Virus veno

Bonjour,
Antivir vient de détecter le virus Tr/Veno.ATrojan
Je voudrais le supprimer mais je n'y arrive pas. Quand j'utilise ccleaner, spybot et avast il ne le trouve pas !
Comment faire ?
Merci d'avance
Configuration: Windows XP
Internet Explorer 6.0

13 réponses

  1. Contributeur sécurité
    ok

    bonne continuation!
    0
    1. Contributeur sécurité
      ok c'est bon

      les alertes c'est normal

      _______________

      il faudra mettre a jour internet explorer avec la version 8

      ___________

      pour antivir il est preferable d'activer la recherche de rootkits

      Search for rootkits..............: off

      ______________

      pour virer ce qui a été utilisé

      Télécharge ToolsCleaner sur ton bureau.
      --> http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
      # Clique sur Recherche et laisse le scan agir ...
      # Clique sur Suppression pour finaliser.
      # Tu peux, si tu le souhaites, te servir des Options facultatives.
      # Clique sur Quitter pour obtenir le rapport.
      # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

      ps : pas besoin de m´envoyer le rapport si tout a été supprimé

      rq:

      pour protéger gratos ton ordi

      http://www.commentcamarche.net/telecharger/logiciel 4 securite

      mettre un antivirus

      ANTIVIR ou AVG8 ou (AVAST )
      https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
      https://www.avira.com/fr/free-antivirus-windows
      -------------
      des anti-espions :
      MalwareByte's Anti-Malware + SPYBOT +/- si tea timer non active de spybot:
      WINDOWS DEFENDER ou SPYWARE TERMINATOR ou SPYWARE GUARD
      +
      SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

      Rq : spybot … sortent de nouvelles versions régulièrement, vérifiez que vous avez la dernière version
      --------
      un pare feu :
      celui de (Windows) ou mieux Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit) ou COMODO

      http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall
      https://www.01net.com/telecharger/windows/Securite/firewall/fiches/39911.html
      https://forum.pcastuces.com/sujet.asp?f=25&s=35606
      https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
      https://manuelsdaide.com/contact/
      http://www.open-files.com/forum/index.php?showtopic=29277
      https://www.01net.com/telecharger/windows/Securite/firewall/fiches/18128.html
      https://www.zonealarm.com/software/free-firewall

      -----------
      CCLEANER pour effacer les traces de surf
      ---------
      naviguer avec firefox ou safari ou opera et non internet explorer plus touché par les virus
      http://www.mozilla-europe.org/fr/products/firefox/
      0
      1. Merci beaucoup pour ton aide
        Isabelle
        0
    2. voici le rapport d'antivir. Il a enfin fait un scan complet
      On dirait qu'il n'y a plus de virus !!! mais 2 warning
      qu'en pense tu ?

      Avira AntiVir Personal
      Report file date: lundi 30 mars 2009 18:58

      Scanning for 1330971 virus strains and unwanted programs.

      Licensed to: Avira AntiVir PersonalEdition Classic
      Serial number: 0000149996-ADJIE-0001
      Platform: Windows XP
      Windows version: (Service Pack 3) [5.1.2600]
      Boot mode: Normally booted
      Username: SYSTEM
      Computer name: ISABELLE-AMD460

      Version information:
      BUILD.DAT : 8.2.0.347 16934 Bytes 16/03/2009 14:45:00
      AVSCAN.EXE : 8.1.4.10 315649 Bytes 25/11/2008 16:42:20
      AVSCAN.DLL : 8.1.4.0 40705 Bytes 17/07/2008 18:33:29
      LUKE.DLL : 8.1.4.5 164097 Bytes 17/07/2008 18:33:31
      LUKERES.DLL : 8.1.4.0 12033 Bytes 17/07/2008 18:33:31
      ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 15:29:00
      ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11/02/2009 15:44:04
      ANTIVIR2.VDF : 7.1.2.199 1008640 Bytes 22/03/2009 19:14:22
      ANTIVIR3.VDF : 7.1.2.231 284672 Bytes 30/03/2009 09:30:45
      Engineversion : 8.2.0.129
      AEVDF.DLL : 8.1.1.0 106868 Bytes 04/02/2009 10:59:47
      AESCRIPT.DLL : 8.1.1.70 369019 Bytes 27/03/2009 09:44:19
      AESCN.DLL : 8.1.1.8 127346 Bytes 06/03/2009 09:07:09
      AERDL.DLL : 8.1.1.3 438645 Bytes 06/11/2008 08:05:10
      AEPACK.DLL : 8.1.3.11 397687 Bytes 26/03/2009 07:53:31
      AEOFFICE.DLL : 8.1.0.36 196987 Bytes 27/02/2009 10:18:24
      AEHEUR.DLL : 8.1.0.111 1679736 Bytes 26/03/2009 07:53:30
      AEHELP.DLL : 8.1.2.2 119158 Bytes 27/02/2009 10:18:20
      AEGEN.DLL : 8.1.1.31 340341 Bytes 27/03/2009 09:44:17
      AEEMU.DLL : 8.1.0.9 393588 Bytes 15/10/2008 11:10:20
      AECORE.DLL : 8.1.6.6 176501 Bytes 18/02/2009 15:13:03
      AEBB.DLL : 8.1.0.3 53618 Bytes 15/10/2008 11:10:18
      AVWINLL.DLL : 1.0.0.12 15105 Bytes 17/07/2008 18:33:29
      AVPREF.DLL : 8.0.2.0 38657 Bytes 17/07/2008 18:33:29
      AVREP.DLL : 8.0.0.2 98344 Bytes 01/08/2008 12:06:26
      AVREG.DLL : 8.0.0.1 33537 Bytes 17/07/2008 18:33:29
      AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
      AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 17/07/2008 18:33:29
      SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
      SMTPLIB.DLL : 1.2.0.23 28929 Bytes 17/07/2008 18:33:31
      NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
      RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 17/07/2008 18:33:26
      RCTEXT.DLL : 8.0.52.0 86273 Bytes 17/07/2008 18:33:26

      Configuration settings for the scan:
      Jobname..........................: Complete system scan
      Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
      Logging..........................: low
      Primary action...................: interactive
      Secondary action.................: ignore
      Scan master boot sector..........: on
      Scan boot sector.................: on
      Boot sectors.....................: C:,
      Process scan.....................: on
      Scan registry....................: on
      Search for rootkits..............: off
      Scan all files...................: Intelligent file selection
      Scan archives....................: on
      Recursion depth..................: 20
      Smart extensions.................: on
      Macro heuristic..................: on
      File heuristic...................: medium

      Start of the scan: lundi 30 mars 2009 18:58

      The scan of running processes will be started
      Scan process 'avscan.exe' - '1' Module(s) have been scanned
      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
      Scan process 'wltuser.exe' - '1' Module(s) have been scanned
      Scan process 'iexplore.exe' - '1' Module(s) have been scanned
      Scan process 'explorer.exe' - '1' Module(s) have been scanned
      Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
      Scan process 'alg.exe' - '1' Module(s) have been scanned
      Scan process 'iPodService.exe' - '1' Module(s) have been scanned
      Scan process 'NMIndexStoreSvr.exe' - '1' Module(s) have been scanned
      Scan process 'NMIndexingService.exe' - '1' Module(s) have been scanned
      Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
      Scan process 'Apache.exe' - '1' Module(s) have been scanned
      Scan process 'nSvcIp.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'SeaPort.exe' - '1' Module(s) have been scanned
      Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
      Scan process 'nSvcLog.exe' - '1' Module(s) have been scanned
      Scan process 'MSCamS32.exe' - '1' Module(s) have been scanned
      Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
      Scan process 'Apache.exe' - '1' Module(s) have been scanned
      Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
      Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
      Scan process 'avguard.exe' - '1' Module(s) have been scanned
      Scan process 'KHALMNPR.exe' - '1' Module(s) have been scanned
      Scan process 'SetPoint.exe' - '1' Module(s) have been scanned
      Scan process 'LogitechDesktopMessenger.exe' - '1' Module(s) have been scanned
      Scan process 'NMBgMonitor.exe' - '1' Module(s) have been scanned
      Scan process 'LightScribeControlPanel.exe' - '1' Module(s) have been scanned
      Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
      Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
      Scan process 'vVX1000.exe' - '1' Module(s) have been scanned
      Scan process 'sched.exe' - '1' Module(s) have been scanned
      Scan process 'GoogleUpdate.exe' - '1' Module(s) have been scanned
      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'lsass.exe' - '1' Module(s) have been scanned
      Scan process 'services.exe' - '1' Module(s) have been scanned
      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
      Scan process 'csrss.exe' - '1' Module(s) have been scanned
      Scan process 'smss.exe' - '1' Module(s) have been scanned
      44 processes with 44 modules were scanned

      Starting master boot sector scan:
      Master boot sector HD0
      [INFO] No virus was found!
      Master boot sector HD1
      [INFO] No virus was found!
      [WARNING] System error [21]: Le périphérique n'est pas prêt.

      Start scanning boot sectors:
      Boot sector 'C:\'
      [INFO] No virus was found!

      Starting to scan the registry.
      The registry was scanned ( '50' files ).

      Starting the file scan:

      Begin scan in 'C:\'
      C:\pagefile.sys
      [WARNING] The file could not be opened!

      End of the scan: lundi 30 mars 2009 19:23
      Used time: 24:58 Minute(s)

      The scan has been done completely.

      7404 Scanning directories
      229099 Files were scanned
      0 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      1 Files cannot be scanned
      229098 Files not concerned
      2329 Archives were scanned
      2 Warnings
      0 Notes
      0
      1. Logfile of random's system information tool 1.06 (written by random/random)
        Run by Isabelle at 2009-03-30 18:50:25
        Microsoft Windows XP Édition familiale Service Pack 3
        System drive C: has 103 GB (67%) free of 153 GB
        Total RAM: 895 MB (51% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:50:26, on 30/03/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Google\Update\GoogleUpdate.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        C:\WINDOWS\vVX1000.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
        C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
        C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
        C:\Program Files\Logitech\SetPoint\SetPoint.exe
        C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
        C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        C:\Program Files\Microsoft LifeCam\MSCamS32.exe
        C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
        C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
        C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
        C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\WINDOWS\system32\wbem\unsecapp.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Program Files\Windows Live\Toolbar\wltuser.exe
        C:\Documents and Settings\Isabelle\Bureau\RSIT.exe
        C:\Program Files\Trend Micro\HijackThis\Isabelle.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://go.microsoft.com/fwlink/?linkid=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
        O2 - BHO: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll (file missing)
        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll (file missing)
        O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
        O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
        O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
        O4 - HKLM\..\Run: [KiweeHook] "C:\Program Files\Kiwee Toolbar\2.8.167\kwtbaim.exe"
        O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [EPSON Stylus SX200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEFE.EXE /FU "C:\WINDOWS\TEMP\E_SBB.tmp" /EF "HKCU"
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
        O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
        O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
        O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
        O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
        O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
        O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
        O23 - Service: Google Update Service (gupdate1c981f49bb73bd0) (gupdate1c981f49bb73bd0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTServ.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
        O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
        O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
        O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O24 - Desktop Component 0: (no name) - http://photos.ashleytisdale.org/albums/photoshoot/Headstrong%20Album%20Promos/1.jpg
        0
        1. Contributeur sécurité
          remets un rapport RSIT

          antivir a trouvé des infections dans les 98%, il bloque sur quel fichier?
          0
          1. Contributeur sécurité
            refais ad remover option B (comme il en manquait une partie...)

            et vire ces deux

            SWEETIM
            Other Adwares Found
            0
            1. Ok c'est fait, voici le rapport
              Peut-tu me dire pourquoi le scan avec antivir bloque à 98%
              merci de ta patience'

              ------- LOGFILE OF AD-REMOVER 1.1.2.4 | ONLY XP/VISTA -------

              Updated by C_XX on 29/03/2009 at 19:20
              Contact: AdRemover.contact@gmail.com
              Website: http://pagesperso-orange.fr/FindyKill.Ad.Remover/

              Start at: 18:21:57, Lun 30/03/2009 | Boot mode: Normal Boot
              Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
              Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
              Computer Name: ISABELLE-AMD460
              Current User: Isabelle - Administrator
              Drive(s):
              - C:\ (File System: NTFS)
              System Drive: C:\
              Windows Directory: C:\WINDOWS\
              System Directory: C:\WINDOWS\System32\

              --- Running Processes: 46

              +-----------------| Boonty/Boonty Games Elements Found:

              .
              .

              +-----------------| Eorezo Elements Found:

              .

              +-----------------| Infected Poker Softwares Elements Found:

              .

              +-----------------| FunWebProducts/MyWay/MyWebSearch Elements Found:

              .
              .

              +-----------------| It's TV Elements Found:

              .

              +-----------------| Sweetim Elements Found:

              .

              ============ Other Adwares Found ============

              .
              .
              C:\Program Files\RelevantKnowledge

              +-----------------| Added Scan:

              ---- Mozilla FireFox Version 3.0.8 ----

              ProfilePath: zrt539kk.default (Isabelle)
              .
              Prefs.js: Browser.Search.SelectedEngine: "Live Search"
              .
              .
              .
              .
              .

              ---- Internet Explorer Version 6.0.2900.5512 ----

              +-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

              Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
              Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
              Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

              +-[HKEY_USERS\S-1-5-21-861567501-113007714-682003330-1004\..\Internet Explorer\Main]

              Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
              Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
              Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

              +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

              Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
              Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Search bar: hxxp://search.msn.com/spbasic.htm
              Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Start page: hxxp://fr.msn.com/

              +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

              Tabs: hxxp://ieframe.dll/tabswelcome.htm

              +---------------------------------------------------------------------------+

              3660 Byte(s) - C:\Ad-Report-Clean-30.03.2009.log
              2869 Byte(s) - C:\Ad-Report-Scan-30.03.2009.log

              2 File(s) - C:\Program Files\Ad-remover\TOOLS\BACKUP
              6 File(s) - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

              End at: 18:26:27 | 30/03/2009
              .
              +-----------------| E.O.F - 65 Lines
              .
              0
          2. Contributeur sécurité
            :files et non : files (pas d'espace)

            ____________

            le rapport AD REMOVER EST INCOMPLET ....

            refais avec option B et vire

            ces 3 :

            Boonty
            Eorezo
            It's TV Elements

            et colle le rapport

            ______________________

            mettre a jour internet explorer
            pour XP
            http://download.microsoft.com/...

            _________________

            mettre à jour adobe reader puis supprimer les anciennes version via le panneau de configuration
            https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html

            ________________

            Mettre a jour java:
            https://javara.fr.malavida.com/

            Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.
            Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)
            Double-clique sur le répertoire JavaRa obtenu.
            Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)
            Clique sur Search For Updates.
            Sélectionne Update Using jucheck.exe puis clique sur Search.
            Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.
            Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.
            Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.
            Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.
            Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log
            (c:\JavaRa.log)
            Ferme l'application.

            si cela ne fonctionne pas

            https://www.java.com/fr/download/windows_manual.jsp?locale=fr&host=www.java.com:80

            tu peux désinstaller les vieilles versions.

            _____________________

            remets un rapport RSIt et dis tes soucis actuels
            0
            1. rebonjour

              oui j'ai bien mis files sans espace mais rien à faire

              voici le rapport ad-remover après avoir supprimer les 3 éléments que tu m'as indiqué. j'espère que cette fois ci il est complet.

              Par contre je n'arrive pas à faire de scan avec antivir. A chaque fois il bloque à 98.7% su scan. Egalement je n'ai plus le message de détection du virus veno trojan.

              merci à toi

              ------- LOGFILE OF AD-REMOVER 1.1.2.4 | ONLY XP/VISTA -------

              Updated by C_XX on 29/03/2009 at 19:20
              Contact: AdRemover.contact@gmail.com
              Website: http://pagesperso-orange.fr/FindyKill.Ad.Remover/

              Start at: 16:09:53, Lun 30/03/2009 | Boot mode: Normal Boot
              Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
              Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
              Computer Name: ISABELLE-AMD460
              Current User: Isabelle - Administrator
              Drive(s):
              - C:\ (File System: NTFS)
              System Drive: C:\
              Windows Directory: C:\WINDOWS\
              System Directory: C:\WINDOWS\System32\

              --- Running Processes: 47

              +-----------------| Boonty/Boonty Games Elements Found:

              .
              .

              +-----------------| Eorezo Elements Found:

              .

              +-----------------| Infected Poker Softwares Elements Found:

              .

              +-----------------| FunWebProducts/MyWay/MyWebSearch Elements Found:

              .
              .

              +-----------------| It's TV Elements Found:

              .

              +-----------------| Sweetim Elements Found:

              HKCR\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
              HKCR\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
              HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
              HKCR\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
              HKCR\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
              HKCR\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
              HKCR\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
              HKCR\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
              HKCR\MediaPlayer.GraphicsUtils
              HKCR\MediaPlayer.GraphicsUtils.1
              HKCR\MgMediaPlayer.GifAnimator
              HKCR\MgMediaPlayer.GifAnimator.1
              HKCR\SWEETIE.IEToolbar
              HKCR\SWEETIE.IEToolbar.1
              HKCR\SWEETIE.SWEETIE
              HKCR\SWEETIE.SWEETIE.3
              HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook
              HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook.1
              HKCR\Toolbar3.SWEETIE
              HKCR\Toolbar3.SWEETIE.1
              HKCR\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
              HKCR\Typelib\{EEE6C35E-6118-11DC-9C72-001320C79847}
              HKCR\Typelib\{EEE6C35F-6118-11DC-9C72-001320C79847}
              HKCU\Software\SweetIM
              HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
              HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
              HKLM\Software\Classes\MediaPlayer.GraphicsUtils
              HKLM\Software\Classes\MediaPlayer.GraphicsUtils.1
              HKLM\Software\Classes\MgMediaPlayer.GifAnimator
              HKLM\Software\Classes\MgMediaPlayer.GifAnimator.1
              HKLM\Software\Classes\SWEETIE.IEToolbar
              HKLM\Software\Classes\SWEETIE.IEToolbar.1
              HKLM\Software\Classes\SWEETIE.SWEETIE
              HKLM\Software\Classes\SWEETIE.SWEETIE.3
              HKLM\Software\Classes\SweetIM_URLSearchHook.ToolbarURLSearchHook
              HKLM\Software\Classes\SweetIM_URLSearchHook.ToolbarURLSearchHook.1
              HKLM\Software\Classes\Toolbar3.SWEETIE
              HKLM\Software\Classes\Toolbar3.SWEETIE.1
              HKLM\Software\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
              HKLM\Software\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}
              HKLM\Software\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}
              HKLM\Software\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
              HKLM\Software\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
              HKLM\Software\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
              HKLM\Software\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
              HKLM\Software\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
              HKLM\Software\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289}
              HKLM\Software\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
              HKLM\Software\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
              HKLM\Software\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
              HKLM\Software\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}
              HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe
              HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{83FA27D5-25B5-4D24-B796-DF742F08A5CF}
              HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{CFA9C824-A778-47EB-90CD-BB4DB82CF348}
              HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}
              HKLM\Software\SweetIM
              HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847}
              HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847}
              HKCR\Installer\Products\428C9AFC877ABE7409DCBBD48BC23F84
              HKCR\Installer\Products\5D72AF385B5242D47B69FD47F2805AFC
              HKLM\Software\Classes\Installer\Products\428C9AFC877ABE7409DCBBD48BC23F84
              HKLM\Software\Classes\Installer\Products\5D72AF385B5242D47B69FD47F2805AFC
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\1AC67655DD68F8240B2860F2D511EBD8
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\351716A953E21214898904032EAE2E81
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\428C9AFC877ABE7409DCBBD48BC23F84
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5D19F074C042AD34BAB463D4175A062E
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\5D72AF385B5242D47B69FD47F2805AFC
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\A189D17A469616C4688D23E192996267
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E337925F629CF4C4FB08F3D9674DD839
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
              HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
              .
              C:\WINDOWS\Installer\31fc25a.msi
              C:\WINDOWS\Installer\31fc25f.msi
              C:\Program Files\SweetIM
              C:\WINDOWS\Installer\{83FA27D5-25B5-4D24-B796-DF742F08A5CF}
              C:\WINDOWS\Installer\{CFA9C824-A778-47EB-90CD-BB4DB82CF348}
              C:\Documents and Settings\All Users\Application Data\SweetIM

              ============ Other Adwares Found ============

              .
              HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{d08d9f98-1c78-4704-87e6-368b0023d831}
              HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RelevantKnowledge
              HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\RelevantKnowledge
              .
              C:\Program Files\RelevantKnowledge
              C:\Documents and Settings\All Users\Menudm~1\Progra~1\RelevantKnowledge
              C:\Documents and Settings\Isabelle\Cookies\isabelle@atdmt[2].txt
              C:\Documents and Settings\Isabelle\Cookies\isabelle@bs.serving-sys[1].txt

              +-----------------| Added Scan:

              ---- Mozilla FireFox Version 3.0.8 ----

              ProfilePath: zrt539kk.default (Isabelle)
              .
              Prefs.js: Browser.Search.SelectedEngine: "Live Search"
              .
              .
              .
              .
              .

              ---- Internet Explorer Version 6.0.2900.5512 ----

              +-[HKEY_CURRENT_USER\..\Internet Explorer\Main]

              Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
              Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
              Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

              +-[HKEY_USERS\S-1-5-21-861567501-113007714-682003330-1004\..\Internet Explorer\Main]

              Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
              Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
              Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Start page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

              +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

              Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
              Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Search bar: hxxp://search.msn.com/spbasic.htm
              Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
              Start page: hxxp://fr.msn.com/

              +-[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

              Tabs: hxxp://ieframe.dll/tabswelcome.htm

              +---------------------------------------------------------------------------+

              2989 Byte(s) - C:\Ad-Report-Clean-30.03.2009.log
              12417 Byte(s) - C:\Ad-Report-Scan-30.03.2009.log

              2 File(s) - C:\Program Files\Ad-remover\TOOLS\BACKUP
              2 File(s) - C:\Program Files\Ad-remover\TOOLS\QUARANTINE

              End at: 16:17:42 | 30/03/2009
              .
              +-----------------| E.O.F - 183 Lines
              .
              0
          3. Contributeur sécurité
            tu as bien mis :files ?

            sinon passe a la suite
            0
            1. > Bonjour,
              >
              > J'ai bien mis : files mais il ne le garde pas : invalid time flag
              >
              > Sinon j'ai fait la suite, ci-dessous le rapport
              >
              > ------- LOGFILE OF AD-REMOVER 1.1.2.4 | ONLY XP/VISTA -------
              >
              > Updated by C_XX on 29/03/2009 at 19:20
              > Contact: AdRemover.contact@gmail.com
              > Website: http://pagesperso-orange.fr/FindyKill.Ad.Remover/
              >
              > Start at: 9:29:03, Lun 30/03/2009 | Boot mode: Normal Boot
              > Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
              > Operating System: Microsoft® Windows XP™ Service Pack 3 (version 5.1.2600)
              > Computer Name: ISABELLE-AMD460
              > Current User: Isabelle - Administrator
              > Drive(s):
              > - C:\ (File System: NTFS)
              > System Drive: C:\
              > Windows Directory: C:\WINDOWS\
              > System Directory: C:\WINDOWS\System32\
              >
              > --- Running Processes: 49
              >
              > +-----------------| Boonty/Boonty Games Elements Found:
              >
              > Service: Boonty Games
              > .
              > HKCU\Software\Boonty
              > HKLM\Software\Boonty
              > HKLM\System\ControlSet001\Services\Boonty Games
              > HKLM\System\CurrentControlSet\Services\Boonty Games
              > HKLM\System\ControlSet003\Services\Boonty Games
              > HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Generate One !_is1
              > HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Singles 2_tdm_is1
              > HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{28EA4E6E-CB71-4C4E-A7B6-C18214E035CE}_is1
              > .
              > C:\Program Files\Boonty
              > C:\Program Files\BoontyGames
              > C:\Program Files\Fichiers communs\BOONTY Shared
              > C:\Documents and Settings\Isabelle\Application Data\Gamelab\Boonty
              > C:\Documents and Settings\All Users\Application Data\BOONTY
              > C:\Documents and Settings\All Users\Menudm~1\Progra~1\BoontyGames
              > C:\Documents and Settings\Isabelle\Cookies\isabelle@ads.boonty[2].txt
              > C:\Documents and Settings\Isabelle\Cookies\isabelle@shell.boonty[1].txt
              >
              > +-----------------| Eorezo Elements Found:
              >
              > HKCR\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
              > HKCR\EoRezoBHO.EoBho
              > HKCR\EoRezoBHO.EoBho.1
              > HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
              > HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
              > HKCU\Software\EoRezo
              > HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
              > HKLM\Software\EoRezo
              > HKLM\Software\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
              > HKLM\Software\Classes\EoRezoBHO.EoBho
              > HKLM\Software\Classes\EoRezoBHO.EoBho.1
              > HKLM\Software\Classes\TypeLib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
              > HKLM\Software\Classes\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
              > HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper
              > Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
              > HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoengine
              > .
              > C:\Program Files\EoRezo
              > C:\Documents and Settings\Isabelle\Application Data\EoRezo
              >
              > +-----------------| Infected Poker Softwares Elements Found:
              >
              > .
              >
              > +-----------------| FunWebProducts/MyWay/MyWebSearch Elements Found:
              >
              > .
              > .
              >
              > +-----------------| It's TV Elements Found:
              >
              > HKCU\Software\ItsLabel
              > HKLM\Software\ItsLabel
              > HKU\S-1-5-21-861567501-113007714-682003330-1004\Software\ItsLabel
              > .
              > C:\Documents and Settings\Isabelle\Application Data\ItsLabel
              >
              > Merci de ta réponse
              0
          4. Ca y est j'ai enlevé avast et adg

            OTmovelt.exe ne veut pas : invalid time flag os2f.tmp-osspdf. dll must be numerical

            J'arrete pour ce soir

            Merci beaucoup
            0
            1. Contributeur sécurité
              slt,

              normal que ton ordi plante! tu as 3 antivirus !! il n'en faut qu'un !

              vire avast comme ceci
              https://www.avast.com/fr-fr/uninstall-utility

              vire avg 8

              garde antivir

              _______________

              télécharge OTMoveIt
              http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.

              double-clique sur OTMoveIt.exe pour le lancer.
              copie la liste qui se trouve en citation ci-dessous,
              et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
              (attention bien mettre :files)

              :files
              C:/windows/temp/os2f.tmp_osspdf.dll
              :commands
              [purity]
              [emptytemp]
              [start explorer]

              clique sur MoveIt! pour lancer la suppression.
              le résultat apparaitra dans le cadre "Results".
              clique sur Exit pour fermer.
              poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

              il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

              ______________________

              Télécharges AD-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :
              http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe

              /!\ Déconnectes toi et fermes toutes applications en cours

              ● Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
              ● Double clique sur l'icône Ad-removersituée sur ton bureau
              ● Au menu principal choisi l'option "A"
              ● Postes le rapport qui apparait à la fin .

              ( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

              (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

              Note :

              "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
              Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
              Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
              0
              1. et ben tu fais do a system scan log et ensuite tu copie le log entier et tu le colle sur hijackthis.de et tu regarde ce kil y a de mechant
                0
                1. Contributeur sécurité
                  slt le plus simple est déjà de nous coller un rapport d'antivir pour voir où se situe l'infection

                  ensuite:

                  Télécharge ici :

                  http://images.malwareremoval.com/random/RSIT.exe

                  random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

                  Double-clique sur RSIT.exe afin de lancer RSIT.

                  Clique Continue à l'écran Disclaimer.

                  Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

                  Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

                  Poste le contenu de log.txt (<<qui sera affiché)
                  ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

                  NB : Les rapports sont sauvegardés dans le dossier C:\rsit
                  0
                  1. je n'arrive pas à copier le rapport d'antivir
                    C:/windows/temp/os2f.tmp_osspdf.dll

                    Antivir vient de me detecter un autre virus : tr/crypt.xpack.gen trojan emplacement c:windows/temp/avast 4/unp203137971.tmp
                    de pire en pire

                    sinon voila ce que me dit rsit

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 17:52:38, on 27/03/2009
                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\program files\relevantknowledge\rlvknlg.exe
                    C:\WINDOWS\vVX1000.exe
                    C:\PROGRA~1\AVG\AVG8\avgtray.exe
                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe
                    C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
                    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                    C:\Program Files\Logitech\SetPoint\SetPoint.exe
                    C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Google\Update\GoogleUpdate.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                    C:\PROGRA~1\AVG\AVG8\avgam.exe
                    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
                    C:\Program Files\Microsoft LifeCam\MSCamS32.exe
                    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                    C:\WINDOWS\system32\nvsvc32.exe
                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\PROGRA~1\AVG\AVG8\avgemc.exe
                    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
                    C:\Program Files\AVG\AVG8\avgcsrvx.exe
                    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\WINDOWS\system32\wbem\unsecapp.exe
                    C:\Program Files\Fichiers communs\Adobe\Updater6\Adobe_Updater.exe
                    C:\WINDOWS\explorer.exe
                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                    C:\Program Files\Windows Live\Toolbar\wltuser.exe
                    C:\Program Files\AVG\AVG8\aAvgApi.exe
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=D4322FEE7CF74A348CB9CE970F098EF5
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lo.st
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
                    O2 - BHO: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
                    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                    O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\EoRezo\EoAdv\EOREZO~1.DLL (file missing)
                    O2 - BHO: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll (file missing)
                    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                    O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                    O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                    O3 - Toolbar: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll (file missing)
                    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                    O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
                    O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
                    O4 - HKLM\..\Run: [KiweeHook] "C:\Program Files\Kiwee Toolbar\2.8.167\kwtbaim.exe"
                    O4 - HKLM\..\Run: [RelevantKnowledge] C:\program files\relevantknowledge\rlvknlg.exe -boot
                    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Fichiers communs\LightScribe\LightScribeControlPanel.exe -hidden
                    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                    O4 - HKCU\..\Run: [EPSON Stylus SX200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEFE.EXE /FU "C:\WINDOWS\TEMP\E_SBB.tmp" /EF "HKCU"
                    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                    O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
                    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                    O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
                    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
                    O20 - Winlogon Notify: RelevantKnowledge - C:\program files\relevantknowledge\rlls.dll
                    O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
                    O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                    O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                    O23 - Service: Google Update Service (gupdate1c981f49bb73bd0) (gupdate1c981f49bb73bd0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTServ.exe
                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                    O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
                    O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                    O24 - Desktop Component 0: (no name) - http://photos.ashleytisdale.org/albums/photoshoot/Headstrong%20Album%20Promos/1.jpg
                    0
                2. slt, essaye hijackthis et malwarebytes et cela devrait etre bon.

                  a++
                  0
                  1. HIJACKTHIS Merci mais je ne sais pas m'en servir
                    0