Virus fenêtres abusives sur internet

Bonjour,
Ci-joint le rapport HijackThis.log
Quel est la marche à suivre ensuite ? Merci de votre aide et conseil.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:37:40, on 10/07/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\TomTom HOME\TomTomHOME.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\mobsync.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9d.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.proximus.be/pickx
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://antoinepetit2000.free.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7B95267E-2664-49A6-8C94-EF2C474958C0} - C:\Users\ANTOIN~1\AppData\Local\Temp\geBuVLff.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\Home Cinema\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\geBuRHWM.dll,#1
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [SpriteService] "C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\ANTOIN~1\AppData\Local\Temp\fccbYrrp.dll,#1
O4 - HKCU\..\Run: [3c85aa0e] rundll32.exe "C:\Users\ANTOIN~1\AppData\Local\Temp\iluverro.dll",b
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O13 - Gopher Prefix:
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - http://update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://wisup.net/_plateforme/Upload/Aurigma/AurigmaActiveX/ImageUploader4.cab
O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MusicManagerPlugin.MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
O16 - DPF: {D3166EE4-3E00-46CA-8F62-8E01D2314A7F} - http://www.cig.canon-europe.com/ph/fr_BE/st/download/ddup/CNIMGUP_01_210102F.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Service Framework McAfee (McAfeeFramework) - Unknown owner - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\Program Files\Common Files\X10\Common\X10nets.exe

--
End of file - 12352 bytes

Merci d'avance de vos réponses
Configuration: Windows Vista
Internet Explorer 7.0
Norton

15 réponses

Résumé de la discussion

Après un rapport HijackThis sur Windows Vista, la discussion porte sur les étapes à suivre pour nettoyer des infections apparentes et sur les difficultés liées au redémarrage et à l'affichage des alertes. Des conseils alternent entre l'utilisation de MalwareBytes en mode sans échec, le recours à ComboFix lorsque possible, et l'examen des éléments de démarrage et des extensions détectées par HijackThis. Plusieurs répondants signalent que certains outils ne fonctionnent pas sous Vista et préconisent des solutions alternatives, et l'importance de vérifier les programmes de démarrage et les BHO pour éviter les suppressions manuelles risquées.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour,

    Tu vas utiliser SDFix téléchargeable à :
    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

    Tu installes le logiciel.
    Tu peux t’aider du tuto suivant :
    https://www.malekal.com/slenfbot-still-an-other-irc-bot/

    Il faut que tu redémarres en mode sans échec.
    Pour cela, tu redémarres ton ordinateur et tu appuies sur la touche F8.

    A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
    Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
    Choisis ton compte.

    Tu lances SDFix en double-cliquant sur RunThis.bat dans le dossier où tu as installé le logiciel.
    Ton ordinateur va redémarrer. il te sera peut-être demander d'appuyer sur une touche pour redémarrer.
    L'outil va continuer à travailler, c'est normal.
    Une fois affiché Finished, appuie sur une touche pour finir l'exécution du logiciel.
    Ton bureau devrait réapparaitre.
    Ouvre le dossier de SDFix sur ton Bureau.
    Copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum.

    Avec un nouveau log HijackThis !

    A+
    1. Contributeur sécurité
      Désolé,

      je viens de voir que tu es sous Vista et cet outil ne fonctionne pas pour l'instant sous Vista.
      Oublie les consignes prédentes.

      Voila ce que tu vas faire.

      Tu télécharges MalwareBytes.
      http://www.malwarebytes.org/mbam/program/mbam-setup.exe

      Tu l'installes. Choisis les options par défaut.
      A la fin de l’installation, il te sera demandé de mettre à jour MalwareBytes et de l’exécuter .
      Ne choisis que la mise à jour. Le logiciel sera lancé en mode sans échec.

      Tu relances l'ordinateur en mode sans échec ( touche F8 après redémarrage ).
      Tu choisis ton compte utilisateur.

      Pour lancer MalwareBytes, double-clique sur le raccourci du bureau.

      Dans l’onglet Recherche, sélectionne Exécuter un examen complet.
      Clique sur recherche. Tu ne sélectionnes que les disques durs de l’ordinateur.
      Clique sur lancer l’examen.

      A la fin de la recherche, Comme il est demandé, clique sur afficher les résultats de la recherche.
      Choisis alors Supprimer la selection pour nettoyer les infections.
      Tu postes le rapport dans ton prochain message.

      Désolé, pour cette erreur d'aiguillage.

      A+
      1. J'ai bien reçu votre réponse et vous en remercie, j'ai branché mon portable pour vous répondre car le pc de base tourne toujours sous l'anti-malware. Vous tiens au courant.
    2. J'ai aussi des programmes de démarrage bloqués, je suppose à vérifier et effacer ?

      Voici le résultat:

      Malwarebytes' Anti-Malware 1.20
      Version de la base de données: 935
      Windows 6.0.6001 Service Pack 1

      16:20:07 10/07/2008
      mbam-log-7-10-2008 (16-20-01).txt

      Type de recherche: Examen complet (C:\|D:\|J:\|)
      Eléments examinés: 169033
      Temps écoulé: 29 minute(s), 10 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 1
      Clé(s) du Registre infectée(s): 5
      Valeur(s) du Registre infectée(s): 5
      Elément(s) de données du Registre infecté(s): 1
      Dossier(s) infecté(s): 1
      Fichier(s) infecté(s): 43

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      C:\Users\Antoine Petit\AppData\Local\Temp\geBuVLff.dll (Trojan.Vundo) -> No action taken.

      Clé(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cf6a352e-7dac-4958-935a-36c980d7ba73} (Trojan.Vundo) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{cf6a352e-7dac-4958-935a-36c980d7ba73} (Trojan.Vundo) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{d95a625d-a0fc-4729-a626-b68642946481} (Trojan.Vundo) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.

      Valeur(s) du Registre infectée(s):
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msserver (Trojan.Vundo) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{d95a625d-a0fc-4729-a626-b68642946481} (Trojan.Vundo) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msserver (Trojan.Vundo) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\System32\TWUNK_16.EXE (Trojan.Agent) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\3c85aa0e (Trojan.Vundo) -> No action taken.

      Elément(s) de données du Registre infecté(s):
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\users\antoin~1\appdata\local\temp\gebuvlff -> No action taken.

      Dossier(s) infecté(s):
      C:\Program Files\PCHealthCenter (Trojan.Fakealert) -> No action taken.

      Fichier(s) infecté(s):
      C:\Users\Antoine Petit\AppData\Local\Temp\geBuVLff.dll (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\ffLVuBeg.ini (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\ffLVuBeg.ini2 (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\geBtTMfD.dll (Trojan.Vundo) -> No action taken.
      C:\Windows\System32\geBuRHWM.dll (Trojan.Vundo) -> No action taken.
      C:\Program Files\PCHealthCenter\0.exe (Trojan.FakeAlert) -> No action taken.
      C:\Program Files\PCHealthCenter\1.exe (Trojan.FakeAlert) -> No action taken.
      C:\Program Files\PCHealthCenter\2.exe (Trojan.FakeAlert) -> No action taken.
      C:\Program Files\PCHealthCenter\3.exe (Trojan.FakeAlert) -> No action taken.
      C:\Program Files\PCHealthCenter\4.exe (Trojan.FakeAlert) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\cbXPfDwu.dll (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\efcCrPfC.dll (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\krdaferj.dll (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\lwpower.exe (Trojan.Fakealert) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\mlJCSmJb.dll (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\nnnllKDV.dll (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\opnklmMc.dll (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\pmnnNheB.dll (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\qoMghETN.dll (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\tmp0000b371 (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\tmp0000cbdb (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\tmp0000fe26 (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\tmp000109a0 (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\tmp00011846 (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\tmp00011e12 (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\tmp00011fa8 (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\tmp00016404 (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\tmp0001a35f (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\tmp000237df (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\tmp00026085 (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\wdiybksq.dll (Trojan.Vundo) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\wvUmnKdc.dll (Trojan.Vundo) -> No action taken.
      C:\Windows\System32\ddcCUkiI.dll (Trojan.Vundo) -> No action taken.
      C:\Program Files\PCHealthCenter\0.gif (Trojan.Fakealert) -> No action taken.
      C:\Program Files\PCHealthCenter\1.gif (Trojan.Fakealert) -> No action taken.
      C:\Program Files\PCHealthCenter\2.gif (Trojan.Fakealert) -> No action taken.
      C:\Program Files\PCHealthCenter\3.gif (Trojan.Fakealert) -> No action taken.
      C:\Program Files\PCHealthCenter\5.exe (Trojan.Fakealert) -> No action taken.
      C:\Program Files\PCHealthCenter\sc.html (Trojan.Fakealert) -> No action taken.
      C:\Program Files\PCHealthCenter\sex1.ico (Trojan.Fakealert) -> No action taken.
      C:\Program Files\PCHealthCenter\sex2.ico (Trojan.Fakealert) -> No action taken.
      C:\Windows\System32\TWUNK_16.EXE (Trojan.Agent) -> No action taken.
      C:\Users\Antoine Petit\AppData\Local\Temp\iluverro.dll (Trojan.Vundo) -> No action taken.

      Merci d'avance de vos conseils.
      1. Contributeur sécurité
        Il va falloir que tu recommences la manipulation.
        Regarde le rapport : No action taken

        Les fichiers n'ont pas été supprimés.
        N'oublie pas, après la recherche et afficher les résultats --> Supprimer la sélection.

        A+
    3. Pourtant j'ai supprimer la sélection, je recommence !
      merci de ton aide verni29.
      1. Contributeur sécurité
        Excuse moi

        Comment as -tu supprimer la sélection ?
        Peux-tu dans ce cas me poster le nouveau rapport.

        On en discute si tu as un doute.

        A+
    4. Voilà, il me trouve encore 7 infections. Lorsque je sélectionne nettoyer les infections, le prg me signale que je dois redémarrer le pc pour supprimer ces fichiers. Une fois redémarrer, comme dit plus haut une alerte en bas du bureau me signale que des prg de démarrage sont bloqués et lorsque j'ouvre cette boite de dialogue pour vérifier, ce sont des prg dont je me sers, ex. Norton etc. J'ai tiré une liste du 1er rapport malware et essayerais de supprimer ces fichiers manuellement ? pour le moment je n'ai pas de fenêtres malveillante !
      Faut que je contrôle tous celà.
      de toutes façon je suis vos conseils, merci.
      1. Contributeur sécurité
        Peux-tu me poster le rapport MalwareBytes ?

        Et si tu peux aussi noter la liste de ces programmes ?
    5. Désolé non car j'ai oublié de la copier !
      Je refais une passe et vous l'envoi.
      Je viens de surfer et pas de problème de pages abusives !
      Bon j'y retourne, merci verni29.
      1. Rapport 1:
        Malwarebytes' Anti-Malware 1.20
        Version de la base de données: 935
        Windows 6.0.6001 Service Pack 1

        16:20:14 10/07/2008
        mbam-log-7-10-2008 (16-20-14).txt

        Type de recherche: Examen complet (C:\|D:\|J:\|)
        Eléments examinés: 169033
        Temps écoulé: 29 minute(s), 10 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 1
        Clé(s) du Registre infectée(s): 5
        Valeur(s) du Registre infectée(s): 5
        Elément(s) de données du Registre infecté(s): 1
        Dossier(s) infecté(s): 1
        Fichier(s) infecté(s): 43

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        C:\Users\Antoine Petit\AppData\Local\Temp\geBuVLff.dll (Trojan.Vundo) -> Unloaded module successfully.

        Clé(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cf6a352e-7dac-4958-935a-36c980d7ba73} (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{cf6a352e-7dac-4958-935a-36c980d7ba73} (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{d95a625d-a0fc-4729-a626-b68642946481} (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msserver (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{d95a625d-a0fc-4729-a626-b68642946481} (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msserver (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Windows\System32\TWUNK_16.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\3c85aa0e (Trojan.Vundo) -> Quarantined and deleted successfully.

        Elément(s) de données du Registre infecté(s):
        HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\users\antoin~1\appdata\local\temp\gebuvlff -> Quarantined and deleted successfully.

        Dossier(s) infecté(s):
        C:\Program Files\PCHealthCenter (Trojan.Fakealert) -> Quarantined and deleted successfully.

        Fichier(s) infecté(s):
        C:\Users\Antoine Petit\AppData\Local\Temp\geBuVLff.dll (Trojan.Vundo) -> Delete on reboot.
        C:\Users\Antoine Petit\AppData\Local\Temp\ffLVuBeg.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\ffLVuBeg.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\geBtTMfD.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Windows\System32\geBuRHWM.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Program Files\PCHealthCenter\0.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\Program Files\PCHealthCenter\1.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\Program Files\PCHealthCenter\2.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\Program Files\PCHealthCenter\3.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\Program Files\PCHealthCenter\4.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\cbXPfDwu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\efcCrPfC.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\krdaferj.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\lwpower.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\mlJCSmJb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\nnnllKDV.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\opnklmMc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\pmnnNheB.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\qoMghETN.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\tmp0000b371 (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\tmp0000cbdb (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\tmp0000fe26 (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\tmp000109a0 (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\tmp00011846 (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\tmp00011e12 (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\tmp00011fa8 (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\tmp00016404 (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\tmp0001a35f (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\tmp000237df (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\tmp00026085 (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\wdiybksq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\wvUmnKdc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Windows\System32\ddcCUkiI.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Program Files\PCHealthCenter\0.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
        C:\Program Files\PCHealthCenter\1.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
        C:\Program Files\PCHealthCenter\2.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
        C:\Program Files\PCHealthCenter\3.gif (Trojan.Fakealert) -> Quarantined and deleted successfully.
        C:\Program Files\PCHealthCenter\5.exe (Trojan.Fakealert) -> Quarantined and deleted successfully.
        C:\Program Files\PCHealthCenter\sc.html (Trojan.Fakealert) -> Quarantined and deleted successfully.
        C:\Program Files\PCHealthCenter\sex1.ico (Trojan.Fakealert) -> Quarantined and deleted successfully.
        C:\Program Files\PCHealthCenter\sex2.ico (Trojan.Fakealert) -> Quarantined and deleted successfully.
        C:\Windows\System32\TWUNK_16.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\iluverro.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

        Rapport 2:
        Malwarebytes' Anti-Malware 1.20
        Version de la base de données: 935
        Windows 6.0.6001 Service Pack 1

        17:23:08 10/07/2008
        mbam-log-7-10-2008 (17-23-08).txt

        Type de recherche: Examen complet (C:\|D:\|J:\|)
        Eléments examinés: 168889
        Temps écoulé: 28 minute(s), 52 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 1
        Clé(s) du Registre infectée(s): 2
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 1
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 3

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        C:\Users\Antoine Petit\AppData\Local\Temp\geBuVLff.dll (Trojan.Vundo) -> Unloaded module successfully.

        Clé(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{286250a4-6a30-40fa-b3b6-bccd9982864c} (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{286250a4-6a30-40fa-b3b6-bccd9982864c} (Trojan.Vundo) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\users\antoin~1\appdata\local\temp\gebuvlff -> Quarantined and deleted successfully.

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        C:\Users\Antoine Petit\AppData\Local\Temp\geBuVLff.dll (Trojan.Vundo) -> Delete on reboot.
        C:\Users\Antoine Petit\AppData\Local\Temp\ffLVuBeg.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
        C:\Users\Antoine Petit\AppData\Local\Temp\ffLVuBeg.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.

        Rapport 3:

        Malwarebytes' Anti-Malware 1.20
        Version de la base de données: 935
        Windows 6.0.6001 Service Pack 1

        18:39:24 10/07/2008
        mbam-log-7-10-2008 (18-39-24).txt

        Type de recherche: Examen complet (C:\|D:\|J:\|)
        Eléments examinés: 168873
        Temps écoulé: 29 minute(s), 3 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 1
        Clé(s) du Registre infectée(s): 2
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 1

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        C:\Users\Antoine Petit\AppData\Local\Temp\geBuVLff.dll (Trojan.Vundo) -> Unloaded module successfully.

        Clé(s) du Registre infectée(s):
        HKEY_CLASSES_ROOT\CLSID\{d2804af3-b6a0-4879-893d-16bf58559e65} (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2804af3-b6a0-4879-893d-16bf58559e65} (Trojan.Vundo) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        C:\Users\Antoine Petit\AppData\Local\Temp\geBuVLff.dll (Trojan.Vundo) -> Delete on reboot.

        En me branchant à l'instant,rebelotte le problème persite !!!
        En ce qui concerne les prg de démarrage je ne sais pas faire un copier collé.
        1. Contributeur sécurité
          Peux-tu me poster le rapport Hijackthis ?

          Analyse et rapport vers 20h30.

          Il faut bien se nourrir. :-)
      2. je vais faire pareil, bon apétit et encore merci verni29
        1. Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 14:37:40, on 10/07/2008
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v7.00 (7.00.6001.18000)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
          C:\Windows\WindowsMobile\wmdc.exe
          C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
          C:\Program Files\Logitech\QuickCam\Quickcam.exe
          C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
          C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          C:\Windows\System32\rundll32.exe
          C:\Program Files\TomTom HOME\TomTomHOME.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\MSN Messenger\msnmsgr.exe
          C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
          C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Windows\System32\mobsync.exe
          C:\Windows\System32\rundll32.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
          C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
          C:\Program Files\Internet Explorer\IEUser.exe
          C:\Windows\system32\Macromed\Flash\FlashUtil9d.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.proximus.be/pickx
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://antoinepetit2000.free.fr/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
          O1 - Hosts: ::1 localhost
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
          O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O2 - BHO: (no name) - {7B95267E-2664-49A6-8C94-EF2C474958C0} - C:\Users\ANTOIN~1\AppData\Local\Temp\geBuVLff.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\Home Cinema\PowerDVD\Language\Language.exe"
          O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
          O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
          O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
          O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
          O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
          O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
          O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
          O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
          O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
          O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\geBuRHWM.dll,#1
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
          O4 - HKCU\..\Run: [SpriteService] "C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe"
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\ANTOIN~1\AppData\Local\Temp\fccbYrrp.dll,#1
          O4 - HKCU\..\Run: [3c85aa0e] rundll32.exe "C:\Users\ANTOIN~1\AppData\Local\Temp\iluverro.dll",b
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
          O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
          O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
          O13 - Gopher Prefix:
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - http://update.microsoft.com/...
          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
          O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://wisup.net/_plateforme/Upload/Aurigma/AurigmaActiveX/ImageUploader4.cab
          O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MusicManagerPlugin.MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
          O16 - DPF: {D3166EE4-3E00-46CA-8F62-8E01D2314A7F} - http://www.cig.canon-europe.com/ph/fr_BE/st/download/ddup/CNIMGUP_01_210102F.cab
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe
          O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
          O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
          O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
          O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
          O23 - Service: Service Framework McAfee (McAfeeFramework) - Unknown owner - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (file missing)
          O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
          O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
          O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\Program Files\Common Files\X10\Common\X10nets.exe
          1. Contributeur sécurité
            1) fermes ton navigateur.
            Lance Hijackthis et tu choisis " Do a system scan only ".
            Tu sélectionnes les lignes suivantes :

            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
            O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\Home Cinema\PowerDVD\Language\Language.exe"
            O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\geBuRHWM.dll,#1
            O4 - HKCU\..\Run: [3c85aa0e] rundll32.exe "C:\Users\ANTOIN~1\AppData\Local\Temp\iluverro.dll",b
            O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O16 - DPF: {D3166EE4-3E00-46CA-8F62-8E01D2314A7F} - http://www.cig.canon-europe.com/ph/fr_BE/st/download/ddup/CNIMGUP_01_210102F.cab
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe

            Tu choisis l'option " Fixchecked" en bas de la page.

            2) Il y a toujours des traces d'infections.
            Tu vas télécharger ComBoFix sur le bureau.
            http://download.bleepingcomputer.com/sUBs/ComboFix.exe

            On va le passer une première fois pour rechercher les infections.
            Pour un meilleur résultat, on va le passer aussi en mode sans échec.

            Redémarre l'ordinateur en mode sans échec ( touche F8 ) et choisis ton compte.

            Double sur Combofix.exe et suis les invites.
            Une fois le scan fini, un rapport va apparaitre.

            Copie/colle ce rapport dans ta prochaine réponse.
            Si tu ne le trouves pas, il est à C:\ComboFix.txt.

            A+
            1. bonsoir

              pour suivre merci

              1. Contributeur sécurité
                Pas de problème. :-)

                Chiquitine 29
            2. Désolé, viens de terminer repas avec mon amie.
              J'ai copier votre réponse et vais essayer.
              Une question, comment désactiver le P2P ! Qu'est-ce ?
              Merci
              1. Contributeur sécurité
                Une erreur de ma part.
                Interférence avec un autre message.

                A+
            3. Contributeur sécurité
              AntoinePetit,

              Tu me posteras aussi un rapport Hijackthis.

              A+
              1. Combofix.exe sur bureau ne fonctionne pas, en mode sans echec n'apparait pas sur le bureau !
                repassé malwarebytes, résultat:
                Malwarebytes' Anti-Malware 1.20
                Version de la base de données: 935
                Windows 6.0.6001 Service Pack 1

                22:48:23 10/07/2008
                mbam-log-7-10-2008 (22-48-23).txt

                Type de recherche: Examen complet (C:\|D:\|J:\|)
                Eléments examinés: 169198
                Temps écoulé: 29 minute(s), 13 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 1
                Clé(s) du Registre infectée(s): 4
                Valeur(s) du Registre infectée(s): 0
                Elément(s) de données du Registre infecté(s): 1
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 3

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                C:\Users\Antoine Petit\AppData\Local\Temp\geBuVLff.dll (Trojan.Vundo) -> Unloaded module successfully.

                Clé(s) du Registre infectée(s):
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a8dd2664-0bb9-4f79-98c9-6f6b30dfa01d} (Trojan.Vundo) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{a8dd2664-0bb9-4f79-98c9-6f6b30dfa01d} (Trojan.Vundo) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

                Valeur(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre infecté(s):
                HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\users\antoin~1\appdata\local\temp\gebuvlff -> Quarantined and deleted successfully.

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                C:\Users\Antoine Petit\AppData\Local\Temp\geBuVLff.dll (Trojan.Vundo) -> Delete on reboot.
                C:\Users\Antoine Petit\AppData\Local\Temp\ffLVuBeg.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\Users\Antoine Petit\AppData\Local\Temp\ffLVuBeg.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.

                HijackThis bloqué avec les autres prg, relancé pc pour y arriver.
                Maintenant j'arrête car doit m'occuper de mes hôtes, reprendrais une autrefois.
                Grand merci verni29 pour ton aide, espère te retrouver plus tard.
                Bonne soirée et à +
                1. Contributeur sécurité
                  AntoinePetit,

                  Si l'icône ComBofix apparait sous Windows, elle devrait aussi apparaitre en mode sans échec.
                  Vérifie bien que tu as choisi ton compte et réessaie de relancer ComBoFix en mode sans échec.

                  Si tu as le même problème, alors passe ComBofix sous Windows.

                  Tu postes le rapport ComBoFix et un rapport Hijackthis.

                  A+
                2. Contributeur sécurité
                  @verni29AntoinePetit,

                  Il faut que tu nettoies tous les fichiers temporaires de ton ordinateur car l'infection se trouve à cet endroit.
                  Tu feras ce nettoyage avant de passer ComBoFix.

                  Tu vas télécharger AFTCleaner, un utilitaire qui ne demande aucune installation.
                  http://www.atribune.org/ccount/click.php?id=1

                  Tu l'enregistres sur ton bureau et double-clique pour le lancer.
                  Choisis l'option Select All puis Empty Selected pour lancer lme nettoyage de l'ordinateur.

                  A +
              2. Contributeur sécurité
                Tiens moi au courant pour ComBofix.
                Il y a d'autres solutions.

                A+
                1. Bonjour, Pas su répondre plutôt. Pas réussi à faire tourner ComBofix.
                  Après une mauvaise manipulations le pc était planté, ai fait une réparation avec le dvd vista, suite à celà plusieur prg ont été effacés dont MalwareBytes etc. j'ai réinstallé MalwareBytes et refait une passe en mode sans échec, les fichiers et dossiers infectés ont été supprimés. Depuis lors le problème semble résolu.
                  Te remercie de tout coeur pour ton aide et à charge de revanche. A +
                2. Contributeur sécurité
                  @topeBonjour,

                  Si tu penses que le problème est règlé, pas de souci.
                  J'aurais aimé simplement que tu m'envoies un rapport Hijackthis.

                  Sinon, mets le sujet en résolu.

                  A+ ou au revoir.
                3. @verni29Voici :
                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 21:59:56, on 10/07/2008
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\WINDOWS\system32\taskeng.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\RtHDVCpl.exe
                  C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                  C:\Windows\System32\mobsync.exe
                  C:\Windows\WindowsMobile\wmdc.exe
                  C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
                  C:\Program Files\Logitech\QuickCam\Quickcam.exe
                  C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
                  C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\TomTom HOME\TomTomHOME.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\MSN Messenger\msnmsgr.exe
                  C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                  C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.proximus.be/pickx
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://antoinepetit2000.free.fr/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                  O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
                  O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
                  O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
                  O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
                  O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
                  O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
                  O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
                  O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                  O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                  O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
                  O4 - HKLM\..\Run: [Malwarebytes Anti-Malware Reboot] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                  O4 - HKCU\..\Run: [SpriteService] "C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe"
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                  O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                  O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
                  O13 - Gopher Prefix:
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - http://update.microsoft.com/...
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                  O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://wisup.net/_plateforme/Upload/Aurigma/AurigmaActiveX/ImageUploader4.cab
                  O16 - DPF: {C45B1500-7B63-47C2-AB25-C28CB46AFDEE} (MusicManagerPlugin.MediaBar) - http://sib1.od2.com/common/musicmanager/installation/MusicManagerPlugin.CAB
                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Planificateur LiveUpdate automatique (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
                  O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                  O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
                  O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
                  O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
                  O23 - Service: Service Framework McAfee (McAfeeFramework) - Unknown owner - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe (file missing)
                  O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                  O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
                  O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                  O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\Program Files\Common Files\X10\Common\X10nets.exe
                4. Contributeur sécurité
                  @topeLe rapport est propre.
                  Bon continuité.

                  salut.