Encore le fameux virus win32

Bonjour,
je suis egalement touché par ce fichu Win 32... avast me lance tous les quarts d'heure une alerte pour plusieurs virus qui commence par win 32 ... j'ai redémarrer mon système via mes 10 CD de relance mais rien n'y fait, le virus survit!!!
j'y connais pas grand chose, et j'ai beau lire tous les forums qui parle de ce virus, je ne trouve pas de solution...
Si quelqu'un peut me filer ce fameux coup de main qui en a aidé plus d'un, je l'embrasserais virtuellement de tout mon cœur!!!!
Merci a tous.
Yoniboko
Configuration: Windows XP
Firefox 3.0.3

29 réponses

Résumé de la discussion

Problème récurrent lié à un message Win32 détecté par Avast et à des alertes fréquentes sur plusieurs virus, alors que Windows XP et Avast restent inopérants malgré redémarrages et tentatives de nettoyage. Des analyses complémentaires montrent une activité malveillante; Malwarebytes Anti-Malware a détecté et supprimé 24 fichiers Trojan.Vundo, et a isolé une entrée du registre associée pour prévenir des réinfections. Par ailleurs, les échanges soulignent que redémarrer Avast ou relancer un scan peut être insuffisant et que Combofix nécessite une approche prudente, les téléchargements pouvant afficher des icônes trompeuses. En revanche, l’expérience montre l’importance d’utiliser des outils fiables et d’étapes de désinfection structurées, notamment en isolant le système et en sauvegardant les données pour éviter les réinfections.

Bobot (l’IA à votre service)
  1. voila...pour le rapport:

    Logfile of HijackThis v1.99.1
    Scan saved at 01:30:29, on 16/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
    C:\Program Files\HP\QuickPlay\QPService.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
    C:\Program Files\BitComet\BitComet.exe
    C:\Program Files\Webteh\BSplayerPro\bsplayer.exe
    C:\Documents and Settings\Yoni Félix Boukobza\Bureau\Nouveau dossier\hijackthis_199\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www8.hp.com/fr/fr/home.html
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [ecf1c42c] rundll32.exe "C:\WINDOWS\system32\mnpsaqks.dll",b
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
    O20 - AppInit_DLLs: bczrrv.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    0
    1. bobonne, je crois pas que redemarrer avast ou en relancer un nouveau changera quoi que ce soit... j'ai deja tout reinitialiser... maintenant j'espere que Destrio saura analyser ce rapport ( perso je n'y comprends absolument rien.. c'est du chinois pour moi...) merci pour vos reponses rapides.
      Yoniboko
      0
      1. Destrio lorsque je telecharge Combofix, l'application telechargé est un icone rouge avec un espece de tigre dessus... ce n'est pas un .exe si je demarre cette appli, une toute petite barre de techargement s'ouvre et rien ne se passe...
        C'est normal.?
        0
        1. voici le rapport combofix merci de me dire ce qu'il en est...
          ComboFix 08-10-15.05 - Yoni Félix Boukobza 2008-10-16 1:53:32.1 - NTFSx86
          Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.520 [GMT 2:00]
          Lancé depuis: C:\Documents and Settings\Yoni Félix Boukobza\Bureau\ComboFix.exe
          * Un nouveau point de restauration a été créé

          [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
          .

          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .

          C:\WINDOWS\system32\bczrrv.dll
          C:\WINDOWS\system32\bnjpgavp.dll
          C:\WINDOWS\system32\cbXOGVon.dll
          C:\WINDOWS\system32\fjwwtcue.dll
          C:\WINDOWS\system32\ionjqo.dll
          C:\WINDOWS\system32\jiaifrac.dll
          C:\WINDOWS\system32\lwkgmc.dll
          C:\WINDOWS\system32\mnpsaqks.dll
          C:\WINDOWS\system32\noVGOXbc.ini
          C:\WINDOWS\system32\noVGOXbc.ini2
          C:\WINDOWS\system32\qvdwgido.ini
          C:\WINDOWS\system32\rexygxwl.dll
          C:\WINDOWS\system32\skqaspnm.ini
          C:\WINDOWS\system32\tcyxwlsl.dll
          C:\WINDOWS\system32\xxyyxvuU.dll
          D:\Autorun.inf
          D:\host.exe

          .
          ((((((((((((((((((((((((((((( Fichiers créés du 2008-09-15 au 2008-10-15 ))))))))))))))))))))))))))))))))))))
          .

          2008-10-16 00:44 . 2008-10-16 00:44 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
          2008-10-14 11:08 . 2008-10-16 00:37 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Application Data\LimeWire
          2008-10-14 11:08 . 2008-10-16 00:37 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Application Data\LimeWire
          2008-10-14 11:08 . 2008-10-16 00:37 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Application Data\LimeWire
          2008-10-14 11:06 . 2008-10-14 11:07 <REP> d-------- C:\Program Files\LimeWire
          2008-10-14 03:11 . 2008-10-14 03:28 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
          2008-10-14 03:08 . 2008-10-14 11:04 <REP> d-------- C:\Program Files\BitComet
          2008-10-14 03:07 . 2008-10-14 03:07 <REP> d-------- C:\Program Files\Webteh
          2008-10-14 03:07 . 2008-10-14 03:07 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Application Data\BSplayer Pro
          2008-10-14 03:07 . 2008-10-14 03:07 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Application Data\BSplayer Pro
          2008-10-14 03:07 . 2008-10-14 03:07 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Application Data\BSplayer Pro
          2008-10-14 03:02 . 2008-10-14 03:02 <REP> d---s---- C:\Documents and Settings\Yoni Félix Boukobza\UserData
          2008-10-14 03:02 . 2008-10-14 03:02 <REP> d---s---- C:\Documents and Settings\Yoni Félix Boukobza\UserData
          2008-10-14 02:47 . 2004-08-03 23:08 26,496 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys
          2008-10-14 02:38 . 2008-10-14 02:38 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Contacts
          2008-10-14 02:38 . 2008-10-14 02:38 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Contacts
          2008-10-14 02:30 . 2008-10-14 02:30 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Application Data\Apple Computer
          2008-10-14 02:30 . 2008-10-14 02:30 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Application Data\Apple Computer
          2008-10-14 02:30 . 2008-10-14 02:30 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Application Data\Apple Computer
          2008-10-14 02:30 . 2008-04-17 13:12 107,368 --a------ C:\WINDOWS\system32\GEARAspi.dll
          2008-10-14 02:30 . 2008-04-17 13:12 15,464 --a------ C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
          2008-10-14 02:29 . 2008-10-14 02:30 <REP> d-------- C:\Program Files\iTunes
          2008-10-14 02:29 . 2008-10-14 02:29 <REP> d-------- C:\Program Files\iPod
          2008-10-14 02:29 . 2008-10-14 02:29 <REP> d-------- C:\Program Files\Bonjour
          2008-10-14 02:29 . 2008-10-14 02:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
          2008-10-14 02:28 . 2008-10-14 02:29 <REP> d-------- C:\Program Files\QuickTime
          2008-10-14 02:28 . 2008-10-14 02:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
          2008-10-14 02:27 . 2008-10-14 02:37 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
          2008-10-14 02:27 . 2008-10-14 02:27 <REP> d-------- C:\Program Files\Apple Software Update
          2008-10-14 02:27 . 2008-10-14 02:27 <REP> d-------- C:\Program Files\Alwil Software
          2008-10-14 02:26 . 2008-10-14 02:28 <REP> d-------- C:\Program Files\Fichiers communs\Apple
          2008-10-14 02:26 . 2008-10-14 02:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
          2008-10-14 02:25 . 2008-10-14 02:37 <REP> d-------- C:\Program Files\Windows Live
          2008-10-14 02:25 . 2008-10-14 02:35 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
          2008-10-14 02:25 . 2008-10-14 02:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
          2008-10-14 02:24 . 2006-06-30 16:10 26,752 -ra------ C:\WINDOWS\system32\drivers\RimSerial.sys
          2008-10-14 02:23 . 2008-10-14 02:23 <REP> d-------- C:\Program Files\Research In Motion
          2008-10-14 02:23 . 2008-10-14 02:23 <REP> d-------- C:\Program Files\Fichiers communs\Research In Motion
          2008-10-14 02:23 . 2008-10-14 02:23 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Application Data\Blackberry Desktop
          2008-10-14 02:23 . 2008-10-14 02:23 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Application Data\Blackberry Desktop
          2008-10-14 02:23 . 2008-10-14 02:23 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Application Data\Blackberry Desktop
          2008-10-14 02:21 . 2008-10-14 02:21 <REP> d--hs---- C:\WINDOWS\ftpcache
          2008-10-14 02:10 . 2008-10-14 02:10 0 --a------ C:\WINDOWS\nsreg.dat
          2008-10-14 01:55 . 2008-10-14 01:55 385 --a------ C:\WINDOWS\ODBC.INI
          2008-10-14 01:53 . 2008-10-14 01:54 <REP> d-------- C:\WINDOWS\ShellNew
          2008-10-14 01:48 . 2008-10-14 01:48 <REP> d-------- C:\Program Files\Sun
          2008-10-14 01:48 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
          2008-10-14 01:36 . 2005-12-07 10:35 47,104 --a------ C:\WINDOWS\system32\WACntlPnl.cpl
          2008-10-14 01:33 . 2006-04-11 13:27 <REP> d--h----- C:\Documents and Settings\Yoni Félix Boukobza\Voisinage réseau
          2008-10-14 01:33 . 2006-04-11 13:27 <REP> d--h----- C:\Documents and Settings\Yoni Félix Boukobza\Voisinage réseau
          2008-10-14 01:33 . 2006-04-11 13:27 <REP> d--h----- C:\Documents and Settings\Yoni Félix Boukobza\Voisinage d'impression
          2008-10-14 01:33 . 2006-04-11 13:27 <REP> d--h----- C:\Documents and Settings\Yoni Félix Boukobza\Voisinage d'impression
          2008-10-14 01:33 . 2008-10-14 10:08 <REP> d--h----- C:\Documents and Settings\Yoni Félix Boukobza\Modèles
          2008-10-14 01:33 . 2008-10-14 10:08 <REP> d--h----- C:\Documents and Settings\Yoni Félix Boukobza\Modèles
          2008-10-14 01:33 . 2008-10-15 07:22 <REP> dr------- C:\Documents and Settings\Yoni Félix Boukobza\Mes documents
          2008-10-14 01:33 . 2008-10-15 07:22 <REP> dr------- C:\Documents and Settings\Yoni Félix Boukobza\Mes documents
          2008-10-14 01:33 . 2008-10-14 10:08 <REP> dr------- C:\Documents and Settings\Yoni Félix Boukobza\Menu Démarrer
          2008-10-14 01:33 . 2008-10-14 10:08 <REP> dr------- C:\Documents and Settings\Yoni Félix Boukobza\Menu Démarrer
          2008-10-14 01:33 . 2008-10-14 01:34 <REP> dr------- C:\Documents and Settings\Yoni Félix Boukobza\Favoris
          2008-10-14 01:33 . 2008-10-14 01:34 <REP> dr------- C:\Documents and Settings\Yoni Félix Boukobza\Favoris
          2008-10-14 01:33 . 2008-10-16 01:51 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Bureau
          2008-10-14 01:33 . 2008-10-16 01:51 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza\Bureau
          2008-10-14 01:33 . 2008-10-14 03:02 <REP> d-------- C:\Documents and Settings\Yoni Félix Boukobza

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-10-15 23:06 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
          2008-10-15 23:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
          2008-10-15 22:46 --------- d-----w C:\Program Files\Google
          2008-10-14 08:14 --------- d-----w C:\Program Files\Synaptics
          2008-10-14 08:14 --------- d-----w C:\Program Files\Sonic
          2008-10-14 08:13 --------- d-----w C:\Program Files\Services en ligne
          2008-10-14 08:13 --------- d-----w C:\Program Files\Microsoft Works
          2008-10-14 08:12 --------- d-----w C:\Program Files\microsoft frontpage
          2008-10-14 08:12 --------- d-----w C:\Program Files\HP
          2008-10-14 08:11 --------- d-----w C:\Program Files\Hewlett-Packard
          2008-10-14 08:11 --------- d-----w C:\Program Files\Fichiers communs\TiVo Shared
          2008-10-14 08:11 --------- d-----w C:\Program Files\Fichiers communs\SureThing Shared
          2008-10-14 08:11 --------- d-----w C:\Program Files\Fichiers communs\Sonic Shared
          2008-10-14 08:11 --------- d-----w C:\Program Files\Fichiers communs\LightScribe
          2008-10-14 08:10 --------- d-----w C:\Program Files\Fichiers communs\Java
          2008-10-14 08:10 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
          2008-10-14 08:10 --------- d-----w C:\Program Files\Fichiers communs\HP
          2008-10-14 08:10 --------- d-----w C:\Program Files\CONEXANT
          2008-10-14 08:10 --------- d-----w C:\Program Files\ATI Technologies
          2008-10-14 08:10 --------- d-----w C:\Program Files\AMD
          2008-10-14 08:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic
          2008-10-14 08:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\SBSI
          2008-10-14 08:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
          2008-10-14 08:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
          2008-10-14 08:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
          2008-10-14 00:43 --------- d-----w C:\Program Files\Symantec
          2008-10-13 23:48 --------- d-----w C:\Program Files\Java
          2008-10-13 23:36 --------- d--h--w C:\Program Files\InstallShield Installation Information
          2008-10-13 23:36 --------- d-----w C:\Program Files\HPQ
          .

          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
          "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
          "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-10-14 171448]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-11-10 344064]
          "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
          "HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
          "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-06-19 729178]
          "ccApp"="c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2005-09-17 52848]
          "QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2005-12-12 94208]
          "eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2005-12-22 405504]
          "Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-08-01 233534]
          "RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 1187840]
          "hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-13 507904]
          "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
          "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]

          C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
          D‚marrage rapide de HP Photosmart Premier.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-24 73728]
          Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
          "AppInit_DLLs"=bczrrv.dll

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%windir%\\system32\\sessmgr.exe"=
          "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
          "C:\\Program Files\\iTunes\\iTunes.exe"=
          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
          "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
          "C:\\Program Files\\BitComet\\BitComet.exe"=
          "C:\\Program Files\\LimeWire\\LimeWire.exe"=

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
          "15625:TCP"= 15625:TCP:BitComet 15625 TCP
          "15625:UDP"= 15625:UDP:BitComet 15625 UDP

          R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
          R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
          R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2005-08-22 231424]
          S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
          .
          Contenu du dossier 'Tâches planifiées'

          2008-10-14 C:\WINDOWS\Tasks\Symantec NetDetect.job
          - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE [2005-09-22 18:21]
          .
          - - - - ORPHELINS SUPPRIMES - - - -

          BHO-{03CE0CC2-C52E-4836-878C-B3FBE9C094E9} - C:\WINDOWS\system32\jiaifrac.dll
          BHO-{9DBBE0A1-D661-4FBD-8858-45D40B676551} - C:\WINDOWS\system32\cbXOGVon.dll
          BHO-{fb769b30-273d-4aab-96f4-0e71011066d5} - C:\WINDOWS\system32\bczrrv.dll
          BHO-{FD417378-F411-4B77-BBEE-4893BB670D4C} - C:\WINDOWS\system32\jkkJaxUO.dll
          HKLM-Run-ecf1c42c - C:\WINDOWS\system32\mnpsaqks.dll
          ShellExecuteHooks-{FD417378-F411-4B77-BBEE-4893BB670D4C} - C:\WINDOWS\system32\jkkJaxUO.dll
          Notify-jkkJaxUO - jkkJaxUO.dll

          .
          ------- Examen supplémentaire -------
          .
          FireFox -: Profile - C:\Documents and Settings\Yoni Félix Boukobza\Application Data\Mozilla\Firefox\Profiles\37eddejh.default\
          FF -: plugin - C:\Program Files\Adobe\Acrobat 6.0\Reader\browser\nppdf32.dll
          FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
          .

          **************************************************************************

          catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-10-16 01:58:37
          Windows 5.1.2600 Service Pack 2 NTFS

          Recherche de processus cachés ...

          Recherche d'éléments en démarrage automatique cachés ...

          HKLM\Software\Microsoft\Windows\CurrentVersion\Run
          Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe??????????>????|?????? ???B?????????????hLC? ??????

          Recherche de fichiers cachés ...

          Scan terminé avec succès
          Fichiers cachés: 0

          **************************************************************************
          .
          ------------------------ Autres processus actifs ------------------------
          .
          C:\WINDOWS\system32\ati2evxx.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
          C:\WINDOWS\system32\ati2evxx.exe
          C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\WINDOWS\system32\wdfmgr.exe
          C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\PROGRA~1\HPQ\shared\HPQTOA~1.EXE
          C:\Program Files\iPod\bin\iPodService.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
          C:\WINDOWS\SoftwareDistribution\Download\aad9f71badc219d6bf410068723b339e\update\update.exe
          .
          **************************************************************************
          .
          Heure de fin: 2008-10-16 2:03:12 - La machine a redémarré
          ComboFix-quarantined-files.txt 2008-10-16 00:03:06

          Avant-CF: 48 179 068 928 octets libres
          Après-CF: 48,140,390,400 octets libres

          227 --- E O F --- 2008-10-14 01:01:18
          0
          1. Combofix a finalement marché...;)
            0
            1. je telecharge MalwareByte's Anti-Malware ou je commence a partir de la manip mode sans echec?
              0
              1. MalwareByte's Anti-Malware a detecté 25 virus. ils ont ete supprimé.
                voici le rapport de MalwareByte's Anti-Malware:

                Malwarebytes' Anti-Malware 1.28
                Version de la base de données: 1274
                Windows 5.1.2600 Service Pack 2

                17/10/2008 01:30:26
                mbam-log-2008-10-17 (01-30-26).txt

                Type de recherche: Examen complet (C:\|D:\|)
                Eléments examinés: 91714
                Temps écoulé: 38 minute(s), 30 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 0
                Valeur(s) du Registre infectée(s): 0
                Elément(s) de données du Registre infecté(s): 1
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 24

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Valeur(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre infecté(s):
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                C:\Qoobox\Quarantine\C\WINDOWS\system32\bczrrv.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\WINDOWS\system32\bnjpgavp.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\WINDOWS\system32\cbXOGVon.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\WINDOWS\system32\fjwwtcue.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\WINDOWS\system32\ionjqo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\WINDOWS\system32\jiaifrac.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\WINDOWS\system32\lwkgmc.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\WINDOWS\system32\mnpsaqks.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\WINDOWS\system32\rexygxwl.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\WINDOWS\system32\tcyxwlsl.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\WINDOWS\system32\xxyyxvuU.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP11\A0001038.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP11\A0001428.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001471.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001472.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001473.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001474.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001475.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001476.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001477.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001478.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001480.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001482.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001483.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                0
                1. ai je autre chose a faire ou est ce que tout est ok maintenant.?

                  Merci pour ton aide precieux Detrio5
                  0
                  1. Malwarebytes' Anti-Malware 1.28
                    Version de la base de données: 1274
                    Windows 5.1.2600 Service Pack 2

                    17/10/2008 01:30:26
                    mbam-log-2008-10-17 (01-30-26).txt

                    Type de recherche: Examen complet (C:\|D:\|)
                    Eléments examinés: 91714
                    Temps écoulé: 38 minute(s), 30 second(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 0
                    Valeur(s) du Registre infectée(s): 0
                    Elément(s) de données du Registre infecté(s): 1
                    Dossier(s) infecté(s): 0
                    Fichier(s) infecté(s): 24

                    Processus mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Valeur(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Elément(s) de données du Registre infecté(s):
                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                    Dossier(s) infecté(s):
                    (Aucun élément nuisible détecté)

                    Fichier(s) infecté(s):
                    C:\Qoobox\Quarantine\C\WINDOWS\system32\bczrrv.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Qoobox\Quarantine\C\WINDOWS\system32\bnjpgavp.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Qoobox\Quarantine\C\WINDOWS\system32\cbXOGVon.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Qoobox\Quarantine\C\WINDOWS\system32\fjwwtcue.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Qoobox\Quarantine\C\WINDOWS\system32\ionjqo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Qoobox\Quarantine\C\WINDOWS\system32\jiaifrac.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Qoobox\Quarantine\C\WINDOWS\system32\lwkgmc.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Qoobox\Quarantine\C\WINDOWS\system32\mnpsaqks.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Qoobox\Quarantine\C\WINDOWS\system32\rexygxwl.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Qoobox\Quarantine\C\WINDOWS\system32\tcyxwlsl.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\Qoobox\Quarantine\C\WINDOWS\system32\xxyyxvuU.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP11\A0001038.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP11\A0001428.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001471.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001472.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001473.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001474.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001475.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001476.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001477.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001478.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001480.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001482.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{B8687C25-491C-4B92-A950-D228172F494F}\RP12\A0001483.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                    0
                    1. dernier rapport HijackThis:

                      Logfile of HijackThis v1.99.1
                      Scan saved at 01:54:38, on 17/10/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\Explorer.EXE
                      c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                      c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                      C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                      C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                      C:\Program Files\HP\QuickPlay\QPService.exe
                      C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
                      C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Program Files\Webteh\BSplayerPro\bsplayer.exe
                      C:\Program Files\BitComet\BitComet.exe
                      C:\Documents and Settings\Yoni Félix Boukobza\Bureau\Nouveau dossier\hijackthis_199\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                      O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                      O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                      O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
                      O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
                      O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
                      O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
                      O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
                      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
                      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
                      O20 - AppInit_DLLs: bczrrv.dll
                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                      0
                      1. ds j'avais posté le mauvais rapport .... un mauvais copier/ coller...
                        0
                        1. dernier rapport HijackThis:

                          Logfile of HijackThis v1.99.1
                          Scan saved at 01:54:38, on 17/10/2008
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\Explorer.EXE
                          c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                          c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                          C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                          C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                          C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                          C:\Program Files\HP\QuickPlay\QPService.exe
                          C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
                          C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe­
                          C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                          C:\Program Files\iPod\bin\iPodService.exe
                          C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\Program Files\Webteh\BSplayerPro\bsplayer.exe
                          C:\Program Files\BitComet\BitComet.exe
                          C:\Documents and Settings\Yoni Félix Boukobza\Bureau\Nouveau dossier\hijackthis_199\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                          O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                          O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                          O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
                          O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
                          O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
                          O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
                          O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
                          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
                          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
                          O20 - AppInit_DLLs: bczrrv.dll
                          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                          0
                          1. Norton est desinstallé de mon PC. Du moins je croyais m'en etre deja chargé.
                            lorsque je vais sur ajout suppression d'un programme norton n'apparait plus... peut il etre encore la sans que je le sache?
                            0
                            1. Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 08:48:28, on 17/10/2008
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\Ati2evxx.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                              C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                              C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                              C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              C:\Program Files\HP\QuickPlay\QPService.exe
                              C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
                              C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\Program Files\BitComet\BitComet.exe
                              C:\Documents and Settings\Yoni Félix Boukobza\Bureau\Nouveau dossier (2)\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                              O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
                              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                              O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
                              O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
                              O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
                              O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                              O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
                              O20 - AppInit_DLLs: bczrrv.dll
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                              0
                              1. Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 09:37:40, on 17/10/2008
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16735)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\Ati2evxx.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\Ati2evxx.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                C:\Program Files\Bonjour\mDNSResponder.exe
                                C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                C:\Program Files\HP\QuickPlay\QPService.exe
                                C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
                                C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
                                C:\Program Files\iPod\bin\iPodService.exe
                                C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
                                C:\Program Files\Alwil Software\Avast4\setup\avast.setup
                                C:\Documents and Settings\Yoni Félix Boukobza\Bureau\Nouveau dossier (2)\HijackThis.exe
                                C:\WINDOWS\system32\wuauclt.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www8.hp.com/fr/fr/home.html
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www8.hp.com/fr/fr/home.html
                                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                                O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
                                O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
                                O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
                                O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
                                O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
                                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O14 - IERESET.INF: START_PAGE_URL=https://www8.hp.com/fr/fr/home.html
                                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                0
                                1. Modérateur
                                  Salut,

                                  - Télécharge HijackThis v2.0.2 sur ton Bureau :
                                  http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

                                  - Double-clique sur HJTInstall afin de lancer l'installation.

                                  - Clique sur Install ensuite sur I Accept.

                                  - Clique sur Do a system scan and save a logfile.

                                  - Le bloc-notes s'ouvrira, fais un copier/coller de tout son contenu ici dans ton prochain message.
                                  -1
                                  1. Bien le bonsoir :)
                                    as tu regardé ce qui est actif dans ton démarrage
                                    en exécutant 'Msconfig'
                                    car j'ai chopé un m... il y a deux jours, avast prévenait et rien ne changeais...........
                                    et dans l'onglet 'démarrage de msconfig, il y avait un illustre inconnu que j'ai désactivé
                                    j'ai aussi désinstallé Avast > redémarrage et retéléchargé Avast et installé et op op tout nickel :)
                                    -1
                                    1. Modérateur
                                      Tu es infecté par Vundo.

                                      ---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
                                      http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                                      /!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

                                      ---> Double-clique sur Combofix.exe
                                      Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
                                      Accepte en cliquant sur "Oui"

                                      ---> Mets-le en langue française F
                                      Tape sur la touche 1 (Yes) pour démarrer le scan.

                                      /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

                                      En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

                                      Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

                                      /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

                                      Note : Le rapport se trouve également là : C:\ComboFix\Combofix.txt
                                      -1
                                      1. Modérateur
                                        La petite barre, oui mais qui ne se passe rien, non.

                                        - Télécharge et installe MalwareByte's Anti-Malware :
                                        http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm

                                        - Mets-le à jour

                                        - Redémarre en mode sans échec (Recommandé) :
                                        https://blog.sosordi.net/

                                        - Choisis ta session habituelle

                                        - Fais un scan complet avec MalwareByte's Anti-Malware

                                        - Supprime tout ce que le logiciel trouve, enregistre le rapport

                                        - Redémarre en mode normal et poste le rapport ici

                                        Tutorial :
                                        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                                        -1
                                        • 1
                                        • 2