Infection trojan

Résolu
Bonjour, mon pc est infecté par un trojan appellé tr/trash.gen. je ne sais comment faire pour le supprimé . quelqu'un pourrais m'aidé SVP merci . mon antivirus est antivir personal .
Configuration: Windows XP
Internet Explorer 6.0

26 réponses

Résumé de la discussion

La discussion porte sur une infection par le trojan tr/trash.gen sur Windows XP avec Internet Explorer 6 et l’antivirus Avira, et sur les méthodes pour supprimer ce malware efficacement. Plusieurs répondants recommandent d’utiliser OTMoveIt3 après avoir temporairement désactivé l’antivirus, afin de déplacer ou supprimer les éléments résistants et d’obtenir un rapport des fichiers touchés. D'autres privilégient un nettoyage en profondeur avec HijackThis, CCleaner et MBAM, puis la purge des données de navigation et la réinitialisation de la restauration système, avec des mises à jour et un navigateur plus sûr. Les rapports démontrent des éléments modifiant les pages de démarrage, des BHO et des clés Run, ce qui souligne l’importance de surveiller les extensions et les programmes auto-démarrants.

Bobot (l’IA à votre service)
  1. Modérateur
    Tu as le rapport de ToolsCleaner ?
    0
    1. Modérateur
      1/

      ---> Désinstalle HijackThis.

      ---> Télécharge ToolsCleaner2 sur ton Bureau.
      * Double-clique sur ToolsCleaner2.exe pour le lancer.
      * Clique sur Recherche et laisse le scan agir.
      * Clique sur Suppression pour finaliser.
      * Tu peux, si tu le souhaites, te servir des Options Facultatives.
      * Clique sur Quitter pour obtenir le rapport.
      * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

      2/

      ---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
      * Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
      * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
      * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs (Sauvegarde la base de registre).

      3/

      ---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger :
      http://www.infos-du-net.com/forum/272480-11-desactiver-activer-restauration-systeme

      ---> Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème :
      https://www.vulgarisation-informatique.com/creer-point-restauration.php

      4/

      Conserve MBAM. Il te servira à scanner les fichiers douteux en complément de l'antivirus et scanne le disque dur régulièrement.

      Comme navigateur, utilise plutôt Mozilla Firefox qu'Internet Explorer. Tu peux utiliser l'extension Noscript pour plus de sécurité.

      Vérifie que les mises à jour automatiques sont bien activées (Menu Démarrer, clique droit sur Poste de travail, Onglet Mises à jour automatiques).

      Tu peux aussi modifier le fichier Hosts pour améliorer la sécurité de ton PC :
      http://www.commentcamarche.net/faq/sujet 5993 modifier son fichier hosts
      https://blog.sosordi.net/category/articles

      Par rapport au P2P :
      http://www.libellules.ch/...

      Voici un dossier complet (A lire avec Adobe Reader ou Foxit Reader) :
      https://www.malekal.com/fichiers/projetantimalwares/prevention-protection.pdf

      Sois plus vigilant sur Internet ;)
      0
      1. re destrio,
        je te remercie pour toute l'aide apportéea la bonne marche de mon pc . MERCI POUR TOUT

        A++++
        0
    2. voici le nouveau rapport que tu a demandé :

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 18:19:48, on 22/12/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16762)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\CDBurnerXP\NMSAccessU.exe
      C:\WINDOWS\system32\oodag.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Analog Devices\Core\smax4pnp.exe
      C:\Program Files\Analog Devices\SoundMAX\smax4.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\system32\LVCOMSX.EXE
      C:\Program Files\Logitech\Video\LogiTray.exe
      C:\WINDOWS\System32\wbem\wmiapsrv.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Picasa2\PicasaMediaDetector.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Documents and Settings\bernard\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
      C:\Program Files\TomTom HOME 2\HOMERunner.exe
      C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
      C:\Program Files\WinZip\WZQKPICK.EXE
      C:\Documents and Settings\bernard\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
      C:\Documents and Settings\bernard\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Logitech\Video\FxSvr2.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\NOTEPAD.EXE
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;localhost
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\Core\smax4pnp.exe"
      O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray
      O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [Picasa Media Detector] "C:\Program Files\Picasa2\PicasaMediaDetector.exe"
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\bernard\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
      O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
      O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
      O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
      O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - S-1-5-18 Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\bernard\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe (User 'SYSTEM')
      O4 - .DEFAULT Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\bernard\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe (User 'Default user')
      O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\bernard\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
      O4 - Global Startup: Barre d'état système d'ATI CATALYST.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
      O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?3623e2aa3b554db39fcc431f1b66e113
      O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?3623e2aa3b554db39fcc431f1b66e113
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
      O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
      O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
      O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
      O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
      O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
      O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://ma-config.com/activex/hardwaredetection_3_0_2_0.cab
      O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - http://abonnement.aliceadsl.fr/configurateur/AccountHelper.cab
      O16 - DPF: {92ABACFE-EF6E-42C7-A824-D50A914B5B70} - http://dx.mastacash.com/loader.cab
      O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} (CamfrogWEB Advanced Unicode Control) - https://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
      O17 - HKLM\System\CCS\Services\Tcpip\..\{81143EEB-E2E3-4868-B33E-8B4E1D50676F}: NameServer = 213.36.80.1
      O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Ares Chatroom server (AresChatServer) - Unknown owner - C:\Program Files\Ares\chatServer.exe (file missing)
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
      O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
      O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
      0
      1. Modérateur
        Alors ne la coche pas.
        0
        1. re destrio,

          quand je fait :do a system scan only, je n'ai pas de ligne : R3 default URLsearchHOOK is missing
          0
          1. Modérateur
            Regarde dans ce lien, il y a la manip' :
            http://www.technos-sources.com/tutorial-installer-ie7-apres-avoir-installe-sp3-windows-xp-98.aspx
            0
            1. slt destrio5,

              desolé pour hier ,je suis parti precipitement. tu me dit de mettre internet explorer a jour, comment faut il faire ? que dois je faire ?

              et quelle modif dois je faire ?
              0
              1. Modérateur
                1/

                ---> Désinstalle les programmes suivants :
                - Java 6 Update 3
                - Java 6 Update 5
                - Java 6 Update 7

                ---> Mets à jour Internet Explorer :
                http://www.microsoft.com/downloads/details.aspx?FamilyId=9AE91EBE-3385-447C-8A30-081805B2F90B&displaylang=fr

                Tu as le SP3 donc tu as une modification à faire pour mettre à jour Internet Explorer :
                http://www.technos-sources.com/tutorial-installer-ie7-apres-avoir-installe-sp3-windows-xp-98.aspx

                2/

                ---> Relance HijackThis et choisis Do a system scan only.

                ---> Coche la case qui est devant la ligne suivante :

                R3 - Default URLSearchHook is missing

                ---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.

                ---> Redémarre ton PC et poste un nouveau rapport HijackThis.
                0
                1. voici les deux rapport:

                  Logfile of random's system information tool 1.05 (written by random/random)
                  Run by bernard at 2008-12-21 20:50:33
                  Microsoft Windows XP Professionnel Service Pack 3
                  System drive C: has 59 GB (75%) free of 79 GB
                  Total RAM: 1023 MB (57% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 20:50:36, on 21/12/2008
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Program Files\CDBurnerXP\NMSAccessU.exe
                  C:\WINDOWS\system32\oodag.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\Program Files\Analog Devices\Core\smax4pnp.exe
                  C:\Program Files\Analog Devices\SoundMAX\smax4.exe
                  C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\WINDOWS\system32\LVCOMSX.EXE
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\iPod\bin\iPodService.exe
                  C:\WINDOWS\explorer.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\WINDOWS\System32\wbem\wmiapsrv.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\Documents and Settings\bernard\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Documents and Settings\bernard\Local Settings\Temporary Internet Files\Content.IE5\0963CP6N\RSIT[1].exe
                  C:\Program Files\Trend Micro\HijackThis\bernard.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://portail.free.fr/
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;localhost
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - Default URLSearchHook is missing
                  O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                  O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                  O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\Core\smax4pnp.exe"
                  O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray
                  O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                  O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                  O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                  O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [Picasa Media Detector] "C:\Program Files\Picasa2\PicasaMediaDetector.exe"
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\bernard\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
                  O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
                  O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
                  O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                  O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                  O4 - S-1-5-18 Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\bernard\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe (User 'SYSTEM')
                  O4 - .DEFAULT Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\bernard\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe (User 'Default user')
                  O4 - Startup: Outil de notification Live Search.lnk = C:\Documents and Settings\bernard\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
                  O4 - Global Startup: Barre d'état système d'ATI CATALYST.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
                  O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                  O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                  O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                  O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                  O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?3623e2aa3b554db39fcc431f1b66e113
                  O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?3623e2aa3b554db39fcc431f1b66e113
                  O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                  O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                  O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
                  O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                  O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                  O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
                  O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
                  O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://ma-config.com/activex/hardwaredetection_3_0_2_0.cab
                  O16 - DPF: {8F48147B-78D9-40F9-ACC0-BDDE59B246F4} (AccountHelper Class) - http://abonnement.aliceadsl.fr/configurateur/AccountHelper.cab
                  O16 - DPF: {92ABACFE-EF6E-42C7-A824-D50A914B5B70} - http://dx.mastacash.com/loader.cab
                  O16 - DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} (CamfrogWEB Advanced Unicode Control) - https://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{81143EEB-E2E3-4868-B33E-8B4E1D50676F}: NameServer = 213.36.80.1
                  O23 - Service: Planificateur Avira AntiVir Personal - Free Antivirus (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Ares Chatroom server (AresChatServer) - Unknown owner - C:\Program Files\Ares\chatServer.exe (file missing)
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                  O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                  O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                  O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
                  0
                  1. Modérateur
                    ---> Supprime le dossier RSIT situé dans C:\

                    ---> Refais un scan RSIT et poste les deux rapports.
                    0
                    1. voici le rapport :

                      Malwarebytes' Anti-Malware 1.31
                      Version de la base de données: 1528
                      Windows 5.1.2600 Service Pack 3

                      21/12/2008 20:37:35
                      mbam-log-2008-12-21 (20-37-35).txt

                      Type de recherche: Examen rapide
                      Eléments examinés: 59334
                      Temps écoulé: 3 minute(s), 17 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 0
                      Valeur(s) du Registre infectée(s): 0
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 0

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Valeur(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      (Aucun élément nuisible détecté)
                      0
                      1. Modérateur
                        ---> Supprime JavaRa.

                        ---> Désinstalle AD-Remover et UsbFix.

                        ---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
                        ---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
                        ---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
                        ---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
                        ---> Sélectionne Exécuter un examen rapide.
                        ---> Clique sur Rechercher. L'analyse démarre.

                        A la fin de l'analyse, un message s'affiche :

                        L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.

                        ---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
                        ---> Ferme tes navigateurs.
                        Si des malwares ont été détectés, clique sur Afficher les résultats.
                        ---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
                        ---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
                        0
                        1. Modérateur
                          Tu n'as rien à payer, je ne sais pas ce que tu as fait.

                          Tu peux télécharger JavaRa ici :
                          http://sd-1.archive-host.com/membres/up/3288717712384394/JavaRa.zip
                          0
                          1. voici le rapport :

                            JavaRa 1.12 Removal Log.

                            Report follows after line.

                            ------------------------------------

                            The JavaRa removal process was started on Sun Dec 21 19:38:07 2008

                            Found and removed: C:\Program Files\Java\jre1.6.0_03

                            Found and removed: C:\Program Files\Java\jre1.6.0_05

                            Found and removed: C:\Program Files\Java\jre1.6.0_07

                            JavaRa 1.12 Removal Log.

                            Report follows after line.

                            ------------------------------------

                            The JavaRa removal process was started on Sun Dec 21 19:48:57 2008
                            0
                        2. Modérateur
                          ---> Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries sur ton Bureau :
                          * Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
                          * Double-clique sur le répertoire JavaRa.
                          * Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
                          * Clique sur Search For Updates.
                          * Sélectionne Update Using jucheck.exe puis clique sur Search.
                          * Autorise le processus à se connecter s'il le demande, clique sur Install et suis les instructions d'installation qui prennent quelques minutes.
                          * L'installation est terminée, reviens à l'écran de JavaRa et clique sur Remove Older Versions.
                          * Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur Ok, puis une deuxième fois sur Ok.
                          * Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
                          * Ferme l'application.
                          Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.
                          0
                          1. re destrio , dans l'installation de javara zip il faut que j'introduide un code ,pour l'avoir il faut que j'envoie un sms ?je le fait ??
                            0
                        3. voici le rapport :

                          -------------- UsbFix V2.413.5 ---------------

                          * User : bernard - BERNARD-8P1PK15
                          * Outils mis a jours le 17/12/2008 par Chiquitine29 et Chimay8
                          * Recherche effectuée à 19:17:01 le 21/12/2008
                          * Windows Xp - Internet Explorer 6.0.2900.5512

                          --------------- [ Processus actifs ] ----------------

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          C:\Program Files\CDBurnerXP\NMSAccessU.exe
                          C:\WINDOWS\system32\oodag.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\system32\userinit.exe
                          C:\WINDOWS\System32\wbem\wmiprvse.exe
                          C:\WINDOWS\System32\wbem\wmiprvse.exe
                          C:\DOCUME~1\bernard\LOCALS~1\Temp\1.tmp\b2e.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\Program Files\Analog Devices\Core\smax4pnp.exe
                          C:\Program Files\Analog Devices\SoundMAX\smax4.exe
                          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                          C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                          C:\Program Files\iTunes\iTunesHelper.exe
                          C:\WINDOWS\system32\LVCOMSX.EXE
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\wbem\wmiapsrv.exe
                          C:\Program Files\iPod\bin\iPodService.exe

                          --------------- [ Informations lecteurs ] ----------------

                          C: - Lecteur fixe

                          --------------- [ Lecteur C ] ----------------

                          C: - Lecteur fixe

                          +- Listing des fichiers présents :

                          [09/08/2007 01:00][--a------] C:\AUTOEXEC.BAT
                          [09/08/2007 01:08][-rahs----] C:\NTDETECT.COM
                          [16/08/2008 10:24][-rahs----] C:\boot.ini
                          [07/12/2008 17:14][--a------] C:\hcwclear.txt
                          [07/12/2008 17:14][--a------] C:\lopR.txt
                          [07/12/2008 17:14][--a------] C:\TB.txt
                          [07/12/2008 17:14][--a------] C:\UsbFix.txt
                          [09/08/2007 01:00][--a------] C:\CONFIG.SYS
                          [09/08/2007 01:00][--a------] C:\IO.SYS
                          [09/08/2007 01:00][--a------] C:\MSDOS.SYS
                          [09/08/2007 01:00][--a------] C:\pagefile.sys

                          --------------- [ Registre / Startup ] ----------------

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                          "Search Page"=""
                          "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                          swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          Picasa Media Detector="C:\Program Files\Picasa2\PicasaMediaDetector.exe"
                          MsnMsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                          CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
                          Google Update="C:\Documents and Settings\bernard\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
                          TomTomHOME.exe="C:\Program Files\TomTom HOME 2\HOMERunner.exe"
                          ares="C:\Program Files\Ares\Ares.exe" -h
                          LDM=C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                          LogitechSoftwareUpdate="C:\Program Files\Logitech\Video\ManifestEngine.exe" boot

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                          SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
                          SoundMAXPnP="C:\Program Files\Analog Devices\Core\smax4pnp.exe"
                          SoundMAX="C:\Program Files\Analog Devices\SoundMAX\smax4.exe" /tray
                          NeroCheck=C:\WINDOWS\system32\NeroCheck.exe
                          High Definition Audio Property Page Shortcut=HDAShCut.exe
                          ATICCC="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
                          Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                          avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                          AppleSyncNotifier=C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                          QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
                          iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
                          LVCOMSX=C:\WINDOWS\system32\LVCOMSX.EXE
                          LogitechVideoRepair=C:\Program Files\Logitech\Video\ISStart.exe
                          LogitechVideoTray=C:\Program Files\Logitech\Video\LogiTray.exe
                          HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                          <NO NAME>=
                          HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
                          Installed=1
                          <NO NAME>=
                          HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
                          NoChange=1
                          Installed=1
                          <NO NAME>=
                          HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
                          Installed=1
                          <NO NAME>=

                          --------------- [ Registre / Mountpoint2 ] ----------------

                          Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4fbd6d97-8b28-11dd-81d5-0015f252dbe2}\Shell\AutoRun\command
                          Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ddb7cb98-9019-11dd-81de-0015f252dbe2}\Shell\AutoRun\command

                          --------------- [ Nettoyage des disques ] ----------------

                          Supprimé ! - [21/12/2008 19:17][--a------] "C:\WINDOWS\system32\drivers\mrxdavv.sys"

                          --------------- [ Resumé ] ----------------

                          -> /!\ Le resultat doit etre interprété par un spécialiste /!\

                          [09/08/2007 01:00][--a------] C:\AUTOEXEC.BAT
                          [09/08/2007 01:08][-rahs----] C:\NTDETECT.COM
                          [16/08/2008 10:24][-rahs----] C:\boot.ini

                          --------------- ! Fin du rapport ! ----------------
                          0
                          1. Modérateur
                            --> Télécharge UsbFix (de Chiquitine29) sur ton Bureau :
                            http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe

                            --> Lance l'installation avec les paramètres par défaut.

                            --> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir.

                            --> Double-clique sur le raccourci UsbFix sur ton Bureau.

                            --> Choisis l'option 1 (Nettoyage).

                            --> Le PC va redémarrer.

                            --> Après redémarrage, poste le rapport UsbFix.txt

                            Note : le rapport UsbFix.txt est sauvegardé à la racine du disque.

                            (Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide)
                            0
                            1. voici le rapport:

                              ========== PROCESSES ==========
                              Process explorer.exe killed successfully.
                              ========== SERVICES/DRIVERS ==========
                              Service Planificateur LiveUpdate automatique stopped successfully.
                              Service Planificateur LiveUpdate automatique deleted successfully.
                              ========== COMMANDS ==========
                              File delete failed. C:\DOCUME~1\bernard\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXAB8DYJ\CAG92PO5.36&u_h=1024&u_w=1280&u_ah=990&u_aw=1280&u_cd=32&u_tz=60&u_his=49&u_java=true&dtd=15 scheduled to be deleted on reboot.
                              File delete failed. C:\DOCUME~1\bernard\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXAB8DYJ\CAXJ7LFD.36&u_h=1024&u_w=1280&u_ah=990&u_aw=1280&u_cd=32&u_tz=60&u_his=49&u_java=true&dtd=31 scheduled to be deleted on reboot.
                              File delete failed. C:\DOCUME~1\bernard\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\CHURCDAJ\affich-10020767-infection-trojan[1] scheduled to be deleted on reboot.
                              File delete failed. C:\DOCUME~1\bernard\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                              File delete failed. C:\DOCUME~1\bernard\LOCALS~1\Temp\Historique\History.IE5\index.dat scheduled to be deleted on reboot.
                              File delete failed. C:\DOCUME~1\bernard\LOCALS~1\Temp\Cookies\index.dat scheduled to be deleted on reboot.
                              File delete failed. C:\DOCUME~1\bernard\LOCALS~1\Temp\IadHide4.dll scheduled to be deleted on reboot.
                              File delete failed. C:\DOCUME~1\bernard\LOCALS~1\Temp\Perflib_Perfdata_328.dat scheduled to be deleted on reboot.
                              User's Temp folder emptied.
                              User's Temporary Internet Files folder emptied.
                              User's Internet Explorer cache folder emptied.
                              Local Service Temp folder emptied.
                              File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                              Local Service Temporary Internet Files folder emptied.
                              File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_14c.dat scheduled to be deleted on reboot.
                              Windows Temp folder emptied.
                              Java cache emptied.
                              FireFox cache emptied.
                              Temp folders emptied.
                              Explorer started successfully

                              OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12212008_185505

                              Files moved on Reboot...
                              C:\DOCUME~1\bernard\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXAB8DYJ\CAG92PO5.36&u_h=1024&u_w=1280&u_ah=990&u_aw=1280&u_cd=32&u_tz=60&u_his=49&u_java=true&dtd=15 moved successfully.
                              C:\DOCUME~1\bernard\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\OXAB8DYJ\CAXJ7LFD.36&u_h=1024&u_w=1280&u_ah=990&u_aw=1280&u_cd=32&u_tz=60&u_his=49&u_java=true&dtd=31 moved successfully.
                              C:\DOCUME~1\bernard\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\CHURCDAJ\affich-10020767-infection-trojan[1] moved successfully.
                              C:\DOCUME~1\bernard\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\index.dat moved successfully.
                              C:\DOCUME~1\bernard\LOCALS~1\Temp\Historique\History.IE5\index.dat moved successfully.
                              C:\DOCUME~1\bernard\LOCALS~1\Temp\Cookies\index.dat moved successfully.
                              DllUnregisterServer procedure not found in C:\DOCUME~1\bernard\LOCALS~1\Temp\IadHide4.dll
                              C:\DOCUME~1\bernard\LOCALS~1\Temp\IadHide4.dll NOT unregistered.
                              C:\DOCUME~1\bernard\LOCALS~1\Temp\IadHide4.dll moved successfully.
                              File C:\DOCUME~1\bernard\LOCALS~1\Temp\Perflib_Perfdata_328.dat not found!
                              File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
                              File C:\WINDOWS\temp\Perflib_Perfdata_14c.dat not found!
                              0
                              1. Modérateur
                                ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

                                ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
                                http://oldtimer.geekstogo.com/OTMoveIt3.exe

                                ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

                                ---> Copie (Ctrl+C) le texte suivant ci-dessous :

                                :processes
                                explorer.exe

                                :services
                                Planificateur LiveUpdate automatique

                                :commands
                                [purity]
                                [emptytemp]
                                [start explorer]
                                [reboot]

                                ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                                ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                                Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                                Accepte en cliquant sur YES.

                                ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                                Le nom du rapport correspond au moment de sa création : date_heure.log
                                0
                                1. re destrio je sais pas si c'est terminé mais j'attend une reponse pour savoir ?? merci pour tout
                                  0
                                  • 1
                                  • 2