Probleme rundll

Résolu
Bonjour,
j'ai un probleme avec mon pc. J'ai eu un virus et depuis j'ai le rundll32.exe a 100% ce fait ramer mon pc.
Voici le log hijackthis.
Merci de votre aide

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:49:26, on 20/01/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: flvdirect - {d8fc52de-5239-b400-3726-2f9eef5e8ee4} - C:\WINDOWS\system32\35IB6iDhE_RB.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RegDokFRT] C:\Program Files\RegistryDoktor 4.1\RegistryDoktor.exe
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll (file missing)
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://ushousecall02.trendmicro.com/...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/...
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Environnement d'exécution Java 1.3.1_18) - http://javadl-esd.sun.com/update/1.3.1/jinstall-13-win32.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Google Update (gupdate1c9f3a2b7af72b0) (gupdate1c9f3a2b7af72b0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\system32\PCTKRNT.SYS

--
End of file - 8015 bytes
Configuration: Windows XP Internet Explorer 7.0

17 réponses

  1. Contributeur sécurité
    Salut bb40

    Bien de rien, cela a été un plaisir ;)

    Bonne soirée
    0
    1. Re dédétraqué
      Merci pour toute l'aide que tu m'as apporté et de tes precieux conseils, simples et efficaces.
      Bonne soirée
      0
      1. Contributeur sécurité
        Salut bb40

        Oui réactive le, je te donne quelques consignes de sécurité :

        - Windows Update parfaitement à jour http://www.windowsupdate.com/windowsupdate/v6/default.aspx (catégories critique, Services Pack et Services Release)
        - pare-feu bien paramétré, je te conseil ZoneAlarm :
        https://www.malekal.com/tutoriel-zonealarm-firewall/
        - antivirus bien paramétré et mis à jour régulièrement (quotidiennement s'il le faut) avec un scan complet régulier (journalier s'il le faut).
        - une attitude prudente vis à vis de la navigation (pas de sites douteux : cracks, warez, sexe...) et vis à vis de la messagerie (fichiers joints aux messages doivent être scannés avant d'être ouverts)
        - pas de téléchargement illégal, qui est le principal facteur d’infection (µTorrent, BitTorrent, eMule, Limewire, etc..) http://forum.malekal.com/ftopic893.php
        - une attitude vigilante (être à l'affût d'un fonctionnement inhabituel de son système)
        - nettoyage hebdomadaire du système (suppression des fichiers inutiles, nettoyage de la base de registre, scandisk, defrag)
        - scan hebdomadaire antispyware, je conseil MalwareByte's Anti-Malware :
        https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
        - un contrôle régulier de la console JAVA pour s'assurer qu'elle est à jour :
        https://www.java.com/en/download/uninstalltool.jsp
        - faire régulièrement un scan de vulnérabilités afin de vérifier que tes logiciels soit à jour sans failles de sécurités :
        https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/

        De bonne lecture si tu veux en savoir plus sur la sécurité et le fonctionnement de Windows :
        http://www.malekal.com/menu_windows_general.php
        http://www.malekal.com/menu_windows_securite.php

        Bonne journée/soirée et bon surf

        @++ :)
        0
        1. Re dédétraqué
          le lien que tu m'as donné est valable uniquement pour Vista et non pour XP
          J'en ai trouvé un autre si ca peut aider quelqu'un : https://www.micro-astuce.com/optimisation/DEP.php
          J'ai donc desactivé le DEP et scanner mon pc, a part 3 mises a jour rien de critique.
          Merci de ton aide

          Ps : Dois je reactiver le DEP ?
          0
          1. Contributeur sécurité
            Salut bb40

            Désactive la protection DEP pour le scan de vulnérabilité :
            http://www.laboratoire-microsoft.org/tips-23871-desactiver-protection-DEP.html

            @++ :)
            0
            1. Contributeur sécurité
              Salut bb40

              Cela est bon, seulement un point de restauration système infecté que l'on va purger :

              Désactive la restauration système sur tous les lecteurs :

              - Clique droit sur le Poste de travail sur le bureau, dans propriété tu cliques sur l'onglet Restauration système

              - Coche la case désactiver la restauration et applique

              Redémarre l’ordinateur et réactive la restauration système.

              Tutoriel XP : http://www.libellules.ch/desactiver_restauration.php

              ------

              On va faire un ménage des outils téléchargés pour la désinfection, télécharge Tools Cleaner sur le bureau :

              http://pc-system.fr/

              - Double clique sur ToolsCleaner2.exe sur le bureau
              - Clique sur Recherche et laisse le scan agir.
              - Clique sur Suppression pour finaliser.
              - Tu peux, si tu le souhaites, te servir des Options facultatives.
              - Clique sur Quitter pour obtenir le rapport.
              - Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
              - Si des outils restes après le passage de Tools Cleaner, tu pourras les supprimer manuellement ainsi que tous les rapports qui on été généré lors de la désinfection.

              -----

              Important de mettre à jour Windows et tes logiciels :
              Mettre Windows(catégories critique, Services Pack et Services Release) à jour : http://www.windowsupdate.com/windowsupdate/v6/default.aspx

              Faire un scan de vulnérabilités afin de vérifier que tes logiciels soit à jour sans failles de sécurités et mettre à jour :
              https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/

              Faire un ménage des fichiers inutiles et de la base de registre :
              https://www.malekal.com/tutoriel-ccleaner/

              Dis moi quand cela est fais où si tu as des soucis et on passe à la résolution du sujet par la suite.

              @++ :)
              0
              1. Dans le doute, j'ai refait un scan.
                Les 2 dernieres cases cochées etaient effectivement l'effacement de la mise en quarantaire et la desinstallation
                du logiciel . Désolé

                Voici le log du scan

                ESETSmartInstaller@High as CAB hook log:
                OnlineScanner.ocx - registred OK
                # version=7
                # IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
                # OnlineScanner.ocx=1.0.0.6211
                # api_version=3.0.2
                # EOSSerial=d3423cb3aba48e48bd59083f09e89941
                # end=finished
                # remove_checked=true
                # archives_checked=true
                # unwanted_checked=true
                # unsafe_checked=false
                # antistealth_checked=true
                # utc_time=2010-01-22 03:29:26
                # local_time=2010-01-22 04:29:26 (+0100, Paris, Madrid)
                # country="France"
                # lang=1033
                # osver=5.1.2600 NT Service Pack 3
                # compatibility_mode=512 16777215 100 0 1268174 1268174 0 0
                # compatibility_mode=769 16775125 100 98 34453 200450700 40140 0
                # compatibility_mode=8192 67108863 100 0 9147 9147 0 0
                # scanned=62688
                # found=1
                # cleaned=1
                # scan_time=4624
                C:\System Volume Information\_restore{317F3BA2-A569-43B2-B17F-F48AC1241D8F}\RP275\A0043037.exe a variant of Win32/Casino application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

                Ps : Les differents scan m'ont desactivé mon logiciel de poker en ligne (everest poker) ???????
                Merci de ton aide
                0
                1. Contributeur sécurité
                  Salut bb40

                  On va vérifier si rien de caché :

                  Faire un scan avec Nod32 en ligne (il faut utiliser Internet Explorer) ici :

                  https://www.eset.com/int/home/online-scanner/

                  (coche toutes les cases à chaque fois)
                  A la fin, colle le rapport : C:\Program Files\EsetOnlineScanner\log.txt

                  @++ :)
                  0
                  1. re dédétraqué
                    j'ai bien suivi tes instructions et j'ai donc fait le scan avec ESET.
                    Il a trouvé un cinquantaine d'infections mais ne m'a pas laissé de log.text dans le dossier indiqué.
                    J'ai coché les 2 cases avant le FINISH, je crois me souvenir que c'etait une histoire d'effacement de mise en quarantaine ( mon anglais etant tres limité ).
                    Ceci en est peut etre la cause.
                    Que faire ? Refaire le scan ? Merci pour tes lumieres

                    Ps : j'avais aussi reactivé le Tea timer de Spyboot . Mea Culpa
                    0
                2. salut dédétraqué
                  et toujours grand MERCI de t'occuper de mon soucis.
                  J'ai suivi tes instructions.
                  ci joint le log

                  All processes killed
                  ========== SERVICES/DRIVERS ==========
                  Service aaaamon32 stopped successfully!
                  Service aaaamon32 deleted successfully!
                  Service getuname32 stopped successfully!
                  Service getuname32 deleted successfully!
                  Service umdmxfrm32 stopped successfully!
                  Service umdmxfrm32 deleted successfully!
                  ========== REGISTRY ==========
                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\\"Notification Packages"|hex(7):73,63,65,63,6c,69,00,00 /E : value set successfully!
                  ========== FILES ==========
                  C:\Program Files\Everest Poker\var folder moved successfully.
                  C:\Program Files\Everest Poker\history folder moved successfully.
                  C:\Program Files\Everest Poker\data\startup\shared\sounds folder moved successfully.
                  C:\Program Files\Everest Poker\data\startup\shared\icons folder moved successfully.
                  C:\Program Files\Everest Poker\data\startup\shared\bitmaps folder moved successfully.
                  C:\Program Files\Everest Poker\data\startup\shared folder moved successfully.
                  C:\Program Files\Everest Poker\data\startup\fr folder moved successfully.
                  C:\Program Files\Everest Poker\data\startup\en folder moved successfully.
                  C:\Program Files\Everest Poker\data\startup folder moved successfully.
                  C:\Program Files\Everest Poker\data\shared\shared\sounds folder moved successfully.
                  C:\Program Files\Everest Poker\data\shared\shared\bitmaps folder moved successfully.
                  C:\Program Files\Everest Poker\data\shared\shared folder moved successfully.
                  C:\Program Files\Everest Poker\data\shared\fr folder moved successfully.
                  C:\Program Files\Everest Poker\data\shared folder moved successfully.
                  C:\Program Files\Everest Poker\data\mp-poker\fr folder moved successfully.
                  C:\Program Files\Everest Poker\data\mp-poker\background folder moved successfully.
                  C:\Program Files\Everest Poker\data\mp-poker folder moved successfully.
                  C:\Program Files\Everest Poker\data\mp-lobby folder moved successfully.
                  C:\Program Files\Everest Poker\data\fonts folder moved successfully.
                  C:\Program Files\Everest Poker\data folder moved successfully.
                  C:\Program Files\Everest Poker folder moved successfully.
                  C:\ccm22858c\N_ folder moved successfully.
                  C:\ccm22858c folder moved successfully.
                  ========== COMMANDS ==========

                  [EMPTYTEMP]

                  User: Administrateur
                  ->Temp folder emptied: 17603316 bytes
                  ->Temporary Internet Files folder emptied: 49077694 bytes

                  User: All Users

                  User: Default User
                  ->Temp folder emptied: 0 bytes
                  ->Temporary Internet Files folder emptied: 33170 bytes

                  User: HelpAssistant

                  User: LocalService
                  ->Temp folder emptied: 66016 bytes
                  ->Temporary Internet Files folder emptied: 32902 bytes

                  User: NetworkService
                  ->Temp folder emptied: 0 bytes
                  ->Temporary Internet Files folder emptied: 583157 bytes

                  %systemdrive% .tmp files removed: 0 bytes
                  %systemroot% .tmp files removed: 2133582 bytes
                  %systemroot%\System32 .tmp files removed: 3590656 bytes
                  %systemroot%\System32\dllcache .tmp files removed: 0 bytes
                  %systemroot%\System32\drivers .tmp files removed: 0 bytes
                  Windows Temp folder emptied: 116233413 bytes
                  %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
                  %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
                  RecycleBin emptied: 1429924 bytes

                  Total Files Cleaned = 182,00 mb

                  OTM by OldTimer - Version 3.1.6.0 log created on 01222010_062823

                  Files moved on Reboot...
                  C:\Documents and Settings\Administrateur\Local Settings\Temp\Rar$EX01.187\trayit4!.dll moved successfully.
                  File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
                  File C:\WINDOWS\temp\Perflib_Perfdata_640.dat not found!

                  Registry entries deleted on Reboot...
                  0
                  1. Contributeur sécurité
                    Salut bb40

                    Important Désactive TeaTimer le résident de Spybot, il va gêner la désinfection en empêchant la modification des BHO

                    - Démarre Spybot clique sur Mode coche Mode avancé
                    - A gauche clique sur Outils ==> Résident

                    - Décoche la case devant Résident "TeaTimer", voir la capture :

                    http://apu.mabul.org/up/5/apu-5-gpdx9e06cwz2dypom2q7n6nc.jpg

                    - Quitte Spybot

                    -----

                    Double clique sur le raccourci d'HijackThis sur ton Bureau, clique sur Do a scan system only coche la case devant la(les) ligne(s) suivante(s) si présente(s)
                    Si pas de raccourci sur le bureau, il ce trouve ici :
                    C:\Program Files\Trend Micro\HijackThis\Administrateur.exe

                    O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - (no file)
                    O2 - BHO: (no name) - {d8fc52de-5239-b400-3726-2f9eef5e8ee4} - (no file)
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKCU\..\Run: [RegDokFRT] C:\Program Files\RegistryDoktor 4.1\RegistryDoktor.exe
                    O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -


                    - Ferme les fenêtres en cours sauf HijackThis, clique sur Fix checked

                    - Quitte HijackThis

                    -----

                    Télécharge OTM (de Old_Timer) sur le bureau :

                    http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/

                    Double-clique sur OTM.exe sur le bureau

                    - Copie le texte qui se trouve en gras ci-dessous et colle le dans le cadre de gauche de OTM nommé Paste Instructions for Items to be Moved

                    :services
                    aaaamon32
                    getuname32
                    umdmxfrm32

                    :reg
                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                    "Notification Packages"=hex(7):73,63,65,63,6c,69,00,00

                    :files
                    C:\Program Files\Everest Poker
                    C:\ccm22858c

                    :commands
                    [purity]
                    [emptytemp]
                    [reboot]


                    - Clique sur MoveIt! pour lancer la suppression.
                    - Ferme OTM

                    Ton PC va redémarrer pour finir la suppression, si il ne le fais pas lui-même, redémarre le.

                    Poste le rapport de OTMoveIt qui se trouve dans C:\_OTM\MovedFiles.

                    @++ :)
                    0
                    1. Oups désolé pour ma precipitation, je voulais seulement signaler que mon probleme initial de rundll etait resolu au redemarage de mon pc apres la desinfection.
                      ci joint le log.txt et merci pour tes conseils avisés.

                      Logfile of random's system information tool 1.06 (written by random/random)
                      Run by Administrateur at 2010-01-22 03:17:32
                      Microsoft Windows XP Professionnel Service Pack 3
                      System drive C: has 32 GB (32%) free of 100 GB
                      Total RAM: 1983 MB (60% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 03:17:37, on 22/01/2010
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Messenger\msmsgs.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\WINDOWS\explorer.exe
                      C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX01.187\TrayIt!.exe
                      C:\Program Files\eMule\emule.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Documents and Settings\Administrateur\Bureau\RSIT.exe
                      C:\Program Files\Trend Micro\HijackThis\Administrateur.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                      O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - (no file)
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                      O2 - BHO: (no name) - {d8fc52de-5239-b400-3726-2f9eef5e8ee4} - (no file)
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                      O4 - HKCU\..\Run: [RegDokFRT] C:\Program Files\RegistryDoktor 4.1\RegistryDoktor.exe
                      O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                      O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                      O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
                      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                      O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://ushousecall02.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
                      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/fr/uno1/GAME_UNO1.cab
                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Environnement d'exécution Java 1.3.1_18) - http://javadl-esd.sun.com/update/1.3.1/jinstall-13-win32.cab
                      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      O23 - Service: Service Google Update (gupdate1c9f3a2b7af72b0) (gupdate1c9f3a2b7af72b0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      O23 - Service: PictureTaker - LANovation - C:\WINDOWS\system32\PCTKRNT.SYS
                      0
                      1. Contributeur sécurité
                        Salut bb40

                        Tu as mis vite en résolu ;)

                        Supprime ce dossier C:\rsit

                        Refais un scan avec RSIT et poste le rapport log.txt seulement à la fin de l’analyse

                        Le rapport est dans le dossier ici C:\rsit

                        @++ :)
                        0
                        1. re dédétraqué, j'ai marqué comme resolu mon post.
                          Neanmoins si quelque chose cloche dans mon rapport, n'hesisites pas a me le faire savoir.
                          Je te remercie encore pour l'aide que tu m'as apportée.
                          0
                          1. Re-bonjour dédétraqué.
                            Je viens de faire l'analyse et MIRACLE mon soucis est résolu.
                            Milles MERCI pour ton aide et ton efficacité.
                            ci joint le rapport.

                            Malwarebytes' Anti-Malware 1.44
                            Version de la base de données: 3607
                            Windows 5.1.2600 Service Pack 3 (Safe Mode)
                            Internet Explorer 8.0.6001.18702

                            21/01/2010 14:47:54
                            mbam-log-2010-01-21 (14-47-54).txt

                            Type de recherche: Examen complet (C:\|E:\|)
                            Eléments examinés: 173819
                            Temps écoulé: 18 minute(s), 55 second(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 26
                            Valeur(s) du Registre infectée(s): 1
                            Elément(s) de données du Registre infecté(s): 0
                            Dossier(s) infecté(s): 0
                            Fichier(s) infecté(s): 31

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            HKEY_CLASSES_ROOT\idwbho2.idwbhocl (Adware.SpeedDownloader) -> Quarantined and deleted successfully.
                            HKEY_CLASSES_ROOT\idwbho2.idwbhocl.1 (Adware.SpeedDownloader) -> Quarantined and deleted successfully.
                            HKEY_CLASSES_ROOT\CLSID\{ef34404a-747c-81d8-843a-d938e181273d} (Adware.BHO.FL) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1c3b806c-c5da-4f6e-ba43-b1ff982f0a02} (Adware.SpeedDownloader) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1c3b806c-c5da-4f6e-ba43-b1ff982f0a02} (Adware.SpeedDownloader) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\RegistryDoktorFrNE (Rogue.RegistryDoctor) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\AppDataLow\HavingFunOnline (Adware.BHO.FL) -> Quarantined and deleted successfully.
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d8fc52de-5239-b400-3726-2f9eef5e8ee4} (Adware.AdRotator) -> Quarantined and deleted successfully.
                            HKEY_CLASSES_ROOT\CLSID\{d8fc52de-5239-b400-3726-2f9eef5e8ee4} (Adware.AdRotator) -> Quarantined and deleted successfully.

                            Valeur(s) du Registre infectée(s):
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\forceclassiccontrolpanel (Hijack.ControlPanelStyle) -> Delete on reboot.

                            Elément(s) de données du Registre infecté(s):
                            (Aucun élément nuisible détecté)

                            Dossier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Fichier(s) infecté(s):
                            C:\ccm22858c\Combo-Fix.sys (Malware.Trace) -> Quarantined and deleted successfully.
                            C:\Documents and Settings\Administrateur\Bureau\registry-doktor-france-v04.exe (Rogue.Installer) -> Quarantined and deleted successfully.
                            C:\Program Files\Windows Live\Messenger\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Program Files\Windows Live\Messenger\riched20.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3REGHK.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3AUXSTB.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3DLGHK.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\firefox\NPMYWEBS.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\Qoobox\Quarantine\C\WINDOWS\system32\f3PSSavr.scr.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\getuname32.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\35IB6iDhE_RB.dll (Adware.AdRotator) -> Quarantined and deleted successfully.
                            0
                            1. Contributeur sécurité
                              Salut bb40

                              -Télécharge et installe MalwareByte's Anti-Malware
                              http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                              - Mets le à jour

                              ---

                              - Redémarre en mode sans échec :

                              Au redémarrage de ton PC tapote sur la touche F8 ou F5, sur l'écran suivant déplace toi avec les flèches de direction et choisis Mode sans échec. Choisis ta session habituelle et non la session Administrateur

                              ---

                              - Double clique sur le raccourci de MalwareByte's Anti-Malware qui est sur le bureau.
                              - Sélectionne Exécuter un examen complet si ce n'est pas déjà fait
                              - clique sur Rechercher

                              - Une fois le scan terminé, une fenêtre s'ouvre, clique sur sur OK

                              - Si MalwareByte's n'a rien détecté, clique sur OK Un rapport va apparaître ferme-le.

                              - Si MalwareByte's a détecté des infections, clique sur Afficher les résultats ensuite sur Supprimer la sélection

                              - Enregistre le rapport sur ton Bureau comme cela il sera plus facile à retrouver, poste ensuite ce rapport.

                              Note : Si MalwareByte's a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur OK

                              Tutoriel pour MalwareByte's ici :
                              https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                              @++ :)
                              0
                              1. Contributeur sécurité
                                Salut bb40

                                Via Ajout/Suppression de programmes désinstalle RegistryDoktor

                                Supprime si encore présent : C:\Program Files\RegistryDoktor 4.1

                                Télécharge RSIT (de random/random) sur le bureau ici :
                                http://images.malwareremoval.com/random/RSIT.exe

                                - Double clique sur RSIT.exe qui est sur le bureau
                                - Clique sur Continue dans la fenêtre
                                - RSIT téléchargera HijackThis si il n’est pas présent où détecté, alors il faudra accepter la licence
                                - Poste le contenue des deux rapports, log.txt et info.txt(réduit dans la barre des tâches) à la fin de l’analyse

                                Les rapports sont dans le dossier ici C:\rsit

                                @++ :)
                                0
                                1. Merci dédétraqué pour ton aide.
                                  Désolé mais je n'ai pas trouvé RegistryDoktor , ni dans suppression de prog ,ni dans programme files,ni dans la recherche de fichier. ???????

                                  ci joint les 2 rapports

                                  Logfile of random's system information tool 1.06 (written by random/random)
                                  Run by Administrateur at 2010-01-21 11:01:12
                                  Microsoft Windows XP Professionnel Service Pack 3
                                  System drive C: has 33 GB (33%) free of 100 GB
                                  Total RAM: 1983 MB (68% free)

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 11:01:16, on 21/01/2010
                                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\nvsvc32.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\Program Files\Messenger\msmsgs.exe
                                  C:\WINDOWS\explorer.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\WINDOWS\system32\wuauclt.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Documents and Settings\Administrateur\Bureau\RSIT.exe
                                  C:\Program Files\Trend Micro\HijackThis\Administrateur.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                  O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - (no file)
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                                  O2 - BHO: flvdirect - {d8fc52de-5239-b400-3726-2f9eef5e8ee4} - C:\WINDOWS\system32\35IB6iDhE_RB.dll
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  O4 - HKLM\..\Run: [UnlockerAssistant] C:\Program Files\Unlocker\UnlockerAssistant.exe
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                  O4 - HKCU\..\Run: [RegDokFRT] C:\Program Files\RegistryDoktor 4.1\RegistryDoktor.exe
                                  O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                  O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                  O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
                                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                  O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                  O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                  O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
                                  O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                                  O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://ushousecall02.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
                                  O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/fr/uno1/GAME_UNO1.cab
                                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                                  O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Environnement d'exécution Java 1.3.1_18) - http://javadl-esd.sun.com/update/1.3.1/jinstall-13-win32.cab
                                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                  O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  O23 - Service: Service Google Update (gupdate1c9f3a2b7af72b0) (gupdate1c9f3a2b7af72b0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                  O23 - Service: PictureTaker - LANovation - C:\WINDOWS\system32\PCTKRNT.SYS
                                  0