes 2008-01-23 02:28:02
                  SMTPLIB.DLL : 1.2.0.19 28929 Bytes 2008-01-24 02:08:39
                  NETNT.DLL : 8.0.0.1 7937 Bytes 2008-01-25 21:05:10
                  RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 2008-03-10 23:37:25
                  RCTEXT.DLL : 8.0.32.0 86273 Bytes 2008-03-06 21:02:11

                  Configuration settings for the scan:
                  Jobname..........................: Complete system scan
                  Configuration file...............: C:\Program Files\Avira\AntiVir PersonalEdition Classic\sysscan.avp
                  Logging..........................: low
                  Primary action...................: interactive
                  Secondary action.................: ignore
                  Scan master boot sector..........: on
                  Scan boot sector.................: on
                  Boot sectors.....................: C:, D:,
                  Scan memory......................: on
                  Process scan.....................: on
                  Scan registry....................: on
                  Search for rootkits..............: off
                  Scan all files...................: All files
                  Scan archives....................: on
                  Recursion depth..................: 20
                  Smart extensions.................: on
                  Macro heuristic..................: on
                  File heuristic...................: medium

                  Start of the scan: 24 juin 2008 11:28

                  The scan of running processes will be started
                  Scan process 'avscan.exe' - '1' Module(s) have been scanned
                  Scan process 'update.exe' - '1' Module(s) have been scanned
                  Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                  Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                  Scan process 'avguard.exe' - '1' Module(s) have been scanned
                  Scan process 'sched.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'VSSVC.exe' - '1' Module(s) have been scanned
                  Scan process 'iexplore.exe' - '1' Module(s) have been scanned
                  Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                  Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
                  Scan process 'iexplore.exe' - '1' Module(s) have been scanned
                  Scan process 'ieuser.exe' - '1' Module(s) have been scanned
                  Scan process 'MpCmdRun.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
                  Scan process 'msdtc.exe' - '1' Module(s) have been scanned
                  Scan process 'hpqste08.exe' - '1' Module(s) have been scanned
                  Scan process 'PDEngine.exe' - '1' Module(s) have been scanned
                  Scan process 'rpsupdaterr.exe' - '1' Module(s) have been scanned
                  Scan process 'SSAComHandler.exe' - '1' Module(s) have been scanned
                  Scan process 'HPHC_Service.exe' - '1' Module(s) have been scanned
                  Scan process 'HPQTOA~1.EXE' - '1' Module(s) have been scanned
                  Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
                  Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                  Scan process 'iPodService.exe' - '1' Module(s) have been scanned
                  Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                  Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
                  Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
                  Scan process 'hpqtra08.exe' - '1' Module(s) have been scanned
                  Scan process 'HP Connections.exe' - '1' Module(s) have been scanned
                  Scan process 'ehtray.exe' - '1' Module(s) have been scanned
                  Scan process 'sidebar.exe' - '1' Module(s) have been scanned
                  Scan process 'realsched.exe' - '1' Module(s) have been scanned
                  Scan process 'RPS.exe' - '1' Module(s) have been scanned
                  Scan process 'SSA.exe' - '1' Module(s) have been scanned
                  Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
                  Scan process 'jusched.exe' - '1' Module(s) have been scanned
                  Scan process 'HPWAMain.exe' - '1' Module(s) have been scanned
                  Scan process 'WiFiMsg.exe' - '1' Module(s) have been scanned
                  Scan process 'QLBCTRL.exe' - '1' Module(s) have been scanned
                  Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
                  Scan process 'QPService.exe' - '1' Module(s) have been scanned
                  Scan process 'igfxpers.exe' - '1' Module(s) have been scanned
                  Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
                  Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
                  Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
                  Scan process 'alg.exe' - '1' Module(s) have been scanned
                  Scan process 'taskeng.exe' - '1' Module(s) have been scanned
                  Scan process 'CLSched.exe' - '1' Module(s) have been scanned
                  Scan process 'hpqwmiex.exe' - '1' Module(s) have been scanned
                  Scan process 'XAudio.exe' - '1' Module(s) have been scanned
                  Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'PnkBstrA.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'PDAgent.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
                  Scan process 'ITMRTSVC.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'dvpapi.vista.exe' - '1' Module(s) have been scanned
                  Scan process 'CLCapSvc.exe' - '1' Module(s) have been scanned
                  Scan process 'CISVC.EXE' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
                  Scan process 'explorer.exe' - '1' Module(s) have been scanned
                  Scan process 'dwm.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'Fws.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
                  Scan process 'audiodg.exe' - '0' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'lsm.exe' - '1' Module(s) have been scanned
                  Scan process 'lsass.exe' - '1' Module(s) have been scanned
                  Scan process 'services.exe' - '1' Module(s) have been scanned
                  Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                  Scan process 'csrss.exe' - '1' Module(s) have been scanned
                  Scan process 'wininit.exe' - '1' Module(s) have been scanned
                  Scan process 'csrss.exe' - '1' Module(s) have been scanned
                  Scan process 'smss.exe' - '1' Module(s) have been scanned
                  91 processes with 91 modules were scanned

                  Starting master boot sector scan:
                  Master boot sector HD0
                  [INFO] No virus was found!

                  Start scanning boot sectors:
                  Boot sector 'C:\'
                  [INFO] No virus was found!
                  Boot sector 'D:\'
                  [INFO] No virus was found!

                  Starting to scan the registry.
                  The registry was scanned ( '15' files ).

                  Starting the file scan:

                  Begin scan in 'C:\'
                  C:\pagefile.sys
                  [WARNING] The file could not be opened!
                  C:\Users\etienne\AppData\Local\Temp\G4B58-tmpa1i.exe
                  [0] Archive type: OVL
                  --> Object
                  [DETECTION] Is the Trojan horse TR/Dldr.Codec.N.8
                  [NOTE] The file was moved to '48a35fff.qua'!
                  C:\Users\etienne\AppData\Local\Temp\GC365-tmpa1i.exe
                  [0] Archive type: OVL
                  --> Object
                  [DETECTION] Is the Trojan horse TR/Dldr.Codec.N.8
                  [NOTE] The file was moved to '48946017.qua'!
                  C:\Windows\ausctv32a.dll
                  [DETECTION] Is the Trojan horse TR/Dldr.Codec.N.8
                  [WARNING] An error has occurred and the file was not deleted. ErrorID: 26003
                  [WARNING]
                  Begin scan in 'D:\' <HP_RECOVERY>

                  End of the scan: 24 juin 2008 17:47
                  Used time: 6:19:08 min

                  The scan has been done completely.

                  27244 Scanning directories
                  641829 Files were scanned
                  3 viruses and/or unwanted programs were found
                  0 Files were classified as suspicious:
                  0 files were deleted
                  0 files were repaired
                  2 files were moved to quarantine
                  0 files were renamed
                  1 Files cannot be scanned
                  641826 Files not concerned
                  2592 Archives were scanned
                  2 WarningsMalwarebytes' Anti-Malware 1.18
                  Version de la base de données: 870

                  09:12:40 2008-06-28
                  mbam-log-6-28-2008 (09-12-03).txt

                  Type de recherche: Examen rapide
                  Eléments examinés: 44900
                  Temps écoulé: 8 minute(s), 29 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 12
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 2

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  HKEY_CLASSES_ROOT\Interface\{48d78be5-cfb9-4b66-9ac4-96d4cf21de06} (Trojan.FakeAlert) -> No action taken.
                  HKEY_CLASSES_ROOT\Typelib\{74d46bba-5638-473a-83b6-97e7804a7411} (Trojan.FakeAlert) -> No action taken.
                  HKEY_CLASSES_ROOT\ausctv32a.video (Trojan.FakeAlert) -> No action taken.
                  HKEY_CLASSES_ROOT\AppID\{d2a8552d-4340-413e-b94e-245827fbc269} (Trojan.FakeAlert) -> No action taken.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2a8552d-4340-413e-b94e-245827fbc269} (Trojan.FakeAlert) -> No action taken.
                  HKEY_CURRENT_USER\Software\RegistrySmart (Rogue.RegistrySmart) -> No action taken.
                  HKEY_CURRENT_USER\Software\MediaHoldings (Adware.PlayMP3Z) -> No action taken.
                  HKEY_CURRENT_USER\Software\Mirar (AdWare.Mirar) -> No action taken.
                  HKEY_CURRENT_USER\Software\ContextProgram (AdWare.Agent) -> No action taken.
                  HKEY_CURRENT_USER\Software\PlayMP3 (Adware.PlayMP3Z) -> No action taken.
                  HKEY_CURRENT_USER\Software\FBrowsingAdvisor (Trojan.FBrowsingAdvisor) -> No action taken.
                  HKEY_CLASSES_ROOT\AppID\ausctv32a.dll (Trojan.FakeAlert) -> No action taken.

                  Valeur(s) du Registre infectée(s):
                  (Aucun élément nuisible détecté)

                  Elément(s) de données du Registre infecté(s):
                  (Aucun élément nuisible détecté)

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  C:\xmp.bat (Trojan.Downloader) -> No action taken.
                  C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Files Secure 2.1.lnk (Rogue.Files-Secure) -> No action taken.
                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 09:36:53, on 2008-06-28
                  Platform: Windows Vista (WinNT 6.00.1904)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Windows\System32\hkcmd.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Program Files\HP\QuickPlay\QPService.exe
                  C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
                  C:\Program Files\Bell\Gestionnaire de securite\RPS.exe
                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
                  C:\Program Files\Bell\Sympatico Security Advisor\SSAComHandler.exe
                  C:\Windows\system32\NOTEPAD.EXE
                  C:\Program Files\Internet Explorer\ieuser.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
                  C:\Users\guy richard\Desktop\HiJackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fsympatico.msn.ca%2fdefaultf.aspx%2f%3f
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.sympatico.ca/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.ca/
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Bell\Gestionnaire de securite\pkR.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                  O2 - BHO: (no name) - {d2a8552d-4340-413e-b94e-245827fbc269} - (no file)
                  O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                  O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                  O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                  O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                  O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                  O4 - HKLM\..\Run: [mpeg wma] "C:\ProgramData\popcompcomp.680kc"
                  O4 - HKLM\..\Run: [vc log bows face] "C:\ProgramData\meal real draw.k5co81"
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
                  O4 - HKLM\..\Run: [Gestionnaire de sécurité Sympatico] "C:\Program Files\Bell\Gestionnaire de securite\Rps.exe"
                  O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Bell\Gestionnaire de securite\ZkRunOnceR.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
                  O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [BTBFirstRun] C:\Program Files\Hewlett-Packard\SDP\hprun.exe
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                  O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
                  O4 - HKCU\..\RunOnce: [IndexCleaner] "C:\Program Files\Bell\Gestionnaire de securite\IdxClnR.exe"
                  O4 - Global Startup: Connexions HP.lnk = C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-ca.cab
                  O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
                  O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                  O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} (HPDDClientExec Class) - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                  O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5302/mcfscan.cab
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{32C4204B-14E6-4E84-984C-5922428C69C9}: NameServer = 207.164.234.129 207.164.234.193
                  O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
                  O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
                  O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - (no file)
                  O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                  O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
                  O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
                  O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: Service de mise-à-jour pour le Gestionnaire de sécurité Sympatico (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Bell\Gestionnaire de securite\rpsupdaterR.exe
                  O23 - Service: Gestionnaire de sécurité Sympatico Coupe-feu (RP_FWS) - Bell Sympatico - C:\Program Files\Bell\Gestionnaire de securite\Fws.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                  1. Salut

                    No action taken. ► n'a pas fonctionné.

                    Supprime Norton complètement
                    http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924

                    Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                    - Va dans démarrer puis panneau de configuration
                    - Double Clique sur l'icône "Comptes d'utilisateurs"
                    - Clique ensuite sur désactiver et valide.
                    "Exécuter en tant qu'administrateur".


                    Télécharges ComboFix à partir d'un de ces liens :
                    En premier
                    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                    Et important, enregistre le sur le bureau.

                    Avant d'utiliser ComboFix :

                    ► Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

                    ► Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

                    Une fois fait, sur ton bureau double-clic sur Combofix.exe.

                    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

                    /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

                    - En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

                    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

                    ► Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

                    ► Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

                    + un log hijackthis

                    A+

                2. Salut,
                  En lisant vos rapports des choses font intérressance :
                  0 Files were classified as suspicious:
                  0 files were deleted
                  0 files were repaired
                  2 files were moved to quarantine
                  0 files were renamed
                  1 Files cannot be scanned
                  641826 Files not concerned
                  2592 Archives were scanned
                  Dans le 2ème :
                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 12
                  Valeur(s) du Registre infectée(s): 0
                  Elément(s) de données du Registre infecté(s): 0
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 2
                  Le dernier :
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll

                  Il faut réfléchir alors ...
                  @+
                  1. Le dernier :
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                    Il faut réfléchir alors ...

                    Ces lignes sont toutes légitimes

                    A+

                3. merci marie voice ce que tu m a demanderLogfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 10:53:27, on 2008-06-29
                  Platform: Windows Vista (WinNT 6.00.1904)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Windows\System32\hkcmd.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\System32\igfxpers.exe
                  C:\Program Files\HP\QuickPlay\QPService.exe
                  C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                  C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
                  C:\Program Files\Bell\Gestionnaire de securite\RPS.exe
                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
                  C:\Program Files\Bell\Sympatico Security Advisor\SSAComHandler.exe
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
                  C:\Windows\Explorer.exe
                  C:\Users\guy richard\Desktop\HiJackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fsympatico.msn.ca%2fdefaultf.aspx%2f%3f
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.ca/
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Bell\Gestionnaire de securite\pkR.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
                  O2 - BHO: (no name) - {d2a8552d-4340-413e-b94e-245827fbc269} - (no file)
                  O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                  O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
                  O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
                  O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                  O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                  O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                  O4 - HKLM\..\Run: [mpeg wma] "C:\ProgramData\popcompcomp.680kc"
                  O4 - HKLM\..\Run: [vc log bows face] "C:\ProgramData\meal real draw.k5co81"
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [SSA.exe] "C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe" /AUTORUN
                  O4 - HKLM\..\Run: [Gestionnaire de sécurité Sympatico] "C:\Program Files\Bell\Gestionnaire de securite\Rps.exe"
                  O4 - HKLM\..\Run: [-FreedomNeedsReboot] "C:\Program Files\Bell\Gestionnaire de securite\ZkRunOnceR.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [BTBFirstRun] C:\Program Files\Hewlett-Packard\SDP\hprun.exe
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                  O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                  O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
                  O4 - Global Startup: Connexions HP.lnk = C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-ca.cab
                  O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
                  O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                  O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} (HPDDClientExec Class) - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                  O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5302/mcfscan.cab
                  O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
                  O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
                  O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
                  O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                  O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: PDAgent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDAgent.exe
                  O23 - Service: PDEngine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk\PDEngine.exe
                  O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: Service de mise-à-jour pour le Gestionnaire de sécurité Sympatico (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Bell\Gestionnaire de securite\rpsupdaterR.exe
                  O23 - Service: Gestionnaire de sécurité Sympatico Coupe-feu (RP_FWS) - Bell Sympatico - C:\Program Files\Bell\Gestionnaire de securite\Fws.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                  1. Salut,
                    On va voir alors avec combofix :
                    Désolé d'avoir répondu tard :
                    Télécharge combofix.exe (par sUBs) sur ton Bureau.

                    -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                    -> Double clique combofix.exe.
                    -> Tape sur la touche 1 (Yes) pour démarrer le scan.
                    -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                    Avant d'utiliser ComboFix :

                    -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

                    -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

                    Une fois fait, sur ton bureau double-clic sur Combofix.exe.

                    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

                    /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

                    - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

                    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

                    -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

                    -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

                    -> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                    @+
                    1. j ai deja fait combofix dit moi ca pas fonctionner je suis tu mieux de le refaire encore une fois
                      merci
                  2. Slt

                    Dans l'ordre

                    1/
                    · Télécharge ToolsCleaner de A.Roshtein sur ton Bureau.(sur un des 2 liens)
                    http://pc-system.fr/

                    · Clique sur Recherche et laisse le scan se terminer.
                    · Clique, sur Suppression pour finaliser.
                    · Tu peux, si tu le souhaites, te servir des Options facultatives.
                    · Clique sur Quitter, pour que le rapport puisse se créer.
                    · Poste moi le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur( C:\).

                    2/
                    Pour Vista, il faut cette version de HijackThis :la 2.0.2
                    https://www.pcastuces.com/logitheque/hijackthis.htm
                    Veille à ce que le contrôle des comptes utilisateurs (UAC) soit désactivé.

                    - Va dans démarrer puis panneau de configuration
                    - Double Clique sur l'icône "Comptes d'utilisateurs"
                    - Clique ensuite sur désactiver et valide.

                    Clic droit sur l'icône de HJT
                    L'exécuter en tant qu'administrateur

                    Dézippe le dans un dossier prévu à cet effet.
                    Par exemple C:\hijackthis < Enregistre le bien dans c : !
                    Démo : (Merci a Balltrap34 pour cette réalisation)
                    http://pageperso.aol.fr/balltrap34/Hijenr.gif
                    http://pageperso.aol.fr/balltrap34/Hijenr.gif
                    Lance le puis:
                    Clique sur "do a system scan and save logfile" (cf démo)
                    Faire un copier coller du log entier sur le forum
                    Démo : (Merci a Balltrap34 pour cette réalisation)
                    http://pageperso.aol.fr/balltrap34/demohijack.htmhttp://pageperso.aol.fr/balltrap34/demohijack.htm
                    http://www.tutoriaux-excalibur.com/hijackthis.htmhttp://www.tutoriaux-excalibur.com/hijackthis.htm

                    3/

                    Télécharge SmitfraudFix
                    Utilitaire de S!Ri: Moe et balltrap34
                    http://siri.urz.free.fr/Fix/SmitfraudFix.php

                    http://www.malekal.com/tutorial_SmitFraudfix.php
                    et télécharge SmitfraudFix.exe.

                    Regarde le tuto

                    Exécute le en choisissant l’option 1,
                    il va générer un rapport
                    Copie/colle le sur le poste stp.

                    Bon courage
                    A++
                    1. bonjour excuser pour le delais j eatait en vacances
                      je vous envoi ce que vous m avez demander masis j ai eu un probleme avec tools cleaners y a rien voulu savoir
                      j ai fait smitfraud et hijackthis je vous postes les rapports
                      merci a l avance
                      guyLogfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 10:13:33, on 2008-08-02
                      Platform: Windows Vista (WinNT 6.00.1904)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                      Boot mode: Normal

                      Running processes:
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\Windows\System32\hkcmd.exe
                      C:\Windows\System32\igfxpers.exe
                      C:\Program Files\HP\QuickPlay\QPService.exe
                      C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
                      C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
                      C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
                      C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
                      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe
                      C:\Program Files\Windows Sidebar\sidebar.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                      C:\Windows\system32\wbem\unsecapp.exe
                      C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
                      C:\Windows\ehome\ehmsas.exe
                      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
                      C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
                      C:\Windows\system32\conime.exe
                      C:\Users\guy richard\Desktop\HiJackThis.exe

                      O13 - Gopher Prefix:
                      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-ca.cab
                      O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
                      O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                      O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} (HPDDClientExec Class) - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                      O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5302/mcfscan.cab
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{32C4204B-14E6-4E84-984C-5922428C69C9}: NameServer = 207.164.234.129 207.164.234.193
                      O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
                      O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
                      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
                      O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.vista.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                      O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                      O23 - Service: Gestionnaire de sécurité Sympatico (Radialpoint Security Services) - Radialpoint Inc. - C:\Program Files\Bell\Gestionnaire de securite\RpsSecurityAware.exe
                      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                      O23 - Service: Service de mise-à-jour pour le Gestionnaire de sécurité Sympatico (RPSUpdaterR) - Bell Sympatico - C:\Program Files\Bell\Gestionnaire de securite\rpsupdaterR.exe
                      O23 - Service: Gestionnaire de sécurité Sympatico Coupe-feu (RP_FWS) - Bell Sympatico - C:\Program Files\Bell\Gestionnaire de securite\Fws.exe
                      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                      O23 - Service: Personal Vault Upgrade Service (VaultClientUpgrade) - BELL - C:\Program Files\Personal Vault\VaultClientUpgrade.exe
                      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe