Infection

Bonjour,
Je poste un rapport Hijackthis, pour savoir si je suis infecté ou pas.
Merci de bien vouloir m'aider =)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:18:32, on 05/06/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Saitek\Software\SaiMfd.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\clement\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Tall Emu\Online Armor\oahlp.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Tall Emu\Online Armor\oacat.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Tall Emu\Online Armor\oaui.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\temp\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.search.yahoo.com/search?fr=mcafee&p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\clement\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - Winlogon Notify: !SASWinLogon - C:\WINDOWS\
O23 - Service: McAfee Application Installer Cleanup (0060891241774065) (0060891241774065mcinstcleanup) - Unknown owner - C:\DOCUME~1\clement\LOCALS~1\Temp\006089~1.EXE (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Google Update (gupdate1c9e21285304d56) (gupdate1c9e21285304d56) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Online Armor Helper Service (OAcat) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oacat.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

--
End of file - 9311 bytes
Configuration: Windows XP
Firefox 3.0.10

34 réponses

Résumé de la discussion

Un utilisateur soumet un rapport HijackThis pour évaluer une éventuelle infection sur un PC fonctionnant sous Windows XP SP3, en détaillant un journal d'exécution et une liste de processus et de modules. Des réponses ultérieures répertorient des barres d'outils et des BHOs potentiellement indésirables (Yahoo!, Google, McAfee SiteAdvisor) ainsi que des services associés, certains jugés légitimes et d'autres à examiner. Le fil mentionne aussi des pages par défaut et des paramètres de recherche modifiés, avec des suppressions comme Start Page MSN et des remplacements par Bing, Yahoo et des partenaires publicitaires. En réponse, certains conseils suggèrent d'effectuer un nouveau log RSIT, de désinstaller des logiciels concurrents comme McAfee, puis d'utiliser VirusTotal pour analyser des fichiers suspects.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    oups

    pas fait gaffe au poste 38

    ;)

    @+
    0
    1. Contributeur sécurité
      MDR :)

      A+ =)
      0
  2. Contributeur sécurité
    @ c-gre

    je pense qu'il y a eu une confusion a ton sujet car l'auteur de ce sujet ici est cleFg et je viens de voir que ton topic a ete clos pour doublon avec celui la :p

    donc tu peux recrer un topic si tu le souhaite mais ton rapport est clean ;)
    0
    1. Contributeur sécurité
      Salut plopus :)

      Oui c'est vrai moi aussi je viens de voir le sujet fermé . merci quand Même :D

      c-gre

      Crées ton propre sujet , et dis leurs qu'il ont fait une confusion entre les sujet en expliquant clairement puis coller le rapport HJT (qui est clean) :)

      A+
      0
  3. Contributeur sécurité
    J'ai vu ton sujet , marie te l'a dit ...

    Elle a fait une erreur ... je ne peux pas s'occuper de deux cas sur un seul sujet ...

    Je vais voir avec marie ...

    ++
    0
    1. C'est ce que j'ai fait, mais on m'a dit de revenir la ...
      0
      1. Contributeur sécurité
        Salut tu crées ton propre sujet . Merci
        0
        1. Bonjour, pouvais vous m'aidez pour l'analyse de ce rapport.
          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 18:15:13, on 28/06/2009
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v8.00 (8.00.6001.18702)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Google\Update\GoogleUpdate.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
          C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
          C:\WINDOWS\System32\PAStiSvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\filehippo.com\UpdateChecker.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
          C:\Program Files\trend micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.search.yahoo.com/search?fr=mcafee&p=%s
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe /boot
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKCU\..\Run: [filehippo.com] "C:\Program Files\filehippo.com\UpdateChecker.exe" /background
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
          O20 - Winlogon Notify: !SASWinLogon - C:\WINDOWS\
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Service Google Update (gupdate1c9e21285304d56) (gupdate1c9e21285304d56) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
          O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: SbPF.Launcher - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
          O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software, Inc. - C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
          O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
          O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
          0
          1. Mais il y a des adresses manquantes ...
            O20 - Winlogon Notify: !SASWinLogon - C:\WINDOWS\
            O23 - Service: McAfee Application Installer Cleanup (0221481244207298) (0221481244207298mcinstcleanup) - Unknown owner - C:\DOCUME~1\clement\LOCALS~1\Temp\022148~1.EXE (file missing)

            ...
            0
            1. Contributeur sécurité
              Tu peux continuer.
              0
          2. Salut
            Le PC tourne bien mais reste quelques soucis : toujours les 292 erreurs d'activeX lorsque je répare le registre avec Ccleaner.
            Et Est-ce grave si j'ai pas cocher toutes les lignes que tu m'a dis ... Y'en avaient que je trouvais pas ! ( Et oui, j'ai bien regardé ;-)
            0
            1. merci encore !
              Y'a pleins de lignes que j'ai pas avec Hijackthis !
              0
              1. Contributeur sécurité
                Comment va le PC?
                0
            2. Contributeur sécurité
              Salut,

              Désolé pour le retard, je suis occupé ces jours là.

              Recouvre Hijackthis,
              Fais "scan only"
              Et coche ces lignes:
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
              O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\clement\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
              O20 - Winlogon Notify: !SASWinLogon - C:\WINDOWS\
              O23 - Service: McAfee Application Installer Cleanup (0221481244207298) (0221481244207298mcinstcleanup) - Unknown owner - C:\DOCUME~1\clement\LOCALS~1\Temp\022148~1.EXE (file missing)


              Clique sur "FIX CHECKED " et valide

              Ensuite:

              Cherche "crawler" et si tu trouves, supprimes et dis-moi.

              Ensuite:

              1/
              ▶ Télécharge ToolsCleaner sur ton Bureau

              Sous XP : Double-clique sur ToolsCleaner2.exe
              ▶ Clique sur Recherche et laisse le scan se terminer.
              ▶ Clique sur Suppression pour finaliser.
              ▶ Tu peux, si tu le souhaites, te servir des Options facultatives.
              ▶ Clique sur Quitter, pour que le rapport puisse se créer.
              ▶ Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse

              *************************************************************************
              2/
              ▶ Refait un nouveau coup CCleaner (registre & nettoyage)

              **************************************************************************
              3/
              Télécharge ATF Cleaner par Atribune

              ▶ Double-clique ATF-Cleaner.exe afin de lancer le programme.
              ▶ Sous l'onglet Main, choisis : Select All
              ▶ Clique sur le bouton Empty Selected
              Si tu utilises le navigateur Firefox :
              Clique Firefox au haut et choisis : Select All
              ▶ Clique le bouton Empty Selected
              NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.
              Si tu utilises le navigateur Opera :
              Clique Opera au haut et choisis : Select All
              ▶ Clique le bouton Empty Selected
              NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.
              ▶ Clique Exit, du menu prinicipal, afin de fermer le programme.
              Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.

              ****************************************************************************
              4/Désactivation/Réactivation de la restauration du système :

              *Désactivation:
              ▶ Cliquer droit sur le "Poste de travail" > Propriétés > onglet "Restauration du système" > cocher la case "Désactiver la Restauration du système sur tous les lecteurs"
              > Appliquer patiente jusqu'à que cela soit marqué "désactivée" puis OK.

              * Activation :
              ▶ Suivre le même chemin ; décocher la case "Désactiver la Restauration du système sur tous les lecteurs"
              ▶ Appliquer attends que cela soit a nouveau sur "surveillance" puis OK.
              Redémarrer l'ordinateur..

              ****************************************************************************
              5/
              -Nettoyage et Défragmentation de tes Disques:

              ****************************************************************************

              5.1/
              *Nettoyage de disque:
              ● Clic droit sur "poste de travail" ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Général"
              ● Cliques sur le bouton "nettoyage de disque", OK
              ● Fais la même chose pour chacun de tes disques

              5.2/
              Défragmentation:

              ● Ouvrir le menu "Démarrer" ==> "Tous les programmes" ==> Accessoires ==> Outils système ==> "Défragumenteur de disque"
              ● Clic sur analyser, s'il te demande de défragmenter, Clique sur "défragmenter"
              Fais le même chose pour chacun de tes disques.

              Note : si tu as un utilitaire pour défragmenter , utilises le à la place

              5.3/

              Vérifications des erreurs :

              ● Clic droit sur "poste de travail" ==> "ouvrir" ==> clic droit sur le disque C ==>Propriétés ==>onglet "Outil"
              "Vérifier maintenant", une boîte s'ouvre, cocher les cases :

              - Réparer automatiquement les erreurs...
              - Rechercher et tenter une récupération...

              --->Démarrer, OK

              Note : s'il te dis de redémarrer ton PC pour le faire , tu redémarres et tu laisses faire, cela prend un peu de temps c'est normal

              _______________________________________________________________________

              Après avoir appliqué ces manipes dis-moi comment vas le PC.

              @+
              0
              1. salut fix200, que dois faire maintenant ?
                0
                1. BitDefender Online Scanner

                  Rapport d'analyse généré à: Sun, Jun 07, 2009 - 17:19:57

                  Voie d'analyse: A:\;C:\;D:\;

                  Statistiques

                  Temps
                  00:18:23

                  Fichiers
                  85097

                  Directoires
                  6316

                  Secteurs de boot
                  0

                  Archives
                  1229

                  Paquets programmes
                  6974

                  Résultats

                  Virus identifiés
                  0

                  Fichiers infectés
                  0

                  Fichiers suspects
                  0

                  Avertissements
                  0

                  Désinfectés
                  0

                  Fichiers effacés
                  0

                  Info sur les moteurs

                  Définition virus
                  3346798

                  Version des moteurs
                  AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

                  Analyse des plugins
                  17

                  Archive des plugins
                  45

                  Unpack des plugins
                  7

                  E-mail plugins
                  6

                  Système plugins
                  4

                  Paramètres d'analyse

                  Première action
                  Désinfecté

                  Seconde Action
                  Supprimé

                  Heuristique
                  Oui

                  Acceptez les avertissements
                  Oui

                  Extensions analysées
                  exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

                  Excludez les extensions

                  Analyse d'emails
                  Oui

                  Analyse des Archives
                  Oui

                  Analyser paquets programmes
                  Oui

                  Analyse des fichiers
                  Oui

                  Analyse de boot
                  Oui

                  Fichier analysé
                  Statut

                  Aucun virus trouvé.
                  0
                  1. Contributeur sécurité
                    Re,
                    Au lieu de le mettre en HTML je l'ai mis en .txt !


                    C'est ça! il faut le poster en .txt
                    0
                    1. salut,
                      j'ai bien fais le scan en ligne et aucun virus a signalé. J'ai merdé lors pour enregistrer le rapport. Au lieu de le mettre en HTML je l'ai mis en .txt !
                      0
                      1. Contributeur sécurité
                        Re,

                        ===============================================================
                        Refait un nouveau coup CCleaner (registre compris).
                        ======================

                        Scanne ton PC avec BitDefender en ligne (uniquement sous Internet Explorer)


                        Regarde ce tutoriel afin de me coller le rapport a ta prochaine réponse.

                        ===============================================================

                        @+++
                        0
                        1. ========== PROCESSES ==========
                          Process explorer.exe killed successfully.
                          ========== REGISTRY ==========
                          Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus\\ deleted successfully.
                          Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall\\ deleted successfully.
                          Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_02­21481244207298MCINSTCLEANUP\0000\\ not found.
                          Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\0221481244207298mcinstcleanup\\ deleted successfully.
                          Unable to delete registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_0221481244207298MCINSTCLEANUP\0000\\ .
                          Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\0221481244207298mcinstcleanup\\ deleted successfully.
                          Unable to delete registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_0221481244207298MCINSTCLEANUP\0000\\ .
                          Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\0221481244207298mcinstcleanup\\ not found.
                          ========== COMMANDS ==========
                          Explorer started successfully
                          File delete failed. C:\DOCUME~1\clement\LOCALS~1\Temp\~DFBF0E.tmp scheduled to be deleted on reboot.
                          User's Temp folder emptied.
                          User's Internet Explorer cache folder emptied.
                          File delete failed. C:\Documents and Settings\clement\Local Settings\Temporary Internet Files\Content.IE5\N9GCHSK0\MsgrConfig[1].asmx scheduled to be deleted on reboot.
                          File delete failed. C:\Documents and Settings\clement\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be deleted on reboot.
                          File delete failed. C:\Documents and Settings\clement\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                          User's Temporary Internet Files folder emptied.
                          File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
                          File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
                          File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
                          Local Service Temp folder emptied.
                          Local Service Temporary Internet Files folder emptied.
                          Network Service Temp folder emptied.
                          Network Service Temporary Internet Files folder emptied.
                          File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
                          File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_4c0.dat scheduled to be deleted on reboot.
                          File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_7e4.dat scheduled to be deleted on reboot.
                          Windows Temp folder emptied.
                          Java cache emptied.
                          FireFox cache emptied.
                          Temp folders emptied.

                          OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 06062009_163304

                          Files moved on Reboot...
                          C:\DOCUME~1\clement\LOCALS~1\Temp\~DFBF0E.tmp moved successfully.
                          C:\Documents and Settings\clement\Local Settings\Temporary Internet Files\Content.IE5\N9GCHSK0\MsgrConfig[1].asmx moved successfully.
                          C:\Documents and Settings\clement\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini moved successfully.
                          File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
                          File C:\WINDOWS\temp\Perflib_Perfdata_4c0.dat not found!
                          File C:\WINDOWS\temp\Perflib_Perfdata_7e4.dat not found!
                          -------------
                          Logfile of random's system information tool 1.06 (written by random/random)
                          Run by Clément at 2009-06-06 16:39:16
                          Microsoft Windows XP Édition familiale Service Pack 3
                          System drive C: has 425 GB (89%) free of 477 GB
                          Total RAM: 3263 MB (84% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 16:25:34, on 05/06/2009
                          Platform: Windows XP SP3 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Tall Emu\Online Armor\oasrv.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Google\Update\GoogleUpdate.exe
                          C:\Program Files\Saitek\Software\SaiMfd.exe
                          C:\WINDOWS\system32\RUNDLL32.EXE
                          C:\Program Files\Tall Emu\Online Armor\oaui.exe
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Tall Emu\Online Armor\oahlp.exe
                          C:\Documents and Settings\clement\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          C:\WINDOWS\system32\nvsvc32.exe
                          C:\Program Files\Tall Emu\Online Armor\oacat.exe
                          C:\WINDOWS\System32\PAStiSvc.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\temp\RSIT(2).exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe
                          C:\temp\Clément.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
                          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.search.yahoo.com/search?fr=mcafee&p=%s
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\Software\SaiMfd.exe
                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                          O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\clement\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
                          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                          O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                          O20 - Winlogon Notify: !SASWinLogon - C:\WINDOWS\
                          O23 - Service: McAfee Application Installer Cleanup (0221481244207298) (0221481244207298mcinstcleanup) - Unknown owner - C:\DOCUME~1\clement\LOCALS~1\Temp\022148~1.EXE (file missing)
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          O23 - Service: Service Google Update (gupdate1c9e21285304d56) (gupdate1c9e21285304d56) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                          O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                          O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                          O23 - Service: Online Armor Helper Service (OAcat) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oacat.exe
                          O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
                          O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
                          O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
                          0
                          1. Contributeur sécurité
                            ---> Sous XP: Double-clique sur OTMoveIt3.exe afin de le lancer.
                            *** Sous Vista: fais un clic droit sur OTMoveIt3.exe et choisis "exécuter en tant qu'administrateur"

                            ---> Copie (Ctrl+C) le texte suivant dans ce lien --> http://www.cijoint.fr/cjlink.php?file=cj200906/cijnYIVkrv.txt

                            ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                            ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                            Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                            Accepte en cliquant sur YES.

                            ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                            Le nom du rapport correspond au moment de sa création : date_heure.log
                            ==============================================================
                            Refait un nouveau coup CCleaner (registre compris).
                            *******
                            Puis poste un nouveau log RSIT pour l'analyse ...
                            0
                            1. 06/06/2009 ---- 15:35:47,18

                              ----------------------------------
                              §§§§§§ [McAfee] §§§§§§
                              ----------------------------------
                              [X] Registre

                              -------------- [ ] rapide
                              -- Fichier --- [ ] disque systeme
                              ------------- [X] complete

                              ********************
                              [Registre]
                              ********************

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-mcafee.com]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-mcafee.com\www]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee-antivirus-2007.com]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee-antivirus-2007.com\www]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\download-mcafee.com]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\download-mcafee.com\www]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\mcafee-antivirus-2007.com]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\mcafee-antivirus-2007.com\www]

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_0221481244207298MCINSTCLEANUP\0000]
                              "DeviceDesc"="McAfee Application Installer Cleanup (0221481244207298)"

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\0221481244207298mcinstcleanup]
                              "DisplayName"="McAfee Application Installer Cleanup (0221481244207298)"

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_0221481244207298MCINSTCLEANUP\0000]
                              "DeviceDesc"="McAfee Application Installer Cleanup (0221481244207298)"

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\0221481244207298mcinstcleanup]
                              "DisplayName"="McAfee Application Installer Cleanup (0221481244207298)"

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_0221481244207298MCINSTCLEANUP\0000]
                              "DeviceDesc"="McAfee Application Installer Cleanup (0221481244207298)"

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\0221481244207298mcinstcleanup]
                              "DisplayName"="McAfee Application Installer Cleanup (0221481244207298)"

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-mcafee.com]

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-mcafee.com\www]

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee-antivirus-2007.com]

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee-antivirus-2007.com\www]

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\download-mcafee.com]

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\download-mcafee.com\www]

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\mcafee-antivirus-2007.com]

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\mcafee-antivirus-2007.com\www]

                              [HKEY_USERS\S-1-5-21-1292428093-926492609-682003330-1004\Software\Microsoft\Internet Explorer\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}]
                              "URL"="https://fr.search.yahoo.com/web?fr=mcafee{searchTerms}"

                              [HKEY_USERS\S-1-5-21-1292428093-926492609-682003330-1004\Software\Microsoft\Internet Explorer\SearchUrl]
                              @="http://fr.search.yahoo.com/search?fr=mcafee&p=%s"

                              [HKEY_USERS\S-1-5-21-1292428093-926492609-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-mcafee.com]

                              [HKEY_USERS\S-1-5-21-1292428093-926492609-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-mcafee.com\www]

                              [HKEY_USERS\S-1-5-21-1292428093-926492609-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee-antivirus-2007.com]

                              [HKEY_USERS\S-1-5-21-1292428093-926492609-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee-antivirus-2007.com\www]

                              [HKEY_USERS\S-1-5-21-1292428093-926492609-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\download-mcafee.com]

                              [HKEY_USERS\S-1-5-21-1292428093-926492609-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\download-mcafee.com\www]

                              [HKEY_USERS\S-1-5-21-1292428093-926492609-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\mcafee-antivirus-2007.com]

                              [HKEY_USERS\S-1-5-21-1292428093-926492609-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\mcafee-antivirus-2007.com\www]

                              [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-mcafee.com]

                              [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-mcafee.com\www]

                              [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee-antivirus-2007.com]

                              [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\mcafee-antivirus-2007.com\www]

                              [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\download-mcafee.com]

                              [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\download-mcafee.com\www]

                              [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\mcafee-antivirus-2007.com]

                              [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\mcafee-antivirus-2007.com\www]

                              *******************
                              [Fichier]
                              *******************

                              *********************
                              [Même date]
                              *********************

                              Aucun fichier créé à la même date détecté

                              Outil Aide Diagnostic By !aur3n7 Version 1.1
                              ----------------------------------
                              §§§§§ Fin Rapport §§§§§
                              ----------------------------------

                              ------------------------------------------------------------------------------------------

                              ========== PROCESSES ==========
                              Process explorer.exe killed successfully.
                              ========== REGISTRY ==========
                              Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ctfmon.exe deleted successfully.
                              Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
                              Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SaiMfd deleted successfully.
                              ========== FILES ==========
                              C:\WINDOWS\is-82SER.exe moved successfully.
                              C:\WINDOWS\_MSRSTRT.EXE moved successfully.
                              ========== SERVICES/DRIVERS ==========
                              Service\Driver McAfee Application Installer Cleanup not found.
                              Service\Driver McAfee Application Installer Cleanup not found.
                              ========== COMMANDS ==========
                              Explorer started successfully
                              File delete failed. C:\DOCUME~1\clement\LOCALS~1\Temp\etilqs_B4CqiveIfD3oz51kUUnT scheduled to be deleted on reboot.
                              User's Temp folder emptied.
                              User's Internet Explorer cache folder emptied.
                              File delete failed. C:\Documents and Settings\clement\Local Settings\Temporary Internet Files\Content.IE5\7Z13M0YG\MsgrConfig[1].asmx scheduled to be deleted on reboot.
                              File delete failed. C:\Documents and Settings\clement\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                              User's Temporary Internet Files folder emptied.
                              File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
                              File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat scheduled to be deleted on reboot.
                              File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
                              Local Service Temp folder emptied.
                              Local Service Temporary Internet Files folder emptied.
                              Network Service Temp folder emptied.
                              Network Service Temporary Internet Files folder emptied.
                              File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
                              File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_8e0.dat scheduled to be deleted on reboot.
                              File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_f0.dat scheduled to be deleted on reboot.
                              Windows Temp folder emptied.
                              Java cache emptied.
                              File delete failed. C:\Documents and Settings\clement\Local Settings\Application Data\Mozilla\Firefox\Profiles\y35onwqj.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
                              File delete failed. C:\Documents and Settings\clement\Local Settings\Application Data\Mozilla\Firefox\Profiles\y35onwqj.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
                              File delete failed. C:\Documents and Settings\clement\Local Settings\Application Data\Mozilla\Firefox\Profiles\y35onwqj.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
                              File delete failed. C:\Documents and Settings\clement\Local Settings\Application Data\Mozilla\Firefox\Profiles\y35onwqj.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
                              File delete failed. C:\Documents and Settings\clement\Local Settings\Application Data\Mozilla\Firefox\Profiles\y35onwqj.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
                              FireFox cache emptied.
                              Temp folders emptied.

                              OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 06062009_152715

                              Files moved on Reboot...
                              File C:\DOCUME~1\clement\LOCALS~1\Temp\etilqs_B4CqiveIfD3oz51kUUnT not found!
                              C:\Documents and Settings\clement\Local Settings\Temporary Internet Files\Content.IE5\7Z13M0YG\MsgrConfig[1].asmx moved successfully.
                              File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
                              File C:\WINDOWS\temp\Perflib_Perfdata_8e0.dat not found!
                              File C:\WINDOWS\temp\Perflib_Perfdata_f0.dat not found!
                              C:\Documents and Settings\clement\Local Settings\Application Data\Mozilla\Firefox\Profiles\y35onwqj.default\Cache\_CACHE_001_ moved successfully.
                              C:\Documents and Settings\clement\Local Settings\Application Data\Mozilla\Firefox\Profiles\y35onwqj.default\Cache\_CACHE_002_ moved successfully.
                              C:\Documents and Settings\clement\Local Settings\Application Data\Mozilla\Firefox\Profiles\y35onwqj.default\Cache\_CACHE_003_ moved successfully.
                              C:\Documents and Settings\clement\Local Settings\Application Data\Mozilla\Firefox\Profiles\y35onwqj.default\Cache\_CACHE_MAP_ moved successfully.
                              C:\Documents and Settings\clement\Local Settings\Application Data\Mozilla\Firefox\Profiles\y35onwqj.default\urlclassifier3.sqlite moved successfully.

                              Par contre lorsque je nettoie le registre avec Ccleaner, il arrive des fois que j'ai 292 erreurs, avec "Java" ... étrange, ça n'arrive pas tout le temps
                              0
                              1. Contributeur sécurité
                                Salut;
                                Désactiver le TeaTimer de Spybot (Merci à Nico):

                                Pour désactiver le TeaTimer :
                                => Ouvrir Spybot S&D
                                => Dans le menu "Mode", séléctionner le mode avancé.
                                => Une fenêtre demande confirmation cliquer sur "oui".
                                => Une fois le mode avancé actif, ouvrir l'onglet "Outils".
                                => Cliquer sur Résident.
                                => La partie Résident comporte deux lignes qui sont normalement cochées :
                                *Résident "SDHelper" (bloqueur de téléchargements nuisibles pour Internet Explorer) actif.

                                * Résident "TeaTimer" (Protection des réglages système fondamentaux) actif.

                                => Décocher la ligne TeaTimer.
                                => Redémarrer Spybot (le fermer et le réouvrir)
                                => Retourner dans le menu Résident et vérifier qu'il soit bien désactivé.

                                ===============================================================

                                Si vous êtes sous Vista Désactivez l'UAC

                                Télécharge OTMoveIt3 sur ton bureau:

                                ---> Sous XP: Double-clique sur OTMoveIt3.exe afin de le lancer.
                                Sous Vista: fais un clic droit sur OTMoveIt3.exe et choisis "exécuter en tant qu'administrateur"

                                ---> Copie (Ctrl+C) le texte suivant ci-dessous :

                                :Processes
                                explorer.exe
                                :Reg
                                [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                                "ctfmon.exe"=-
                                [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                "Adobe Reader Speed Launcher"=-
                                "SaiMfd"=-
                                :Files
                                C:\WINDOWS\is-82SER.exe
                                C:\WINDOWS\_MSRSTRT.EXE
                                :services
                                McAfee Application Installer Cleanup
                                :Commands
                                [start explorer]
                                [emptytemp]
                                [purity]


                                ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                                ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                                Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                                Accepte en cliquant sur YES.

                                ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                                Le nom du rapport correspond au moment de sa création : date_heure.log

                                =========================================

                                Essaye cet outil pour supprimer Superantispyware:

                                http://cdn.superantispyware.com/SASUNINST.EXE

                                =========================================
                                Refais un nouveau coup CCleaner (Registre compris)
                                =========================================

                                Télécharge OAD de !aur3n7

                                ▶ Enregistre le sur ton Bureau

                                ▶ Double clique sur le OAD.exe pour le lancer

                                ▶ Nom de fichier à rechercher tape ou fais un copier coller de : McAfee

                                ▶ Type de recherche : sélectionne l'option 6
                                puis valide [entrée]

                                OAD va maintenant rechercher le fichier. Laisse le travailler jusqu'à ce qu'il en ai terminé.

                                Le rapport de recherche s'affichera automatiquement à dès qu'il en aura terminé.

                                Fais un copier / coller de ce rapport dans ton prochain post.

                                Note importante : Suivant la taille des disques dur cette recherche peut prendre plusieurs minutes. Sois patient(e)

                                @+
                                0
                                • 1
                                • 2