Probleme non identifié

Bonjour,

Ya quelques jours, mon ordi a été infectée et j'ai trouvé aucuns moyens afin de regler le probleme c'est pourquoi je poste un message ici en esperant une reponse qui maidera..

Lorsque j'ouvre mon ordinateur, elle est très lente du moment ou windows xp se charge. Quand j'ouvre ma session c'est encore pire. Windows prend 15 minutes avant d'ouvrir, en comptant les fichiers qui ouvrent au demarrage (que j'ai réduis a antivirus, firewall et antispyware). Svchost plante toujours, Generic Host Process aussi. Une fois que mon ordi est completement ouverte, la moindre action prend le triple du temps normal et tout est au ralenti. J'ai eu beau faire des scans avec Bitdefender, ca donne rien, seulement quelques fois il attrape des trojan mais ca ne regle jamais rien. Spybot a supprimé tout ce qu'il detectait. ZoneAlarm bloque en permanence des connections venant de in-addr.arpa, et me parle de multidiffusion et de connexions entrantes. J'ai meme eu des apparitions de Sysfader. A lorigine jetais sur une connection sans fil, mais apres environ 20 minutes d'utilisation, elle plante et quand je veux choisir un reseau sans fil, windows me dit qu'un autre programme gere ma connexion.

J'apprecierais avoir des conseils..
Configuration: Windows XP
Internet Explorer 7.0

23 réponses

Résumé de la discussion

Un ordinateur sous Windows XP est fortement ralenti après une infection présumée, Svchost plantant et le processus Generic Host bloquant le démarrage et rendant chaque action extrêmement lente. Plusieurs outils antivirus et antimalware ont été utilisés, dont Bitdefender et Spybot, mais les scans n’ont pas résolu le problème et des alertes ZoneAlarm sur des connexions entrantes persistent. Des conseils recommandent d’employer HijackThis pour diagnostiquer sans modifier les lignes, puis de déconnecter le PC et d’analyser les rapports selon un guide étape par étape. D’autres retours indiquent qu’en désactivant TeaTimer de Spybot et en utilisant SuperAntiSpyware, l’ordinateur gagne en stabilité, bien que l’origine des connexions entrantes reste à identifier.

Bobot (l’IA à votre service)
  1. ok tu pourras me faire ceci en mode sans echec aussi stp ? :

    ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

    ---> Copie (Ctrl+C) le texte suivant ci-dessous :



    :processes
    explorer.exe

    :services
    :files
    C:\WINDOWS\system32\GameMon.des.exe

    :reg
    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]


    ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

    ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

    Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
    Accepte en cliquant sur YES.

    ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
    Le nom du rapport correspond au moment de sa création : date_heure.log
    1. ========== PROCESSES ==========
      Process explorer.exe killed successfully.
      ========== SERVICES/DRIVERS ==========
      Service\Driver nProtect GameGuard Service not found.
      Service\Driver nProtect GameGuard Service not found.
      Service\Driver nProtect GameGuard Service not found.
      Service\Driver npggsvc deleted successfully.
      ========== FILES ==========
      File/Folder C:\WINDOWS\system32\GameMon.des.exe not found.
      ========== REGISTRY ==========
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\\ deleted successfully.
      HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\"C:\WINDOWS\system32\sessmgr.exe"|"C:\WINDOWS\system32\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019" /E : value set successfully!
      Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bc3211af-0508-11de-a0f1-001cf0633050}\\ deleted successfully.
      ========== COMMANDS ==========
      User's Temp folder emptied.
      User's Temporary Internet Files folder emptied.
      User's Internet Explorer cache folder emptied.
      Local Service Temp folder emptied.
      File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
      Local Service Temporary Internet Files folder emptied.
      File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_118.dat scheduled to be deleted on reboot.
      Windows Temp folder emptied.
      Java cache emptied.
      FireFox cache emptied.
      Temp folders emptied.
      Explorer started successfully

      OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 03212009_015055

      Files moved on Reboot...
      File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
      File C:\WINDOWS\temp\Perflib_Perfdata_118.dat not found!

      Voila pour ce rapport, SDFix faisait son scan antimalware.. je lai laissé faire durant 1h30 environ puis jai ouvert le gestionnaire de tache et jai vu quil nutilisait plus de memoire donc jai cliqué sur x. Windows a demarré et SDFix s'est relancé a la meme etape ou il etait.. je vais le laisser faire durant la nuit
      1. Deja, ca a fait un enorme changement, jte remercie enormement
        Mais la.. mon ordi reste a : Finishing Malware Check, Please Be Patient As This May Take Several Minutes
        Ca me dit que ca va prendre plusieurs minutes... mais la ca dur depuis plus que 45 minutes, cest normal ?
        1. Dakore, voici le deuxieme rapport de Ad remover apres avoir faite le clean

          ------- LOGFILE OF AD-REMOVER 1.1.1.9 | ONLY XP/VISTA -------

          Updated by C_XX on 18/03/2009 at 21:20 - AdRemover.contact@gmail.com

          **** LIMITED TO ****

          Boonty/BoontyGames
          Eorezo
          Infected Poker Softwares
          FunWebProduct/MyWay/MyWebSearch
          It's TV
          Sweetim
          Other Adwares

          ********************

          Start at: 1:37:15, Sam 2009-03-21 | Boot mode: Normal Boot
          Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
          Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
          Computer Name: ERMENEGILLE
          Current User: gui - Administrator
          Drive(s):
          - C:\ (File System: NTFS)
          System Drive: C:\
          Windows Directory: C:\WINDOWS\
          System Directory: C:\WINDOWS\System32\

          --- Running Processes: 30

          (!) ---- IE start pages/Tabs reset

          +-----------------| Boonty/Boonty Games Elements Deleted :

          .
          .

          +-----------------| Eorezo Elements Deleted :

          .

          +-----------------| Infected Poker Softwares Elements Deleted :

          .

          +-----------------| FunWebProducts/MyWay/MyWebSearch Elements Deleted :

          .
          .

          +-----------------| It's TV Elements Deleted :

          .

          +-----------------| Sweetim Elements Deleted :

          .

          ============ Other Adwares Deleted ============

          .
          .
          C:\Documents and Settings\gui\Cookies\gui@atdmt[2].txt

          (!) ---- Temp files deleted.
          (!) ---- Recycle bin emptied in all drives.

          +-----------------| Added Scan :

          ---- Mozilla FireFox Version 3.0.7 ----

          ProfilePath: j0u0oj0q.default (gui)
          .
          .
          .
          .
          .
          .

          ---- Internet Explorer Version 7.0.5730.13 ----

          +-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

          Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
          Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
          Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

          +-[HKEY_USERS\S-1-5-21-448539723-1532298954-839522115-1003\..\Internet Explorer\Main]

          Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
          Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
          Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

          +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

          Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
          Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Search bar: hxxp://search.msn.com/spbasic.htm
          Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Start page: hxxp://fr.msn.com/

          +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

          Tabs: hxxp://ieframe.dll/tabswelcome.htm

          +---------------------------------------------------------------------------+

          3008 Byte(s) - C:\Ad-Report-Clean-20.9-.3-21.log
          2271 Byte(s) - C:\Ad-Report-Scan-20.9-.3-20.log

          1 File(s) - C:\Program Files\Ad-remover\TOOLS\BACKUP
          1 File(s) - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

          End at: 1:47:23 | 2009-03-21
          .
          +-----------------| E.O.F - 74 Lines
          .

          J'ai fais les manipulations avec OTMoveit3 et je fais de ce pas les manipulations avec SDfix
          1. Désactiver le TeaTimer de Spybot (Merci à Nico):

            Pour désactiver le TeaTimer :
            => Ouvrir Spybot S&D
            => Dans le menu "Mode", séléctionner le mode avancé.
            => Une fenêtre demande confirmation cliquer sur "oui".
            => Une fois le mode avancé actif, ouvrir l'onglet "Outils".
            => Cliquer sur Résident.
            => La partie Résident comporte deux lignes qui sont normalement cochées :
            *Résident "SDHelper" (bloqueur de téléchargements nuisibles pour Internet Explorer) actif.

            * Résident "TeaTimer" (Protection des réglages système fondamentaux) actif.

            => Décocher la ligne TeaTimer.
            => Redémarrer Spybot (le fermer et le réouvrir)
            => Retourner dans le menu Résident et vérifier qu'il soit bien désactivé.

            ensuite :


            ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

            ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :

            ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

            ---> Copie (Ctrl+C) le texte suivant ci-dessous :



            :processes
            explorer.exe

            :services
            nProtect GameGuard Service
            npggsvc

            :files
            C:\WINDOWS\system32\GameMon.des.exe
            C:\WINDOWS\system32\GameMon.des

            :reg
            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
            "C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019"
            [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bc3211af-0508-11de-a0f1-001cf0633050}]

            :commands
            [purity]
            [emptytemp]
            [start explorer]
            [reboot]


            ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

            ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

            Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
            Accepte en cliquant sur YES.

            ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
            Le nom du rapport correspond au moment de sa création : date_heure.log

            ensuite :

            Télécharge SDFix sur ton bureau :
            ici :SDFix
            ou ici SDFix
            ou ici SDFix

            --> Double-clique sur SDFix.exe et choisis "Install" .

            Tuto

            Puis une fois l'installe faite ,

            Impératif : Démarrer en mode sans echec .

            /!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

            Comment aller en Mode sans échec :
            1) Redémarre ton ordi .
            2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip" .
            3) Tu tapotes jusqu' à l'apparition de l'écran avec les options de démarrage .
            4) Choisis la première option : Sans Échec , et valide en tapant sur [Entrée] .
            5) Choisis ton compte habituel ( et pas Administrateur ).
            attention : pas de connexion possible en mode sans échec , donc copie ou imprime bien la manipe pour éviter les erreurs ...

            Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double-clique sur RunThis.bat pour lancer l'outil .
            -->Tapes Y pour lancer le script ...
            Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire , donc :
            presses une touche pour redémarrer quand il te le sera demandé .

            Le PC va mettre du temps avant de démarrer ( c'est normal ), après le chargement du Bureau presses une touche lorsque "Finished" s'affiche .

            Le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier
            C:\SDFix sous le nom "Report.txt".

            Poste ce dernier dans ta prochaine réponse

            Si SDfix ne se lance pas (ça arrive!)

            * Démarrer->Exécuter

            * Copie/colle ceci :

            %systemroot%\system32\cmd.exe /K %systemdrive%\SDFix\apps\FixPath.exe

            * Clique sur ok, et valide.

            * Redémarre et essaye de nouveau de lancer SDfix.


            1. execute Ad-Remover option 2 pour remettre tes pages internet d'origine
              1. ======List of files/folders created in the last 2 months======

                2009-03-21 01:17:12 ----D---- C:\rsit
                2009-03-20 22:46:17 ----A---- C:\rollback.ini
                2009-03-20 19:15:35 ----D---- C:\Program Files\SUPERAntiSpyware
                2009-03-20 19:13:26 ----D---- C:\Program Files\Ad-remover
                2009-03-20 14:33:36 ----D---- C:\Documents and Settings\gui\Application Data\SUPERAntiSpyware.com
                2009-03-20 14:33:36 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
                2009-03-20 14:32:51 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
                2009-03-20 01:44:31 ----D---- C:\Program Files\Trend Micro
                2009-03-19 21:56:56 ----A---- C:\WINDOWS\ntbtlog.txt
                2009-03-19 14:02:19 ----A---- C:\WINDOWS\wininit.ini
                2009-03-19 03:44:42 ----D---- C:\Documents and Settings\gui\Application Data\Malwarebytes
                2009-03-19 03:44:30 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
                2009-03-19 03:44:30 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                2009-03-19 01:29:50 ----D---- C:\Program Files\Spybot - Search & Destroy
                2009-03-19 00:10:45 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                2009-03-18 21:10:08 ----D---- C:\Documents and Settings\All Users\Application Data\MailFrontier
                2009-03-18 21:09:29 ----A---- C:\WINDOWS\zllsputility_loc040c.dll
                2009-03-18 21:09:29 ----A---- C:\WINDOWS\system32\imslsp_install_loc040c.dll
                2009-03-18 21:09:29 ----A---- C:\WINDOWS\system32\imsinstall_loc040c.dll
                2009-03-18 21:09:28 ----A---- C:\WINDOWS\system32\vsutil_loc040c.dll
                2009-03-18 21:09:12 ----A---- C:\WINDOWS\zllsputility.exe
                2009-03-18 21:09:10 ----A---- C:\WINDOWS\system32\SpOrder.dll
                2009-03-18 21:07:59 ----A---- C:\WINDOWS\system32\vsregexp.dll
                2009-03-18 21:07:59 ----A---- C:\WINDOWS\system32\libeay32_0.9.6l.dll
                2009-03-18 21:07:54 ----A---- C:\WINDOWS\system32\zlcommdb.dll
                2009-03-18 21:07:54 ----A---- C:\WINDOWS\system32\zlcomm.dll
                2009-03-18 21:07:37 ----A---- C:\WINDOWS\system32\vswmi.dll
                2009-03-18 21:07:35 ----A---- C:\WINDOWS\system32\zpeng24.dll
                2009-03-18 21:07:35 ----A---- C:\WINDOWS\system32\vsxml.dll
                2009-03-18 21:07:34 ----D---- C:\WINDOWS\system32\ZoneLabs
                2009-03-18 21:07:34 ----D---- C:\Program Files\Zone Labs
                2009-03-18 21:07:34 ----A---- C:\WINDOWS\system32\vspubapi.dll
                2009-03-18 21:07:34 ----A---- C:\WINDOWS\system32\vsmonapi.dll
                2009-03-18 21:06:57 ----A---- C:\WINDOWS\system32\vsdata.dll
                2009-03-18 21:06:56 ----D---- C:\WINDOWS\Internet Logs
                2009-03-18 21:06:56 ----A---- C:\WINDOWS\system32\vsutil.dll
                2009-03-18 21:06:56 ----A---- C:\WINDOWS\system32\vsinit.dll
                2009-03-17 12:45:20 ----D---- C:\WINDOWS\SxsCaPendDel
                2009-03-16 16:05:43 ----A---- C:\WINDOWS\system32\forx228967.exe
                2009-03-16 14:50:42 ----A---- C:\WINDOWS\system32\u141618742.dll
                2009-03-16 14:50:37 ----A---- C:\WINDOWS\system32\forx512916.exe
                2009-03-16 13:46:44 ----A---- C:\WINDOWS\system32\u131698441.dll
                2009-03-15 23:08:44 ----D---- C:\Program Files\Alwil Software
                2009-03-15 14:48:02 ----A---- C:\WINDOWS\a.ini
                2009-03-15 14:32:57 ----A---- C:\WINDOWS\1.ini
                2009-03-15 14:32:29 ----A---- C:\WINDOWS\system32\u141531227.dll
                2009-03-14 09:39:28 ----D---- C:\Program Files\Circle Dvelopement
                2009-03-13 17:39:58 ----D---- C:\CFLog
                2009-03-12 21:08:11 ----D---- C:\Program Files\G4box
                2009-03-12 19:05:28 ----A---- C:\Program Files\Age of EmpiresAgeEx.dll
                2009-03-12 19:05:28 ----A---- C:\Program Files\Age of EmpiresAge.dll
                2009-03-12 19:05:27 ----A---- C:\Program Files\Age of EmpiresEMPIRES.exe
                2009-03-10 23:38:19 ----D---- C:\Documents and Settings\gui\Application Data\Mozilla
                2009-03-10 23:37:49 ----D---- C:\Program Files\Mozilla Firefox
                2009-03-04 16:34:37 ----D---- C:\Program Files\Duke Nukem - Manhattan Project
                2009-03-04 16:34:36 ----D---- C:\Shortcuts
                2009-02-27 15:57:07 ----D---- C:\Documents and Settings\gui\Application Data\U3
                2009-02-26 14:46:50 ----A---- C:\WINDOWS\system32\xfcodec.dll
                2009-02-22 11:14:31 ----D---- C:\Documents and Settings\All Users\Application Data\Blizzard
                2009-02-21 17:18:42 ----D---- C:\Program Files\Fichiers communs\Blizzard Entertainment
                2009-02-21 17:18:09 ----D---- C:\Program Files\World of Warcraft
                2009-02-16 12:09:03 ----D---- C:\Program Files\Windows Live Safety Center
                2009-02-16 10:36:12 ----D---- C:\Program Files\mIRC
                2009-02-16 10:36:12 ----D---- C:\Documents and Settings\gui\Application Data\mIRC
                2009-02-16 00:40:29 ----D---- C:\col4425
                2009-02-14 15:57:33 ----HD---- C:\ASUS.000
                2009-02-14 11:42:04 ----D---- C:\Program Files\NHN USA
                2009-02-14 11:42:04 ----A---- C:\WINDOWS\system32\PubPlugin.dll
                2009-02-14 11:42:04 ----A---- C:\WINDOWS\system32\ijjiSetup.exe
                2009-02-14 11:42:04 ----A---- C:\WINDOWS\system32\ijjiPlugin2.dll
                2009-02-12 19:43:58 ----A---- C:\WINDOWS\PhotoSnapViewer.INI
                2009-02-10 21:14:10 ----D---- C:\Documents and Settings\gui\Application Data\Xfire
                2009-02-10 21:13:13 ----SD---- C:\Program Files\Xfire

                ======List of files/folders modified in the last 2 months======

                2009-03-21 01:27:50 ----D---- C:\WINDOWS\Temp
                2009-03-21 01:27:17 ----D---- C:\WINDOWS\system32\CatRoot2
                2009-03-21 01:19:42 ----A---- C:\WINDOWS\SchedLgU.Txt
                2009-03-21 01:17:27 ----D---- C:\WINDOWS\Prefetch
                2009-03-21 00:51:17 ----SH---- C:\boot.ini
                2009-03-21 00:51:17 ----A---- C:\WINDOWS\win.ini
                2009-03-21 00:51:17 ----A---- C:\WINDOWS\system.ini
                2009-03-21 00:43:07 ----D---- C:\WINDOWS\security
                2009-03-20 21:20:01 ----RSHDC---- C:\WINDOWS\system32\dllcache
                2009-03-20 21:19:56 ----A---- C:\WINDOWS\system32\svchost.exe
                2009-03-20 21:19:31 ----AD---- C:\WINDOWS
                2009-03-20 19:16:36 ----SHD---- C:\WINDOWS\Installer
                2009-03-20 19:15:35 ----D---- C:\Program Files
                2009-03-20 17:04:33 ----D---- C:\WINDOWS\system32
                2009-03-20 14:32:51 ----D---- C:\Program Files\Fichiers communs
                2009-03-20 14:15:58 ----D---- C:\WINDOWS\network diagnostic
                2009-03-20 04:54:55 ----D---- C:\WINDOWS\WinSxS
                2009-03-20 04:53:35 ----D---- C:\Program Files\BitDefender
                2009-03-20 04:50:36 ----D---- C:\WINDOWS\system32\drivers
                2009-03-20 04:49:56 ----A---- C:\WINDOWS\bdagent.INI
                2009-03-20 03:57:24 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
                2009-03-19 05:44:51 ----SD---- C:\WINDOWS\Tasks
                2009-03-19 02:29:21 ----D---- C:\WINDOWS\inf
                2009-03-18 19:08:40 ----D---- C:\Program Files\BitTorrent
                2009-03-16 03:47:08 ----SHD---- C:\System Volume Information
                2009-03-16 03:47:08 ----D---- C:\WINDOWS\system32\Restore
                2009-03-16 03:46:34 ----HD---- C:\Program Files\InstallShield Installation Information
                2009-03-15 22:27:30 ----D---- C:\Documents and Settings
                2009-03-15 18:11:24 ----A---- C:\WINDOWS\NeroDigital.ini
                2009-03-14 21:48:38 ----SD---- C:\WINDOWS\Downloaded Program Files
                2009-03-14 21:39:49 ----HD---- C:\Documents and Settings\gui\Application Data\ijjigame
                2009-03-14 09:39:16 ----D---- C:\Program Files\Messenger Plus! Live
                2009-03-12 19:06:03 ----D---- C:\Program Files\Microsoft Games
                2009-02-27 12:48:53 ----D---- C:\WINDOWS\system32\CatRoot
                2009-02-26 17:53:06 ----A---- C:\WINDOWS\GunzLauncher.INI
                2009-02-22 18:51:53 ----D---- C:\Program Files\Postal2STP
                2009-02-20 16:48:42 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
                2009-02-19 15:53:51 ----D---- C:\Documents and Settings\gui\Application Data\vlc
                2009-02-18 18:13:35 ----D---- C:\ec
                2009-02-15 21:59:31 ----A---- C:\WINDOWS\wa.INI
                2009-02-14 16:01:55 ----HD---- C:\ASUS.SYS
                2009-02-12 04:57:35 ----D---- C:\Documents and Settings\gui\Application Data\DNA
                2009-02-12 04:40:03 ----D---- C:\WINDOWS\system32\LogFiles
                2009-02-12 04:40:03 ----D---- C:\WINDOWS\Debug
                2009-02-11 23:44:06 ----D---- C:\Program Files\DNA
                2009-01-24 19:26:17 ----A---- C:\AILog.txt

                ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2007-12-17 12400]
                R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2008-07-21 24392]
                R1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 40576]
                R1 kbdhid;Pilote HID de clavier; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14720]
                R1 KLIF;KLIF; C:\WINDOWS\system32\DRIVERS\klif.sys [2007-07-19 127768]
                R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2008-07-07 56108]
                R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2008-07-09 394952]
                R3 AnyDVD;AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [2008-08-21 99648]
                R3 ElbyDelay;ElbyDelay; C:\WINDOWS\System32\Drivers\ElbyDelay.sys [2007-02-15 11984]
                R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
                R3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
                R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-05-20 4800000]
                R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys []
                R3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-23 12288]
                R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-12 5810]
                R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-09-17 6132576]
                R3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys [2005-06-10 21760]
                R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2004-08-21 5888]
                R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
                R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
                R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
                R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
                S1 SASDIFSV;SASDIFSV; \??\F:\Superantispyware\SASDIFSV.SYS []
                S1 SASKUTIL;SASKUTIL; \??\F:\Superantispyware\SASKUTIL.sys []
                S3 AR5416;D-Link Xtreme N Service; C:\WINDOWS\system32\DRIVERS\ar5416.sys [2006-09-24 1037088]
                S3 CCCP106;CIF USB Camera (2110A); C:\WINDOWS\system32\DRIVERS\cccp106.sys [2003-04-09 227200]
                S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
                S3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller; C:\WINDOWS\system32\DRIVERS\l1e51x86.sys [2008-03-11 36864]
                S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
                S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
                S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
                S3 Profos;Profos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\profos.sys []
                S3 SASENUM;SASENUM; \??\F:\Superantispyware\SASENUM.SYS []
                S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
                S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
                S3 Trufos;Trufos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\trufos.sys []
                S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
                S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
                S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2004-08-11 18944]
                S3 WSIMD;wsimd Service; C:\WINDOWS\system32\DRIVERS\wsimd.sys []
                S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
                S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

                ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

                R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-25 152984]
                R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-01-14 170640]
                R2 MDM;Machine Debug Manager; C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
                R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-09-17 163908]
                R2 ProtexisLicensing;ProtexisLicensing; C:\WINDOWS\system32\PSIService.exe [2007-06-05 177704]
                R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-08-11 38912]
                S2 netmantow;Network Ming; C:\WINDOWS\System32\svchost.exe [2009-03-20 14336]
                S2 softyinforwow1;.Freame Micer; C:\WINDOWS\System32\svchost.exe [2009-03-20 14336]
                S2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2008-07-09 75304]
                S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2003-02-20 32768]
                S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
                S3 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-06-29 800040]
                S3 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848]
                S3 npggsvc;nProtect GameGuard Service; C:\WINDOWS\system32\GameMon.des [2009-02-16 2741114]
                S3 ose;Office Source Engine; C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
                S3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
                S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2009-03-20 14336]
                S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]

                -----------------EOF-----------------

                Voila, et je recois en permanence des connexions entrantes...
                1. Voila, ca a fonctionné

                  Logfile of random's system information tool 1.05 (written by random/random)
                  Run by gui at 2009-03-21 01:28:06
                  Microsoft Windows XP Professionnel Service Pack 3
                  System drive C: has 64 GB (41%) free of 156 GB
                  Total RAM: 3071 MB (84% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 01:28:23, on 2009-03-21
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\WINDOWS\system32\PSIService.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\WINDOWS\RTHDCPL.EXE
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Documents and Settings\gui\Bureau\RSIT.exe
                  C:\Program Files\Trend Micro\HijackThis\gui.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://isohunt.com/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                  O3 - Toolbar: SYSTRAN Toolbar - {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll (file missing)
                  O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKUS\S-1-5-21-448539723-1532298954-839522115-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Administrateur')
                  O4 - S-1-5-18 Startup: Realtek Configuration audio HD.lnk = C:\WINDOWS\system32\RTSndMgr.cpl (User 'SYSTEM')
                  O4 - .DEFAULT Startup: Realtek Configuration audio HD.lnk = C:\WINDOWS\system32\RTSndMgr.cpl (User 'Default user')
                  O4 - Startup: Realtek Configuration audio HD.lnk = C:\WINDOWS\system32\RTSndMgr.cpl
                  O8 - Extra context menu item: Consulter les dictionnaires (SYSTRAN) - res://C:\Program Files\SYSTRAN\6\\GUIres.dll/lookup.js
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                  O8 - Extra context menu item: Traduire (SYSTRAN) - res://C:\Program Files\SYSTRAN\6\\GUIres.dll/translate.js
                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                  O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com/...
                  O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-03.sun.com/...
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                  O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
                  O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                  O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
                  O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                  1. en attedant fais ceci :

                    /!\ Déconnecte-toi et ferme toutes applications en cours /!\

                    Double-clique sur AD-Remover pour le lancer : au menu principal, choisis l'option B.

                    Choisis A

                    Puis choisis S, le programme va travailler.

                    Poste le rapport qui apparaît à la fin.

                    (Le rapport est sauvegardé aussi sous C:\Ad-report.log)

                    /!\ Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide) /!\

                    Note :

                    "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                    Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                    Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...)


                    1. Ok finalement, j'ai desactivé mon firewall qui menpechait de telecharger Random's System Information Tool (RSIT) mais la ca fonctionne donc le rapport suivra
                      Au faite, mon ordi fonctionne mieux de 50%... mais elle n'a pas encore récupérée sa pleine capacité. La connection internet fonctionne et ne lache plus, mais je recois en permanence des demandes de connexions entrantes et je les bloque puisque je n'ai aucune idée d'ou elles proviennent et lorsque je les bloque elles nempechent pas le fonctionnement de mon ordinateur.. donc
                      Merci beaucoup pour l'aide que tu m'as apporté jusqu'a present
                      1. ??????

                        je sais pas s il va trouver grand chose :)

                        Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

                        ! Déconnecte toi et ferme toutes tes applications en cours !

                        Double-clique sur " RSIT.exe " pour le lancer .

                        -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

                        * Devant l'option "List files/folders created ..." , tu choisis : 2 months

                        * clique ensuite sur " Continue " pour lancer l'analyse ...

                        -> laisse faire le scan et ne touche pas au PC ...

                        Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

                        Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

                        Important : poste un rapport, puis l'autre dans la réponse suivante
                        Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

                        ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
                        1. ------- LOGFILE OF AD-REMOVER 1.1.1.9 | ONLY XP/VISTA -------

                          Updated by C_XX on 18/03/2009 at 21:20 - AdRemover.contact@gmail.com

                          Start at: 20:33:27, Ven 2009-03-20 | Boot mode: Normal Boot
                          Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
                          Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
                          Computer Name: ERMENEGILLE
                          Current User: gui - Administrator
                          Drive(s):
                          - C:\ (File System: NTFS)
                          System Drive: C:\
                          Windows Directory: C:\WINDOWS\
                          System Directory: C:\WINDOWS\System32\

                          --- Running Processes: 29

                          +-----------------| Boonty/Boonty Games Elements Found:

                          .
                          .

                          +-----------------| Eorezo Elements Found:

                          .

                          +-----------------| Infected Poker Softwares Elements Found:

                          .

                          +-----------------| FunWebProducts/MyWay/MyWebSearch Elements Found:

                          .
                          .

                          +-----------------| It's TV Elements Found:

                          .

                          +-----------------| Sweetim Elements Found:

                          .

                          ============ Other Adwares Found ============

                          .
                          .

                          +-----------------| Added Scan:

                          ---- Mozilla FireFox Version 3.0.7 ----

                          ProfilePath: j0u0oj0q.default (gui)
                          .
                          .
                          .
                          .
                          .
                          .

                          ---- Internet Explorer Version 7.0.5730.13 ----

                          +-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

                          Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                          Start page: hxxp://isohunt.com/

                          +-[HKEY_USERS\S-1-5-21-448539723-1532298954-839522115-1003\..\Internet Explorer\Main]

                          Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                          Start page: hxxp://isohunt.com/

                          +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

                          Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
                          Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                          Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                          Start page: hxxp://go.microsoft.com/fwlink/?LinkId=69157

                          +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

                          Tabs: hxxp://ieframe.dll/tabswelcome.htm

                          +---------------------------------------------------------------------------+

                          2031 Byte(s) - C:\Ad-Report-Scan-20.9-.3-20.log

                          0 File(s) - C:\Program Files\Ad-remover\TOOLS\BACKUP
                          0 File(s) - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

                          End at: 20:49:48 | 2009-03-20
                          .
                          +-----------------| E.O.F - 54 Lines
                          .

                          Voila pour le rapport
                          Je suis en train de faire un scan antivirus/antiespion avec Zonealarm
                          1. Télécharges AD-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :

                            /!\ Déconnectes toi et fermes toutes applications en cours

                            ? Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
                            ? Double clique sur l'icône Ad-removersituée sur ton bureau
                            ? Au menu principal choisi l'option "Recherche"
                            ? Postes le rapport qui apparait à la fin .

                            ( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

                            (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                            Note :

                            "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                            Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                            Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall)
                            1. SUPERAntiSpyware Scan Log
                              https://www.superantispyware.com/

                              Generated 03/20/2009 at 04:33 PM

                              Application Version : 4.25.1014

                              Core Rules Database Version : 3784
                              Trace Rules Database Version: 1741

                              Scan type : Complete Scan
                              Total Scan Time : 01:44:02

                              Memory items scanned : 389
                              Memory threats detected : 2
                              Registry items scanned : 5927
                              Registry threats detected : 1
                              File items scanned : 15066
                              File threats detected : 13

                              Adware.Vundo/Variant-DER
                              C:\WINDOWS\SYSTEM32\DER8589582.DLL
                              C:\WINDOWS\SYSTEM32\DER8589582.DLL

                              Adware.Vundo/Variant-2009
                              C:\WINDOWS\SYSTEM32\200935039.DLL
                              C:\WINDOWS\SYSTEM32\200935039.DLL

                              Adware.Tracking Cookie
                              C:\Documents and Settings\gui\Cookies\gui@ad.yieldmanager[2].txt
                              C:\Documents and Settings\gui\Cookies\gui@smartadserver[2].txt
                              C:\Documents and Settings\gui\Cookies\gui@ads.networldmedia[1].txt
                              C:\Documents and Settings\gui\Cookies\gui@xiti[1].txt
                              C:\Documents and Settings\gui\Cookies\gui@doubleclick[1].txt
                              C:\Documents and Settings\gui\Cookies\gui@serials[1].txt
                              C:\Documents and Settings\gui\Cookies\gui@myroitracking[1].txt
                              C:\Documents and Settings\gui\Cookies\gui@atdmt[1].txt
                              C:\Documents and Settings\gui\Cookies\gui@zedo[1].txt
                              C:\Documents and Settings\gui\Cookies\gui@ads.clicksor[1].txt
                              C:\Documents and Settings\gui\Cookies\gui@ads.widgetbucks[1].txt

                              Adware.MyWebSearch/FunWebProducts
                              HKCR\CLSID\{9AFB8248-617F-460d-9366-D71CDEDA3179}

                              Voila pour le scan
                              1. Merci encore pour la reponse..
                                Ce matin en me reveillant, jai tente douvrir une page internet sur l<ordinateur host de mon reseau (qui comporte mon ordinateur defectueux et celle-ci) et je recevais

                                Your Home Networking Modem has intercepted your web page request to provide you with this important message. The following devices on your network are using a large number of simultaneous Internet sessions:

                                Ordi

                                The most likely cause of this issue is a ~blaster~ type virus which has infected the device. It is strongly recommended that the devices above be scanned for potential viruses.

                                Mais je cours de ce pas effectuer ce que tu mas dit
                                1. Désactiver le TeaTimer de Spybot (Merci à Nico):

                                  Pour désactiver le TeaTimer :
                                  => Ouvrir Spybot S&D
                                  => Dans le menu "Mode", séléctionner le mode avancé.
                                  => Une fenêtre demande confirmation cliquer sur "oui".
                                  => Une fois le mode avancé actif, ouvrir l'onglet "Outils".
                                  => Cliquer sur Résident.
                                  => La partie Résident comporte deux lignes qui sont normalement cochées :
                                  *Résident "SDHelper" (bloqueur de téléchargements nuisibles pour Internet Explorer) actif.

                                  * Résident "TeaTimer" (Protection des réglages système fondamentaux) actif.

                                  => Décocher la ligne TeaTimer.
                                  => Redémarrer Spybot (le fermer et le réouvrir)
                                  => Retourner dans le menu Résident et vérifier qu'il soit bien désactivé.

                                  ensuite :


                                  Télécharge Superantispyware (SAS)

                                  Choisis "enregistrer" et enregistre-le sur ton bureau.

                                  Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

                                  Créé une icône sur le bureau.

                                  Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

                                  - Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
                                  - Sous Configuration and Preferences, clique sur le bouton "Preferences"
                                  - Clique sur l'onglet "Scanning Control "
                                  - Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

                                  Close browsers before scanning
                                  Scan for tracking cookies
                                  Terminate memory threats before quarantining
                                  - Laisse les autres lignes décochées.

                                  - Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

                                  - Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

                                  Dans la colonne de gauche, coche C:\Fixed Drive.

                                  Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

                                  Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

                                  A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

                                  Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

                                  Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

                                  Pour recopier les informations sur le forum, fais ceci :

                                  - après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
                                  - Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
                                  - Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

                                  - Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

                                  - Copie son contenu dans ta réponse.

                                  Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
                                  1. Jsuis sincerement desole pour la repetition mais quand jles ai poste ils naffichaient pas donc jai reposte et... jai aucune idee si je peux les supprimers, ne prenez pas la peine de tout les verifier car les 3 rapports sont identiques

                                    Merci davance
                                    1. Bon... un autre test, au fait merci pour la reponse
                                      voici le rapport

                                      Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 01:46:03, on 2009-03-20
                                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                                      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\Program Files\Java\jre6\bin\jqs.exe
                                      C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                                      C:\WINDOWS\system32\nvsvc32.exe
                                      C:\WINDOWS\system32\PSIService.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
                                      C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                                      C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                                      C:\WINDOWS\system32\ctfmon.exe
                                      C:\WINDOWS\RTHDCPL.EXE
                                      C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.mpaa.org/watch-it-legally
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                                      O3 - Toolbar: SYSTRAN Toolbar - {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll (file missing)
                                      O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                                      O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
                                      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
                                      O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                      O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
                                      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                      O4 - S-1-5-18 Startup: Realtek Configuration audio HD.lnk = C:\WINDOWS\system32\RTSndMgr.cpl (User 'SYSTEM')
                                      O4 - .DEFAULT Startup: Realtek Configuration audio HD.lnk = C:\WINDOWS\system32\RTSndMgr.cpl (User 'Default user')
                                      O4 - Startup: Realtek Configuration audio HD.lnk = C:\WINDOWS\system32\RTSndMgr.cpl
                                      O8 - Extra context menu item: Consulter les dictionnaires (SYSTRAN) - res://C:\Program Files\SYSTRAN\6\\GUIres.dll/lookup.js
                                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                      O8 - Extra context menu item: Traduire (SYSTRAN) - res://C:\Program Files\SYSTRAN\6\\GUIres.dll/translate.js
                                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                                      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                                      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
                                      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-03.sun.com/s/ESD5/JSCDL/jdk/6u10/jinstall-6u10-windows-i586-jc.cab?e=1224971954314&h=cb659ac2bba2b6a925a748fef45f402a/&filename=jinstall-6u10-windows-i586-jc.cab
                                      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                                      O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
                                      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                                      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                                      O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing)
                                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                      O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
                                      O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                      O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                                      O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
                                      • 1
                                      • 2