Ils.dll ??

Bonjour,

Avast vient de détecter un virus dans système 32 "ils.dll" se serait un rootkit processus cachés.
Je ne sais pas quoi faire du tout, ignorer ou supprimer les deux ne marches pas .

Merci d'avance pour votre aide
Configuration: Windows XP
Firefox 3.0.4

17 réponses

Résumé de la discussion

Une détection par Avast signale la présence d'un fichier système suspect, system32 ils.dll, potentiellement un rootkit, et suscite une incertitude sur la marche à suivre face à cette alerte antivirus. Plusieurs réponses conseillent de ne pas supprimer ce fichier, le considérer légitime et recommandent de changer d’antivirus ou d’effectuer une vérification approfondie, car une fausse détection antivirus peut survenir. Un extrait de journal système présente un log détaillé et une liste étendue de processus et de services, ce qui peut indiquer une infection ou une interaction complexe avec des outils de sécurité. En cas d’analyse, il est noté la présence de nombreux services et pilotes antivirus et d’outils tiers, ce qui peut nécessiter une évaluation ciblée et des scans complémentaires.

Bobot (l’IA à votre service)
  1. bonjours,

    ne supprimer pas ce fichiers c est légitime c est sur

    et changer d antivirus car c est pas la premeire fois
    3
    1. comme vous etes nombreux c est surement un faux positif pour tout le monde.

      a choisir mettez le en quarantaine au lieu de le supprimer, c est valable pour tout ce qui est repere.
      1
      1. Logfile of random's system information tool 1.04 (written by random/random)
        Run by alex at 2008-12-15 13:55:25
        Microsoft Windows XP Professionnel Service Pack 3
        System drive C: has 20 GB (17%) free of 114 GB
        Total RAM: 1023 MB (28% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 13:55:55, on 15/12/2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\ehome\ehtray.exe
        C:\WINDOWS\ATK0100\HControl.exe
        C:\Program Files\ASUS\ASUS Live Update\ALU.exe
        C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Wireless Console 2\wcourier.exe
        C:\WINDOWS\sm56hlpr.exe
        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
        C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
        C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\USB Disk Win98 Driver\Res.EXE
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\HiYo\bin\HiYo.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\Asus\Asus ChkMail\ChkMail.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        C:\WINDOWS\eHome\ehRecvr.exe
        C:\WINDOWS\eHome\ehSched.exe
        C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
        C:\WINDOWS\ATK0100\ATKOSD.exe
        C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        C:\Program Files\Spyware Doctor\sdhelp.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\wdfmgr.exe
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
        C:\WINDOWS\ehome\mcrdsvc.exe
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
        C:\WINDOWS\system32\dllhost.exe
        C:\WINDOWS\eHome\ehmsas.exe
        C:\WINDOWS\System32\alg.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
        C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
        C:\Program Files\Alwil Software\Avast4\setup\avast.setup
        C:\Documents and Settings\alex\Bureau\RSIT.exe
        C:\WINDOWS\system32\wbem\wmiprvse.exe
        C:\Program Files\trend micro\alex.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/french/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
        O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
        O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
        O4 - HKLM\..\Run: [ASUS Live Update] "C:\Program Files\ASUS\ASUS Live Update\ALU.exe"
        O4 - HKLM\..\Run: [Power_Gear] "C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe" 1
        O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
        O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
        O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
        O4 - HKLM\..\Run: [Wireless Console 2] "C:\Program Files\Wireless Console 2\wcourier.exe"
        O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
        O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [USB Storage Toolbox] "C:\Program Files\USB Disk Win98 Driver\Res.EXE"
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [HiYo] C:\Program Files\HiYo\bin\HiYo.exe /RunFromStartup
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
        O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: Bluetooth Manager.lnk = ?
        O4 - Global Startup: ASUS ChkMail.lnk = C:\Program Files\Asus\Asus ChkMail\ChkMail.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
        O14 - IERESET.INF: START_PAGE_URL=https://www.asus.com/fr/
        O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} (CamfrogWEB Advanced Unicode Control) - http://activex.camfrogweb.com/advanced/2.0.2.20/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe
        O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
        O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
        O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
        O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
        1
        1. Contributeur sécurité
          slt
          totobetourne, et chiquitine29

          mariem,

          oui c'est un faux positif
          avec mise a jour dans les prochains jour il ne devrait plus être

          fais ceci car tu as -*par contre des infections autres:

          Telecharge UsbFix sur ton bureau
          http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe

          --> Lance l installation avec les parametres par default

          Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

          --> Double clic sur le raccourci UsbFix sur ton bureau

          --> Le pc va redémarer

          -->Apres redémarrage post le rapport UsbFix.txt

          Note : le rapport UsbFix.txt est sauvegardé a la racine du disque
          Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

          ____________________

          Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
          http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
          Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
          • Redémarre ton ordinateur
          • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
          • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
          • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
          • Choisis ton compte.
          Déroule la liste des instructions ci-dessous :
          • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
          • Appuie sur Y pour commencer le processus de nettoyage.
          • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
          • Appuie sur une touche pour redémarrer le PC.
          • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
          • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
          • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
          • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
          • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum
          1
          1. rapport USBfix : (je fais SDFix maintenant)

            -------------- UsbFix V2.413.4 ---------------

            * User : Administrateur - GD
            * Outils mis a jours le 11/12/2008 par Chiquitine29 et Chimay8
            * Recherche effectuée à 14:49:53 le 15/12/2008
            * Windows Xp - Internet Explorer 6.0.2900.2180

            --------------- [ Processus actifs ] ----------------

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\userinit.exe
            C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\2.tmp\b2e.exe

            --------------- [ Informations lecteurs ] ----------------

            C: - Lecteur fixe

            E: - Lecteur fixe

            F: - Lecteur amovible

            --------------- [ Lecteur C ] ----------------

            C: - Lecteur fixe

            +- Listing des fichiers présents :

            [24/08/2006 18:32][--a------] C:\AUTOEXEC.BAT
            [03/08/2004 23:38][-rahs----] C:\NTDETECT.COM
            [29/08/2006 18:15][--ahs----] C:\boot.ini
            [29/08/2006 18:15][--ahs----] C:\ioSpecial.ini
            [20/10/2008 15:17][--a------] C:\rapport.txt
            [20/10/2008 15:17][--a------] C:\TCleaner.txt
            [20/10/2008 15:17][--a------] C:\UsbFix.txt
            [24/08/2006 18:32][--a------] C:\CONFIG.SYS
            [24/08/2006 18:32][--a------] C:\hiberfil.sys
            [24/08/2006 18:32][--a------] C:\IO.SYS
            [24/08/2006 18:32][--a------] C:\MSDOS.SYS
            [24/08/2006 18:32][--a------] C:\pagefile.sys

            --------------- [ Lecteur E ] ----------------

            E: - Lecteur fixe

            +- Listing des fichiers présents :

            [31/01/2007 18:01][--a------] E:\setupfre.exe
            [31/01/2007 18:01][--a------] E:\vpsupd.exe

            --------------- [ Lecteur F ] ----------------

            F: - Lecteur amovible

            +- Listing des fichiers présents :

            [22/05/2008 11:34][-r-hs----] F:\tfk8.exe

            --------------- [ Registre / Startup ] ----------------

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
            ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
            ATIPTA=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
            SunJavaUpdateSched="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
            TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
            Installed=1
            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
            Installed=1
            NoChange=1
            HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
            Installed=1

            --------------- [ Registre / Mountpoint2 ] ----------------

            Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5f79672-3810-11db-ae58-00c09fa7bc2d}\Shell\AutoRun\command

            --------------- [ Nettoyage des disques ] ----------------

            Supprimé ! - [20/10/2008 15:16][--a------] C:\WINDOWS\system32\tmp.reg
            Supprimé ! - [20/10/2008 15:16][--a------] C:\WINDOWS\system32\tmp.txt
            Supprimé ! - [22/05/2008 11:34][-r-hs----] F:\tfk8.exe

            --------------- [ Resumé ] ----------------

            -> /!\ Le resultat doit etre interprété par un spécialiste /!\

            [24/08/2006 18:32][--a------] C:\AUTOEXEC.BAT
            [03/08/2004 23:38][-rahs----] C:\NTDETECT.COM
            [29/08/2006 18:15][--ahs----] C:\boot.ini
            [29/08/2006 18:15][--ahs----] C:\ioSpecial.ini
            [31/01/2007 18:01][--a------] E:\setupfre.exe
            [31/01/2007 18:01][--a------] E:\vpsupd.exe

            --------------- ! Fin du rapport ! ----------------
            0
        2. UN SEUL ANTIVIRUS SUR UN PC, DESINSTALLE AVAST.

          spyware doctor inutil a desinstaller.

          attend jlpjlp car il y a surement quelquechose mais lui si connait plus que moi, comme tout le monde ecrit si tu n as pas de nouvelles de sa part envoie lui un message privee avec le lien du topic et dis lui ce que tu as fait.
          1
          1. n oublie pas que sd fix est a passer en mode sans echec.lit bien ce qui est indique.
            1
            1. Contributeur sécurité
              tu as le lien exact? donne le C/....

              et analyse le fichier sur virus total et colle le rapport

              https://www.virustotal.com/gui/

              et

              Télécharge ici :

              http://images.malwareremoval.com/random/RSIT.exe

              random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

              Double-clique sur RSIT.exe afin de lancer RSIT.

              Clique Continue à l'écran Disclaimer.

              Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

              Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

              Poste le contenu de log.txt (<<qui sera affiché)
              ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

              NB : Les rapports sont sauvegardés dans le dossier C:\rsit
              0
              1. le rapport avec virus total est :

                Antivirus Version Dernière mise à jour Résultat
                AhnLab-V3 2008.12.15.3 2008.12.15 -
                AntiVir 7.9.0.45 2008.12.15 -
                Authentium 5.1.0.4 2008.12.14 -
                Avast 4.8.1281.0 2008.12.15 -
                AVG 8.0.0.199 2008.12.15 -
                BitDefender 7.2 2008.12.15 -
                CAT-QuickHeal 10.00 2008.12.15 -
                ClamAV 0.94.1 2008.12.15 -
                Comodo 754 2008.12.14 -
                DrWeb 4.44.0.09170 2008.12.15 -
                eSafe 7.0.17.0 2008.12.14 -
                eTrust-Vet 31.6.6261 2008.12.15 -
                Ewido 4.0 2008.12.15 -
                F-Prot 4.4.4.56 2008.12.14 -
                F-Secure 8.0.14332.0 2008.12.15 -
                Fortinet 3.117.0.0 2008.12.14 -
                GData 19 2008.12.15 -
                Ikarus T3.1.1.45.0 2008.12.15 -
                K7AntiVirus 7.10.553 2008.12.13 -
                Kaspersky 7.0.0.125 2008.12.15 -
                McAfee 5464 2008.12.14 -
                McAfee+Artemis 5464 2008.12.14 -
                Microsoft 1.4205 2008.12.15 -
                NOD32 3692 2008.12.15 -
                Norman 5.80.02 2008.12.12 -
                Panda 9.0.0.4 2008.12.15 -
                PCTools 4.4.2.0 2008.12.15 -
                Prevx1 V2 2008.12.15 -
                Rising 21.08.02.00 2008.12.15 -
                SecureWeb-Gateway 6.7.6 2008.12.15 -
                Sophos 4.36.0 2008.12.15 -
                Sunbelt 3.2.1801.2 2008.12.11 -
                Symantec 10 2008.12.15 -
                TheHacker 6.3.1.4.188 2008.12.14 -
                TrendMicro 8.700.0.1004 2008.12.15 -
                VBA32 3.12.8.10 2008.12.14 -
                ViRobot 2008.12.15.1518 2008.12.15 -
                VirusBuster 4.5.11.0 2008.12.14 -
                Information additionnelle
                File size: 81920 bytes
                MD5...: 1dd2454b6157f81627efe09745614eb4
                SHA1..: da4162e1c0dcc12ee7fdf3af22140e035ae6b580
                SHA256: 45683e80053a9f375eb03e5218e1f4d756041dfa883d06e6ee242e88964c443b
                SHA512: edc226a262e3bd53d548a8e04723bcaf1aa97e8da3ca15c1dd230bbabb4cf437
                6242676d920a7236a2e09ba7e54a686cad2f1ea8c0d927db1ee6342d577f5a16
                ssdeep: 1536:EnTB8iOSDRv6cLR3GMdMzAUHvTXiZpFPHg36zLOoOho:ETBRvp92EglHvmZ
                pFPGmSoOh
                PEiD..: -
                TrID..: File type identification
                DirectShow filter (90.9%)
                Win32 Executable Generic (3.8%)
                Win32 Dynamic Link Library (generic) (3.4%)
                Generic Win/DOS Executable (0.9%)
                DOS Executable Generic (0.9%)
                PEInfo: PE Structure information

                ( base data )
                entrypointaddress.: 0x66d1fa67
                timedatestamp.....: 0x411095ef (Wed Aug 04 07:53:19 2004)
                machinetype.......: 0x14c (I386)

                ( 4 sections )
                name viradd virsiz rawdsiz ntrpy md5
                .text 0x1000 0xf380 0x10000 6.37 25a4c59faa140c9779de2703e292d5af
                .data 0x11000 0x1bc 0x1000 0.57 bb9b0ba197316c1051978da0519859df
                .rsrc 0x12000 0x4b8 0x1000 1.26 5f1f251e4c4759cf5aa0d188210d8500
                .reloc 0x13000 0xbe6 0x1000 4.97 8ec95c2ff3341003e5f337f73c2d35a8

                ( 7 imports )
                > msvcrt.dll: _adjust_fdiv, malloc, _initterm, free
                > KERNEL32.dll: EnterCriticalSection, InitializeCriticalSection, DeleteCriticalSection, DisableThreadLibraryCalls, lstrcmpA, GetModuleFileNameA, MultiByteToWideChar, WideCharToMultiByte, IsBadWritePtr, CloseHandle, TerminateThread, GetTickCount, SetEvent, lstrcatA, CreateThread, CreateEventA, GetLastError, LeaveCriticalSection, GetCurrentThreadId, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetProcAddress, SetErrorMode, GetVersionExA, LoadLibraryExA, lstrcpynA, GetSystemDirectoryA, InterlockedDecrement, lstrlenA, LocalAlloc, lstrcpyA, lstrcmpiA, InterlockedIncrement, LocalFree, FreeLibrary
                > ADVAPI32.dll: RegOpenKeyExA, RegCreateKeyA, RegQueryValueExA, RegCreateKeyExA, RegSetValueExA, RegOpenKeyA, RegEnumKeyExA, RegCloseKey, RegDeleteKeyA, RegFlushKey
                > USER32.dll: PeekMessageA, TranslateMessage, DispatchMessageA, DefWindowProcA, PostMessageA, CreateWindowExA, RegisterClassA, LoadCursorA, LoadIconA, UnregisterClassA, DestroyWindow, wsprintfA, IsWindow, MsgWaitForMultipleObjects, KillTimer, CharNextA, SetTimer, PostQuitMessage
                > OLEAUT32.dll: -, -
                > WSOCK32.dll: -, -, -, -, -
                > WLDAP32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -

                ( 4 exports )
                DllCanUnloadNow, DllGetClassObject, DllRegisterServer, DllUnregisterServer
                0
              2. log.txt :

                Logfile of random's system information tool 1.04 (written by random/random)
                Run by Administrateur at 2008-12-15 13:59:43
                Microsoft Windows XP Professionnel Service Pack 2
                System drive C: has 2 GB (7%) free of 30 GB
                Total RAM: 1022 MB (56% free)

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 13:59:44, on 15/12/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
                C:\Program Files\MSN Messenger\msnmsgr.exe
                C:\Program Files\MSN Messenger\usnsvc.exe
                C:\Documents and Settings\Administrateur\Bureau\RSIT.exe
                C:\Program Files\trend micro\Administrateur.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.fr/?gws_rd=ssl
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.gamenext.com
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                F3 - REG:win.ini: load=C:\windows\system32\wincfgs.exe
                O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\Msdxm6.ocx
                O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\RunServices: [Winamp Player] spwhost.exe
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\Office\Office10\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
                O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
                O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://mariemazuy.spaces.live.com/PhotoUpload/MsnPUpld.cab
                O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Fichiers communs\Macromedia Shared\Service\Macromedia Licensing.exe
                0
              3. info.txt logfile of random's system information tool 1.04 2008-12-15 13:57:48

                ======Uninstall list======

                -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                Adobe Acrobat 5.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.dll"
                Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                Adobe Illustrator 10-->"C:\Program Files\InstallShield Installation Information\{412033BC-44CF-48D9-B813-4B835101F4D3}\setup.exe"
                Adobe InDesign CS2-->msiexec /I{7F4C8163-F259-49A0-A018-2857A90578BC}
                Adobe Photoshop CS-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EFB21DE7-8C19-4A88-BB28-A766E16493BC}\setup.exe" -l0x40c
                Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
                Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                ATI - Utilitaire de désinstallation du logiciel-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
                ATI Control Panel-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
                ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
                AutoCAD 2006 - Français-->MsiExec.exe /I{5783F2D7-4001-040C-0002-0060B0CE6BBA}
                avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
                CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                Conexant AC-Link Audio-->CIAunwdm.exe
                eMule-->"C:\Program Files\eMule\Uninstall.exe"
                Google Earth-->MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
                HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
                Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
                LiveUpdate 2.7 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
                Macromedia Dreamweaver MX-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8B4AB829-DFD3-436D-B808-D9733D76C590}\Setup.exe" -l0x40c mmUninstall
                Macromedia Flash MX 2004-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2F353D44-73BB-4971-B31D-F7642E9E9531}\Setup.exe" -l0x40c UNINSTALL
                Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
                Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                Mise à jour de sécurité pour Windows XP (KB913433)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB913433.inf
                Mozilla Firefox (3.0.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
                MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                Nero 6 Ultra Edition-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
                PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
                QuickTime-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{3868A8EE-5051-4DB0-8DF6-4F4B8A98D083} /l1036
                Ranch Rush-->"C:\Program Files\Ranch Rush\Uninstall.exe"
                RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                SketchUp 5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B357C4B4-9024-4B64-9B3F-A6729031C3DD}\setup.exe" -l0x40c
                SoftV92 Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_8086&DEV_266D&SUBSYS_00661025\HXFSETUP.EXE -U -Iqta00665.inf
                VideoLAN VLC media player 0.7.2-->C:\Program Files\VLC\uninstall.exe
                Virtual Farm-->"C:\Program Files\Virtual Farm\Uninstall.exe"
                Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
                Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

                Hosts File Missing
                0
              4. que dis tu de ces rapports jlp jlp ?
                0
            2. fait ce que t indique jlpjlp.
              0
              1. Salut a vous, idem chez moi >> je viens de traiter le meme cas >> de pire en pire chez avast !!!
                0
            3. Comme beaucoup de monde j'ai le même souci avec avast, surement un faux positif, à suivre:
              http://img300.imageshack.us/img300/605/ilsdllxl7.jpg
              0
              1. info.txt logfile of random's system information tool 1.04 2008-12-15 13:56:00

                ======Uninstall list======

                -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DD4F051C-1A2B-4A91-B187-B093C597418C}\setup.exe" -l0x40c anything
                -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                7-Zip 4.58 beta-->"C:\Program Files\7-Zip\Uninstall.exe"
                Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                Adobe Reader 8.1.3 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81300000003}
                Adobe Shockwave Player-->C:\WINDOWS\system32\MACROMED\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\MACROMED\SHOCKW~1\Install.log
                Adware Spyware Scanner Deleter version 0.2-->"C:\Program Files\AdwareSpywareScannerDeleter\unins000.exe"
                Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
                Asus ChkMail-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Asus\Asus ChkMail\Uninst.isu"
                ASUS Live Update-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}\Setup.exe" -l0x9
                ATK0100 ACPI UTILITY-->C:\WINDOWS\ATK0100\XPunin.exe
                avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
                AVG Anti-Spyware 7.5-->C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exe
                Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
                Bluetooth Stack for Windows-->MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
                CamfrogWEB Advanced ActiveX Plugin (remove only)-->"C:\Program Files\CFWebAdvancedU\Uninstall.exe"
                CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
                CDex extraction audio-->"C:\Program Files\CDex_170b2\uninstall.exe"
                Correctif n° 2 pour Windows XP Édition Media Center 2005-->C:\WINDOWS\$NtUninstallKB900325$\spuninst\spuninst.exe
                Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                CutePDF Writer 2.7-->C:\Program Files\Acro Software\CutePDF Writer\uninscpw.exe /uninstall
                eMule-->"C:\eMule\Uninstall.exe"
                End It All-->C:\Program Files\End It All\uninstall.exe
                EndItAll 2-->C:\Program Files\EndItAll\Uninstal.exe
                EVEREST Ultimate Edition v4.20-->"C:\Program Files\Lavalys\EVEREST Ultimate Edition\unins000.exe"
                Favorit-->"c:\documents and settings\alex\local settings\application data\zckvmu.exe" -uninstall
                Football Manager 2008-->"C:\Program Files\Sports Interactive\Football Manager 2008\Uninstall_Football Manager 2008\Uninstall Football Manager 2008.exe"
                Galerie de photos Windows Live-->MsiExec.exe /X{A70FA218-6598-4AC9-813D-63597C5DD068}
                Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
                Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
                High Definition Audio - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
                HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                Hitman Pro-->"C:\Program Files\Hitman Pro\unins000.exe"
                HiYo -->MsiExec.exe /X{8F3A13FC-DFDA-4001-A6C3-030495A1E66E} ARPVAL="UnInst" /qf /L*V "%temp%\HiYoUninstallLog.log"
                HiYo-->MsiExec.exe /X{8F3A13FC-DFDA-4001-A6C3-030495A1E66E}
                Hotfix for Windows Media Player 10 (KB903157)-->"C:\WINDOWS\$NtUninstallKB903157$\spuninst\spuninst.exe"
                IsoBuster 2.4-->"C:\Program Files\Smart Projects\IsoBuster\Uninst\unins000.exe"
                IZArc 3.6-->"C:\Program Files\IZArc\unins000.exe"
                Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
                Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
                K-Lite Codec Pack 3.9.0 Full-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
                LFP Manager 08 Demo-->C:\Program Files\EA SPORTS\LFP Manager 08 Demo\uninstall.exe 1036
                LNH Handball Manager 2008-->"C:\Program Files\Gost In Game\LNH Handball Manager 2008\unins000.exe"
                Logiciel Intel(R) PROSet/Wireless-->C:\WINDOWS\Installer\iProInst.exe
                Ma-Config.com plugin-->MsiExec.exe /I{6F06A42D-525C-49ED-8622-E16790956CD8}
                mCore-->MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}
                mDriver-->MsiExec.exe /I{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}
                mDrWiFi-->MsiExec.exe /I{F6090A17-0967-4A8A-B3C3-422A1B514D49}
                mHelp-->MsiExec.exe /I{8C6BB412-D3A8-4AAE-A01B-35B681789D68}
                Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
                Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Lecteur Windows Media 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB953838)-->"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956390)-->"C:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB958215)-->"C:\WINDOWS\$NtUninstallKB958215$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                Mise à jour pour Lecteur Windows Media 10 (KB913800)-->"C:\WINDOWS\$NtUninstallKB913800$\spuninst\spuninst.exe"
                Mise à jour pour Lecteur Windows Media 10 (KB926251)-->"C:\WINDOWS\$NtUninstallKB926251$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
                mIWA-->MsiExec.exe /I{3E9D596A-61D4-4239-BD19-2DB984D2A16F}
                mLogView-->MsiExec.exe /I{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}
                mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
                Module de compatibilité pour Microsoft Office System 2007-->MsiExec.exe /X{90120000-0020-040C-0000-0000000FF1CE}
                Motorola SM56 Data Fax Modem-->C:\WINDOWS\Motorola\SMSERIAL\sm56unst.exe
                Mozilla Firefox (3.0.4)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
                mPfWiz-->MsiExec.exe /I{90B0D222-8C21-4B35-9262-53B042F18AF9}
                mProSafe-->MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
                mSCfg-->MsiExec.exe /I{829CD169-E692-48E8-9BDE-A3E8D8B65538}
                MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
                MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
                mWlsSafe-->MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
                mZConfig-->MsiExec.exe /I{94658027-9F16-4509-BBD7-A59FE57C3023}
                NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
                PDFCreator-->C:\Program Files\PDFCreator\unins000.exe
                Power4 Gear-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4462AD13-F2AA-4CBD-9F95-293C38EED870}\Setup.exe" -l0x9
                ProtectDisc Helper Driver 10-->C:\Program Files\ProtectDisc Driver Installer\uninstall_v10.exe
                RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
                REALTEK PCIE NIC Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17E2F183-BAC4-4D01-BD7A-59F781E17EFA}\Setup.exe" -l0x40c REMOVE
                Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
                SopCast 3.0.3-->C:\Program Files\SopCast\uninst.exe
                Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                Spyware Doctor 4.0-->C:\Program Files\Spyware Doctor\unins000.exe
                SpywareBlaster v3.5.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
                Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
                System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
                TVAnts 1.0-->C:\PROGRA~1\TVANTS\UNWISE.EXE C:\PROGRA~1\TVANTS\INSTALL.LOG
                USB Disk Win98 Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4E79A62F-7A2D-4058-BCE0-94E6B9E2F162}\Setup.exe"
                USB2.0 1.3M Web Cam-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A87869D7-B133-498C-A347-D9BE109FF6C8}\Setup.exe" -l0x40c
                VideoLAN VLC media player 0.8.6e-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
                Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
                Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
                Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
                Windows XP Media Center Edition 2005 KB919803-->"C:\WINDOWS\$NtUninstallKB919803$\spuninst\spuninst.exe"
                Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
                WinFlash-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DE10AB76-4756-4913-BE25-55D1C1051F9A}\Setup.exe" -l0x9
                Wireless Console 2-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{83F73CB1-7705-49D1-9852-84D839CA2A45}\setup.exe" -l0x9 -removeonly

                ======Security center information======

                AV: Avira AntiVir PersonalEdition
                AV: avast! antivirus 4.8.1296 [VPS 081215-1]

                ======Environment variables======

                "ComSpec"=%SystemRoot%\system32\cmd.exe
                "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Smart Projects\IsoBuster
                "windir"=%SystemRoot%
                "FP_NO_HOST_CHECK"=NO
                "OS"=Windows_NT
                "PROCESSOR_ARCHITECTURE"=x86
                "PROCESSOR_LEVEL"=6
                "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 6, GenuineIntel
                "PROCESSOR_REVISION"=0f06
                "NUMBER_OF_PROCESSORS"=2
                "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                "TEMP"=%SystemRoot%\TEMP
                "TMP"=%SystemRoot%\TEMP

                -----------------EOF-----------------
                0
                1. Contributeur sécurité
                  et aussi tu as avast et antivir????

                  vire avast sinon l'ordi va planter avec deux antivirus:

                  https://www.avast.com/fr-fr/uninstall-utility

                  ensuite fais le message 14
                  0
                  1. oui d'accord sauf un truc, je dois désintaller avast parce que je vais télécharger un autre antivirus ? USBFix et SDfix sont des antivirus ? à quel moment je désintalle avast? après USBfix et avant SDFix ?
                    0
                2. non , pas antivirus . fix specifiques pour certains type d infection.

                  avast enleve le maintenant car peut creer des pb avec l autre antivirus.
                  0
                  1. oula attends : si FIX n'est pas un antivirus alors quel est "l'autre antivirus" car si je désintalle avast alors je n'ai plus aucun antivirus! y a un truc que je pige pas...
                    0
                3. Contributeur sécurité
                  non tu vire avast car tu as aussi l'antivirus antivir!

                  USBFix et SDfix sont des antivirus ?

                  non

                  à quel moment je désintalle avast? après USBfix et avant SDFix ?

                  dès maintenant et tu fais le message 14
                  0
                  1. si je désintalle avast alors je n'ai plus aucun antivirus! y a un truc que je pige pas...

                    et antivir c est pas un antivirus par exemple, donc tu as bien un antivirus d actif sur ton pc apres avoir desinstaller avast.
                    fait le comme indique :avant sd fix et apres usd fix.
                    0
                    1. d'ac je ne savais pas que j'avais antivir

                      alors j'y vais avec USBFix je dois faire 1-nettoyage ?
                      0
                  2. Contributeur sécurité
                    oui nettoyage
                    0
                    1. j'ai posté le rapport USBfix un peu plus haut.

                      en ce qui concerne SDFix c'est super long quand il fait checking process...il ne se passe rien, je dois attendre longtemps avant qu'il me dise d'appuyer sur une touche ?
                      0
                  3. Contributeur sécurité
                    oui il faut attendre
                    0