Probleme redictions sur recherche google

Bonjour a tous,
Lorsque je fais une recherche sous google, en cliquant sur un résultat de la recherche, je me retrouve sur des sites n'ayant rien a voir. J'ai fais tout ce que je pouvais pour regler ce probleme, mais sans succès. J'ai fais les méthodes préliminaires de désinfections, sans succès, je vous demande donc votre aide... et vous en remercie par avance !

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:03:48, on 13/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=www.wanadoo.fr
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B6245CBB-495E-4700-913A-339A146456AC}: NameServer = 212.27.54.252,212.27.53.252
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 7400 bytes
Configuration: Windows XP
Internet Explorer 7.0

24 réponses

  1. Salut,

    * Télécharge FixWareout de ce site sur le bureau:
    http://download.bleepingcomputer.com/lonny/Fixwareout.exe

    * Lance le fix: clique sur Next, puis Install, puis assure toi que "Run fixit" est activé puis clique sur Finish.
    Le fix va commencer, suis les messages à l'écran. Il te sera demandé de redémarrer ton ordinateur, fais le. Ton système mettra un peu plus de temps au démarrage, c'est normal.

    *Poste (Copie/colle) le contenu du rapport qui va s'afficher à l'écran (report.txt) avec un nouveau rapport HijackThis! dans ta prochaine réponse.

    0
    1. Bonjour et merci pour ton aide.

      RAPPORT FIXWAREOUT :
      Username "Papa" - 13/08/2008 19:14:09 [Fixwareout edited 9/01/2007]

      ~~~~~ Prerun check

      Cache de résolution DNS vidé.

      System was rebooted successfully.

      ~~~~~ Postrun check
      HKLM\SOFTWARE\~\Winlogon\ "System"=""
      ....
      ....
      ~~~~~ Misc files.
      ....
      ~~~~~ Checking for older varients.
      ....

      ~~~~~ Current runs (hklm hkcu "run" Keys Only)
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "IAAnotif"="C:\\Program Files\\Intel\\Intel Application Accelerator\\iaanotif.exe"
      "SoundMAXPnP"="C:\\Program Files\\Analog Devices\\SoundMAX\\SMax4PNP.exe"
      "SoundMAX"="\"C:\\Program Files\\Analog Devices\\SoundMAX\\Smax4.exe\" /tray"
      "Acrobat Assistant 8.0"="\"C:\\Program Files\\Adobe\\Acrobat 8.0\\Acrobat\\Acrotray.exe\""
      "AVG8_TRAY"="C:\\PROGRA~1\\AVG\\AVG8\\avgtray.exe"

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
      "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
      "Yahoo! Pager"="\"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\YAHOOM~1.EXE\" -quiet"
      "Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AdobeUpdater]
      ....
      Hosts file was reset, If you use a custom hosts file please replace it...
      ~~~~~ End report ~~~~~

      RAPPORT HIJACTHIS:
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:17:41, on 13/08/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16674)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\WINDOWS\system32\svchost.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\notepad.exe
      C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
      C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
      C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
      C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
      C:\Program Files\Skype\Plugin Manager\skypePM.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
      O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
      O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=www.wanadoo.fr
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{B6245CBB-495E-4700-913A-339A146456AC}: NameServer = 212.27.54.252,212.27.53.252
      O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
      O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O20 - AppInit_DLLs: avgrsstx.dll
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      0
      1. réouvre hijackthis
        fais scan only
        coches ces lignes :

        O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

        tu les coches et tu clic sur fix checked

        ensuite :

        Télécharge cet outil de SiRi:

        http://siri.urz.free.fr/Softs/RHosts.exe)
        http://siri.urz.free.fr/RHosts.php

        Double cliquer dessus pour l'exécuter

        et cliquer sur " Restore original Hosts "

        ps : c est normal que rien ne se passe

        ensuite redémarer le pc et test
        0
        1. J'ai fais tout ça, mais le probleme persiste; pas sur toutes mes recherches, mais celle qui marche a tous les coups, c'est rechercher le mot "meteo" cliquer sur le site meteo France, et la boum, je me retrouve je sais pas ou ...

          J'ai fais un scan Hijacthis :

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 19:31:53, on 13/08/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16674)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
          C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
          C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
          C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
          C:\PROGRA~1\AVG\AVG8\avgtray.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Skype\Phone\Skype.exe
          C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
          C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
          C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
          C:\WINDOWS\system32\svchost.exe
          C:\PROGRA~1\AVG\AVG8\avgrsx.exe
          C:\PROGRA~1\AVG\AVG8\avgemc.exe
          C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          C:\Program Files\Skype\Plugin Manager\skypePM.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
          O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
          O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
          O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
          O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
          O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
          O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
          O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
          O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
          O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
          O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
          O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
          O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
          O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
          O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
          O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
          O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O14 - IERESET.INF: START_PAGE_URL=www.wanadoo.fr
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
          O17 - HKLM\System\CCS\Services\Tcpip\..\{B6245CBB-495E-4700-913A-339A146456AC}: NameServer = 212.27.54.252,212.27.53.252
          O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
          O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
          O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
          O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O20 - AppInit_DLLs: avgrsstx.dll
          O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
          O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
          O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
          O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
          0
          1. Télécharge sur ton bureau DSS (ex Comboscan) de Deckard:

            http://deckard.geekstogo.com/dss.exe

            (choisis enregistrer, puis Bureau comme emplacement)

            Ferme toutes les applications en cours.

            Double-clic sur DSS.exe pour lancer l'outil.

            Une fenêtre s'ouvre, invitant à fermer toutes les applications, clique sur OK.

            A la fin de l'analyse, une fenêtre s'ouvre, clique sur OK.

            Le rapport main.txt va s'afficher, copie le dans ta prochaine réponse.
            Si un rapport complémentaire a été créé ( extra.txt ), poste le aussi dans ta réponse.

            Les rapports sont ici :
            (!) C:\Deckard\System Scanner\main.txt
            (!) C:\Deckard\System Scanner\extra.txt

            (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

            0
            1. Voici le(s) rapports :
              Deckard's System Scanner v20071014.68
              Run by Papa on 2008-08-13 19:40:07
              Computer is in Normal Mode.
              --------------------------------------------------------------------------------

              -- System Restore --------------------------------------------------------------

              Failed to create restore point; unknown error code 0x0000001F

              -- Last 5 Restore Point(s) --
              18: 2008-08-12 12:15:23 UTC - RP38 - Supprimé Ad-Aware
              17: 2008-08-12 12:13:51 UTC - RP37 - Installed AVG Free 8.0
              16: 2008-08-03 20:07:49 UTC - RP36 - Software Distribution Service 3.0
              15: 2008-08-02 11:58:37 UTC - RP35 - Point de vérification système
              14: 2008-07-27 10:15:31 UTC - RP34 - Point de vérification système

              -- First Restore Point --
              1: 2008-05-11 16:05:10 UTC - RP21 - Point de vérification système

              Backed up registry hives.
              Performed disk cleanup.

              -- HijackThis (run as Papa.exe) ------------------------------------------------

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 19:40:41, on 13/08/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16674)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
              C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
              C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
              C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
              C:\PROGRA~1\AVG\AVG8\avgtray.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\Skype\Phone\Skype.exe
              C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
              C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
              C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
              C:\WINDOWS\system32\svchost.exe
              C:\PROGRA~1\AVG\AVG8\avgrsx.exe
              C:\PROGRA~1\AVG\AVG8\avgemc.exe
              C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
              C:\Program Files\Skype\Plugin Manager\skypePM.exe
              C:\Documents and Settings\Papa\Bureau\dss.exe
              C:\PROGRA~1\TRENDM~1\HIJACK~1\Papa.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
              O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
              O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
              O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
              O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
              O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
              O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
              O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
              O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
              O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
              O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
              O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
              O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
              O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
              O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
              O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
              O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
              O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O14 - IERESET.INF: START_PAGE_URL=www.wanadoo.fr
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{B6245CBB-495E-4700-913A-339A146456AC}: NameServer = 212.27.54.252,212.27.53.252
              O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
              O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
              O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
              O20 - AppInit_DLLs: avgrsstx.dll
              O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
              O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
              O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
              O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
              O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
              0
              1. Fix.reg

                Ouvre le bloc-notes (click droit sur le bureau > dans l´arborescence choisie nouveau et nouveau fichier texte) et fais un copier coller de ce qui est en citation ci-dessous (copie tout d'un trait-sans les barres(x)) :

                XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
                REGEDIT4

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "@"=-

                XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
                Note : Regedit4 est sur la premiere ligne dans le bloc note et il y a une ligne blanche a la fin.
                Puis click sur "fichier"/"enregistrer sous" :
                dans : sur le bureau
                Nom du fichier : fix.reg
                Type de fichier : "tous les fichiers"
                clique sur "enregistrer"

                ca doit ressembler a ca une fois enrregistré :

                http://img520.imageshack.us/img520/4251/screenshot005ps2.png

                double clique sur fix.reg => tu dois obligatoirement avoir un message "voulez-vous vraiment ajouter les informations contenues dans ce fichier .reg au registre ?"
                Si c'est bien le cas, clique sur "oui"

                ensuite redémarre le pc et test si toujours soucis, refais un scan DSS et post main.txt
                0
                1. Toujours le même probleme suite modif du registre.
                  LOG DSS:
                  Deckard's System Scanner v20071014.68
                  Run by Papa on 2008-08-13 19:55:16
                  Computer is in Normal Mode.
                  --------------------------------------------------------------------------------

                  -- HijackThis (run as Papa.exe) ------------------------------------------------

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 19:55:23, on 13/08/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
                  C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                  C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
                  C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
                  C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Program Files\Skype\Phone\Skype.exe
                  C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
                  C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
                  C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                  C:\PROGRA~1\AVG\AVG8\avgemc.exe
                  C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                  C:\Program Files\Skype\Plugin Manager\skypePM.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Documents and Settings\Papa\Bureau\dss.exe
                  C:\PROGRA~1\TRENDM~1\HIJACK~1\Papa.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                  O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                  O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                  O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
                  O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
                  O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                  O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                  O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
                  O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
                  O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                  O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                  O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                  O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                  O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                  O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                  O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                  O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                  O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                  O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O14 - IERESET.INF: START_PAGE_URL=www.wanadoo.fr
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{B6245CBB-495E-4700-913A-339A146456AC}: NameServer = 212.27.54.252,212.27.53.252
                  O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
                  O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
                  O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 212.27.54.252 212.27.53.252
                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                  O20 - AppInit_DLLs: avgrsstx.dll
                  O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                  O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                  O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
                  O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                  0
                  1. la modif n a pas été prise en compte mais bon

                    télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau.
                    double-clique sur OTMoveIt.exe pour le lancer.
                    Assure toi que la case Unregister Dll's and Ocx's soit bien cochée
                    copie la liste qui se trouve en gras ci-dessous,
                    et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                    C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
                    C:\Documents and Settings\Papa\Application Data\SUPERAntiSpyware.com
                    C:\WINDOWS\system32\ezsidmv.dat
                    C:\WINDOWS\system32\tmp.reg
                    C:\WINDOWS\system32\WS2Fix.exe
                    C:\WINDOWS\system32\VCCLSID.exe
                    C:\WINDOWS\system32\VACFix.exe
                    C:\WINDOWS\system32\SrchSTS.exe
                    C:\WINDOWS\system32\Process.exe
                    C:\WINDOWS\system32\dumphive.exe
                    C:\WINDOWS\system32\404Fix.exe


                    clique sur MoveIt! pour lancer la suppression.
                    le résultat apparaitra dans le cadre "Results".
                    clique sur Exit pour fermer.
                    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                    ensuite :

                    Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                    -> Double clique sur combofix.exe.
                    -> Tape sur la touche 1 (Yes) pour démarrer le scan.
                    -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                    Avant d'utiliser ComboFix :

                    -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

                    -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

                    Une fois fait, sur ton bureau double-clic sur Combofix.exe.

                    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

                    /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

                    - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

                    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

                    -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

                    -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
                    0
                    1. RAPPORT OTMoveIT:

                      C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware moved successfully.
                      C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com moved successfully.
                      C:\Documents and Settings\Papa\Application Data\SUPERAntiSpyware.com moved successfully.
                      C:\WINDOWS\system32\ezsidmv.dat moved successfully.
                      C:\WINDOWS\system32\tmp.reg moved successfully.
                      C:\WINDOWS\system32\WS2Fix.exe moved successfully.
                      C:\WINDOWS\system32\VCCLSID.exe moved successfully.
                      C:\WINDOWS\system32\VACFix.exe moved successfully.
                      C:\WINDOWS\system32\SrchSTS.exe moved successfully.
                      C:\WINDOWS\system32\Process.exe moved successfully.
                      C:\WINDOWS\system32\dumphive.exe moved successfully.
                      C:\WINDOWS\system32\404Fix.exe moved successfully.

                      OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08132008_200325

                      RAPPORT COMBOFIX:

                      ComboFix 08-08-12.01 - Papa 2008-08-13 20:07:41.1 - NTFSx86
                      Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.710 [GMT 2:00]
                      Endroit: C:\Documents and Settings\Papa\Bureau\ComboFix.exe

                      [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                      .

                      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      C:\WINDOWS\system32\drivers\msliksurserv.sys
                      C:\WINDOWS\system32\msliksurcredo.dll
                      C:\WINDOWS\system32\msliksurdns.dll

                      .
                      ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-13 to 2008-08-13 ))))))))))))))))))))))))))))))))))))
                      .

                      2008-08-13 20:03 . 2008-08-13 20:03 <REP> d-------- C:\_OTMoveIt
                      2008-08-13 19:39 . 2008-08-13 19:39 <REP> d-------- C:\Deckard
                      2008-08-13 19:13 . 2008-08-13 19:16 <REP> d-------- C:\fixwareout
                      2008-08-13 18:51 . 2008-08-13 18:51 <REP> d-------- C:\Program Files\Trend Micro
                      2008-08-12 18:42 . 2008-08-12 18:42 <REP> d--h----- C:\$AVG8.VAULT$
                      2008-08-12 15:37 . 2008-08-13 18:51 <REP> d-------- C:\WINDOWS\system32\drivers\Avg
                      2008-08-12 15:37 . 2008-08-12 15:37 <REP> d-------- C:\Program Files\AVG
                      2008-08-12 15:37 . 2008-08-12 18:24 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
                      2008-08-12 15:37 . 2008-08-12 18:25 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
                      2008-08-12 15:37 . 2008-08-12 18:24 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
                      2008-08-12 15:30 . 2008-08-12 15:37 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avg8
                      2008-08-12 12:39 . 2008-08-12 12:39 <REP> d-------- C:\Documents and Settings\Papa\Application Data\Grisoft
                      2008-08-12 12:39 . 2008-08-12 12:39 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
                      2008-08-12 12:38 . 2008-08-12 14:09 <REP> d-------- C:\WINDOWS\BDOSCAN8
                      2008-08-12 12:32 . 2008-08-12 12:32 <REP> d-------- C:\Program Files\CCleaner
                      2008-08-12 11:09 . 2008-08-11 18:07 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
                      2008-08-11 18:03 . 2008-08-12 12:41 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
                      2008-08-11 16:45 . 2008-08-11 17:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                      2008-08-11 16:42 . 2008-08-11 16:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
                      2008-08-11 16:22 . 2008-03-05 14:00 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
                      2008-08-11 16:22 . 2008-03-05 14:00 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
                      2008-08-11 16:22 . 2008-03-05 13:03 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
                      2008-08-11 16:22 . 2008-03-05 14:00 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
                      2008-08-11 16:22 . 2008-03-05 14:00 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
                      2008-08-11 16:22 . 2008-03-05 14:00 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
                      2008-08-11 16:22 . 2008-03-05 14:00 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
                      2008-08-11 16:22 . 2008-08-12 15:37 <REP> d-------- C:\Documents and Settings\Administrateur
                      2008-08-11 16:07 . 2008-08-11 16:07 <REP> d-------- C:\Program Files\CleanUp!
                      2008-08-10 17:58 . 2008-08-13 18:50 <REP> d-------- C:\Documents and Settings\Papa\Application Data\skypePM
                      2008-08-10 17:57 . 2008-08-10 17:57 <REP> d-------- C:\Program Files\Skype
                      2008-08-10 17:57 . 2008-08-10 17:57 <REP> d-------- C:\Program Files\Fichiers communs\Skype
                      2008-08-10 17:57 . 2008-08-13 20:04 <REP> d-------- C:\Documents and Settings\Papa\Application Data\Skype
                      2008-08-10 17:57 . 2008-08-10 17:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Skype
                      2008-08-08 17:12 . 2008-08-08 17:12 38 --a------ C:\WINDOWS\AviSplitter.INI

                      .
                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2008-08-10 16:03 --------- d-----w C:\Documents and Settings\Papa\Application Data\Canon
                      2008-08-09 05:47 --------- d-----w C:\Documents and Settings\Papa\Application Data\uTorrent
                      2008-08-08 15:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
                      2008-08-07 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
                      2008-08-07 17:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
                      2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
                      2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
                      2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
                      2008-06-18 11:36 --------- d-----w C:\Program Files\Yahoo!
                      2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
                      .

                      ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      REGEDIT4
                      *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:54 15360]
                      "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
                      "Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2007-08-30 17:43 4670704]
                      "Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-07-23 14:11 21738792]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "IAAnotif"="C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 12:23 135168]
                      "SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 17:28 790528]
                      "Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 19:54 623992]
                      "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-12 18:25 1232152]

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                      "AppInit_DLLs"=avgrsstx.dll

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                      "vidc.ffds"= ffdshow.ax
                      "msacm.ac3filter"= ac3filter.acm

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                      "%windir%\\system32\\sessmgr.exe"=
                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                      "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                      "C:\\Program Files\\uTorrent\\uTorrent.exe"=
                      "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
                      "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
                      "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
                      "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
                      "C:\\Program Files\\Skype\\Phone\\Skype.exe"=

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                      "5267:TCP"= 5267:TCP:Livechat

                      R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-12 18:24]
                      R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-12 18:24]
                      R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-12 18:24]
                      R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-12 18:25]
                      R3 camvid20;Philips ToUcam Camera; Video;C:\WINDOWS\system32\DRIVERS\camdrv21.sys []
                      .
                      .
                      ------- Supplementary Scan -------
                      .
                      R0 -: HKCU-Main,Start Page = hxxp://www.google.fr/
                      R1 -: HKCU-Internet Settings,ProxyOverride = *.local
                      O8 -: Ajouter au fichier PDF existant - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                      O8 -: Convertir en Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                      O8 -: Convertir la cible du lien en Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                      O8 -: Convertir la cible du lien en un fichier PDF existant - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                      O8 -: Convertir la sélection en Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                      O8 -: Convertir la sélection en un fichier PDF existant - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                      O8 -: Convertir les liens sélectionnés en fichier Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                      O8 -: Convertir les liens sélectionnés en un fichier PDF existant - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                      O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                      O17 -: HKLM\CCS\Interface\{B6245CBB-495E-4700-913A-339A146456AC}: NameServer = 212.27.54.252,212.27.53.252

                      **************************************************************************

                      catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2008-08-13 20:10:01
                      Windows 5.1.2600 Service Pack 2 NTFS

                      Balayage processus cach‚s ...

                      Balayage cach‚ autostart entries ...

                      Balayage des fichiers cach‚s ...

                      Scan termin‚ avec succŠs
                      Les fichiers cach‚s: 0

                      **************************************************************************
                      .
                      ------------------------ Other Running Processes ------------------------
                      .
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\Program Files\Intel\Intel Application Accelerator\IAANTmon.exe
                      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                      C:\Program Files\AVG\AVG8\avgtray.exe
                      C:\PROGRA~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
                      C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                      C:\Program Files\Skype\Plugin Manager\skypePM.exe
                      C:\Program Files\AVG\AVG8\avgrsx.exe
                      .
                      **************************************************************************
                      .
                      Temps d'accomplissement: 2008-08-13 20:12:13 - machine was rebooted [Papa]
                      ComboFix-quarantined-files.txt 2008-08-13 18:11:43

                      Pre-Run: 88,757,391,360 octets libres
                      Post-Run: 88,755,593,216 octets libres

                      144 --- E O F --- 2008-08-07 21:28:42
                      0
                      1. double-clique sur OTMoveIt.exe pour le lancer.
                        Assure toi que la case Unregister Dll's and Ocx's soit bien cochée
                        copie la liste qui se trouve en gras ci-dessous,
                        et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                        C:\WINDOWS\system32\IEDFix.C.exe
                        C:\Program Files\CleanUp!


                        clique sur MoveIt! pour lancer la suppression.
                        le résultat apparaitra dans le cadre "Results".
                        clique sur Exit pour fermer.
                        poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                        il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                        et dis moi comment va le pc apres ça stp
                        0
                        1. Alors, j'ai tout fais, et il semblerait que ça va mieux: pas de redirection lorsque je vais sur le site d ela meteo !
                          A suivre donc...
                          Voici le rapport demandé :
                          C:\WINDOWS\system32\IEDFix.C.exe moved successfully.
                          C:\Program Files\CleanUp! moved successfully.

                          OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08132008_202245

                          PS: Puis-je te poster ici un rapport HijackThis d'une autre de mes machines afin que tu puisse me dire si elle est OK ?
                          0
                          1. ok oui tu peux m envoyer le rapport pas de soucis
                            0
                            1. Le VOICI:

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 20:33:18, on 13/08/2008
                              Platform: Windows 2003 SP2 (WinNT 5.02.3790)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.3790.3959)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\csrss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\system32\msdtc.exe
                              C:\PROGRA~1\APC\POWERC~1\agent\pbeagent.exe
                              C:\PROGRA~1\APC\POWERC~1\server\PBESER~1.EXE
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\inetsrv\inetinfo.exe
                              C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe
                              C:\Program Files\Moon Secure Antivirus\msavcore.exe
                              C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Iomega\REV System Software\RevUDF.exe
                              C:\Program Files\Iomega\REV System Software\ImIconXp.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\fxssvc.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\System32\alg.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Moon Secure Antivirus\moontray.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                              C:\Hexoutils\HexOutils.exe
                              C:\WINDOWS\system32\wbem\wmiprvse.exe
                              C:\WINDOWS\system32\csrss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\rdpclip.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Iomega\REV System Software\imiconxp.exe
                              C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                              C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\WTQRWDM7\HiJackThis[1].exe
                              C:\WINDOWS\system32\wbem\wmiprvse.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O4 - HKLM\..\Run: [Iomega ImIconXP] C:\Program Files\Iomega\REV System Software\imiconxp.exe
                              O4 - HKLM\..\Run: [Moon Secure Antivirus] "C:\Program Files\Moon Secure Antivirus\moontray.exe"
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                              O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
                              O4 - Startup: HexOutils.lnk = C:\Hexoutils\HexOutils.exe
                              O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                              O15 - Trusted Zone: https://www.impots.gouv.fr/
                              O15 - ESC Trusted Zone: https://www.credit-agricole.fr/ca-nmp/particulier.html
                              O15 - ESC Trusted Zone: http://www.cellard.com
                              O15 - ESC Trusted Zone: https://www.ricoh.com.au/
                              O15 - ESC Trusted Zone: https://marketingplatform.google.com/about/enterprise/
                              O15 - ESC Trusted Zone: https://account.dyn.com/
                              O15 - ESC Trusted Zone: https://www.google.fr/?gws_rd=ssl
                              O15 - ESC Trusted Zone: https://www8.hp.com/fr/fr/home.html
                              O15 - ESC Trusted Zone: http://www.laboratoire-microsoft.org
                              O15 - ESC Trusted Zone: https://www.avanquest.com/France/microapp/
                              O15 - ESC Trusted Zone: https://espace-client.orange.fr/page-accueil
                              O15 - ESC Trusted Zone: http://webmail15.orange.fr
                              O15 - ESC Trusted Zone: https://www.orange.fr/portail
                              O15 - ESC Trusted Zone: https://www.ricoh-europe.com/support/index.html
                              O15 - ESC Trusted Zone: https://www.ricoh.be/index.html
                              O15 - ESC Trusted Zone: https://www.ricoh.ca/en
                              O15 - ESC Trusted Zone: http://support.ricoh.com
                              O15 - ESC Trusted Zone: https://www.service-public.fr
                              O15 - ESC Trusted Zone: http://www.cognacqjayimage.com/en/homepage/
                              O15 - ESC Trusted Zone: https://www.orange.fr/portail
                              O15 - ESC Trusted IP range: http://209.85.135.104
                              O15 - ESC Trusted IP range: http://192.168.0.100
                              O16 - DPF: {A06BE318-C096-11D4-964F-0010A4D06F69} (TeleTVA Control) - https://tva.dgi.minefi.gouv.fr/activeX/TeleTVA.tva
                              O17 - HKLM\System\CCS\Services\Tcpip\..\{37363853-A725-47B5-AD53-67224A095B13}: NameServer = 192.168.0.100
                              O17 - HKLM\System\CS1\Services\Tcpip\..\{37363853-A725-47B5-AD53-67224A095B13}: NameServer = 192.168.0.100
                              O17 - HKLM\System\CS2\Services\Tcpip\..\{37363853-A725-47B5-AD53-67224A095B13}: NameServer = 192.168.0.100
                              O23 - Service: APC PBE Agent (APCPBEAgent) - APC - C:\PROGRA~1\APC\POWERC~1\agent\pbeagent.exe
                              O23 - Service: APC PBE Server (APCPBEServer) - APC - C:\PROGRA~1\APC\POWERC~1\server\PBESER~1.EXE
                              O23 - Service: Moon Secure Antivirus Core (msav) - Unknown owner - C:\Program Files\Moon Secure Antivirus\msavcore.exe
                              O23 - Service: RevUDFService - Iomega Corp - C:\Program Files\Iomega\REV System Software\RevUDF.exe
                              0
                              1. Sur la machine precedente :

                                Télécharge ToolsCleaner sur ton bureau.
                                -->
                                ftp://ftp.commentcamarche.com/download/ToolsCleaner2.exe
                                http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
                                http://pc-system.fr/

                                # Clique sur Recherche et laisse le scan agir ...
                                # Clique sur Suppression pour finaliser.
                                # Tu peux, si tu le souhaites, te servir des Options facultatives.
                                # Clique sur Quitter pour obtenir le rapport.
                                # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                                sur la seconde machine :

                                réouvre hijackthis
                                fais scan only
                                coches ces lignes :

                                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')

                                O16 - DPF: {A06BE318-C096-11D4-964F-0010A4D06F69} (TeleTVA Control) - https://tva.dgi.minefi.gouv.fr/activeX/TeleTVA.tva

                                tu les coches et tu clic sur fix checked

                                ensuite :

                                Télécharge ce fichier sur le bureau :

                                http://downloads.malwareremoval.com/Nel/FixP.zip

                                Extrait et double clique sur Fix_Protocol_zones_ranges.reg.

                                Acceptes lorsqu'il te demande de fusionner avec le registre.

                                ensuite désinstal adobe reader car pas a jours et telecharge et instal cette vesrion :

                                https://get2.adobe.com/reader/otherversions/

                                ensuite refais un scan hijackthis et post le rapport stp
                                0
                                1. Merci pour ton aide.

                                  Voici le log de tools cleaner, sachant que j'avais déja fait pas mal de ménage manuellement :
                                  -->- Recherche:

                                  C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
                                  C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
                                  C:\Documents and Settings\Papa\Bureau\HijackThis.lnk: trouvé !
                                  C:\Program Files\Trend Micro\HijackThis: trouvé !
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !

                                  ---------------------------------
                                  -->- Suppression:

                                  C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
                                  C:\Documents and Settings\Papa\Bureau\HijackThis.lnk: supprimé !
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
                                  C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
                                  C:\Program Files\Trend Micro\HijackThis: supprimé !

                                  Pour la seconde machine, c'est le serveur Win 2003 de mon travail, et j ele trouve de plus en plus lent sur internet; je vais faire ce que tu demande et revenir poster le résultat.
                                  0
                                  1. QUOI QUE; tu es CERTAIN que je peux virer les lignes en 04 "CTFMON" ????????????
                                    0
                                    1. Oui car inutile au demarrage comme celles la :

                                      O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')

                                      qui sont la preuve que ton windows n est pas légale
                                      0
                                      1. Bon, Clarifions honnetement les choses; la premiere machine, OK, win pas légal; machine perso.
                                        La seconde, le serveur Win 2003, totalement legal, serveur d'entreprise, ça ma couté la peau du cul.

                                        Maintenant, il semble que les lignes que tu me demande d'effacer ne soient pas a effacer : exemple 016 tele tva, ça c'est obligatoire pour les entreprises...

                                        Bref, si faut te sortir les factures d'achat du materiel et logiciel, pas de soucis... Mais dans ce cas ci, il faut faire tres attention a ce que l'on va faire pour nettoyer ...

                                        Bref, je recolle le log hijackthis que je viens de faire, et validons si ya des choses qui ne devraient pas etre sur cette machine (Normalement, tout doit etre OK, car c'est un serveur d'entreprise, pas d'enfants qui jouent avec...).

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 21:53:42, on 13/08/2008
                                        Platform: Windows 2003 SP2 (WinNT 5.02.3790)
                                        MSIE: Internet Explorer v6.00 SP2 (6.00.3790.3959)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\csrss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\system32\spoolsv.exe
                                        C:\WINDOWS\system32\msdtc.exe
                                        C:\PROGRA~1\APC\POWERC~1\agent\pbeagent.exe
                                        C:\PROGRA~1\APC\POWERC~1\server\PBESER~1.EXE
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\system32\inetsrv\inetinfo.exe
                                        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe
                                        C:\Program Files\Moon Secure Antivirus\msavcore.exe
                                        C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\Program Files\Iomega\REV System Software\RevUDF.exe
                                        C:\Program Files\Iomega\REV System Software\ImIconXp.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\system32\fxssvc.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\System32\alg.exe
                                        C:\WINDOWS\Explorer.EXE
                                        C:\Program Files\Moon Secure Antivirus\moontray.exe
                                        C:\WINDOWS\system32\ctfmon.exe
                                        C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                                        C:\Hexoutils\HexOutils.exe
                                        C:\WINDOWS\system32\wbem\wmiprvse.exe
                                        C:\WINDOWS\system32\csrss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\rdpclip.exe
                                        C:\WINDOWS\Explorer.EXE
                                        C:\Program Files\Iomega\REV System Software\imiconxp.exe
                                        C:\WINDOWS\system32\ctfmon.exe
                                        C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                                        C:\WINDOWS\system32\wbem\wmiprvse.exe
                                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                        O4 - HKLM\..\Run: [Iomega ImIconXP] C:\Program Files\Iomega\REV System Software\imiconxp.exe
                                        O4 - HKLM\..\Run: [Moon Secure Antivirus] "C:\Program Files\Moon Secure Antivirus\moontray.exe"
                                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                        O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE RÉSEAU')
                                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                        O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
                                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                        O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
                                        O4 - Startup: HexOutils.lnk = C:\Hexoutils\HexOutils.exe
                                        O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                                        O15 - Trusted Zone: https://www.impots.gouv.fr/
                                        O15 - ESC Trusted Zone: https://www.credit-agricole.fr/ca-nmp/particulier.html
                                        O15 - ESC Trusted Zone: http://www.cellard.com
                                        O15 - ESC Trusted Zone: https://www.ricoh.com.au/
                                        O15 - ESC Trusted Zone: https://marketingplatform.google.com/about/enterprise/
                                        O15 - ESC Trusted Zone: https://account.dyn.com/
                                        O15 - ESC Trusted Zone: https://www.google.fr/?gws_rd=ssl
                                        O15 - ESC Trusted Zone: https://www8.hp.com/fr/fr/home.html
                                        O15 - ESC Trusted Zone: http://www.laboratoire-microsoft.org
                                        O15 - ESC Trusted Zone: https://www.avanquest.com/France/microapp/
                                        O15 - ESC Trusted Zone: https://espace-client.orange.fr/page-accueil
                                        O15 - ESC Trusted Zone: http://webmail15.orange.fr
                                        O15 - ESC Trusted Zone: https://www.orange.fr/portail
                                        O15 - ESC Trusted Zone: https://www.ricoh-europe.com/support/index.html
                                        O15 - ESC Trusted Zone: https://www.ricoh.be/index.html
                                        O15 - ESC Trusted Zone: https://www.ricoh.ca/en
                                        O15 - ESC Trusted Zone: http://support.ricoh.com
                                        O15 - ESC Trusted Zone: https://www.service-public.fr
                                        O15 - ESC Trusted Zone: http://www.cognacqjayimage.com/en/homepage/
                                        O15 - ESC Trusted Zone: https://www.orange.fr/portail
                                        O15 - ESC Trusted IP range: http://209.85.135.104
                                        O15 - ESC Trusted IP range: http://192.168.0.100
                                        O16 - DPF: {A06BE318-C096-11D4-964F-0010A4D06F69} (TeleTVA Control) - https://tva.dgi.minefi.gouv.fr/activeX/TeleTVA.tva
                                        O17 - HKLM\System\CCS\Services\Tcpip\..\{37363853-A725-47B5-AD53-67224A095B13}: NameServer = 192.168.0.100
                                        O17 - HKLM\System\CS1\Services\Tcpip\..\{37363853-A725-47B5-AD53-67224A095B13}: NameServer = 192.168.0.100
                                        O17 - HKLM\System\CS2\Services\Tcpip\..\{37363853-A725-47B5-AD53-67224A095B13}: NameServer = 192.168.0.100
                                        O23 - Service: APC PBE Agent (APCPBEAgent) - APC - C:\PROGRA~1\APC\POWERC~1\agent\pbeagent.exe
                                        O23 - Service: APC PBE Server (APCPBEServer) - APC - C:\PROGRA~1\APC\POWERC~1\server\PBESER~1.EXE
                                        O23 - Service: Moon Secure Antivirus Core (msav) - Unknown owner - C:\Program Files\Moon Secure Antivirus\msavcore.exe
                                        O23 - Service: RevUDFService - Iomega Corp - C:\Program Files\Iomega\REV System Software\RevUDF.exe
                                        0
                                        1. le reste est clean y a pas de soucis

                                          la 016 tu peux fixer y a pas de danger c est un active X mais bon laisse le il fait pas de mal

                                          sinon ras
                                          0
                                          • 1
                                          • 2