Page internet qui s'ouvre tout seul

Bonjour,

j'ai des page internet qui s'ouvre tout seul
j'ai fait une analyse antivirus avec avast rien
j'ai fait une analyse en ligne avec norton rien non plus

si qu'elle qu'un peut m'aider d'avance je le remerci

internet exploreur 7 sous vista SP1
Configuration: Windows Vista
Internet Explorer 7.0

28 réponses

Résumé de la discussion

Plusieurs messages décrivent des pages qui s'ouvrent systématiquement sur Windows Vista avec Internet Explorer 7, malgré des analyses antivirus Avast et Norton qui ne détectent rien et sans explication claire. Des outils comme NaviPromo et Catchme ont été utilisés et suggèrent que des résultats pourraient être légitimes, nécessitant une vérification attentive avant toute suppression et parfois une consultation spécialisée. Plusieurs échanges évoquent le contrôle de l'UAC et des mesures de sécurité, avec des indications sur des nettoyages et des outils comme HijackThis pour vérifier les entrées de registre et les éléments au démarrage. En cas de persistance, certains suggèrent un nouvel examen avec HijackThis et un diagnostic approfondi sur un support adapté, afin d'identifier toute persistance résiduelle potentielle précise.

Bobot (l’IA à votre service)
  1. hello,

    fenêtres pop-up, pub diverses, c'est bien ça?

    si c'est le cas Trojan vundo
    0
    1. c'est de page
      comme cdiscont, mc afee, rue ducommerce
      0
      1. Contributeur sécurité
        Bonjour

        Télécharge le fichier d’installation d’Hijackthis en cliquant sur ce lien

        http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

        * Enregistre HJTInstall.exe sur ton bureau.

        * Double-clique sur HJTInstall.exe pour lancer le programme

        Tuto : https://www.malekal.com/tutoriel-hijackthis/
        http://pagesperso-orange.fr/rginformatique/section%20virus/Hijenr.gif
        http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm

        * Accepte la license en cliquant sur le bouton "I Accept"
        * Choisis l'option "Do a system scan and save a log file"
        * Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
        * Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

        * Colle le rapport que tu viens de copier sur ce forum
        0
        1. ok merci voila c fait

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 21:15:20, on 17/12/2008
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v7.00 (7.00.6001.18000)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe
          C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
          C:\Program Files\Google\Google EULA\GoogleEULALauncher.exe
          C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
          C:\Program Files\Toshiba\Toshiba Online Product Information\TOPI.exe
          C:\Program Files\Apoint2K\Apoint.exe
          C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
          C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
          C:\Program Files\Toshiba\SmoothView\SmoothView.exe
          C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
          C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe
          C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
          C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Windows\WindowsMobile\wmdc.exe
          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Microsoft Money\System\mnyexpr.exe
          C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
          C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Users\utilisateur\AppData\Local\azthbsd.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
          C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
          C:\Program Files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe
          C:\Program Files\Apoint2K\ApMsgFwd.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
          c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
          C:\Program Files\Apoint2K\Apntex.exe
          C:\Program Files\Apoint2K\HidFind.exe
          c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
          C:\Windows\System32\mobsync.exe
          C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
          C:\Program Files\IncrediMail\bin\IMApp.exe
          c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
          c:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
          C:\Program Files\Internet Explorer\ieuser.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
          C:\Windows\system32\conime.exe
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
          C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\Windows\system32\SearchFilterHost.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O1 - Hosts: ::1 localhost
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
          O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
          O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
          O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
          O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
          O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
          O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
          O4 - HKLM\..\Run: [cfFncEnabler.exe] cfFncEnabler.exe
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [Google EULA Launcher] c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA
          O4 - HKLM\..\Run: [Toshiba TEMPO] C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
          O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
          O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
          O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
          O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
          O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
          O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
          O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
          O4 - HKLM\..\Run: [HDMICtrlMan] C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
          O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
          O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
          O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
          O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
          O4 - HKCU\..\Run: [toscdspd] TOSCDSPD.EXE
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [azthbsd] "c:\users\utilisateur\appdata\local\azthbsd.exe" azthbsd
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user')
          O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
          O4 - Global Startup: Adobe Gamma Loader.lnk = ?
          O4 - Global Startup: Bluetooth Manager.lnk = ?
          O4 - Global Startup: TOSHIBA Face Recognition Watcher.lnk = C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
          O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
          O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
          O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
          O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
          O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
          O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
          O13 - Gopher Prefix:
          O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
          O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe
          O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
          O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
          O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
          O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe
          O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Service.exe
          O23 - Service: Notebook Performance Tuning Service (TempoMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TempoSVC.exe
          O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
          O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
          O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
          O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
          O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
          O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
          0
          1. Contributeur sécurité
            Désactive le contrôle des comptes utilisateurs
            (tu le réactiveras après ta désinfection):

            * Va dans démarrer puis panneau de configuration
            * Double Clique sur l'icône "Comptes d'utilisateurs"
            * Clique ensuite sur désactiver et valide.

            Tuto : https://forum.malekal.com/viewtopic.php?f=59&t=6517

            https://forum.pcastuces.com/navilog_de_il_mafioso_pour_vista-f31s12.htm

            Télécharge maintenant Navilog1 depuis-ce lien :

            http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

            * Enregistre la cible (du lien) sous... et enregistre-le sur ton bureau.
            Ensuite double clique sur navilog1.exe pour lancer l'installation.
            Une fois l'installation terminée :
            * Fais un Clic-droit sur le raccourci Navilog1 présent sur ton bureau et choisis
            "Exécuter en tant qu'administrateur".

            * Au menu principal, fais le choix 1
            Laisse toi guider et patiente.
            Patiente jusqu'au message :
            *** Analyse Terminée le ..... ***
            * Appuie sur une touche le blocnote va s'ouvrir.
            Copie-colle l'intégralité du rapport dans une réponse.
            * Referme le blocnote
            Le rapport fixnavi.txt est en outre sauvegardé dans %systemdrive%.

            0
            1. Search Navipromo version 3.7.0 commencé le 17/12/2008 à 21:26:04,62

              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
              !!! Postez ce rapport sur le forum pour le faire analyser !!!
              !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

              Outil exécuté depuis C:\Program Files\navilog1

              Mise à jour le 10.12.2008 à 21h00 par IL-MAFIOSO

              Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
              X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU P8400 @ 2.26GHz )
              BIOS : PhoenixBIOS 4.0 Release 6.1
              USER : utilisateur ( Administrator )
              BOOT : Normal boot

              C:\ (Local Disk) - NTFS - Total:117 Go (Free:74 Go)
              D:\ (Local Disk) - NTFS - Total:232 Go (Free:232 Go)
              F:\ (Local Disk) - NTFS - Total:113 Go (Free:108 Go)
              G:\ (CD or DVD)

              Recherche executé en mode normal

              *** Recherche Programmes installés ***

              *** Recherche dossiers dans "C:\Windows" ***

              *** Recherche dossiers dans "C:\Program Files" ***

              *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

              *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

              *** Recherche dossiers dans "C:\ProgramData" ***

              *** Recherche dossiers dans "c:\users\utilis~1\appdata\roaming\micros~1\windows\startm~1\programs" ***

              *** Recherche dossiers dans "C:\Users\utilisateur\AppData\Local\virtualstore\Program Files" ***

              *** Recherche dossiers dans "C:\Users\utilisateur\AppData\Roaming" ***

              *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
              pour + d'infos : http://www.gmer.net

              *** Recherche avec GenericNaviSearch ***
              !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
              !!! A vérifier impérativement avant toute suppression manuelle !!!

              * Recherche dans "C:\Windows\system32" *

              * Recherche dans "C:\Users\utilisateur\AppData\Local\Microsoft" *

              * Recherche dans "C:\Users\utilisateur\AppData\Local\virtualstore\windows\system32" *

              * Recherche dans "C:\Users\utilisateur\AppData\Local" *

              *** Recherche fichiers ***

              *** Recherche clés spécifiques dans le Registre ***
              !! Les clés trouvées ne sont pas forcément infectées !!

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "azthbsd"="\"c:\\users\\utilisateur\\appdata\\local\\azthbsd.exe\" azthbsd"

              *** Module de Recherche complémentaire ***
              (Recherche fichiers spécifiques)

              1)Recherche nouveaux fichiers Instant Access :

              2)Recherche Heuristique :

              * Dans "C:\Windows\system32" :

              * Dans "C:\Users\utilisateur\AppData\Local\Microsoft" :

              * Dans "C:\Users\utilisateur\AppData\Local\virtualstore\windows\system32" :

              * Dans "C:\Users\utilisateur\AppData\Local" :

              azthbsd.exe trouvé !
              azthbsd.dat trouvé !
              azthbsd_nav.dat trouvé !
              azthbsd_navps.dat trouvé !

              3)Recherche Certificats :

              Certificat Egroup absent !
              Certificat Electronic-Group trouvé !
              Certificat Montorgueil absent !
              Certificat OOO-Favorit trouvé !
              Certificat Sunny-Day-Design-Ltd absent !

              4)Recherche autres dossiers et fichiers connus :

              *** Analyse terminée le 17/12/2008 à 21:53:49,52 ***
              0
              1. Contributeur sécurité
                Assure-toi que l'UAC-User Account Control -contrôle des comptes utilisateurs est bien désactivé.

                Clique-droit sur le raccourci Navilog1 sur le Bureau et choisis "Exécuter en tant qu' Administrateur".

                * Sur le menu principal, choisis 2.
                * Suis les instructions et patiente.
                * L'outil va t'informer qu'il redémarrera ton ordinateur.
                * Sauvegarde les documents ouverts, s'il y en a, puis ferme toutes les fenêtres.
                * Appuie sur une touche ainsi que demandé.
                * Si ton ordinateur ne redémarre pas automatiquement, fais le manuellement.
                * Choisis ta session habituelle si nécessaire.
                Patiente jusqu'au message *** Nettoyage terminé le ….*** (il se peut que ça prenne un certain temps).
                Un document du Bloc-notes est créé. Sauvegarde le rapport de manière à le retrouver.
                * Copie/colle le contenu de ce compte-rendu dans ta prochaine réponse.
                Referme le Bloc-notes.
                Ton Bureau va réapparaître.

                Note : Si ton Bureau ne réapparaît pas, presse Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
                Onglet "Processus" > Fichier (menu) > Nouvelle tâche (Exécuter...) > tape explorer et clique sur OK.


                0
                1. voila c fait

                  Clean Navipromo version 3.7.0 commencé le 17/12/2008 à 22:27:07,19

                  Outil exécuté depuis C:\Program Files\navilog1

                  Mise à jour le 10.12.2008 à 21h00 par IL-MAFIOSO

                  Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                  X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU P8400 @ 2.26GHz )
                  BIOS : PhoenixBIOS 4.0 Release 6.1
                  USER : utilisateur ( Administrator )
                  BOOT : Normal boot

                  C:\ (Local Disk) - NTFS - Total:117 Go (Free:74 Go)
                  D:\ (Local Disk) - NTFS - Total:232 Go (Free:232 Go)
                  F:\ (Local Disk) - NTFS - Total:113 Go (Free:108 Go)
                  G:\ (CD or DVD)

                  Mode suppression automatique
                  avec prise en charge résultats Catchme et GNS

                  Nettoyage exécuté au redémarrage de l'ordinateur

                  *** fsbl1.txt non trouvé ***
                  (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                  *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                  * Suppression dans "C:\Windows\System32" *

                  * Suppression dans "C:\Users\utilisateur\AppData\Local\Microsoft" *

                  * Suppression dans "C:\Users\utilisateur\AppData\Local\virtualstore\windows\system32" *

                  * Suppression dans "C:\Users\utilisateur\AppData\Local" *

                  *** Suppression dossiers dans "C:\Windows" ***

                  *** Suppression dossiers dans "C:\Program Files" ***

                  *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                  *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

                  *** Suppression dossiers dans "C:\ProgramData" ***

                  *** Suppression dossiers dans c:\users\utilis~1\appdata\roaming\micros~1\windows\startm~1\programs ***

                  *** Suppression dossiers dans "C:\Users\utilisateur\AppData\Local\virtualstore\Program Files" ***

                  *** Suppression dossiers dans "C:\Users\utilisateur\AppData\Roaming" ***

                  *** Suppression fichiers ***

                  *** Suppression fichiers temporaires ***

                  Nettoyage contenu C:\Windows\Temp effectué !
                  Nettoyage contenu C:\Users\UTILIS~1\AppData\Local\Temp effectué !

                  *** Traitement Recherche complémentaire ***
                  (Recherche fichiers spécifiques)

                  1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                  2)Recherche, création sauvegardes et suppression Heuristique :

                  * Dans "C:\Windows\system32" *

                  * Dans "C:\Users\utilisateur\AppData\Local\Microsoft" *

                  * Dans "C:\Users\utilisateur\AppData\Local\virtualstore\windows\system32" *

                  * Dans "C:\Users\utilisateur\AppData\Local" *

                  azthbsd.exe trouvé !
                  Copie azthbsd.exe réalisée avec succès !
                  azthbsd.exe supprimé !

                  azthbsd.dat trouvé !
                  Copie azthbsd.dat réalisée avec succès !
                  azthbsd.dat supprimé !

                  *** Sauvegarde du Registre vers dossier Safebackup ***

                  sauvegarde du Registre réalisée avec succès !

                  *** Nettoyage Registre ***

                  Nettoyage Registre Ok

                  *** Certificats ***

                  Certificat Egroup absent !
                  Certificat Electronic-Group supprimé !
                  Certificat Montorgueil absent !
                  Certificat OOO-Favorit supprimé !
                  Certificat Sunny-Day-Design-Ltdt absent !

                  *** Recherche autres dossiers et fichiers connus ***

                  *** Nettoyage terminé le 17/12/2008 à 22:31:18,01 ***
                  0
                  1. Contributeur sécurité
                    OK
                    Fais un nouvel Hijackthis stp.
                    0
                    1. voila c fait

                      Search Navipromo version 3.7.0 commencé le 17/12/2008 à 22:38:25,31

                      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                      !!! Postez ce rapport sur le forum pour le faire analyser !!!
                      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                      Outil exécuté depuis C:\Program Files\navilog1

                      Mise à jour le 10.12.2008 à 21h00 par IL-MAFIOSO

                      Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                      X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU P8400 @ 2.26GHz )
                      BIOS : PhoenixBIOS 4.0 Release 6.1
                      USER : utilisateur ( Administrator )
                      BOOT : Normal boot

                      C:\ (Local Disk) - NTFS - Total:117 Go (Free:74 Go)
                      D:\ (Local Disk) - NTFS - Total:232 Go (Free:232 Go)
                      F:\ (Local Disk) - NTFS - Total:113 Go (Free:108 Go)
                      G:\ (CD or DVD)

                      Recherche executé en mode normal

                      *** Recherche Programmes installés ***

                      *** Recherche dossiers dans "C:\Windows" ***

                      *** Recherche dossiers dans "C:\Program Files" ***

                      *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                      *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

                      *** Recherche dossiers dans "C:\ProgramData" ***

                      *** Recherche dossiers dans "c:\users\utilis~1\appdata\roaming\micros~1\windows\startm~1\programs" ***

                      *** Recherche dossiers dans "C:\Users\utilisateur\AppData\Local\virtualstore\Program Files" ***

                      *** Recherche dossiers dans "C:\Users\utilisateur\AppData\Roaming" ***

                      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                      pour + d'infos : http://www.gmer.net

                      *** Recherche avec GenericNaviSearch ***
                      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                      !!! A vérifier impérativement avant toute suppression manuelle !!!

                      * Recherche dans "C:\Windows\system32" *

                      * Recherche dans "C:\Users\utilisateur\AppData\Local\Microsoft" *

                      * Recherche dans "C:\Users\utilisateur\AppData\Local\virtualstore\windows\system32" *

                      * Recherche dans "C:\Users\utilisateur\AppData\Local" *

                      *** Recherche fichiers ***

                      *** Recherche clés spécifiques dans le Registre ***
                      !! Les clés trouvées ne sont pas forcément infectées !!

                      *** Module de Recherche complémentaire ***
                      (Recherche fichiers spécifiques)

                      1)Recherche nouveaux fichiers Instant Access :

                      2)Recherche Heuristique :

                      * Dans "C:\Windows\system32" :

                      * Dans "C:\Users\utilisateur\AppData\Local\Microsoft" :

                      * Dans "C:\Users\utilisateur\AppData\Local\virtualstore\windows\system32" :

                      * Dans "C:\Users\utilisateur\AppData\Local" :

                      3)Recherche Certificats :

                      Certificat Egroup absent !
                      Certificat Electronic-Group absent !
                      Certificat Montorgueil absent !
                      Certificat OOO-Favorit absent !
                      Certificat Sunny-Day-Design-Ltd absent !

                      4)Recherche autres dossiers et fichiers connus :

                      *** Analyse terminée le 17/12/2008 à 22:50:09,33 ***
                      0
                      1. ok dsl voila c fait

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 22:55:13, on 17/12/2008
                        Platform: Windows Vista SP1 (WinNT 6.00.1905)
                        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                        Boot mode: Normal

                        Running processes:
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\system32\conime.exe
                        C:\Windows\notepad.exe
                        C:\Program Files\Windows Defender\MSASCui.exe
                        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe
                        C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
                        C:\Program Files\Google\Google EULA\GoogleEULALauncher.exe
                        C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
                        C:\Program Files\Toshiba\Toshiba Online Product Information\TOPI.exe
                        C:\Program Files\Apoint2K\Apoint.exe
                        C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
                        C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
                        C:\Program Files\Toshiba\SmoothView\SmoothView.exe
                        C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
                        C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe
                        C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                        C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Windows\WindowsMobile\wmdc.exe
                        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                        C:\Windows\ehome\ehtray.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Program Files\Microsoft Money\System\mnyexpr.exe
                        C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
                        C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
                        C:\Program Files\Apoint2K\ApMsgFwd.exe
                        C:\Windows\ehome\ehmsas.exe
                        C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
                        C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
                        C:\Program Files\Apoint2K\Apntex.exe
                        C:\Program Files\Apoint2K\HidFind.exe
                        C:\Windows\System32\mobsync.exe
                        C:\Program Files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe
                        C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
                        C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                        c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
                        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                        C:\Program Files\Windows Sidebar\sidebar.exe
                        C:\Program Files\IncrediMail\bin\IMApp.exe
                        c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
                        c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
                        c:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
                        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
                        C:\Windows\notepad.exe
                        C:\Windows\system32\Taskmgr.exe
                        C:\Windows\explorer.exe
                        C:\Windows\system32\SearchFilterHost.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        O1 - Hosts: ::1 localhost
                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
                        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                        O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                        O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                        O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
                        O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                        O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
                        O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                        O4 - HKLM\..\Run: [cfFncEnabler.exe] cfFncEnabler.exe
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [Google EULA Launcher] c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA
                        O4 - HKLM\..\Run: [Toshiba TEMPO] C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
                        O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                        O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
                        O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                        O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
                        O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                        O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                        O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                        O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                        O4 - HKLM\..\Run: [HDMICtrlMan] C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
                        O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
                        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
                        O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                        O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                        O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
                        O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
                        O4 - HKCU\..\Run: [toscdspd] TOSCDSPD.EXE
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                        O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user')
                        O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                        O4 - Global Startup: Adobe Gamma Loader.lnk = ?
                        O4 - Global Startup: Bluetooth Manager.lnk = ?
                        O4 - Global Startup: TOSHIBA Face Recognition Watcher.lnk = C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
                        O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                        O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                        O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                        O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                        O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
                        O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                        O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
                        O13 - Gopher Prefix:
                        O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                        O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe
                        O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
                        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                        O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
                        O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                        O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
                        O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe
                        O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Service.exe
                        O23 - Service: Notebook Performance Tuning Service (TempoMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TempoSVC.exe
                        O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
                        O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                        O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
                        O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                        O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
                        O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                        O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                        0
                        1. Contributeur sécurité
                          OK, as-tu encore des problèmes ?
                          0
                          1. depuis le redemarrage je n'ai rien eu

                            tu pense que c bon
                            0
                            1. Contributeur sécurité
                              Il y a certaines choses à mettre à jour et un peu d'optimisation à faire.
                              Je te donne tout ça demain matin.
                              0
                              1. ok un grand merci
                                et une bonne soirée
                                0
                                1. Contributeur sécurité
                                  Mets à jour java et Adobe :

                                  mettre à jour java

                                  https://www.java.com/fr/download/manual.jsp

                                  Choisis la première ligne de téléchargement puis installe java.

                                  En fin d'installation, revient sur la page pour vérifier ton installation.

                                  Quand l'installation a réussi, ouvre le panneau de configuration, Ajout/suppression de programmes et supprime les anciennes versions.

                                  Tuto : https://forum.pcastuces.com/default.asp

                                  mettre à jour adobe reader
                                  https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html

                                  Relance HijackThis.

                                  Clique sur Do a System Scan Only et coche les lignes suivantes :

                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                  O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
                                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

                                  Ferme toutes les autres fenêtres, tous les autres programmes. Pas de connection Internet.

                                  Clique sur Fix checked puis clique sur OK
                                  Puis ferme HijackThis.

                                  Tuto : https://forum.pcastuces.com/hijackthis__fixer_les_elements_indesirables-f31s16.htm

                                  0
                                  1. voila c fait

                                    apres j'ai refait une analyse cmme sur le tuto

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 22:55:13, on 17/12/2008
                                    Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\Windows\system32\taskeng.exe
                                    C:\Windows\system32\Dwm.exe
                                    C:\Windows\system32\conime.exe
                                    C:\Windows\notepad.exe
                                    C:\Program Files\Windows Defender\MSASCui.exe
                                    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ItSecMng.exe
                                    C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
                                    C:\Program Files\Google\Google EULA\GoogleEULALauncher.exe
                                    C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
                                    C:\Program Files\Toshiba\Toshiba Online Product Information\TOPI.exe
                                    C:\Program Files\Apoint2K\Apoint.exe
                                    C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
                                    C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
                                    C:\Program Files\Toshiba\SmoothView\SmoothView.exe
                                    C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
                                    C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe
                                    C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                                    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                                    C:\Program Files\iTunes\iTunesHelper.exe
                                    C:\Windows\WindowsMobile\wmdc.exe
                                    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                    C:\Program Files\Windows Sidebar\sidebar.exe
                                    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
                                    C:\Windows\ehome\ehtray.exe
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                    C:\Program Files\Microsoft Money\System\mnyexpr.exe
                                    C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
                                    C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
                                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
                                    C:\Program Files\Apoint2K\ApMsgFwd.exe
                                    C:\Windows\ehome\ehmsas.exe
                                    C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
                                    C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
                                    C:\Program Files\Apoint2K\Apntex.exe
                                    C:\Program Files\Apoint2K\HidFind.exe
                                    C:\Windows\System32\mobsync.exe
                                    C:\Program Files\Toshiba\HDMICtrlMan\HCMSoundChanger.exe
                                    C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe
                                    C:\Program Files\Internet Explorer\iexplore.exe
                                    c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
                                    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                                    c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
                                    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                    C:\Program Files\Windows Sidebar\sidebar.exe
                                    C:\Program Files\IncrediMail\bin\IMApp.exe
                                    c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
                                    c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
                                    c:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
                                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
                                    C:\Windows\notepad.exe
                                    C:\Windows\system32\Taskmgr.exe
                                    C:\Windows\explorer.exe
                                    C:\Windows\system32\SearchFilterHost.exe
                                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                    O1 - Hosts: ::1 localhost
                                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
                                    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                                    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                                    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                                    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
                                    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                                    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
                                    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                                    O4 - HKLM\..\Run: [cfFncEnabler.exe] cfFncEnabler.exe
                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                    O4 - HKLM\..\Run: [Google EULA Launcher] c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe IE PA
                                    O4 - HKLM\..\Run: [Toshiba TEMPO] C:\Program Files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe
                                    O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                                    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
                                    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                                    O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
                                    O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                                    O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                                    O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                                    O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                                    O4 - HKLM\..\Run: [HDMICtrlMan] C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
                                    O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                                    O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
                                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
                                    O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                                    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                    O4 - HKLM\..\Run: [Windows Mobile Device Center] %windir%\WindowsMobile\wmdc.exe
                                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
                                    O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                                    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe"
                                    O4 - HKCU\..\Run: [toscdspd] TOSCDSPD.EXE
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                    O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (User 'Default user')
                                    O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                                    O4 - Global Startup: Adobe Gamma Loader.lnk = ?
                                    O4 - Global Startup: Bluetooth Manager.lnk = ?
                                    O4 - Global Startup: TOSHIBA Face Recognition Watcher.lnk = C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
                                    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
                                    O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                                    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                                    O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
                                    O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
                                    O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
                                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                                    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
                                    O13 - Gopher Prefix:
                                    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                                    O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe
                                    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
                                    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                    O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
                                    O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                                    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                                    O23 - Service: O2Micro Flash Memory Card Service (o2flash) - O2Micro International - C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe
                                    O23 - Service: SmartFaceVWatchSrv - Toshiba - C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe
                                    O23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Service.exe
                                    O23 - Service: Notebook Performance Tuning Service (TempoMonitoringService) - Toshiba Europe GmbH - C:\Program Files\Toshiba TEMPRO\TempoSVC.exe
                                    O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
                                    O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                                    O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
                                    O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                                    O23 - Service: TOSHIBA SMART Log Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
                                    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                                    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                    0
                                    1. Contributeur sécurité
                                      Bien, on complète par un grand nettoyage :

                                      Imprime ces instructions ou sauvegarde les sur ton Bureau car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                                      Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton bureau à partir de ce lien :

                                      https://download.cnet.com/Malwarebytes/3000-8022_4-10804572.html

                                      A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

                                      Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

                                      Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

                                      MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :

                                      Dans l'onglet analyse, vérifie que "Exécuter une analyse rapide" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

                                      MBAM analyse ton ordinateur. L'analyse peut prendre un certain teps. Il suffit de vérifier de temps en temps son avancement.

                                      A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

                                      Si des malwares ont été détectés, leur liste s'affiche.
                                      En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

                                      MBAM va ouvrir le bloc-notes et y copier le rapport d'analyse. Ferme le bloc-note. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

                                      Ferme MBAM en cliquant sur Quitter.

                                      Poste le rapport sur le forum.

                                      0
                                      1. voila c fait

                                        Malwarebytes' Anti-Malware 1.31
                                        Version de la base de données: 1512
                                        Windows 6.0.6001 Service Pack 1

                                        18/12/2008 14:12:35
                                        mbam-log-2008-12-18 (14-12-35).txt

                                        Type de recherche: Examen rapide
                                        Eléments examinés: 55015
                                        Temps écoulé: 2 minute(s), 44 second(s)

                                        Processus mémoire infecté(s): 0
                                        Module(s) mémoire infecté(s): 0
                                        Clé(s) du Registre infectée(s): 1
                                        Valeur(s) du Registre infectée(s): 0
                                        Elément(s) de données du Registre infecté(s): 0
                                        Dossier(s) infecté(s): 0
                                        Fichier(s) infecté(s): 0

                                        Processus mémoire infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Module(s) mémoire infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Clé(s) du Registre infectée(s):
                                        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4} (Trojan.BHO) -> Quarantined and deleted successfully.

                                        Valeur(s) du Registre infectée(s):
                                        (Aucun élément nuisible détecté)

                                        Elément(s) de données du Registre infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Dossier(s) infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Fichier(s) infecté(s):
                                        (Aucun élément nuisible détecté)
                                        0
                                        • 1
                                        • 2