Virus

Bonjour à tous !

Je viens vous demander de l'aide car je ne suis pas très doué en informatique et j'ai l'impression d'avoir attrapé un virus, lorsque je suis sur internet je trouve que il a beaucoup plus de page web qui s'ouvre seule et je pense avoir un virus.

en faite, j'ai déjà eu un virus comme ça mais ça fait un moment et je crois que l'on m'avait aidé grâce au programme hijack this, mais le problème c'est que je ne sait plus du tout comment j'avais fait, et je crois qu'il y a une histoire de rapport, mais je suis complètement perdu

aidez moi SVP

50 réponses

Résumé de la discussion

Des symptômes de navigation perturbée et de pages qui s’ouvrent seules soulèvent une suspicion de malware ou virus, et l’historique d’analyse évoque l’utilisation de HijackThis pour diagnostiquer. Plusieurs éléments évoquent des scans encore en cours, des paramètres modifiés et des barres d’outils potentiellement indésirables, tandis que les rapports HijackThis et les journaux système servent à repérer les entrées suspectes. D’autres interventions indiquent l’emploi d’outils de nettoyage comme ComboFix et la création d’un point de restauration, avec une liste d’éléments détectés et d’éléments démarrés au boot, parfois suspects. Enfin, un balayage rootkit n’a pas détecté d’éléments cachés, ce qui précise le contexte mais n’exclut pas d’autres nettoyages ou vérifications à effectuer ou des analyses complémentaires.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut,

    - Télécharge HijackThis V 2.02 (HijackThis Installer) :
    http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

    - Fais un double-clic sur HJTInstall.exe afin de lancer l'installation

    - Clique sur Install ensuite sur I Accept

    - Clique sur Do a scan system and save log file

    - Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
    1. alors g suivi tote tes recommandation
      j'ai désactiver UAC
      j'ai installé navilog1
      j'ai tapé F
      mai ensuite il me met : "getpatchs a cessé de fonctionné"
      "accès refusé"
      :s
  2. merci
    voici le rapport :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 00:41:24, on 28/08/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16711)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
    C:\Windows\ehome\ehtray.exe
    C:\Users\Cocotte\AppData\Local\mtbhekk.exe
    C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Windows\system32\conime.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Program Files\Internet Explorer\IEUser.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: IE Toolbar - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
    O1 - Hosts: ::1 localhost
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: IE Toolbar - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [MSPService] C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
    O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
    O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [mtbhekk] "c:\users\cocotte\appdata\local\mtbhekk.exe" mtbhekk
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
    O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O13 - Gopher Prefix:
    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://topachat.pixawin.com/ImageUploader4.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    1. Modérateur
      Important : Désactive TeaTimer, le résident de Spybot, il va gêner la désinfection en empêchant la modification des BHO.

      ---> Démarre Spybot, clique sur Mode, coche Mode avancé
      ---> A gauche, clique sur Outils, puis sur Résident
      ---> Décoche la case devant Résident "TeaTimer" :
      http://apu.mabul.org/up/5/apu-5-gpdx9e06cwz2dypom2q7n6nc.jpg
      ---> Quitte Spybot

      Note : Je te conseille de ne pas le réactiver, il a été incapable d'empêcher l'infection de ton PC.

      ---> Désactive l'UAC le temps de la désinfection :
      https://www.zebulon.fr/astuces/pratique/220-desactiver-l-uac-dans-vista.html

      - Télécharge Navilog1 (de IL-MAFIOSO) et enregistre-le sur le bureau :
      http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

      - Double-clique sur Navilog1.exe afin de lancer l'installation

      - Si le fix ne lance pas automatiquement après son installation, double-clique sur Navilog1 présent sur le bureau

      - Appuie sur F ou f puis valide par Entrée

      - Appuie sur une touche de ton clavier à chaque fois que cela est demandé, tu arriveras au menu des options

      - Choisis l'option 1 et appuie sur la touche Entrée pour valider ton choix

      - Patiente jusqu'au message : *** Analyse Termine le ..... ***

      - Le scan fini, le bloc-notes contenant le rapport sera affiché, poste le contenu de ce rapport dans ta prochaine réponse

      - Si le résultat du scan ne s'affiche pas, tu le trouveras dans C:\fixnavi.txt

      N'utilise pas l'option 2, 3 et 4 sans notre accord, des fichiers légitimes peuvent être inclus dans ce scan.
      1. salut

        j'ai un petit problème depuis que j'ai fait l'étape de désactivé et restauré le système je n'arrive plus à ouvrir ma boite hotmail, par le biais de MSN il me dit que internet explorer ne marche plus.

        Pour pouvoir accèder à ma boite email j'ai du passé par internet
    2. Modérateur
      ---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
      http://download.bleepingcomputer.com/sUBs/ComboFix.exe

      /!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

      ---> Double-clique sur Combofix.exe
      Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
      Accepte en cliquant sur "Oui"

      ---> Mets-le en langue française F
      Tape sur la touche 1 (Yes) pour démarrer le scan.

      /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

      En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

      Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

      /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

      Note : Le rapport se trouve également là : C:\ComboFix.txt
      1. ComboFix 08-08-27.01 - Cocotte 2008-08-28 1:13:19.1 - NTFSx86
        Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1797 [GMT 2:00]
        Endroit: C:\Users\Cocotte\Desktop\ComboFix.exe
        * Création d'un nouveau point de restauration
        .

        (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
        .

        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware-Secure
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk
        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Website.lnk
        C:\Users\Cocotte\AppData\Local\mtbhekk.dat
        C:\Users\Cocotte\AppData\Local\mtbhekk.exe
        C:\Users\Cocotte\AppData\Local\mtbhekk_nav.dat
        C:\Users\Cocotte\AppData\Local\mtbhekk_navps.dat
        C:\Users\Cocotte\AppData\Roaming\Microsoft\Windows\Cookies\cocotte@serving-sys[2].txt

        .
        ((((((((((((((((((((((((((((( Fichiers créés 2008-07-27 to 2008-08-27 ))))))))))))))))))))))))))))))))))))
        .

        Pas de nouveau fichier créé dans cet espace de temps

        .
        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-08-27 22:56 --------- d-----w C:\Program Files\Navilog1
        2008-08-27 20:20 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
        2008-08-27 20:00 --------- d-----w C:\Program Files\Spybot - Search & Destroy
        2008-08-27 11:32 --------- d-----w C:\Users\Cocotte\AppData\Roaming\uTorrent
        2008-08-23 18:17 --------- d-----w C:\ProgramData\Roxio
        2008-08-22 18:03 --------- d-----w C:\ProgramData\Microsoft Help
        2008-08-20 14:21 --------- d-----w C:\Program Files\eMule
        2008-08-19 17:23 --------- d-----w C:\Users\Cocotte\AppData\Roaming\LimeWire
        2008-08-19 17:17 --------- d-----w C:\Program Files\LimeWire
        2008-08-17 11:02 --------- d-----w C:\Program Files\uTorrent
        2008-08-15 14:44 27,525 ----a-w C:\Users\Cocotte\AppData\Roaming\nvModes.dat
        2008-08-13 16:38 --------- d-----w C:\Program Files\Windows Mail
        2008-08-12 11:21 --------- d-----w C:\Program Files\Sun
        2008-08-12 11:20 --------- d-----w C:\Program Files\Java
        2008-08-08 20:47 --------- d-----w C:\Users\Cocotte\AppData\Roaming\dvdcss
        2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe
        2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll
        2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll
        2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll
        2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
        2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll
        2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
        2008-07-18 20:08 163,904 ----a-w C:\Windows\System32\wuwebv.dll
        2008-07-18 18:44 31,232 ----a-w C:\Windows\System32\wuapp.exe
        2008-07-15 23:48 2,048 ----a-w C:\Windows\System32\tzres.dll
        2008-07-14 11:30 --------- d-----w C:\ProgramData\Bluetooth
        2008-07-12 19:41 --------- d-----w C:\ProgramData\Lavasoft
        2008-07-12 19:40 --------- d-----w C:\Program Files\Lavasoft
        2008-07-12 19:39 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
        2008-07-09 14:11 174 --sha-w C:\Program Files\desktop.ini
        2008-06-29 18:15 --------- d-----w C:\Program Files\Picasa2
        2008-06-27 03:54 826,368 ----a-w C:\Windows\System32\wininet.dll
        2008-06-27 03:54 56,320 ----a-w C:\Windows\System32\iesetup.dll
        2008-06-27 03:54 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
        2008-06-27 03:54 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
        2008-06-26 00:34 7,964,672 ----a-w C:\Windows\System32\NlsLexicons0024.dll
        2008-06-26 00:33 9,892,864 ----a-w C:\Windows\System32\NlsLexicons000a.dll
        2008-06-19 03:25 61,440 ----a-w C:\Windows\System32\winipsec.dll
        2008-06-19 03:25 361,984 ----a-w C:\Windows\System32\IPSECSVC.DLL
        2008-06-19 03:25 28,672 ----a-w C:\Windows\System32\FwRemoteSvr.dll
        2008-06-19 03:25 272,896 ----a-w C:\Windows\System32\polstore.dll
        2008-06-12 06:54 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
        2008-06-12 06:54 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
        2008-06-12 01:21 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
        2008-04-02 17:15 216 ----a-w C:\Users\Cocotte\AppData\Roaming\wklnhst.dat
        2008-05-26 08:24 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
        2008-05-26 08:24 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
        2008-05-26 08:24 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
        .

        ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "SmpcSys"="C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe" [2007-07-19 15:32 1120568]
        "MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
        "DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 15:08 136136]
        "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "JMB36X IDE Setup"="C:\Windows\RaidTool\xInsIDE.exe" [2007-03-20 23:36 36864]
        "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-24 00:40 857648]
        "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-08-16 22:19 86016]
        "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-08-16 22:19 8478720]
        "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-08-16 22:19 81920]
        "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-01-11 11:40 232184]
        "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-10-11 20:25 243200]
        "MSPService"="C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe" [2007-06-12 23:36 102400]
        "toolbar_eula_launcher"="C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 18:20 28672]
        "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 14:00 174872]
        "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
        "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 03:23 443968]

        C:\Users\Cocotte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
        Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2008-03-03 20:41:35 3450608]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
        "EnableLUA"= 0 (0x0)

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
        "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
        "VIDC.YV12"= yv12vfw.dll

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
        "DisableMonitoring"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
        "DisableMonitoring"=dword:00000001

        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
        "DisableMonitoring"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
        "{81A4C2FB-17A9-4AC1-A24B-DC4CA25B219F}"= C:\Program Files\CyberLink\MagicSports\MagicSports.exe:CyberLink MagicSports
        "{8CFAF2DD-D6B4-41E9-B373-1C6B49139173}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
        "{E49364BE-2EBE-4F8B-B6E0-32A40E432BA8}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
        "{C705A4A7-F6A5-415C-8D18-E3001A85C5AC}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
        "{F5AD5918-9574-4D48-9D8E-E5399A4D533C}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
        "{FD936027-835B-4539-8FD8-A50F5A497A9B}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
        "{018C708D-40AA-4FA9-916D-BFA52C35EB7B}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
        "{D6569BFC-D3E9-48DC-B71E-DEA355445D1D}"= UDP:6346:shareaza
        "{C4A71E23-007E-49F4-A850-736927C79158}"= UDP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
        "{DEDD9646-106B-4137-9F01-E6CA4110A197}"= TCP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
        "{AADA4C36-1A50-4CB3-9849-FE83E28571C3}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
        "{116371E8-2265-4F1C-88D7-8D10C5E314C5}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
        "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

        R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-03-29 19:31]
        R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
        R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 19:32]
        R3 itecir;ITECIR Infrared Receiver;C:\Windows\system32\DRIVERS\itecir.sys [2007-01-08 13:38]
        R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-01-09 10:00]
        S3 Start BT in service;Start BT in service;C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2007-04-26 09:22]

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{235c17a3-e09e-11dc-93c4-00030d000001}]
        \shell\AutoRun\command - H:\188qsm.bat
        \shell\explore\Command - H:\188qsm.bat
        \shell\open\Command - H:\188qsm.bat

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3017a823-3318-11dd-b942-00030d000001}]
        \shell\AutoRun\command - G:\jfvkcsy.bat
        \shell\explore\Command - G:\jfvkcsy.bat
        \shell\open\Command - G:\jfvkcsy.bat

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6297ab85-e15b-11dc-9ebc-00030d000001}]
        \shell\AutoRun\command - H:\6l6w8.com
        \shell\explore\Command - H:\6l6w8.com
        \shell\open\Command - H:\6l6w8.com

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9c7d2022-dca5-11dc-a80e-00030d000001}]
        \shell\AutoRun\command - 3wcxx91.cmd
        \shell\explore\Command - 3wcxx91.cmd
        \shell\open\Command - 3wcxx91.cmd

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd527717-e3c4-11dc-86e4-00030d000001}]
        \shell\AutoRun\command - F:\SETUP.EXE
        \shell\configure\command - F:\SETUP.EXE
        \shell\install\command - F:\SETUP.EXE

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8571f94-edb2-11dc-8141-00030d000001}]
        \shell\AutoRun\command - H:\188qsm.bat
        \shell\explore\Command - H:\188qsm.bat
        \shell\open\Command - H:\188qsm.bat

        *Newly Created Service* - PROCEXP90
        .
        Contenu du dossier 'Scheduled Tasks/Tâches planifiées'

        2008-08-27 C:\Windows\Tasks\Extension de garantie.job
        - C:\Program Files\Packard Bell\SetupmyPC\PBCarNot.exe [2006-11-21 18:38]

        2008-08-27 C:\Windows\Tasks\Recovery DVD Creator.job
        - C:\Program Files\Packard Bell\SetupMyPc\MCDCheck.exe [2006-11-21 18:34]
        .
        - - - - ORPHANS REMOVED - - - -

        HKCU-Run-mtbhekk - c:\users\cocotte\appdata\local\mtbhekk.exe

        .
        ------- Supplementary Scan -------
        .
        FireFox -: Profile - C:\Users\Cocotte\AppData\Roaming\Mozilla\Firefox\Profiles\rp3fdx8w.default\
        FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
        FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
        .

        **************************************************************************

        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-08-28 01:14:44
        Windows 6.0.6000 NTFS

        Balayage processus cachés ...

        Balayage caché autostart entries ...

        Balayage des fichiers cachés ...

        Scan terminé avec succès
        Les fichiers cachés: 0

        **************************************************************************
        .
        Temps d'accomplissement: 2008-08-28 1:15:31
        ComboFix-quarantined-files.txt 2008-08-27 23:15:24

        Pre-Run: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
        Post-Run: 53,651,763,200 octets libres

        187 --- E O F --- 2008-08-27 09:13:33

        j'ai réactivé avast ça suffi pour la protection?
        1. ComboFix 08-08-27.01 - Cocotte 2008-08-28 1:13:19.1 - NTFSx86
          Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1797 [GMT 2:00]
          Endroit: C:\Users\Cocotte\Desktop\ComboFix.exe
          * Création d'un nouveau point de restauration
          .

          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .

          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware-Secure
          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Spyware-Secure trial.lnk
          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware-Secure\Website.lnk
          C:\Users\Cocotte\AppData\Local\mtbhekk.dat
          C:\Users\Cocotte\AppData\Local\mtbhekk.exe
          C:\Users\Cocotte\AppData\Local\mtbhekk_nav.dat
          C:\Users\Cocotte\AppData\Local\mtbhekk_navps.dat
          C:\Users\Cocotte\AppData\Roaming\Microsoft\Windows\Cookies\cocotte@serving-sys[2].txt

          .
          ((((((((((((((((((((((((((((( Fichiers créés 2008-07-27 to 2008-08-27 ))))))))))))))))))))))))))))))))))))
          .

          Pas de nouveau fichier créé dans cet espace de temps

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-08-27 22:56 --------- d-----w C:\Program Files\Navilog1
          2008-08-27 20:20 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
          2008-08-27 20:00 --------- d-----w C:\Program Files\Spybot - Search & Destroy
          2008-08-27 11:32 --------- d-----w C:\Users\Cocotte\AppData\Roaming\uTorrent
          2008-08-23 18:17 --------- d-----w C:\ProgramData\Roxio
          2008-08-22 18:03 --------- d-----w C:\ProgramData\Microsoft Help
          2008-08-20 14:21 --------- d-----w C:\Program Files\eMule
          2008-08-19 17:23 --------- d-----w C:\Users\Cocotte\AppData\Roaming\LimeWire
          2008-08-19 17:17 --------- d-----w C:\Program Files\LimeWire
          2008-08-17 11:02 --------- d-----w C:\Program Files\uTorrent
          2008-08-15 14:44 27,525 ----a-w C:\Users\Cocotte\AppData\Roaming\nvModes.dat
          2008-08-13 16:38 --------- d-----w C:\Program Files\Windows Mail
          2008-08-12 11:21 --------- d-----w C:\Program Files\Sun
          2008-08-12 11:20 --------- d-----w C:\Program Files\Java
          2008-08-08 20:47 --------- d-----w C:\Users\Cocotte\AppData\Roaming\dvdcss
          2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe
          2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll
          2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll
          2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll
          2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
          2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll
          2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
          2008-07-18 20:08 163,904 ----a-w C:\Windows\System32\wuwebv.dll
          2008-07-18 18:44 31,232 ----a-w C:\Windows\System32\wuapp.exe
          2008-07-15 23:48 2,048 ----a-w C:\Windows\System32\tzres.dll
          2008-07-14 11:30 --------- d-----w C:\ProgramData\Bluetooth
          2008-07-12 19:41 --------- d-----w C:\ProgramData\Lavasoft
          2008-07-12 19:40 --------- d-----w C:\Program Files\Lavasoft
          2008-07-12 19:39 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
          2008-07-09 14:11 174 --sha-w C:\Program Files\desktop.ini
          2008-06-29 18:15 --------- d-----w C:\Program Files\Picasa2
          2008-06-27 03:54 826,368 ----a-w C:\Windows\System32\wininet.dll
          2008-06-27 03:54 56,320 ----a-w C:\Windows\System32\iesetup.dll
          2008-06-27 03:54 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
          2008-06-27 03:54 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
          2008-06-26 00:34 7,964,672 ----a-w C:\Windows\System32\NlsLexicons0024.dll
          2008-06-26 00:33 9,892,864 ----a-w C:\Windows\System32\NlsLexicons000a.dll
          2008-06-19 03:25 61,440 ----a-w C:\Windows\System32\winipsec.dll
          2008-06-19 03:25 361,984 ----a-w C:\Windows\System32\IPSECSVC.DLL
          2008-06-19 03:25 28,672 ----a-w C:\Windows\System32\FwRemoteSvr.dll
          2008-06-19 03:25 272,896 ----a-w C:\Windows\System32\polstore.dll
          2008-06-12 06:54 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
          2008-06-12 06:54 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
          2008-06-12 01:21 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
          2008-04-02 17:15 216 ----a-w C:\Users\Cocotte\AppData\Roaming\wklnhst.dat
          2008-05-26 08:24 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
          2008-05-26 08:24 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
          2008-05-26 08:24 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
          .

          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "SmpcSys"="C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe" [2007-07-19 15:32 1120568]
          "MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
          "DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 15:08 136136]
          "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "JMB36X IDE Setup"="C:\Windows\RaidTool\xInsIDE.exe" [2007-03-20 23:36 36864]
          "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-24 00:40 857648]
          "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-08-16 22:19 86016]
          "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-08-16 22:19 8478720]
          "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-08-16 22:19 81920]
          "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-01-11 11:40 232184]
          "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-10-11 20:25 243200]
          "MSPService"="C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe" [2007-06-12 23:36 102400]
          "toolbar_eula_launcher"="C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 18:20 28672]
          "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 14:00 174872]
          "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
          "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 03:23 443968]

          C:\Users\Cocotte\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
          Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2008-03-03 20:41:35 3450608]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
          "EnableLUA"= 0 (0x0)

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
          "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
          "VIDC.YV12"= yv12vfw.dll

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
          "DisableMonitoring"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
          "DisableMonitoring"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
          "DisableMonitoring"=dword:00000001

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
          "{81A4C2FB-17A9-4AC1-A24B-DC4CA25B219F}"= C:\Program Files\CyberLink\MagicSports\MagicSports.exe:CyberLink MagicSports
          "{8CFAF2DD-D6B4-41E9-B373-1C6B49139173}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
          "{E49364BE-2EBE-4F8B-B6E0-32A40E432BA8}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
          "{C705A4A7-F6A5-415C-8D18-E3001A85C5AC}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
          "{F5AD5918-9574-4D48-9D8E-E5399A4D533C}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
          "{FD936027-835B-4539-8FD8-A50F5A497A9B}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
          "{018C708D-40AA-4FA9-916D-BFA52C35EB7B}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
          "{D6569BFC-D3E9-48DC-B71E-DEA355445D1D}"= UDP:6346:shareaza
          "{C4A71E23-007E-49F4-A850-736927C79158}"= UDP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
          "{DEDD9646-106B-4137-9F01-E6CA4110A197}"= TCP:C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe:BlueSoleil
          "{AADA4C36-1A50-4CB3-9849-FE83E28571C3}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
          "{116371E8-2265-4F1C-88D7-8D10C5E314C5}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
          "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

          R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-03-29 19:31]
          R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
          R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 19:32]
          R3 itecir;ITECIR Infrared Receiver;C:\Windows\system32\DRIVERS\itecir.sys [2007-01-08 13:38]
          R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-01-09 10:00]
          S3 Start BT in service;Start BT in service;C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [2007-04-26 09:22]

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{235c17a3-e09e-11dc-93c4-00030d000001}]
          \shell\AutoRun\command - H:\188qsm.bat
          \shell\explore\Command - H:\188qsm.bat
          \shell\open\Command - H:\188qsm.bat

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3017a823-3318-11dd-b942-00030d000001}]
          \shell\AutoRun\command - G:\jfvkcsy.bat
          \shell\explore\Command - G:\jfvkcsy.bat
          \shell\open\Command - G:\jfvkcsy.bat

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6297ab85-e15b-11dc-9ebc-00030d000001}]
          \shell\AutoRun\command - H:\6l6w8.com
          \shell\explore\Command - H:\6l6w8.com
          \shell\open\Command - H:\6l6w8.com

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9c7d2022-dca5-11dc-a80e-00030d000001}]
          \shell\AutoRun\command - 3wcxx91.cmd
          \shell\explore\Command - 3wcxx91.cmd
          \shell\open\Command - 3wcxx91.cmd

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dd527717-e3c4-11dc-86e4-00030d000001}]
          \shell\AutoRun\command - F:\SETUP.EXE
          \shell\configure\command - F:\SETUP.EXE
          \shell\install\command - F:\SETUP.EXE

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8571f94-edb2-11dc-8141-00030d000001}]
          \shell\AutoRun\command - H:\188qsm.bat
          \shell\explore\Command - H:\188qsm.bat
          \shell\open\Command - H:\188qsm.bat

          *Newly Created Service* - PROCEXP90
          .
          Contenu du dossier 'Scheduled Tasks/Tâches planifiées'

          2008-08-27 C:\Windows\Tasks\Extension de garantie.job
          - C:\Program Files\Packard Bell\SetupmyPC\PBCarNot.exe [2006-11-21 18:38]

          2008-08-27 C:\Windows\Tasks\Recovery DVD Creator.job
          - C:\Program Files\Packard Bell\SetupMyPc\MCDCheck.exe [2006-11-21 18:34]
          .
          - - - - ORPHANS REMOVED - - - -

          HKCU-Run-mtbhekk - c:\users\cocotte\appdata\local\mtbhekk.exe

          .
          ------- Supplementary Scan -------
          .
          FireFox -: Profile - C:\Users\Cocotte\AppData\Roaming\Mozilla\Firefox\Profiles\rp3fdx8w.default\
          FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
          FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
          .

          **************************************************************************

          catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-08-28 01:14:44
          Windows 6.0.6000 NTFS

          Balayage processus cachés ...

          Balayage caché autostart entries ...

          Balayage des fichiers cachés ...

          Scan terminé avec succès
          Les fichiers cachés: 0

          **************************************************************************
          .
          Temps d'accomplissement: 2008-08-28 1:15:31
          ComboFix-quarantined-files.txt 2008-08-27 23:15:24

          Pre-Run: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
          Post-Run: 53,651,763,200 octets libres

          187 --- E O F --- 2008-08-27 09:13:33

          j'ai réactivé avast ça suffi pour la protection?
          1. Modérateur
            Tu as été infecter également par un périphérique infecté genre clé USB, baladeur mp3, disque dur externe,...

            Je ne sais pas si le tool suivant fonctionne avec Vista donc tu me dis s'il ne fonctionne pas :

            - Télécharge RavAntivirus d'Evosla sur ton bureau :
            http://ww25.evosla.com/compteur.php?soft=rav_antivirus

            - Branche tes disques amovibles à ton PC (clefs USB, disque dur externe, etc...) sans les ouvrir avant de lancer le fix

            - Clique droit sur le fichier rav.zip, puis "Extraire Ici".

            - Doucle-clique sur "rav.exe" pour lancer le fix.

            - Laisse le programme agir : il scanne automatiquement tous les lecteurs (disques fixes et amovibles)

            - En cas d'infections un rapport sera généré : poste-le dans ta prochaine réponse stp.

            - Ensuite : retire tes disques amovibles et redémarre le PC.
            1. c bon le scan est en cours
              dsl c un peu lon je ne sais pas combien de temps ça peu prendre mai surtout ne part pas sinon je serai complètement perdu

              merci pour ton aide c'est sympa de nous aider, nous les "pas très bon en informatique" ;)
              1. ben il continu a scané il y a une barre bleu qui bouge en bas de gaucha à droite alors je suppose qu'il scan toujours !
                enfin je pense :s
                1. Modérateur
                  "O4 - HKCU\..\Run: [mtbhekk] "c:\users\cocotte\appdata\local\mtbhekk.exe" mtbhekk"

                  ---> Cette infection se traite avec Navilog1. Comme Navilog1 n'a pas fonctionné, je t'ai fait utililser ComboFix qui a vu et supprimer l'infection :

                  (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))

                  [...]
                  C:\Users\Cocotte\AppData\Local\mtbhekk.dat
                  C:\Users\Cocotte\AppData\Local\mtbhekk.exe
                  C:\Users\Cocotte\AppData\Local\mtbhekk_nav.dat
                  C:\Users\Cocotte\AppData\Local\mtbhekk_navps.dat

                  ComboFix a révélé une autre infection, celle que Rav traite.
                  1. alors je fait quoi maintenant parce que RAV est en train de scanner depuis 30 minutes et je ne sais pa si c'est normal
                    il ma supprimé 2 virus au début et depuis plus rien
                    est ce que je doit attendre?
                    1. Modérateur
                      Quitte Rav. Je vais te faire un script.
                      1. ok g lancé navilog1
                        g tapé f
                        puis entré
                        puis g tapé 1
                        et j'attend le rapport
                      2. Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 03:30:15, on 28/08/2008
                        Platform: Windows Vista (WinNT 6.00.1904)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16711)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                        C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
                        C:\Windows\ehome\ehtray.exe
                        C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
                        C:\Windows\ehome\ehmsas.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
                        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Windows\system32\conime.exe
                        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                        C:\Windows\system32\SearchFilterHost.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        R3 - URLSearchHook: IE Toolbar - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                        O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                        O3 - Toolbar: IE Toolbar - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
                        O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
                        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                        O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                        O4 - HKLM\..\Run: [MSPService] C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                        O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                        O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                        O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                        O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
                        O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
                        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                        O13 - Gopher Prefix:
                        O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://topachat.pixawin.com/ImageUploader4.cab
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                        O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                        O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                        O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
                        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                      3. dsl pour hier j'ai installé le programme que tu m'a demandé mais comme c'était super long et que je pensais que je n'arrivai plus a recevoir tes messages je me suis endormi, c'était un peu tard comm horaire pour moi.

                        enfin bref, le programme a fini par s'installé avec succès et je voulais savoir si tu était toujours d'accord pour m'aider a finir les opération nécessaire

                        merci d'avance,

                        et merci pour le temps que tu m'a déjà consacé hier soir :)
                      4. Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 21:57:15, on 28/08/2008
                        Platform: Windows Vista SP1 (WinNT 6.00.1905)
                        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\Explorer.EXE
                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                        C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
                        C:\Windows\ehome\ehtray.exe
                        C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
                        C:\Windows\System32\rundll32.exe
                        C:\Windows\ehome\ehmsas.exe
                        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                        C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
                        C:\Windows\system32\conime.exe
                        C:\Windows\System32\wsqmcons.exe
                        C:\Program Files\Internet Explorer\IEUser.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                        C:\Windows\system32\Macromed\Flash\FlashUtil9e.exe
                        C:\Windows\system32\SearchFilterHost.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                        C:\Windows\system32\DllHost.exe
                        c:\program files\google\googletoolbar1user.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        R3 - URLSearchHook: IE Toolbar - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll (file missing)
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                        O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                        O3 - Toolbar: IE Toolbar - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll (file missing)
                        O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
                        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                        O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                        O4 - HKLM\..\Run: [MSPService] C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                        O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                        O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                        O4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"
                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
                        O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
                        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                        O13 - Gopher Prefix:
                        O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://topachat.pixawin.com/ImageUploader4.cab
                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                        O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                        O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                        O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
                        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

                        --
                        End of file - 8884 bytes
                        ___________________________________
                    • 1
                    • 2
                    • 3