Spyware tenace. Help please!

Résolu
Bonjour,

j'aimerais si possible de l'aide concernant un spyware qui ne cesse de revenir à la charge environ toutes les 10 minutes sur mon ordi. Le message varie un peu, mais l'intitulé de départ est toujours le même:
"Windows Security Alert
To help protect your computer, Windows Firewall has detected activity of harmful software.
Do you want to block this software from sending data over the internet?"
Ad aware le détecte, le vire, mais il revient sans arrêt ;)

Je vous remercie par avance.
Configuration: Windows XP
Internet Explorer 6.0

17 réponses

Résumé de la discussion

Une infection spyware sur Windows XP déclenche régulièrement l’alerte 'Windows Security Alert' et réapparaît environ toutes les dix minutes malgré les tentatives de suppression. Ad-Aware le détecte et le supprime, mais le malware revient et des outils comme HijackThis et Malwarebytes révèlent des trojans et un ensemble d'éléments persistants. Les tests mentionnent des scans ciblés, la désinfection via HijackThis et les rapports de logs, et parfois l'usage de SDFix, puis la suppression manuelle des entrées et services. Pour les utilisateurs, des éléments ajoutés au démarrage et des services tiers proposés par des programmes comme Lexmark, Daemon Tools et MySpace IM ont été signalés comme possibles vecteurs, nécessitant une revue exhaustive des autorisations.

Bobot (l’IA à votre service)
  1. bonjour
    Commence par poster un rapport HijackThis stp,
    >Télécharge HiJackThis : http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis
    - Lance le programme, puis sélectionne < do a system scan and save a logfile >
    - Enregistre le rapport sur ton bureau.
    Et envoie, par copier/coller, ton log Hijackthis sur le forum,

    A+

    Tuto : si problème : http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
    0
    1. Merci beacoup!

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 16:18:07, on 18/09/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\WINDOWS\Explorer.EXE
      C:\Documents and Settings\All Users\Application Data\xwlqhwxs\fgvufiba.exe
      C:\WINDOWS\system32\MAFWTray.exe
      C:\Program Files\D-Tools\daemon.exe
      C:\PROGRA~1\DAP\DAP.EXE
      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
      C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\WINDOWS\TBPanel.exe
      C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
      C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\MySpace\IM\MySpaceIM.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\WINDOWS\system32\twvmrihq.exe
      C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\MySpace\IM\MySpaceIM.exe
      C:\WINDOWS\system32\lxdicoms.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Steinberg\Nuendo 3\Nuendo3.exe
      C:\PROGRA~1\SYNCRO~1\POS\SYNSOPOS.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Outlook Express\msimn.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\twvmrihq.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.football365.fr/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\DAP\DAPBHO.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\system32\MAFWTray.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
      O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A
      O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
      O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
      O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [shapiwin] C:\WINDOWS\system32\twvmrihq.exe
      O4 - HKLM\..\Policies\Explorer\Run: [uHQS0WalKk] C:\Documents and Settings\All Users\Application Data\xwlqhwxs\fgvufiba.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
      O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
      O21 - SSODL: uiwinset - {5F63355F-8787-FB5E-0DC7-0066D6F55A5E} - C:\Program Files\ukyclnc\uiwinset.dll
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
      O23 - Service: lxdi_device - - C:\WINDOWS\system32\lxdicoms.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      0
      1. effectivement

        Fais un scan avec cet antispyware :

        Telecharge malwarebytes + tutoriel :

        -> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

        Tu l´instale; le programme va se mettre automatiquement a jour.

        Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

        Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

        Puis click sur "rechercher".

        Laisse le scanner le pc...

        Si des elements on ete trouvés > click sur supprimer la selection.

        si il t´es demandé de redemarrer > click sur "yes".

        A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

        Copie et colle le rapport stp.
        0
    2. Désolé, c'est long ;)
      je poste le rapport dès qu'il a fini de balayer mon système.
      0
      1. y a pas de soucis...
        surtout n oublies pas de supprimer les infections si trouvees
        a+
        0
    3. OuF, voilà, il a mis le temps. Mon ordi était vérolé comme pas permis apparemment, pourtant j'ai ad aware 2008 et antivir, le dernier n'étant pas considéré comme une passoire me semble-t-il. Et je contrôle tous les jours les rootkit.
      Enfin bon, voilà le rapport:

      Malwarebytes' Anti-Malware 1.28
      Version de la base de données: 1168
      Windows 5.1.2600 Service Pack 2

      18/09/2008 19:23:44
      mbam-log-2008-09-18 (19-23-44).txt

      Type de recherche: Examen complet (C:\|D:\|E:\|)
      Eléments examinés: 248845
      Temps écoulé: 2 hour(s), 46 minute(s), 49 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 21
      Valeur(s) du Registre infectée(s): 4
      Elément(s) de données du Registre infecté(s): 1
      Dossier(s) infecté(s): 3
      Fichier(s) infecté(s): 64

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      HKEY_CLASSES_ROOT\CLSID\{5F63355F-8787-FB5E-0DC7-0066D6F55A5E} (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9dd4258a-7138-49c4-8d34-587879a5c7a4} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b8c0220d-763d-49a4-95f4-61dfdec66ee6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c3bcc488-1ae7-11d4-ab82-0010a4ec2338} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000000da-0786-4633-87c6-1aa7a4429ef1} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\dpcproxy (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\HOL5_VXIEWER.FULL.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Classes\applications\accessdiver.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\fwbd (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\HolLol (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Inet Delivery (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mslagent (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Golden Palace Casino NEW (Trojan.DNSChanger) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\iTunesMusic (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SYSTEM\currentcontrolset\Services\rdriv (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\wkey (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\mwc (Malware.Trace) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\uiwinset (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\shapiwin (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\uhqs0walkk (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SystemCheck2 (Trojan.Agent) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

      Dossier(s) infecté(s):
      C:\WINDOWS\mslagent (Adware.EGDAccess) -> Quarantined and deleted successfully.
      C:\Program Files\akl (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\smp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.

      Fichier(s) infecté(s):
      C:\Program Files\ukyclnc\uiwinset.dll (Trojan.FakeAlert.H) -> Delete on reboot.
      C:\WINDOWS\system32\twvmrihq.exe (Trojan.FakeAlert.H) -> Delete on reboot.
      C:\Documents and Settings\All Users\Application Data\xwlqhwxs\fgvufiba.exe (Trojan.FakeAlert.H) -> Delete on reboot.
      D:\System Volume Information\_restore{35942FD5-8FED-4B17-BE02-0CB4308B82FC}\RP148\A0023502.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
      C:\WINDOWS\mslagent\2_mslagent.dll (Adware.EGDAccess) -> Quarantined and deleted successfully.
      C:\WINDOWS\mslagent\mslagent.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
      C:\WINDOWS\mslagent\uninstall.exe (Adware.EGDAccess) -> Quarantined and deleted successfully.
      C:\Program Files\akl\akl.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\Program Files\akl\akl.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\Program Files\akl\uninstall.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\Program Files\akl\unsetup.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\smp\msrc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\a.bat (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\base64.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\FVProtect.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\userconfig9x.dll (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\winsystem.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\zip1.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\zip2.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\zip3.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\zipped.tmp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
      C:\WINDOWS\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\iTunesMusic.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\akttzn.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\anticipator.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\awtoolb.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\bdn.com (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\bsva-egihsg52.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\dpcproxy.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\h@tkeysh@@k.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\hoproxy.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\hxiwlgpm.dat (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\hxiwlgpm.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\msgp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\msnbho.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\mssecu.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\msvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\mtr2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\mwin32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\netode.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\newsd32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ps1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\psof1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\psoft1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\regc64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\regm64.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\Rundl1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\sncntr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ssurf022.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ssvchost.com (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ssvchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\sysreq.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\taack.dat (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\taack.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\temp#01.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\thun.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\thun32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\VBIEWER.OCX (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\vcatchpi.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\winlogonpc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\winsystem.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\WINWGPX.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\vbsys2.dll (Trojan.Clicker) -> Quarantined and deleted successfully.
      0
      1. Je viens de relancer un examen rapide par malwarebytes, et antivr trouve régulièrement des trojans, et bloque malwarebytes le temps que je supprime les données infectées. C'est bizarre, j'avais pas eu de probleme de cet ordre avant.
        En tous les cas, merci beaucoup, je n'ai plus l'alerte, et malwarebytes me dit qu'il n'y a plus de probleme rencontré. Je ne comprends pas bien pourquoi d'un seul coup tout s'est emballé, mais bon, au moins, c'est supprimé...
        0
        1. t emballes pas...
          ton pc est toujours tres infecté....
          va ds la quarantaine de MAMB et supprime tout...
          ensuite fait ceci

          Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
          http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
          Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
          • Redémarre ton ordinateur
          • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
          • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
          • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
          • Choisis ton compte.
          Déroule la liste des instructions ci-dessous :
          • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
          • Appuie sur Y pour commencer le processus de nettoyage.
          • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
          • Appuie sur une touche pour redémarrer le PC.
          • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
          • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
          • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
          • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
          • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum
          0
      2. bonjour hola ton ordinateur étai super infecter :o pu d erreur ?
        0
        1. non, c'est bon maintenant, merci ;)
          0
          1. oki
            Clé(s) du Registre infectée(s): 21
            Valeur(s) du Registre infectée(s): 4
            Elément(s) de données du Registre infecté(s): 1
            Dossier(s) infecté(s): 3
            Fichier(s) infecté(s): 64
            64fichier infecter ses dega baeucoup et
            21 cle du registre je comprenez les erreur^^
            0
            1. et oui, je me demande comment j'ai pu être infecté à ce point en aussi peu de temps. Strange.
              0
              1. fait ce que je dis post: 11
                t en est pas encore sorti!!!!!!
                a+
                0
            2. OK, j'avais pas vu, j'y cours.
              0
              1. Bon déjà, je suppose qu'il n'y a rien en quarantaine, puisqu'il y a n'y a pas de dossier quarantaine dans mon fichier malwarebytes.
                Ensuite, je lance sdfix, antivir me trouve un trojan dedans: restartit.exe is the TR/Crypt.xpack.gEN tROJAN
                0
                1. ok
                  j attends ton rapport

                  saches que sd fix detecteente autres les trojans!!!!!!
                  a+
                  0
              2. Alors voici le rapport. Quand je parlais de restartit, qui est compris dans SDfix, il est considéré comme un trojan par antivir, c'est pour cette raison que je le soulignais ;)

                [b]SDFix: Version 1.226 [/b]
                Run by farewell on 18/09/2008 at 21:00

                Microsoft Windows XP [version 5.1.2600]
                Running From: C:\SDFix

                [b]Checking Services [/b]:

                Restoring Default Security Values
                Restoring Default Hosts File

                Rebooting

                [b]Checking Files [/b]:

                No Trojan Files Found

                Removing Temp Files

                [b]ADS Check [/b]:

                [b]Final Check [/b]:

                catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-09-18 21:05:54
                Windows 5.1.2600 Service Pack 2 NTFS

                scanning hidden processes ...

                scanning hidden services & system hive ...

                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40]
                "khjeh"=hex:20,02,00,00,7d,a8,2b,fd,80,c7,02,4d,35,ff,46,00,86,b1,10,cc,ad,..
                "hj34z0"=hex:62,54,8c,9b,8a,a3,50,74,90,ed,07,b8,39,7e,8e,e1,2f,89,93,09,a7,..

                scanning hidden registry entries ...

                scanning hidden files ...

                scan completed successfully
                hidden processes: 0
                hidden services: 0
                hidden files: 0

                [b]Remaining Services [/b]:

                Authorized Application Key Export:

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
                "C:\\Program Files\\ABC\\abc.exe"="C:\\Program Files\\ABC\\abc.exe:*:Enabled:abc"
                "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
                "C:\\WINDOWS\\system32\\lxdicoms.exe"="C:\\WINDOWS\\system32\\lxdicoms.exe:*:Enabled:Lexmark Communications System"
                "C:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"="C:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe:*:Enabled:Lexmark Device Monitor"
                "C:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"="C:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe:*:Enabled:Lexmark Imaging Studio"
                "C:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"="C:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe:*:Enabled:ABBYY FineReader"
                "C:\\Program Files\\Lexmark Fax Solutions\\FaxCtr.exe"="C:\\Program Files\\Lexmark Fax Solutions\\FaxCtr.exe:*:Enabled:Fax software"
                "C:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"="C:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe:*:Enabled:Device Monitor"
                "C:\\Documents and Settings\\farewell\\Local Settings\\Temp\\lxdi\\wireless\\FRENCH\\lxdiwpss.exe"="C:\\Documents and Settings\\farewell\\Local Settings\\Temp\\lxdi\\wireless\\FRENCH\\lxdiwpss.exe:*:Enabled: "
                "C:\\WINDOWS\\system32\\lxdicfg.exe"="C:\\WINDOWS\\system32\\lxdicfg.exe:*:Enabled:Printer Communication System"
                "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe:*:Enabled:Printer Status Window Interface"
                "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe:*:Enabled:Lexmark Connect Time Executable"
                "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdijswx.exe"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdijswx.exe:*:Enabled:Job Status Window Interface"
                "E:\\jeux\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe"="E:\\jeux\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)"
                "E:\\jeux\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe"="E:\\jeux\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe:*:Enabled:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)"
                "C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"="C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe:*:Enabled:MySpaceIM"

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
                "C:\\Program Files\\Lexmark 3500-4500 Series\\app4r.exe"="C:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe:*:Enabled:Lexmark Imaging Studio"

                [b]Remaining Files [/b]:

                [b]Files with Hidden Attributes [/b]:

                Mon 15 Sep 2008 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
                Fri 27 Apr 2007 23,040 ...H. --- "C:\Documents and Settings\farewell\Bureau\~WRL0004.tmp"
                Fri 27 Apr 2007 25,600 ...H. --- "C:\Documents and Settings\farewell\Bureau\~WRL0214.tmp"
                Fri 27 Apr 2007 27,648 ...H. --- "C:\Documents and Settings\farewell\Bureau\~WRL1528.tmp"
                Fri 27 Apr 2007 24,064 ...H. --- "C:\Documents and Settings\farewell\Bureau\~WRL1634.tmp"
                Fri 27 Apr 2007 28,672 ...H. --- "C:\Documents and Settings\farewell\Bureau\~WRL2443.tmp"
                Fri 27 Apr 2007 27,136 ...H. --- "C:\Documents and Settings\farewell\Bureau\~WRL3594.tmp"
                Fri 27 Apr 2007 23,552 ...H. --- "C:\Documents and Settings\farewell\Application Data\Microsoft\Word\~WRL1428.tmp"

                [b]Finished![/b]
                0
                1. fait ceci maintenant
                  ---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
                  http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                  /!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

                  ---> Double-clique sur Combofix.exe
                  Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
                  Accepte en cliquant sur "Oui"

                  ---> Mets-le en langue française F
                  Tape sur la touche 1 (Yes) pour démarrer le scan.

                  /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

                  En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

                  Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

                  /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

                  Note : Le rapport se trouve également là : C:\ComboFix.txt
                  0
              3. et voila

                ComboFix 08-09-16.05 - farewell 2008-09-18 21:43:46.1 - NTFSx86
                Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1579 [GMT 2:00]
                Lancé depuis: D:\installs\utilitaires\MALWARE\ComboFix.exe
                * Un nouveau point de restauration a été créé

                [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                .

                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                .

                C:\Documents and Settings\farewell\Cookies\farewell@ad.yieldmanager[3].txt
                C:\Documents and Settings\farewell\Cookies\farewell@ad.yieldmanager[6].txt
                C:\Documents and Settings\farewell\Cookies\farewell@bluestreak[3].txt
                C:\Documents and Settings\farewell\Cookies\farewell@bluestreak[4].txt
                C:\Documents and Settings\farewell\Cookies\farewell@bluestreak[6].txt
                C:\Documents and Settings\farewell\Cookies\farewell@edt02[1].txt
                C:\Documents and Settings\farewell\Cookies\farewell@edt02[2].txt
                C:\Documents and Settings\farewell\Cookies\farewell@ehg-dig.hitbox[1].txt
                C:\Documents and Settings\farewell\Cookies\farewell@forum.ncix[2].txt
                C:\Documents and Settings\farewell\Cookies\farewell@msn[1].txt
                C:\Documents and Settings\farewell\Cookies\farewell@myspace[7].txt
                C:\Documents and Settings\farewell\Cookies\farewell@secure.ncix[2].txt
                C:\Documents and Settings\farewell\Cookies\farewell@tracker.affistats[2].txt
                C:\Documents and Settings\farewell\Cookies\farewell@vote[1].txt
                C:\Documents and Settings\farewell\Cookies\farewell@vote[2].txt
                C:\Documents and Settings\farewell\Cookies\farewell@www.solostocks[2].txt

                .
                ((((((((((((((((((((((((((((( Fichiers créés du 2008-08-18 au 2008-09-18 ))))))))))))))))))))))))))))))))))))
                .

                2008-09-18 20:54 . 2008-09-18 20:54 268 --ah----- C:\sqmdata14.sqm
                2008-09-18 20:54 . 2008-09-18 20:54 244 --ah----- C:\sqmnoopt14.sqm
                2008-09-18 20:41 . 2008-09-18 20:41 578,048 --a--c--- C:\WINDOWS\system32\dllcache\user32.dll
                2008-09-18 20:38 . 2008-09-18 20:39 <REP> d-------- C:\WINDOWS\ERUNT
                2008-09-18 20:20 . 2008-09-18 21:08 <REP> d-------- C:\SDFix
                2008-09-18 16:29 . 2008-09-18 16:29 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                2008-09-18 16:29 . 2008-09-18 16:29 <REP> d-------- C:\Documents and Settings\farewell\Application Data\Malwarebytes
                2008-09-18 16:29 . 2008-09-18 16:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                2008-09-18 16:29 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
                2008-09-18 16:29 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                2008-09-18 15:59 . 2008-09-18 15:59 <REP> d-------- C:\Program Files\Trend Micro
                2008-09-18 13:18 . 2008-09-18 19:26 <REP> d-------- C:\Program Files\ukyclnc
                2008-09-18 13:18 . 2008-09-18 19:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\xwlqhwxs
                2008-09-15 16:09 . 2008-09-15 16:09 <REP> d-------- C:\Program Files\Fichiers communs\Native Instruments
                2008-09-15 14:08 . 2008-09-15 14:08 <REP> d-------- C:\Program Files\Fichiers communs\KORG
                2008-09-15 14:01 . 2008-09-15 14:01 <REP> d-------- C:\Korg Legacy Collection Digital Edition Standalone Vsti Rtas v1.0Iso-h2O
                2008-09-15 12:00 . 2008-09-17 16:30 3,532 --a------ C:\drmHeader.bin
                2008-09-04 21:14 . 2008-09-04 21:14 <REP> d-------- C:\Program Files\Sun

                .
                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2008-09-18 17:21 --------- d-----w C:\Program Files\eMule
                2008-09-15 14:09 --------- d-----w C:\Program Files\Native Instruments
                2008-09-04 19:14 --------- d-----w C:\Program Files\Java
                2008-09-04 18:05 --------- d-----w C:\Program Files\NOS
                2008-09-04 18:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\NOS
                2008-07-30 10:48 --------- d-----w C:\Documents and Settings\farewell\Application Data\AdobeUM
                2008-07-29 17:56 --------- d-----w C:\Program Files\Fichiers communs\Adobe AIR
                2008-07-29 17:56 --------- d-----w C:\Program Files\Fichiers communs\Adobe
                2008-07-29 17:54 --------- d-----w C:\Program Files\Google
                2008-07-28 12:24 --------- d-----w C:\Program Files\Spectrasonics
                2008-07-27 23:32 --------- d-----w C:\Program Files\Lavasoft
                2008-07-27 23:31 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
                2008-07-27 23:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
                2008-07-20 22:18 --------- d--h--r C:\Documents and Settings\farewell\Application Data\SecuROM
                2008-07-04 18:39 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
                2007-01-02 12:29 1,808 ----a-w C:\Program Files\uninstal.log
                .

                ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                REGEDIT4

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-19 8720384]
                "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "MAFWTaskbarApp"="C:\WINDOWS\system32\MAFWTray.exe" [2004-12-20 151552]
                "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
                "DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 81920]
                "DownloadAccelerator"="C:\PROGRA~1\DAP\DAP.EXE" [2007-01-02 1139712]
                "ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-06-16 221184]
                "ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
                "H2O"="C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe" [2005-11-01 307200]
                "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-17 266497]
                "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-11 413696]
                "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
                "Gainward"="C:\WINDOWS\TBPanel.exe" [2007-11-01 2185768]
                "lxdimon.exe"="C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe" [2007-07-16 434864]
                "lxdiamon"="C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe" [2007-07-16 25264]
                "FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2007-07-16 311984]
                "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 13529088]
                "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-03 86016]
                "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
                "nwiz"="nwiz.exe" [2008-05-03 C:\WINDOWS\system32\nwiz.exe]

                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 15360]
                "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2007-12-19 8720384]

                C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                Acrobat Assistant.lnk - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-05-15 217193]
                Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2007-01-02 113664]
                Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]

                [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                "AntiVirusDisableNotify"=dword:00000001
                "UpdatesDisableNotify"=dword:00000001

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                "EnableFirewall"= 0 (0x0)

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                "%windir%\\system32\\sessmgr.exe"=
                "C:\\Program Files\\eMule\\emule.exe"=
                "C:\\Program Files\\ABC\\abc.exe"=
                "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                "C:\\WINDOWS\\system32\\lxdicoms.exe"=
                "C:\\Program Files\\Lexmark 3500-4500 Series\\lxdiamon.exe"=
                "C:\\Program Files\\Lexmark 3500-4500 Series\\App4R.exe"=
                "C:\\Program Files\\Abbyy FineReader 6.0 Sprint\\Scan\\ScanMan6.exe"=
                "C:\\Program Files\\Lexmark Fax Solutions\\FaxCtr.exe"=
                "C:\\Program Files\\Lexmark 3500-4500 Series\\lxdimon.exe"=
                "C:\\WINDOWS\\system32\\lxdicfg.exe"=
                "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdipswx.exe"=
                "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxditime.exe"=
                "C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxdijswx.exe"=
                "E:\\jeux\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe"=
                "E:\\jeux\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe"=
                "C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=

                R2 lxdi_device;lxdi_device;C:\WINDOWS\system32\lxdicoms.exe [2007-06-11 517040]
                R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 33792]
                R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN51.SYS [2005-03-22 28672]
                S2 lxdiCATSCustConnectService;lxdiCATSCustConnectService;C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe [2007-06-11 99248]
                S3 Usblink;Usblink Driver;C:\WINDOWS\system32\Drivers\ulink.sys [2003-06-02 40060]

                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
                \Shell\AutoRun\command - E:\setupSNK.exe

                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
                \Shell\AutoRun\command - G:\Setup.exe

                *Newly Created Service* - PROCEXP90
                .
                - - - - ORPHELINS SUPPRIMES - - - -

                Notify-AtiExtEvent - (no file)

                .
                ------- Examen supplémentaire -------
                .
                R0 -: HKCU-Main,Start Page = hxxp://www.football365.fr/
                O8 -: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
                O8 -: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
                O18 -: Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\PROGRA~1\DAP\dapie.dll
                O18 -: Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\PROGRA~1\DAP\dapie.dll
                O18 -: Name-Space Handler: HTTPS\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - C:\PROGRA~1\DAP\dapie.dll

                O16 -: DirectAnimation Java Classes - file://C:\WINDOWS\Java\classes\dajava.cab
                C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd

                O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
                C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
                .

                **************************************************************************

                catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-09-18 21:45:14
                Windows 5.1.2600 Service Pack 2 NTFS

                Recherche de processus cachés ...

                Recherche d'éléments en démarrage automatique cachés ...

                Recherche de fichiers cachés ...

                Scan terminé avec succès
                Fichiers cachés: 0

                **************************************************************************
                .
                Heure de fin: 2008-09-18 21:46:11
                ComboFix-quarantined-files.txt 2008-09-18 19:45:57

                Avant-CF: 60,996,698,112 octets libres
                AprŠs-CF: 61,374,164,992 octets libres

                165
                0
                1. ok
                  refait 1 scan hijajack stp
                  a+
                  0
              4. Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 21:59:29, on 18/09/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                C:\WINDOWS\system32\lxdicoms.exe
                C:\WINDOWS\system32\nvsvc32.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\notepad.exe
                C:\WINDOWS\system32\MAFWTray.exe
                C:\Program Files\D-Tools\daemon.exe
                C:\PROGRA~1\DAP\DAP.EXE
                C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                C:\WINDOWS\TBPanel.exe
                C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
                C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
                C:\Program Files\MySpace\IM\MySpaceIM.exe
                C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
                C:\Program Files\MySpace\IM\MySpaceIM.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\WINDOWS\system32\notepad.exe
                C:\WINDOWS\explorer.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.football365.fr/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\DAP\DAPBHO.dll
                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
                O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\system32\MAFWTray.exe
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
                O4 - HKLM\..\Run: [DownloadAccelerator] C:\PROGRA~1\DAP\DAP.EXE /STARTUP
                O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A
                O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
                O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
                O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
                O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
                O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
                O23 - Service: lxdi_device - - C:\WINDOWS\system32\lxdicoms.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                0
                1. reprend hijackthis
                  et selectionne do a scan only
                  et fixe cette ligne
                  O2 - BHO: DAPHelper Class - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:\Program Files\DAP\DAPBHO.dll
                  a+
                  0
              5. c'est fait
                0
                1. re hiujack stp
                  0
              6. Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 22:37:17, on 18/09/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\MAFWTray.exe
                C:\Program Files\D-Tools\daemon.exe
                C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                C:\WINDOWS\TBPanel.exe
                C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
                C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                C:\WINDOWS\system32\RUNDLL32.EXE
                C:\Program Files\MySpace\IM\MySpaceIM.exe
                C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                C:\WINDOWS\system32\lxdicoms.exe
                C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
                C:\WINDOWS\system32\nvsvc32.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\MySpace\IM\MySpaceIM.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Program Files\ABC\abc.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.football365.fr/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
                O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\system32\MAFWTray.exe
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
                O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A
                O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
                O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
                O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
                O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
                O23 - Service: lxdi_device - - C:\WINDOWS\system32\lxdicoms.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                0
                1. Bon apparemment, je suis sauvé! ;) Merci mille fois pour ton aide archet9, tu m'as tiré une belle épine du pied là.
                  @ plus
                  0
                  1. de rien....
                    je vins de regarder to dernier scan hijajck

                    tout est net....
                    met le topic en resolu stp...
                    en haut a droite acote du titre de ton pemier message
                    a+
                    0