Rapport hijack

Résolu
Bonjour a tous ;)
voici le rapport que je viens d'effectuer

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:15:34, on 20/05/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\carpserv.exe
C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CardDetector\HUAWEI\CardDetector.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe
C:\Program Files\OrangeHSS\Launcher\Launcher.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\1\FTCOMModule.exe
C:\Program Files\OrangeHSS\systray\systrayapp.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
c:\documents and settings\môa\local settings\application data\wycceya.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Watch] C:\PROGRA~1\Minitel\Watch.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [CardDetectorHUAWEI] C:\Program Files\CardDetector\HUAWEI\CardDetector.exe
O4 - HKLM\..\Run: [BEWINTERNET-FR-DMGP-V2SessionManager] "C:\Program Files\Orange\IEWInternet\SessionManager\SessionManager.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
O4 - HKLM\..\RunOnce: [End_Install] C:\DOCUME~1\MAAF78~1\LOCALS~1\Temp\SHK0.bat
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [wycceya] "c:\documents and settings\môa\local settings\application data\wycceya.exe" wycceya
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mappy.com
O15 - Trusted Zone: http://*.orange.fr
O15 - Trusted Zone: http://rw.search.ke.voila.fr
O15 - Trusted Zone: http://orange.weborama.fr
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

--
End of file - 10280 bytes

pouvez vous me dire si tout va bien ?
Merci.
Configuration: Windows XP
Firefox 3.0.10

31 réponses

Résumé de la discussion

Un utilisateur présente un rapport HijackThis et demande si le système Windows XP est sain après l’analyse, en évaluant les processus, les services et les éléments de démarrage listés. Des entrées suspectes apparaissent, notamment wycceya.exe dans le dossier Application Data, et plusieurs composants comme SweetIM, Google Toolbar et Java suscitent des inquiétudes. Plusieurs réponses divergent: l’une affirme que tout n’est pas net et signale des plantages MSN, tandis qu’une autre conseille de retirer une vieille toolbar SD et d’en télécharger une nouvelle. La quatrième intervention propose un guide de nettoyage avec Navilog1 (Navipromo), détaillant l’installation, le choix des options et l’extraction du rapport pour publier le résultat et poursuivre le processus de nettoyage.

Bobot (l’IA à votre service)
  1. Merci a vous tous pour nous aider nous inconscients de l'internet !
    je serais plus vigilante dorénavant ;)
    Encore merci a toi et a ton équipe !

    Les problèmes informatiques se situent généralement entre le clavier et la chaise lol !
    1. Modérateur
      1/

      ---> Désinstalle HijackThis.

      ---> Télécharge ToolsCleaner2 sur ton Bureau.
      * Double-clique sur ToolsCleaner2.exe pour le lancer.
      * Clique sur Recherche et laisse le scan agir.
      * Clique sur Suppression pour finaliser.
      * Tu peux, si tu le souhaites, te servir des Options Facultatives.
      * Clique sur Quitter pour obtenir le rapport.
      * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

      2/

      ---> Télécharge et installe CCleaner Slim.
      * Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
      * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
      * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs (Sauvegarde la base de registre).

      3/

      ---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger.

      ==Prévention==

      Conserve MBAM. Il te servira à scanner les fichiers douteux en complément de l'antivirus et scanne le disque dur régulièrement.

      Comme navigateur, utilise plutôt Mozilla Firefox qu'Internet Explorer.

      Vérifie que les mises à jour automatiques sont bien activées (Menu Démarrer, clique droit sur Poste de travail, onglet Mises à jour automatiques).

      Par rapport au P2P : Lien

      Voici un dossier complet (A lire avec Adobe Reader ou Foxit Reader) : Lien

      Sois plus vigilant(e) sur Internet ;)
      1. ========== PROCESSES ==========
        Process explorer.exe killed successfully.
        ========== SERVICES/DRIVERS ==========

        Service\Driver AGWinService deleted successfully.
        ========== FILES ==========
        C:\Program Files\AGI\tmp moved successfully.
        C:\Program Files\AGI\Python25\Lib\xml\sax moved successfully.
        C:\Program Files\AGI\Python25\Lib\xml\parsers moved successfully.
        C:\Program Files\AGI\Python25\Lib\xml\etree moved successfully.
        C:\Program Files\AGI\Python25\Lib\xml\dom moved successfully.
        C:\Program Files\AGI\Python25\Lib\xml moved successfully.
        C:\Program Files\AGI\Python25\Lib\logging moved successfully.
        C:\Program Files\AGI\Python25\Lib\hotshot moved successfully.
        C:\Program Files\AGI\Python25\Lib\encodings moved successfully.
        C:\Program Files\AGI\Python25\Lib\email\mime moved successfully.
        C:\Program Files\AGI\Python25\Lib\email moved successfully.
        C:\Program Files\AGI\Python25\Lib\ctypes moved successfully.
        C:\Program Files\AGI\Python25\Lib\compiler moved successfully.
        C:\Program Files\AGI\Python25\Lib moved successfully.
        C:\Program Files\AGI\Python25\DLLs moved successfully.
        C:\Program Files\AGI\Python25 moved successfully.
        C:\Program Files\AGI\common\win32comext\shell moved successfully.
        C:\Program Files\AGI\common\win32comext\axcontrol moved successfully.
        C:\Program Files\AGI\common\win32comext\authorization moved successfully.
        C:\Program Files\AGI\common\win32comext\adsi moved successfully.
        C:\Program Files\AGI\common\win32comext moved successfully.
        C:\Program Files\AGI\common\win32com\server moved successfully.
        C:\Program Files\AGI\common\win32com\client moved successfully.
        C:\Program Files\AGI\common\win32com moved successfully.
        C:\Program Files\AGI\common\win32\scripts moved successfully.
        C:\Program Files\AGI\common\win32\lib moved successfully.
        C:\Program Files\AGI\common\win32 moved successfully.
        C:\Program Files\AGI\common\pyagcore\search\provider moved successfully.
        C:\Program Files\AGI\common\pyagcore\search\algorithm moved successfully.
        C:\Program Files\AGI\common\pyagcore\search moved successfully.
        C:\Program Files\AGI\common\pyagcore\protection moved successfully.
        C:\Program Files\AGI\common\pyagcore\process moved successfully.
        C:\Program Files\AGI\common\pyagcore\lilw moved successfully.
        C:\Program Files\AGI\common\pyagcore\install\installers moved successfully.
        C:\Program Files\AGI\common\pyagcore\install\dependency moved successfully.
        C:\Program Files\AGI\common\pyagcore\install moved successfully.
        C:\Program Files\AGI\common\pyagcore\config moved successfully.
        C:\Program Files\AGI\common\pyagcore moved successfully.
        C:\Program Files\AGI\common\dateutil\zoneinfo moved successfully.
        C:\Program Files\AGI\common\dateutil moved successfully.
        C:\Program Files\AGI\common\comtypes\tools moved successfully.
        C:\Program Files\AGI\common\comtypes\server moved successfully.
        C:\Program Files\AGI\common\comtypes\gen moved successfully.
        C:\Program Files\AGI\common\comtypes\client moved successfully.
        C:\Program Files\AGI\common\comtypes moved successfully.
        C:\Program Files\AGI\common moved successfully.
        C:\Program Files\AGI moved successfully.
        ========== REGISTRY ==========
        Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}\\ deleted successfully.
        ========== COMMANDS ==========
        File delete failed. C:\DOCUME~1\MAAF78~1\LOCALS~1\Temp\~DF3E0D.tmp scheduled to be deleted on reboot.
        User's Temp folder emptied.
        User's Internet Explorer cache folder emptied.
        File delete failed. C:\Documents and Settings\Môa\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
        User's Temporary Internet Files folder emptied.
        Local Service Temp folder emptied.
        File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
        Local Service Temporary Internet Files folder emptied.
        Network Service Temp folder emptied.
        Network Service Temporary Internet Files folder emptied.
        File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_2dc.dat scheduled to be deleted on reboot.
        Windows Temp folder emptied.
        Java cache emptied.
        FireFox cache emptied.
        Temp folders emptied.

        OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05202009_214506

        Files moved on Reboot...
        C:\DOCUME~1\MAAF78~1\LOCALS~1\Temp\~DF3E0D.tmp moved successfully.
        File C:\WINDOWS\temp\Perflib_Perfdata_2dc.dat not found!
        1. Modérateur
          ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

          ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau.

          ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

          ---> Copie (Ctrl+C) le texte suivant ci-dessous :

          :processes
          explorer.exe

          :services
          AGWinService

          :files
          C:\Program Files\AGI

          :reg
          [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}]

          :commands
          [purity]
          [emptytemp]
          [reboot]

          ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

          ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

          Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
          Accepte en cliquant sur YES.

          ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
          Le nom du rapport correspond au moment de sa création : date_heure.log
          1. Malwarebytes' Anti-Malware 1.36
            Version de la base de données: 2159
            Windows 5.1.2600 Service Pack 3

            20/05/2009 21:01:46
            mbam-log-2009-05-20 (21-01-46).txt

            Type de recherche: Examen rapide
            Eléments examinés: 76233
            Temps écoulé: 8 minute(s), 13 second(s)

            Processus mémoire infecté(s): 0
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 0
            Valeur(s) du Registre infectée(s): 0
            Elément(s) de données du Registre infecté(s): 3
            Dossier(s) infecté(s): 0
            Fichier(s) infecté(s): 0

            Processus mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Valeur(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Elément(s) de données du Registre infecté(s):
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

            Dossier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Fichier(s) infecté(s):
            (Aucun élément nuisible détecté)
            1. Modérateur
              ---> Désinstalle Java 6 Update 7.

              ---> Mets à jour Java.

              ---> Mets à jour Adobe Reader.

              ---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
              ---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
              ---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
              ---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
              ---> Sélectionne Exécuter un examen rapide.
              ---> Clique sur Rechercher. L'analyse démarre.

              A la fin de l'analyse, un message s'affiche :

              L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.

              ---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
              ---> Ferme tes navigateurs.
              Si des malwares ont été détectés, clique sur Afficher les résultats.
              ---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
              ---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
              1. Et voila le rapport :

                ========== PROCESSES ==========
                Process explorer.exe killed successfully.
                ========== FILES ==========
                C:\Program Files\SweetIM\Messenger moved successfully.
                C:\Program Files\SweetIM moved successfully.
                ========== COMMANDS ==========
                File delete failed. C:\DOCUME~1\MAAF78~1\LOCALS~1\Temp\etilqs_DDVhp5aOhq4tWSPQC8DN scheduled to be deleted on reboot.
                File delete failed. C:\DOCUME~1\MAAF78~1\LOCALS~1\Temp\~DF62F1.tmp scheduled to be deleted on reboot.
                File delete failed. C:\DOCUME~1\MAAF78~1\LOCALS~1\Temp\~DFC19B.tmp scheduled to be deleted on reboot.
                User's Temp folder emptied.
                User's Internet Explorer cache folder emptied.
                File delete failed. C:\Documents and Settings\Môa\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                User's Temporary Internet Files folder emptied.
                Local Service Temp folder emptied.
                File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                Local Service Temporary Internet Files folder emptied.
                Network Service Temp folder emptied.
                File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                Network Service Temporary Internet Files folder emptied.
                Windows Temp folder emptied.
                Java cache emptied.
                File delete failed. C:\Documents and Settings\Môa\Local Settings\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\Môa\Local Settings\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\Môa\Local Settings\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\Môa\Local Settings\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
                File delete failed. C:\Documents and Settings\Môa\Local Settings\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
                FireFox cache emptied.
                Temp folders emptied.

                OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05202009_200723

                Files moved on Reboot...
                File C:\DOCUME~1\MAAF78~1\LOCALS~1\Temp\etilqs_DDVhp5aOhq4tWSPQC8DN not found!
                File C:\DOCUME~1\MAAF78~1\LOCALS~1\Temp\~DF62F1.tmp not found!
                C:\DOCUME~1\MAAF78~1\LOCALS~1\Temp\~DFC19B.tmp moved successfully.
                C:\Documents and Settings\Môa\Local Settings\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\Cache\_CACHE_001_ moved successfully.
                C:\Documents and Settings\Môa\Local Settings\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\Cache\_CACHE_002_ moved successfully.
                C:\Documents and Settings\Môa\Local Settings\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\Cache\_CACHE_003_ moved successfully.
                C:\Documents and Settings\Môa\Local Settings\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\Cache\_CACHE_MAP_ moved successfully.
                C:\Documents and Settings\Môa\Local Settings\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\urlclassifier3.sqlite moved successfully.
                1. Modérateur
                  ---> Désinstalle Navilog1 et Ad-Remover.

                  ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

                  ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau.

                  ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

                  ---> Copie (Ctrl+C) le texte suivant ci-dessous :

                  :processes
                  explorer.exe

                  :files
                  C:\Program Files\SweetIM

                  :commands
                  [purity]
                  [emptytemp]
                  [reboot]

                  ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                  ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                  Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                  Accepte en cliquant sur YES.

                  ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                  Le nom du rapport correspond au moment de sa création : date_heure.log
                  1. voilà le rapport :

                    ------- LOGFILE OF AD-REMOVER 1.1.4.1 | ONLY XP/VISTA -------

                    Updated by C_XX on 19/05/2009 at 18:40
                    Contact: AdRemover.contact@gmail.com
                    Website: http://pagesperso-orange.fr/NosTools/ad_remover.html

                    **** LIMITED TO ****

                    Known Adwares
                    Eorezo
                    It's TV
                    Sweetim

                    ********************

                    Start at: 19:41:59, 20/05/2009 | Boot mode: Normal Boot
                    Option: Clean | Executed from: C:\Program Files\Ad-remover\
                    Operating System: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
                    Computer Name: CPQ18277198112
                    Current User: M“a - Administrator

                    (!) -- IE start pages/Tabs reset

                    ============ Known Adwares Deleted ============

                    .
                    .
                    C:\Documents and Settings\M“a\Cookies\m“a@atdmt[2].txt
                    C:\Documents and Settings\M“a\Cookies\m“a@bs.serving-sys[2].txt

                    +-----------------| Eorezo Elements Deleted :

                    .

                    +-----------------| It's TV Elements Deleted :

                    .

                    +-----------------| Sweetim Elements Deleted :

                    HKCR\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
                    HKCR\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
                    HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
                    HKCR\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
                    HKCR\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
                    HKCR\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
                    HKCR\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
                    HKCR\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
                    HKCR\MediaPlayer.GraphicsUtils
                    HKCR\MediaPlayer.GraphicsUtils.1
                    HKCR\MgMediaPlayer.GifAnimator
                    HKCR\MgMediaPlayer.GifAnimator.1
                    HKCR\SWEETIE.IEToolbar
                    HKCR\SWEETIE.IEToolbar.1
                    HKCR\SWEETIE.SWEETIE
                    HKCR\SWEETIE.SWEETIE.3
                    HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook
                    HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook.1
                    HKCR\Toolbar3.SWEETIE
                    HKCR\Toolbar3.SWEETIE.1
                    HKCR\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
                    HKCR\Typelib\{EEE6C35E-6118-11DC-9C72-001320C79847}
                    HKCR\Typelib\{EEE6C35F-6118-11DC-9C72-001320C79847}
                    HKCU\Software\SweetIM
                    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
                    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
                    HKLM\Software\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289}
                    HKLM\Software\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}
                    HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{266C7330-C0F4-49E5-8F20-A56F9F822875}
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}
                    HKLM\Software\SweetIM
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Sweetim
                    HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847}
                    HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847}
                    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847}
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\1AC67655DD68F8240B2860F2D511EBD8
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\351716A953E21214898904032EAE2E81
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5D19F074C042AD34BAB463D4175A062E
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\A189D17A469616C4688D23E192996267
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E337925F629CF4C4FB08F3D9674DD839
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
                    HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
                    .
                    C:\WINDOWS\Installer\81f1589.msi
                    C:\WINDOWS\Installer\81f158e.msi
                    /!\ NOT DELETED - C:\Program Files\SweetIM
                    C:\Documents and Settings\M“a\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\searchplugins\sweetim.xml
                    C:\Documents and Settings\M“a\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
                    C:\Documents and Settings\M“a\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\SweetIMToolbarData
                    C:\Documents and Settings\All Users\Application Data\SweetIM
                    C:\Documents and Settings\M“a\Bureau\SweetImSetup.exe
                    C:\WINDOWS\Prefetch\SWEETIM.EXE-114201E6.pf

                    (!) -- Temp files deleted.
                    (!) -- Recycle bin emptied in all drives.

                    ********** /!\ FILE(S)/FOLDER(S) NOT DELETED /!\ **********

                    "C:\Program Files\SweetIM"

                    Second run ...

                    /!\ RESIST ! - "C:\Program Files\SweetIM"

                    +-----------------| Added Scan:

                    ---- Mozilla FireFox Version 3.0.10 ----

                    ProfilePath: x6yib4zc.default (M“a)
                    .
                    (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.10");
                    .
                    (Prefs.js) Removed: user_pref("keyword.URL", "hxxp://search.sweetim.com/search.asp?src=2&q=");
                    (Prefs.js) Removed: user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
                    (Prefs.js) Removed: user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
                    (Prefs.js) Removed: user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
                    (Prefs.js) Removed: user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
                    (Prefs.js) Removed: user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
                    (Prefs.js) Removed: user_pref("sweetim.toolbar.mode.debug", "false");
                    (Prefs.js) Removed: user_pref("sweetim.toolbar.previous.keyword.URL", "chrome://browser-region/locale/region.properties");
                    (Prefs.js) Removed: user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engine=\"hxxp://*google.*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://search.yahoo.com/*\" param=\"p=\" /><EXTERNAL_SEARCH engine=\"hxxp://search.sweetim.*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://*.live.*/*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://*youtube.com/\" param=\"search_query=\" /><EXTERNAL_SEARCH engine=\"hxxp://*.ebay.*/search/*\" param=\"satitle=\" /><EXTERNAL_SEARCH engine=\"hxxp://*.amazon.com/s/*\" param=\"field-keywords=\" /></TOOLBAR>");
                    (Prefs.js) Removed: user_pref("sweetim.toolbar.search.history.capacity", "10");
                    (Prefs.js) Removed: user_pref("sweetim.toolbar.simapp_id", "{5CB91F00-309D-11DE-84C3-000BCD8B6E82}");
                    (Prefs.js) Removed: user_pref("sweetim.toolbar.version", "1.0.0.8");

                    ---- Internet Explorer Version 7.0.5730.11 ----

                    [HKEY_CURRENT_USER\..\Internet Explorer\Main]

                    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                    [HKEY_USERS\S-1-5-21-2931578194-2979417811-388342862-1006\..\Internet Explorer\Main]

                    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

                    [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

                    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Search bar: hxxp://search.msn.com/spbasic.htm
                    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                    Start Page: hxxp://fr.msn.com/

                    [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

                    Tabs: hxxp://ieframe.dll/tabswelcome.htm

                    =========== Suspicious ==========

                    +---------------------------------------------------------------------------+

                    12455 Byte(s) - C:\Ad-Report-Clean-20.05.2009.log
                    12986 Byte(s) - C:\Ad-Report-Scan-20.05.2009.log

                    19 File(s) - C:\Program Files\Ad-remover\BACKUP
                    7 File(s) - C:\Program Files\Ad-remover\QUARANTINE

                    End at: 19:54:03 | 20/05/2009
                    .
                    +-----------------| E.O.F
                    .
                    1. Modérateur
                      ● Désinstalle SweetIM.

                      /!\ Déconnecte-toi et ferme toutes applications en cours /!\

                      ● Double-clique sur AD-Remover pour le lancer : au menu principal, choisis l'option B.

                      ● Coche A à l'écran de sélection :
                      http://sd-1.archive-host.com/membres/up/16506160323759868/Capturer-ADR.JPG

                      ● Puis choisis S, le programme va travailler.

                      ● Poste le rapport qui apparaît à la fin (C:\Ad-Report-Clean-(date).log).

                      /!\ Si le Bureau ne réapparaît pas, presse Ctrl + Alt + Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide /!\
                      1. Pfiou c'étais long ;)

                        ------- LOGFILE OF AD-REMOVER 1.1.4.1 | ONLY XP/VISTA -------

                        Updated by C_XX on 19/05/2009 at 18:40
                        Contact: AdRemover.contact@gmail.com
                        Website: http://pagesperso-orange.fr/NosTools/ad_remover.html

                        Start at: 18:44:00, 20/05/2009 | Boot mode: Normal Boot
                        Option: Scan | Executed from: C:\Program Files\Ad-remover\
                        Operating System: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
                        Computer Name: CPQ18277198112
                        Current User: M“a - Administrator

                        ============ Known Adwares Found ============

                        .
                        .
                        C:\Documents and Settings\M“a\Cookies\m“a@atdmt[2].txt
                        C:\Documents and Settings\M“a\Cookies\m“a@bs.serving-sys[2].txt

                        +-----------------| Eorezo Elements Found:

                        .

                        +-----------------| It's TV Elements Found:

                        .

                        +-----------------| Sweetim Elements Found:

                        HKCR\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
                        HKCR\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
                        HKCR\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
                        HKCR\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
                        HKCR\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
                        HKCR\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
                        HKCR\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
                        HKCR\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
                        HKCR\MediaPlayer.GraphicsUtils
                        HKCR\MediaPlayer.GraphicsUtils.1
                        HKCR\MgMediaPlayer.GifAnimator
                        HKCR\MgMediaPlayer.GifAnimator.1
                        HKCR\SWEETIE.IEToolbar
                        HKCR\SWEETIE.IEToolbar.1
                        HKCR\SWEETIE.SWEETIE
                        HKCR\SWEETIE.SWEETIE.3
                        HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook
                        HKCR\SweetIM_URLSearchHook.ToolbarURLSearchHook.1
                        HKCR\Toolbar3.SWEETIE
                        HKCR\Toolbar3.SWEETIE.1
                        HKCR\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
                        HKCR\Typelib\{EEE6C35E-6118-11DC-9C72-001320C79847}
                        HKCR\Typelib\{EEE6C35F-6118-11DC-9C72-001320C79847}
                        HKCU\Software\SweetIM
                        HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
                        HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
                        HKLM\Software\Classes\MediaPlayer.GraphicsUtils
                        HKLM\Software\Classes\MediaPlayer.GraphicsUtils.1
                        HKLM\Software\Classes\MgMediaPlayer.GifAnimator
                        HKLM\Software\Classes\MgMediaPlayer.GifAnimator.1
                        HKLM\Software\Classes\SWEETIE.IEToolbar
                        HKLM\Software\Classes\SWEETIE.IEToolbar.1
                        HKLM\Software\Classes\SWEETIE.SWEETIE
                        HKLM\Software\Classes\SWEETIE.SWEETIE.3
                        HKLM\Software\Classes\SweetIM_URLSearchHook.ToolbarURLSearchHook
                        HKLM\Software\Classes\SweetIM_URLSearchHook.ToolbarURLSearchHook.1
                        HKLM\Software\Classes\Toolbar3.SWEETIE
                        HKLM\Software\Classes\Toolbar3.SWEETIE.1
                        HKLM\Software\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19}
                        HKLM\Software\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}
                        HKLM\Software\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}
                        HKLM\Software\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A}
                        HKLM\Software\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064}
                        HKLM\Software\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}
                        HKLM\Software\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}
                        HKLM\Software\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}
                        HKLM\Software\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289}
                        HKLM\Software\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847}
                        HKLM\Software\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847}
                        HKLM\Software\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847}
                        HKLM\Software\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F}
                        HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{266C7330-C0F4-49E5-8F20-A56F9F822875}
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}
                        HKLM\Software\SweetIM
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Sweetim
                        HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847}
                        HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847}
                        HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847}
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\07D5290CDBDAE4242926B8E6CA650501
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\08E33F7B61DEFF24BB9673ED7D467636
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\0E3D8A5B48622A445A7DF73FEFF32C3F
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\1AC67655DD68F8240B2860F2D511EBD8
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\34EDDB1BFB3A2D448845F3EFD0F15A43
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\351716A953E21214898904032EAE2E81
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\397C771A7BCAC904697C3EC629ED33ED
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\427EA997C413D1D47907CBFC7B2DB432
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\4318DF19719275242801CBE292063A4C
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\45FC115D1FEAEF849A4E1610D6EC8BF0
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\46A5861A389ADB844AF89E31BC9DF0A1
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\49B0E1A6FF50BBE4289E4E23DE6EA0C7
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\4CCCAC049F34D0540AAC13011398BEDB
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5C4389D0BFB302C479DE4178BD5D9EBA
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5D19F074C042AD34BAB463D4175A062E
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\5D2B09BDEF4FE54418E6F3373CDBC7AC
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\61B65D3397A1FBF4CB1571B5E4F6B5B0
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\68E8A05C60DD9254591DBD16C94EDDBF
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\697E782CF574CC34CBB9566440BA12BC
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\6AE27A8613CF7EA4782F2886F67295E5
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\7CE172051F585E04187BCB97570BFA74
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\86A901BA5265452499DCBF719C378EE3
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\88ABD1CD5C40EC84789A7F6EF86DAC5E
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\98CC8BF5A4A6E6C4ABF7051DDAB8B058
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\9A4B7EF3789F871419D9302583B20C15
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\A189D17A469616C4688D23E192996267
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\A6C53B0F76C44004A8F36716213017DB
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\B59F2D8189784CC46A4597F2842480B0
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\BD746FB95FB8E5B45BF66BE54D5FD91F
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\CCF399FCD6D2D3F46BF02A1378654FC9
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D149C1355C98DE24E82CEFBD996FE06A
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D15DAF33C220F91468A1D7D57C31ACD7
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D3BA76A44C779424889063D5098ED2D6
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\D6D0EB9FDBD90C04D92A7E729058F10D
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\DB59FDB786388EA4D897F3EE715683AC
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\DB8DAD19CFBCC2049A4477183787E8C5
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E1C820A74ED67374BA048B52CB3C3804
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E337925F629CF4C4FB08F3D9674DD839
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\E4748F9A4181FCE46A23C13B517B9420
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\EC65F200D112357449C8B1BC3CFA03D0
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\F327D0C73C0973644A21E8CC852267A0
                        HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
                        .
                        C:\WINDOWS\Installer\81f1589.msi
                        C:\WINDOWS\Installer\81f158e.msi
                        C:\Program Files\SweetIM
                        C:\Documents and Settings\M“a\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\searchplugins\sweetim.xml
                        C:\Documents and Settings\M“a\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
                        C:\Documents and Settings\M“a\Application Data\Mozilla\Firefox\Profiles\x6yib4zc.default\SweetIMToolbarData
                        C:\Documents and Settings\All Users\Application Data\SweetIM
                        C:\Documents and Settings\M“a\Bureau\SweetImSetup.exe
                        C:\WINDOWS\Prefetch\SWEETIM.EXE-114201E6.pf

                        +-----------------| Added Scan:

                        ---- Mozilla FireFox Version 3.0.10 ----

                        ProfilePath: x6yib4zc.default (M“a)
                        .
                        (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.10");
                        .
                        (Prefs.js) Found: user_pref("keyword.URL", "hxxp://search.sweetim.com/search.asp?src=2&q=");
                        (Prefs.js) Found: user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0");
                        (Prefs.js) Found: user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7");
                        (Prefs.js) Found: user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log");
                        (Prefs.js) Found: user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000");
                        (Prefs.js) Found: user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7");
                        (Prefs.js) Found: user_pref("sweetim.toolbar.mode.debug", "false");
                        (Prefs.js) Found: user_pref("sweetim.toolbar.previous.keyword.URL", "chrome://browser-region/locale/region.properties");
                        (Prefs.js) Found: user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engine=\"hxxp://*google.*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://search.yahoo.com/*\" param=\"p=\" /><EXTERNAL_SEARCH engine=\"hxxp://search.sweetim.*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://*.live.*/*\" param=\"q=\" /><EXTERNAL_SEARCH engine=\"hxxp://*youtube.com/\" param=\"search_query=\" /><EXTERNAL_SEARCH engine=\"hxxp://*.ebay.*/search/*\" param=\"satitle=\" /><EXTERNAL_SEARCH engine=\"hxxp://*.amazon.com/s/*\" param=\"field-keywords=\" /></TOOLBAR>");
                        (Prefs.js) Found: user_pref("sweetim.toolbar.search.history.capacity", "10");
                        (Prefs.js) Found: user_pref("sweetim.toolbar.simapp_id", "{5CB91F00-309D-11DE-84C3-000BCD8B6E82}");
                        (Prefs.js) Found: user_pref("sweetim.toolbar.version", "1.0.0.8");

                        ---- Internet Explorer Version 7.0.5730.11 ----

                        [HKEY_CURRENT_USER\..\Internet Explorer\Main]

                        Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        Start Page: hxxp://www.google.fr/

                        [HKEY_USERS\S-1-5-21-2931578194-2979417811-388342862-1006\..\Internet Explorer\Main]

                        Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                        Start Page: hxxp://www.google.fr/

                        [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

                        Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
                        Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                        Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                        Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157

                        [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

                        Tabs: hxxp://ieframe.dll/tabswelcome.htm

                        =========== Suspicious ==========

                        +---------------------------------------------------------------------------+

                        12768 Byte(s) - C:\Ad-Report-Scan-20.05.2009.log

                        1 File(s) - C:\Program Files\Ad-remover\BACKUP
                        0 File(s) - C:\Program Files\Ad-remover\QUARANTINE

                        End at: 18:58:32 | 20/05/2009
                        .
                        +-----------------| E.O.F
                        .
                        1. Modérateur
                          ● Télécharge Ad-Remover (de Cyrildu17 / C_XX) sur ton Bureau.

                          /!\ Déconnecte-toi d'Internet et ferme toutes applications en cours. /!\

                          ● Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program Files).
                          ● Double-clique sur le raccourci d'Ad-Remover située sur ton Bureau.
                          (Sous Vista, il faut cliquer droit sur le raccourci d'Ad-Remover et choisir Exécuter en tant qu'administrateur)
                          ● Au menu principal, choisis l'option A.
                          ● Poste le rapport généré (C:\Ad-Report-Scan-(date).log).

                          (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

                          Note : "Process.exe", une composante de l'outil, est détectée par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                          1. rapport log :
                            Logfile of random's system information tool 1.06 (written by random/random)
                            Run by Môa at 2009-05-20 17:52:48
                            Microsoft Windows XP Édition familiale Service Pack 3
                            System drive C: has 8 GB (21%) free of 38 GB
                            Total RAM: 447 MB (20% free)

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 17:53:04, on 20/05/2009
                            Platform: Windows XP SP3 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16762)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                            C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe
                            C:\WINDOWS\system32\HPConfig.exe
                            C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\carpserv.exe
                            C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
                            C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\Program Files\SweetIM\Messenger\SweetIM.exe
                            C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
                            C:\Program Files\CardDetector\HUAWEI\CardDetector.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\Program Files\OrangeHSS\systray\systrayapp.exe
                            C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
                            C:\Program Files\OrangeHSS\Launcher\Launcher.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
                            C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
                            C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
                            C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\1\FTCOMModule.exe
                            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                            C:\Program Files\Windows Live\Contacts\wlcomm.exe
                            C:\Program Files\Mozilla Firefox\firefox.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Documents and Settings\Môa\Bureau\RSIT.exe
                            C:\Program Files\Trend Micro\HijackThis\Môa.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
                            R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
                            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                            O2 - BHO: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files\AGI\common\agcutils.dll
                            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                            O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                            O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                            O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                            O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
                            O4 - HKLM\..\Run: [CARPService] carpserv.exe
                            O4 - HKLM\..\Run: [Watch] C:\PROGRA~1\Minitel\Watch.exe
                            O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                            O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
                            O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
                            O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
                            O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
                            O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                            O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
                            O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
                            O4 - HKLM\..\Run: [CardDetectorHUAWEI] C:\Program Files\CardDetector\HUAWEI\CardDetector.exe
                            O4 - HKLM\..\Run: [BEWINTERNET-FR-DMGP-V2SessionManager] "C:\Program Files\Orange\IEWInternet\SessionManager\SessionManager.exe"
                            O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
                            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O15 - Trusted Zone: http://*.mappy.com
                            O15 - Trusted Zone: http://*.orange.fr
                            O15 - Trusted Zone: http://rw.search.ke.voila.fr
                            O15 - Trusted Zone: http://orange.weborama.fr
                            O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab
                            O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
                            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                            O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                            O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
                            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
                            O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\1\FTRTSVC.exe
                            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
                            O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
                            O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            1. Modérateur
                              --> Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

                              --> Double-clique sur RSIT.exe afin de lancer le programme.
                              (Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)

                              --> Clique sur Continue à l'écran Disclaimer.

                              --> Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

                              --> Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

                              Note : les rapports sont sauvegardés dans le dossier C:\rsit.
                              • 1
                              • 2