Un nouveau rapport hijackthis

Bonjour,
Violette, enchantée !

Comme vous devez l'imaginezj'ai eu quelques soucis avec svchost.exe, pu de connexion internet (je jongle entre deux ordis T_T), de son, enfin pu grand chose de possible, j'ai lu plusieurs post et me voilà avec un rapport hijackthis, j'espère qu'il pourra vous éclairer ?!
Je vais le lire afin d'voir si j'trouve quelque chose par moi même tout de même.
En vous remerciant, bonne journée :)
Configuration: Windows Vista
Internet Explorer 7.0

84 réponses

Résumé de la discussion

La discussion porte sur des symptômes d'infection informatique affectant SVCHOST.EXE et la connexion Internet, avec des difficultés sonores et l'utilisation d'un rapport HijackThis pour identifier les causes potentielles. Des conseils techniques préconisent d'éviter MSConfig pour démarrer en mode sans échec lorsque le PC est infecté et d'utiliser des outils spécialisés comme SmitFraudFix ou UsbFix pour nettoyer et récupérer des paramètres réseau. Des rapports et indices DNS modifiés et des difficultés réseau sont évoqués, avec des solutions impliquant l'exécution de rapports de diagnostic, la vérification des serveurs DNS et l'activation d'outils de scan.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut,

    Il ne faut pas utiliser msconfig pour redémarrer en mode sans échec surtout quand le PC est infecté, ça plante le PC.
    2
    1. Contributeur sécurité
      ok lance tool cleaner pour virer ce qui a été utilisé:

      http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner

      pour protéger gratos ton ordi
      http://www.commentcamarche.net/telecharger/logiciel 4 securite

      mettre un antivirus

      ANTIVIR
      https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
      -------------
      des anti-espions :
      MALWAREBYTE ANTIMALWARE + SPYBOT
      +
      SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

      --------
      un pare feu :
      (celui de Windows) ou mieux COMODO ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)

      http://www.clubic.com/telecharger-fiche11071-sunbelt-persona­l-firewall-e(...)
      https://manuelsdaide.com/contact/
      http://www.open-files.com/forum/index.php?showtopic=29277
      https://www.commentcamarche.net/telecharger/ 157 zonealarm

      -----------

      CCLEANER pour effacer les traces de surf
      0
      1. Okay c'est fait, baah non j'crois que ça va aller j'te remercie :)
        0
        1. Contributeur sécurité
          ok vire ce qui est en quarantaine dans antivir

          et fais gaffe a ce que tu télécharge !!!

          encore des soucis???
          0
          1. J'avais des chansons infectées, j'ai mis "repair"

            Avira AntiVir Personal
            Report file date: mercredi 15 avril 2009 16:47

            Scanning for 1352883 virus strains and unwanted programs.

            Licensee : Avira AntiVir Personal - FREE Antivirus
            Serial number : 0000149996-ADJIE-0000001
            Platform : Windows XP
            Windows version : (Service Pack 2) [5.1.2600]
            Boot mode : Normally booted
            Username : SYSTEM
            Computer name : VIOLETTE

            Version information:
            BUILD.DAT : 9.0.0.387 17962 Bytes 24/03/2009 11:04:00
            AVSCAN.EXE : 9.0.3.3 464641 Bytes 24/02/2009 10:13:26
            AVSCAN.DLL : 9.0.3.0 40705 Bytes 27/02/2009 08:58:24
            LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 09:35:49
            LUKERES.DLL : 9.0.2.0 12033 Bytes 27/02/2009 08:58:52
            ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 10:30:36
            ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 11/02/2009 18:33:26
            ANTIVIR2.VDF : 7.1.3.0 1330176 Bytes 01/04/2009 09:14:55
            ANTIVIR3.VDF : 7.1.3.53 246272 Bytes 15/04/2009 09:15:18
            Engineversion : 8.2.0.143
            AEVDF.DLL : 8.1.1.0 106868 Bytes 27/01/2009 15:36:42
            AESCRIPT.DLL : 8.1.1.75 373113 Bytes 15/04/2009 09:15:27
            AESCN.DLL : 8.1.1.10 127348 Bytes 15/04/2009 09:15:26
            AERDL.DLL : 8.1.1.3 438645 Bytes 29/10/2008 16:24:41
            AEPACK.DLL : 8.1.3.12 397687 Bytes 15/04/2009 09:15:26
            AEOFFICE.DLL : 8.1.0.36 196987 Bytes 26/02/2009 18:01:56
            AEHEUR.DLL : 8.1.0.116 1708407 Bytes 15/04/2009 09:15:24
            AEHELP.DLL : 8.1.2.2 119158 Bytes 26/02/2009 18:01:56
            AEGEN.DLL : 8.1.1.34 340340 Bytes 15/04/2009 09:15:20
            AEEMU.DLL : 8.1.0.9 393588 Bytes 09/10/2008 12:32:40
            AECORE.DLL : 8.1.6.9 176500 Bytes 15/04/2009 09:15:19
            AEBB.DLL : 8.1.0.3 53618 Bytes 09/10/2008 12:32:40
            AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 06:47:59
            AVPREF.DLL : 9.0.0.1 43777 Bytes 05/12/2008 08:32:15
            AVREP.DLL : 8.0.0.3 155905 Bytes 20/01/2009 12:34:28
            AVREG.DLL : 9.0.0.0 36609 Bytes 05/12/2008 08:32:09
            AVARKT.DLL : 9.0.0.1 292609 Bytes 09/02/2009 05:52:24
            AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 08:37:08
            SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 13:03:49
            SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 06:21:33
            NETNT.DLL : 9.0.0.0 11521 Bytes 05/12/2008 08:32:10
            RCIMAGE.DLL : 9.0.0.21 2438401 Bytes 09/02/2009 09:45:45
            RCTEXT.DLL : 9.0.35.0 87297 Bytes 11/03/2009 13:55:12

            Configuration settings for the scan:
            Jobname.............................: Complete system scan
            Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
            Logging.............................: low
            Primary action......................: interactive
            Secondary action....................: ignore
            Scan master boot sector.............: on
            Scan boot sector....................: on
            Boot sectors........................: C:, D:, K:,
            Process scan........................: on
            Scan registry.......................: on
            Search for rootkits.................: on
            Integrity checking of system files..: off
            Scan all files......................: All files
            Scan archives.......................: on
            Recursion depth.....................: 20
            Smart extensions....................: on
            Macro heuristic.....................: on
            File heuristic......................: medium

            Start of the scan: mercredi 15 avril 2009 16:47

            Starting search for hidden objects.
            '79819' objects were checked, '0' hidden objects were found.

            The scan of running processes will be started
            Scan process 'avscan.exe' - '1' Module(s) have been scanned
            Scan process 'avcenter.exe' - '1' Module(s) have been scanned
            Scan process 'getPlus_HelperSvc.exe' - '1' Module(s) have been scanned
            Scan process 'getPlus_HelperSvc.exe' - '1' Module(s) have been scanned
            Scan process 'firefox.exe' - '1' Module(s) have been scanned
            Scan process 'soffice.bin' - '1' Module(s) have been scanned
            Scan process 'soffice.exe' - '1' Module(s) have been scanned
            Scan process 'iTunes.exe' - '1' Module(s) have been scanned
            Scan process 'bittorrent.exe' - '1' Module(s) have been scanned
            Scan process 'btdna.exe' - '1' Module(s) have been scanned
            Scan process 'wlcomm.exe' - '1' Module(s) have been scanned
            Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'alg.exe' - '1' Module(s) have been scanned
            Scan process 'iPodService.exe' - '1' Module(s) have been scanned
            Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
            Scan process 'WlanCU.exe' - '1' Module(s) have been scanned
            Scan process 'dslmon.exe' - '1' Module(s) have been scanned
            Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
            Scan process 'cfp.exe' - '1' Module(s) have been scanned
            Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
            Scan process 'cssurf.exe' - '1' Module(s) have been scanned
            Scan process 'avguard.exe' - '1' Module(s) have been scanned
            Scan process 'rundll32.exe' - '1' Module(s) have been scanned
            Scan process 'avgnt.exe' - '1' Module(s) have been scanned
            Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
            Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
            Scan process 'kbd.exe' - '1' Module(s) have been scanned
            Scan process 'ALCWZRD.EXE' - '1' Module(s) have been scanned
            Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned
            Scan process 'hpsysdrv.exe' - '1' Module(s) have been scanned
            Scan process 'jusched.exe' - '1' Module(s) have been scanned
            Scan process 'explorer.exe' - '1' Module(s) have been scanned
            Scan process 'sched.exe' - '1' Module(s) have been scanned
            Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'cmdagent.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'lsass.exe' - '1' Module(s) have been scanned
            Scan process 'services.exe' - '1' Module(s) have been scanned
            Scan process 'winlogon.exe' - '1' Module(s) have been scanned
            Scan process 'csrss.exe' - '1' Module(s) have been scanned
            Scan process 'smss.exe' - '1' Module(s) have been scanned
            46 processes with 46 modules were scanned

            Starting master boot sector scan:

            Start scanning boot sectors:

            Starting to scan executable files (registry).
            The registry was scanned ( '69' files ).

            Starting the file scan:

            Begin scan in 'C:\' <PRESARIO>
            C:\hiberfil.sys
            [WARNING] The file could not be opened!
            [NOTE] This file is a Windows system file.
            [NOTE] This file cannot be opened for scanning.
            C:\pagefile.sys
            [WARNING] The file could not be opened!
            [NOTE] This file is a Windows system file.
            [NOTE] This file cannot be opened for scanning.
            C:\Documents and Settings\Compaq_Propriétaire\Mes documents\Photoshop\Keygen Photoshop CS2 Fr.exe
            [DETECTION] Contains recognition pattern of the WORM/Autorun.cxl worm
            C:\Documents and Settings\Violette\Mes documents\Ma musique\Django Reinhardt\django reinhardt brazil.mpg
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            Begin scan in 'D:\' <PRESARIO_RP>
            Begin scan in 'K:\' <FAITH>
            K:\VIO PORT\Sounds\The Prodigy - Smack my bitch up.mp3
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            K:\VIO PORT\Sounds\TTC - Dans le club.mp3
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            K:\Ma musique\Django Reinhardt\django reinhardt brazil.mpg
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            K:\Ma musique\TTC\TTC - Dans le club.mp3
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            K:\Recycled\Dk17\blue fondation 2009.mp3
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            K:\Recycled\Dk17\blue fondation (hot new track).au
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            K:\Recycled\Dk17\warriors gary numan - greatest hits.mp3
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit

            Beginning disinfection:
            C:\Documents and Settings\Compaq_Propriétaire\Mes documents\Photoshop\Keygen Photoshop CS2 Fr.exe
            [DETECTION] Contains recognition pattern of the WORM/Autorun.cxl worm
            [NOTE] The file was moved to '4a5f06ac.qua'!
            C:\Documents and Settings\Violette\Mes documents\Ma musique\Django Reinhardt\django reinhardt brazil.mpg
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            [NOTE] The file was moved to '4a4706b1.qua'!
            K:\VIO PORT\Sounds\The Prodigy - Smack my bitch up.mp3
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            [NOTE] The file was moved to '4a4b06b0.qua'!
            K:\VIO PORT\Sounds\TTC - Dans le club.mp3
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            [NOTE] The file was moved to '4a29069c.qua'!
            K:\Ma musique\Django Reinhardt\django reinhardt brazil.mpg
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            [NOTE] The file was moved to '4a4706b2.qua'!
            K:\Ma musique\TTC\TTC - Dans le club.mp3
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            [NOTE] The file was moved to '4a29069e.qua'!
            K:\Recycled\Dk17\blue fondation 2009.mp3
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            [NOTE] The file was moved to '4a5b06b6.qua'!
            K:\Recycled\Dk17\blue fondation (hot new track).au
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            [NOTE] The file was moved to '4bf9abb7.qua'!
            K:\Recycled\Dk17\warriors gary numan - greatest hits.mp3
            [DETECTION] Contains recognition pattern of the EXP/ASF.GetCodec.Gen exploit
            [NOTE] The file was moved to '4a5806ab.qua'!

            End of the scan: mercredi 15 avril 2009 18:07
            Used time: 1:19:25 Hour(s)

            The scan has been done completely.

            13281 Scanned directories
            371642 Files were scanned
            9 Viruses and/or unwanted programs were found
            0 Files were classified as suspicious
            0 files were deleted
            0 Viruses and unwanted programs were repaired
            9 Files were moved to quarantine
            0 Files were renamed
            2 Files cannot be scanned
            371631 Files not concerned
            7801 Archives were scanned
            2 Warnings
            11 Notes
            79819 Objects were scanned with rootkit scan
            0 Hidden objects were found
            0
            1. Contributeur sécurité
              ok a plus
              0
              1. Antivir est lent car je fais d'autres trucs en même temps, mais l'ordi roule bien quand même, je te poste ça quand j'ai.
                0
                1. Comodo bloque mon firefox oO
                  J'ai essayé de mettre dans trusted application mais ça n'change rien, la ducoup j'l'ai rangé mais si j'le ferme ça coupe firefox
                  0
                  1. Contributeur sécurité
                    parfait fais le reste et cela devrait etre finit!
                    0
                    1. Fichier cssdll32.dll reçu le 2009.03.21 19:56:24 (CET)
                      Situation actuelle: terminé
                      Résultat: 0/39 (0.00%)
                      Formaté Formaté
                      Impression des résultats Impression des résultats
                      Antivirus Version Dernière mise à jour Résultat
                      a-squared 4.0.0.101 2009.03.21 -
                      AhnLab-V3 5.0.0.2 2009.03.21 -
                      AntiVir 7.9.0.120 2009.03.20 -
                      Authentium 5.1.2.4 2009.03.21 -
                      Avast 4.8.1335.0 2009.03.20 -
                      AVG 8.5.0.283 2009.03.20 -
                      BitDefender 7.2 2009.03.21 -
                      CAT-QuickHeal 10.00 2009.03.21 -
                      ClamAV 0.94.1 2009.03.21 -
                      Comodo 1078 2009.03.21 -
                      DrWeb 4.44.0.09170 2009.03.21 -
                      eSafe 7.0.17.0 2009.03.19 -
                      eTrust-Vet 31.6.6409 2009.03.20 -
                      F-Prot 4.4.4.56 2009.03.20 -
                      F-Secure 8.0.14470.0 2009.03.21 -
                      Fortinet 3.117.0.0 2009.03.21 -
                      GData 19 2009.03.21 -
                      Ikarus T3.1.1.48.0 2009.03.21 -
                      K7AntiVirus 7.10.678 2009.03.21 -
                      Kaspersky 7.0.0.125 2009.03.21 -
                      McAfee 5560 2009.03.21 -
                      McAfee+Artemis 5560 2009.03.21 -
                      McAfee-GW-Edition 6.7.6 2009.03.20 -
                      Microsoft 1.4502 2009.03.21 -
                      NOD32 3953 2009.03.21 -
                      Norman 6.00.06 2009.03.20 -
                      nProtect 2009.1.8.0 2009.03.21 -
                      Panda 10.0.0.10 2009.03.21 -
                      PCTools 4.4.2.0 2009.03.21 -
                      Prevx1 V2 2009.03.21 -
                      Rising 21.21.52.00 2009.03.21 -
                      Sophos 4.39.0 2009.03.21 -
                      Sunbelt 3.2.1858.2 2009.03.20 -
                      Symantec 1.4.4.12 2009.03.21 -
                      TheHacker 6.3.3.1.287 2009.03.21 -
                      TrendMicro 8.700.0.1004 2009.03.20 -
                      VBA32 3.12.10.1 2009.03.20 -
                      ViRobot 2009.3.20.1658 2009.03.20 -
                      VirusBuster 4.6.5.0 2009.03.21 -
                      Information additionnelle
                      File size: 253688 bytes
                      MD5...: a20a975ad5c804ea4a9b043ce50237c8
                      SHA1..: 02a8238fa69bebdd7a218a226b972f4e8a12aa11
                      SHA256: 77ec9eb9b0f988085996589b7e0f3d6c3a3f5eac95a3c60771178f5d63c8fac6
                      SHA512: 0a39c3d445f824d3bfc2ad54393c34c3a81ce221c3a8e17e2feaed7a6e1f6384
                      621cf3e1643c71d58ee69dd32e6196581ba9667454add0368cba9d8070b39520
                      ssdeep: 3072:9AeQB96Y+OeGdkPt0AJMVeAk77AG1vP7c+LZGk5kF4OqXF40Mi0LgjgGsxb
                      9WGWK:9P4ZAJMHknA471Gk581h7zw0/
                      PEiD..: -
                      TrID..: File type identification
                      Win64 Executable Generic (59.6%)
                      Win32 Executable MS Visual C++ (generic) (26.2%)
                      Win32 Executable Generic (5.9%)
                      Win32 Dynamic Link Library (generic) (5.2%)
                      Generic Win/DOS Executable (1.3%)
                      PEInfo: PE Structure information

                      ( base data )
                      entrypointaddress.: 0x290c
                      timedatestamp.....: 0x4991c4e1 (Tue Feb 10 18:18:09 2009)
                      machinetype.......: 0x14c (I386)

                      ( 5 sections )
                      name viradd virsiz rawdsiz ntrpy md5
                      .text 0x1000 0x9cb7 0xa000 6.57 b1c181e04e0037b8855cddeff57451eb
                      .rdata 0xb000 0x401a 0x5000 4.66 0f4cc9fc429eccb2b64d167e8c302924
                      .data 0x10000 0x1c9c 0x1000 2.28 027809311db36d743f35bdb32310ab8a
                      .rsrc 0x12000 0x29454 0x2a000 7.08 7b1d2a23916d1bd6761468532410092e
                      .reloc 0x3c000 0x1eb0 0x2000 4.75 a6f3a2a65113d791f3cb2b8b00d29c1c

                      ( 7 imports )
                      > ntdll.dll: RtlUnwind, _wcslwr, RtlImageNtHeader, RtlInitUnicodeString, ZwQueryValueKey, ZwOpenKey, wcsstr, RtlImageDirectoryEntryToData, ZwClose
                      > SHLWAPI.dll: PathFindFileNameA, wnsprintfA
                      > VERSION.dll: GetFileVersionInfoA, VerQueryValueA, GetFileVersionInfoSizeA
                      > KERNEL32.dll: LCMapStringA, GetStringTypeW, GetStringTypeA, GetLocaleInfoA, MultiByteToWideChar, GetCurrentThreadId, CloseHandle, VirtualAlloc, GetCurrentProcessId, GetModuleFileNameW, GetModuleFileNameA, CreateThread, ExitProcess, GetModuleHandleA, LoadLibraryA, GetCurrentThread, VirtualFree, VirtualQuery, LCMapStringW, InterlockedCompareExchange, ResumeThread, FlushInstructionCache, GetCurrentProcess, GetThreadContext, SetThreadContext, GetLastError, SuspendThread, SetLastError, HeapSize, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, WriteFile, InitializeCriticalSection, RaiseException, GetSystemTimeAsFileTime, GetTickCount, QueryPerformanceCounter, VirtualProtect, HeapFree, GetEnvironmentStringsW, WideCharToMultiByte, FreeEnvironmentStringsW, GetCommandLineA, GetVersionExA, HeapAlloc, GetProcessHeap, HeapDestroy, HeapCreate, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, HeapReAlloc, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetProcAddress, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, InterlockedDecrement, Sleep, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings
                      > USER32.dll: LoadImageA, PostQuitMessage, GetWindowLongA, CallWindowProcA, SetWindowTextA, PostMessageA, DialogBoxParamA, SetCursor, GetDlgItem, SetWindowLongA, SendMessageA, LoadCursorA, MessageBoxA
                      > GDI32.dll: SetBkMode, CreateFontA, GetStockObject, SetTextColor
                      > SHELL32.dll: SHGetFileInfoA
                      0
                      1. -----------\\ ToolBar S&D 1.2.8 XP/Vista

                        Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
                        X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 3.06GHz )
                        BIOS : BIOS Date: 09/30/05 18:13:56 Ver: 08.00.10
                        USER : Compaq_Propriétaire ( Administrator )
                        BOOT : Normal boot
                        Antivirus : AntiVir Desktop 9.0.1.26 (Activated)
                        Firewall : COMODO Firewall 3.5 (Activated)
                        C:\ (Local Disk) - NTFS - Total:143 Go (Free:34 Go)
                        D:\ (Local Disk) - FAT32 - Total:5 Go (Free:5 Go)
                        E:\ (CD or DVD)
                        F:\ (USB)
                        G:\ (USB)
                        H:\ (USB)
                        I:\ (USB)
                        K:\ (Local Disk) - FAT32 - Total:232 Go (Free:167 Go)

                        "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                        Option : [2] ( 15/04/2009|16:17 )
                        C:\DOCUME~1\COMPAQ~1.VIO\LOCALS~1\Temp\nstE7.tmp

                        -----------\\ SUPPRESSION

                        Supprime! - C:\Program Files\AskBarDis\bar
                        Supprime! - C:\Program Files\AskBarDis\unins000.dat
                        Supprime! - C:\Program Files\AskBarDis\unins000.exe
                        Supprime! - C:\Program Files\KaZaA\My Shared Folder
                        Supprime! - C:\DOCUME~1\COMPAQ~1.VIO\LOCALS~1\Temp\nstE7.tmp
                        Supprime! - C:\Program Files\AskBarDis
                        Supprime! - C:\Program Files\KaZaA

                        -----------\\ Recherche de Fichiers / Dossiers ...

                        -----------\\ Extensions

                        (Compaq_Propriétaire) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} => freecorder
                        (Compaq_Propriétaire) - {635abd67-4fe9-1b23-4f01-e679fa7484c1} => ytoolbar
                        (Compaq_Propriétaire) - {dd30bf68-268a-4815-ad48-8740b774c764} => redcats_green

                        (Compaq_Propriétaire.VIOLETTE) - {E9A1DEE0-C623-4439-8932-001E7D17607D} => ajtoolbar

                        -----------\\ [..\Internet Explorer\Main]

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                        "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                        "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                        "Start Page"="https://www.comodo.com/search/"

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                        "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                        "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                        "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                        "Start Page"="https://www.msn.com/fr-fr/"

                        --------------------\\ Recherche d'autres infections

                        Aucune autre infection trouvée !

                        1 - "C:\ToolBar SD\TB_1.txt" - 15/04/2009|16:20 - Option : [2]

                        -----------\\ Fin du rapport a 16:20:36,73
                        0
                        1. Contributeur sécurité
                          Et le firewall n'arrete pas de se mettre pour les applications, tant que c'est moi qui lance, je mets ok ?!

                          oui

                          mais en general il te faut accepter pour toujours pour ne pas avoir l'alerte en permanence

                          ___________________

                          analyse ce fichier sur virus total et colle le rapport: https://www.virustotal.com/gui/

                          C:\WINDOWS\system32\cssdll32.dll

                          ______________________

                          tu as mis ask search : il est preferable de le virer: avec toolbar sd option 2

                          Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
                          https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                          * Lance l'installation du programme en exécutant le fichier téléchargé.
                          * Double-clique maintenant sur le raccourci de Toolbar-S&D.
                          * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
                          * Choisis maintenant l'option 2. Patiente jusqu'à la fin de la recherche.
                          * Poste le rapport généré. (C:\TB.txt)

                          __________________________

                          tu me colle un rapport avec antivir pour verifier

                          __________________________

                          mettre a jour internet explorer
                          pour XP
                          https://www.microsoft.com/en-us/download

                          _________________

                          mettre à jour adobe reader puis supprimer les anciennes version via le panneau de configuration
                          https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html

                          _______________

                          Mettre a jour java:
                          https://javara.fr.malavida.com/

                          Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries.
                          Décompresse le fichier sur ton bureau (clique droit > Extraire tout.)
                          Double-clique sur le répertoire JavaRa obtenu.
                          Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher)
                          Clique sur Search For Updates.
                          Sélectionne Update Using jucheck.exe puis clique sur Search.
                          Autorise le processus à se connecter s'il te le demande, clique sur Install et suis les instructions d'installation. Cela prendra quelques minutes.
                          Quand l'installation est terminée, revient à l'écran de JavaRa et clique sur Remove Older Versions.
                          Clique sur Oui pour confirmer. L'outil va travailler, clique ensuite sur Ok, puis une deuxième fois sur Ok.
                          Un rapport va s'ouvrir, copie-colle le dans ta prochaine réponse.
                          Note : le rapport se trouve aussi à la racine de la partition système, en général C:\ sous le nom JavaRa.log
                          (c:\JavaRa.log)
                          Ferme l'application.

                          si cela ne fonctionne pas

                          https://www.java.com/fr/download/windows_manual.jsp?locale=fr&host=www.java.com:80

                          tu peux désinstaller les vieilles versions.
                          __________________
                          0
                          1. J'ai encore enlevé un trojan et un autre truc.. =S
                            Murf !
                            Et le firewall n'arrete pas de se mettre pour les applications, tant que c'est moi qui lance, je mets ok ?!
                            0
                            1. info.txt logfile of random's system information tool 1.06 2009-04-15 13:44:05

                              ======Uninstall list======

                              -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
                              -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
                              -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
                              -->c:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
                              -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                              Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                              Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
                              Adobe Reader 7.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70000000000}
                              Ask Toolbar-->"C:\Program Files\AskBarDis\unins000.exe"
                              Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
                              Choice Guard-->MsiExec.exe /I{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}
                              COMODO Internet Security-->C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe -u
                              COMODO SafeSurf-->C:\Program Files\COMODO\SafeSurf\cssconfg.exe -u
                              Compaq Multimedia Keyboard Software-->C:\HP\KBD\KBD.EXE uninstalled
                              Connexion Facile à Internet-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{8105684D-8CA6-440D-8F58-7E5FD67A499D} /l1036
                              Correctif Windows XP - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
                              Correctif Windows XP - KB883667-->C:\WINDOWS\$NtUninstallKB883667$\spuninst\spuninst.exe
                              Correctif Windows XP - KB885250-->C:\WINDOWS\$NtUninstallKB885250$\spuninst\spuninst.exe
                              Correctif Windows XP - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
                              Correctif Windows XP - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
                              Correctif Windows XP - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
                              Correctif Windows XP - KB887742-->C:\WINDOWS\$NtUninstallKB887742$\spuninst\spuninst.exe
                              Correctif Windows XP - KB888113-->C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe
                              Correctif Windows XP - KB888239-->C:\WINDOWS\$NtUninstallKB888239$\spuninst\spuninst.exe
                              Correctif Windows XP - KB890175-->C:\WINDOWS\$NtUninstallKB890175$\spuninst\spuninst.exe
                              Correctif Windows XP - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
                              Correctif Windows XP - KB893066-->"C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe"
                              Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
                              High Definition Audio - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
                              HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                              HP Software Update-->MsiExec.exe /X{ECFDD6BD-E0C0-41CC-A171-E6D6AF4C0E93}
                              Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                              Installation Windows Live-->MsiExec.exe /I{7370DF47-B4F9-4279-BFC3-3F09919F720D}
                              InterVideo WinDVD Player-->"C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
                              iTunes-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{523E6F2A-2D59-4D91-90E8-6C49931C9F50}
                              J2SE Runtime Environment 5.0-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150000}
                              Junk Mail filter update-->MsiExec.exe /I{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}
                              Lecteur Windows Media 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                              Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                              Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                              Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                              Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                              Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                              Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
                              Microsoft Works-->MsiExec.exe /I{A059DE09-1B49-4450-B340-7AE097EC3F04}
                              Mise à jour de sécurité pour Windows XP (KB883939)-->"C:\WINDOWS\$NtUninstallKB883939$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
                              Mise à jour de sécurité pour Windows XP (KB896422)-->"C:\WINDOWS\$NtUninstallKB896422$\spuninst\spuninst.exe"
                              Mozilla Firefox (3.0.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                              MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                              NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
                              Orange - Logiciels Internet-->C:\Program Files\OrangeHSS\installation\core\Installgui.exe -u
                              Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                              PC-Doctor 5 for Windows-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{AB61A692-5543-4C48-979B-8CEA1C52FE9C} /l1036
                              PS2-->C:\WINDOWS\system32\ps2.exe uninstall
                              Python 2.2 pywin32 extensions (build 203)-->"C:\Python22\Removepywin32.exe" -u "C:\Python22\pywin32-wininst.log"
                              Python 2.2.3-->C:\Python22\UNWISE.EXE C:\Python22\INSTALL.LOG
                              QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
                              Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
                              Sonic Express Labeler-->MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
                              Sonic MyDVD Plus-->MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}
                              Sonic RecordNow Audio-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
                              Sonic RecordNow Copy-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
                              Sonic RecordNow Data-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
                              Sonic Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
                              Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                              UsbFix-->J:\UsbFix\Uninstal.exe
                              Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
                              Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                              Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
                              Windows Live Mail-->MsiExec.exe /I{63DC2DA0-2A6C-4C38-9249-B75395458657}
                              Windows Live Messenger-->MsiExec.exe /X{059C042E-796A-4ACC-A81A-ECC2010BB78C}
                              Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll

                              ======Hosts File======

                              127.0.0.1 www.007guard.com
                              127.0.0.1 007guard.com
                              127.0.0.1 008i.com
                              127.0.0.1 www.008k.com
                              127.0.0.1 008k.com
                              127.0.0.1 www.00hq.com
                              127.0.0.1 00hq.com
                              127.0.0.1 010402.com
                              127.0.0.1 www.032439.com
                              127.0.0.1 032439.com

                              ======Security center information======

                              AV: AntiVir Desktop
                              FW: COMODO Firewall

                              ======System event log======

                              Computer Name: VIOLETTE
                              Event Code: 7035
                              Message: Un contrôle Démarrer a correctement été envoyé au service Compatibilité avec le Changement rapide d'utilisateur.

                              Record Number: 5
                              Source Name: Service Control Manager
                              Time Written: 20090414111814.000000+120
                              Event Type: Informations
                              User: AUTORITE NT\SYSTEM

                              Computer Name: VIOLETTE
                              Event Code: 7036
                              Message: Le service Services Terminal Server est entré dans l'état : en cours d'exécution.

                              Record Number: 4
                              Source Name: Service Control Manager
                              Time Written: 20090414111814.000000+120
                              Event Type: Informations
                              User:

                              Computer Name: VIOLETTE
                              Event Code: 6005
                              Message: Le service d'Enregistrement d'événement a démarré.

                              Record Number: 3
                              Source Name: EventLog
                              Time Written: 20090414111731.000000+120
                              Event Type: Informations
                              User:

                              Computer Name: VIOLETTE
                              Event Code: 6009
                              Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Uniprocessor Free.

                              Record Number: 2
                              Source Name: EventLog
                              Time Written: 20090414111731.000000+120
                              Event Type: Informations
                              User:

                              Computer Name: Violette
                              Event Code: 115
                              Message: Le suivi de la Restauration système a été activé sur tous les lecteurs.

                              Record Number: 1
                              Source Name: SRService
                              Time Written: 20090414111634.000000+120
                              Event Type: Informations
                              User:

                              ======Environment variables======

                              "ComSpec"=%SystemRoot%\system32\cmd.exe
                              "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;c:\Python22
                              "windir"=%SystemRoot%
                              "FP_NO_HOST_CHECK"=NO
                              "OS"=Windows_NT
                              "PROCESSOR_ARCHITECTURE"=x86
                              "PROCESSOR_LEVEL"=15
                              "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
                              "PROCESSOR_REVISION"=0401
                              "NUMBER_OF_PROCESSORS"=1
                              "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                              "TEMP"=%SystemRoot%\TEMP
                              "TMP"=%SystemRoot%\TEMP
                              "SonicCentral"=c:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\

                              -----------------EOF-----------------
                              0
                              1. Logfile of random's system information tool 1.06 (written by random/random)
                                Run by Compaq_Propriétaire at 2009-04-15 13:39:00
                                Microsoft Windows XP Édition familiale Service Pack 2
                                System drive C: has 36 GB (25%) free of 146 GB
                                Total RAM: 1023 MB (43% free)

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 13:44:02, on 15/04/2009
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                                C:\windows\system\hpsysdrv.exe
                                C:\WINDOWS\SOUNDMAN.EXE
                                C:\WINDOWS\ALCWZRD.EXE
                                C:\HP\KBD\KBD.EXE
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                                C:\WINDOWS\system32\rundll32.exe
                                C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                C:\Program Files\COMODO\SafeSurf\cssurf.exe
                                C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe
                                C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
                                C:\WINDOWS\system32\nvsvc32.exe
                                C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                                C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
                                C:\Program Files\iPod\bin\iPodService.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                C:\Program Files\Windows Live\Contacts\wlcomm.exe
                                C:\Program Files\Mozilla Firefox\firefox.exe
                                C:\Documents and Settings\Compaq_Propriétaire.VIOLETTE\Bureau\RSIT.exe
                                C:\Program Files\trend micro\Compaq_Propriétaire.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comodo.com/search/
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                                R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
                                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
                                O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                                O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                                O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
                                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                                O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
                                O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
                                O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                                O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
                                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                                O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
                                O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
                                O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                                O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
                                O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                O4 - Global Startup: Wireless Configuration Utility.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
                                O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
                                O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
                                O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
                                O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                                O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O12 - Plugin for .xml: C:\Program Files\Internet Explorer\PLUGINS\NPMyrMus.dll
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{D274E393-331E-496C-8594-046D911D7852}: NameServer = 192.168.1.1
                                O20 - AppInit_DLLs: C:\WINDOWS\system32\cssdll32.dll
                                O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
                                O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                0
                                1. Contributeur sécurité
                                  mets déjà ceci

                                  MalwareByte's Anti-Malware + SPYBOT
                                  SPYWAREBLASTER

                                  pour virer ceux dont tu n'a pas besoin lance tool cleaner

                                  le disque D etait branché pendant la désinfection? branche le sans l'ouvrir et remets un rapport RSIT
                                  0
                                  1. "des anti-espions :
                                    MalwareByte's Anti-Malware + SPYBOT +/- si tea timer non active de spybot:
                                    WINDOWS DEFENDER ou SPYWARE TERMINATOR ou SPYWARE GUARD
                                    +
                                    SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)... "

                                    Je mets tous ceux là ?
                                    0
                                    1. Tu vas rire, il m'a fallu d'installer firefox !
                                      Je vais maintenant installer les autres logiciels que tu m'as conseillé.
                                      Puis je enlever les logiciels et programmes inutils sur mon pc ? De meme que mon disque D est a craqué pour rien.. et j'n'arrive pas à le formater.. =)
                                      J'te remercie en et encore en tout cas vraiment !
                                      0
                                      1. J'ai déjà essayé, sur réseau local, mais c'est mon réseau à distance orange qui est marqué d'une croix rouge. Et ce lui là n'a pas toutes ces options de masque et passerelle.
                                        Quand je vais sur internet, je suis en mode hors connexion et quand j'enleve dans e menu fichier ça revient. :S
                                        0
                                        • 1
                                        • 2
                                        • 3
                                        • 4
                                        • 5