Vrus?? trojan??

Résolu
Bonjour, mon ordinateur est vraiment ralentit ces derniers temps , j'ai effectué un full scan avec kaspersky et spybot et je n'ai rien trouvé!! Je dois vraiment patienter longtemps pour l'affichage des pages sur internet ou les videos , alors que c'était immédiat il y a quelques jours!! merçi de votre aide :))
Configuration: Windows Vista
Firefox 2.0.0.10

23 réponses

  1. Bonjour je vous reposte mon email car je le vois pas la page est vierge
    J,ai fait ceci j,espère que c'est correct
    je vous le poste
    merci missielabelle

    logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 00:07:07, on 2010-01-27
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16981)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\RegCure\RegCure.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Fichiers communs\New Boundary\PrismXL\PRISMXL.SYS
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\VTtrayp.exe
    C:\WINDOWS\system32\VTTimer.exe
    C:\Program Files\VIAudioi\SBADeck\ADeck.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Logitech\Logitech Vid\vid.exe
    C:\Program Files\BigFix\BigFix.exe
    C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\IncrediMail\bin\IMApp.exe
    c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    H:\Common\Database\bin\fbserver.exe
    H:\Common\Database\bin\fabs.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\WINDOWS\system32\logonui.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Owner\Bureau\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.ca/0SEFRCA/SAOS01
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\msgr.fr.fr-ca\msntb.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
    O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [TrayServer] H:\magix\TrayServer.exe
    O4 - HKLM\..\Run: [QuickTime Task] "H:\Programme\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
    O4 - HKCU\..\RunOnce: [RealPlayer0] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - S-1-5-18 Startup: Logitech . Enregistrement du produit.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: Logitech . Enregistrement du produit.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe (User 'Default user')
    O4 - Startup: Logitech . Enregistrement du produit.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe
    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsearch.html
    O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar2.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar2.dll/cmcache.html
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsimilar.html
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - Unknown owner - H:\Common\Database\bin\fbserver.exe (file missing)
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Fichiers communs\New Boundary\PrismXL\PRISMXL.SYS
    O23 - Service: UPnPService - Magix AG - C:\Program Files\Fichiers communs\MAGIX Shared\UPnPService\UPnPService.exe
    0
    1. voici le rapport de

      merci
      logfile of Trend Micro HijackThis v2.0.2

      Scan saved at 00:07:07, on 2010-01-27
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16981)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\RegCure\RegCure.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      c:\program files\mcafee.com\agent\mcdetect.exe
      c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\HPZipm12.exe
      C:\Program Files\Fichiers communs\New Boundary\PrismXL\PRISMXL.SYS
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\VTtrayp.exe
      C:\WINDOWS\system32\VTTimer.exe
      C:\Program Files\VIAudioi\SBADeck\ADeck.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Logitech\Logitech Vid\vid.exe
      C:\Program Files\BigFix\BigFix.exe
      C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\IncrediMail\bin\IMApp.exe
      c:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
      H:\Common\Database\bin\fbserver.exe
      H:\Common\Database\bin\fabs.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\WINDOWS\system32\logonui.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\Owner\Bureau\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.fr.msn.ca/0SEFRCA/SAOS01
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mystart.incredimail.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
      O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.2607.0\msgr.fr.fr-ca\msntb.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
      O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
      O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
      O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
      O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
      O4 - HKLM\..\Run: [TrayServer] H:\magix\TrayServer.exe
      O4 - HKLM\..\Run: [QuickTime Task] "H:\Programme\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe"
      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe" /hide
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [Logitech Vid] "C:\Program Files\Logitech\Logitech Vid\vid.exe" -bootmode
      O4 - HKCU\..\RunOnce: [RealPlayer0] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - S-1-5-18 Startup: Logitech . Enregistrement du produit.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe (User 'SYSTEM')
      O4 - .DEFAULT Startup: Logitech . Enregistrement du produit.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe (User 'Default user')
      O4 - Startup: Logitech . Enregistrement du produit.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe
      O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Install Pending Files.LNK = C:\Program Files\SIFXINST\SIFXINST.EXE
      O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsearch.html
      O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar2.dll/cmbacklinks.html
      O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar2.dll/cmcache.html
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar2.dll/cmsimilar.html
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
      O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - Unknown owner - H:\Common\Database\bin\fbserver.exe (file missing)
      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
      O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
      O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Fichiers communs\New Boundary\PrismXL\PRISMXL.SYS
      O23 - Service: UPnPService - Magix AG - C:\Program Files\Fichiers communs\MAGIX Shared\UPnPService\UPnPService.exe
      0
      1. Bonjour,
        J'ai windowsXP
        Il y a 2 jours mon ordi a commencé a être lente et j'ai mis mon anti virus Avast Pro et j' ai eu comme résultats 2 malwares que j'ai mis en quarantaine
        je ne vois plus mes entêtes de page le haut est noir,quand je veux ouvrir un programme il ouvre par flash si on veut mais jamais au complet,
        J'ai voulu aller dans mon panneau de configuration il n'ouvre pas. Impossible aussi de faire une restauration.
        que me suggéré vous j'ai passé aussi regcure j'ai essayer de graver pour sauver des choses mais je ne peux pas non plus rien foctionne.Mon ordi portable fonctionne par contre .. dois je formater ou si je peux m'en sauver.
        Merci de m'aider si vous avez le temps....Luce
        0
        1. merçi encore

          C:\_OtMoveIt: trouvé !
          C:\Program Files\Navilog1: trouvé !
          C:\Program Files\Trend Micro\HijackThis: trouvé !
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
          C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
          C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
          C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
          C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
          C:\Users\Kam\AppData\Roaming\Microsoft\Windows\Recent\HijackThis.lnk: trouvé !
          C:\Users\Kam\Desktop\HijackThis.lnk: trouvé !
          C:\Users\Kam\Desktop\OtMoveIt.exe: trouvé !
          C:\Users\Kam\Desktop\HJTInstall.exe: trouvé !
          C:\Users\Kam\Desktop\Clean: trouvé !
          C:\Users\Kam\Desktop\clean\Clean: trouvé !

          ---------------------------------
          -->- Suppression:

          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
          C:\Users\Kam\AppData\Roaming\Microsoft\Windows\Recent\HijackThis.lnk: supprimé !
          C:\Users\Kam\Desktop\HijackThis.lnk: supprimé !
          C:\Users\Kam\Desktop\OtMoveIt.exe: supprimé !
          C:\Users\Kam\Desktop\HJTInstall.exe: supprimé !
          C:\_OtMoveIt: supprimé !
          C:\Program Files\Navilog1: supprimé !
          C:\Program Files\Trend Micro\HijackThis: supprimé !
          C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: Erreur de suppression !
          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !
          C:\Users\Kam\Desktop\Clean: supprimé !
          0
          1. Supprime TOUT les logiciels que je t'ai fait installer
            Pour compléter leur suppression
            · Télécharge ToolsCleaner de A.Roshtein sur ton Bureau.
            http://pagesperso-orange.fr/AceRothstein/ToolsCleaner2.exe
            · Clique sur Recherche et laisse le scan se terminer.
            · Clique, sur Suppression pour finaliser.
            · Tu peux, si tu le souhaites, te servir des Options facultatives.
            · Clique sur Quitter, pour que le rapport puisse se créer.
            · Poste moi le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur( C:\).
            0
            1. Tout est rentré dans l'ordre c'est nickel !! merçi beaucoup :))
              0
              1. Suppression des véroles que tu avais avec les Fix que je t'ai fait passer

                Comment se comporte ton PC ??

                0
                1. Voila le rapport : C:\Windows\OEM02Mon.exe moved successfully.

                  Created on 12/04/2007 15:26:59

                  si il est possible d'avoir ton avis sur ce qui a pu se passer ce serait cool ! :))
                  en tout cas merçi pour ton aide c'est tres gentil !!
                  (et oui le casino c'est normal)
                  0
                  1. Mets ta console Java à jour en cliquant sur ce lien
                    N'oublie pas de supprimer les versions obsolètes (ajout/supp)
                    https://www.java.com/fr/download/manual.jsp

                    Casino-On-Net ► tu joues en ligne ???

                    Fais tout ce qui suit dans l' ordre ...

                    (si ce n’ est déjà fait) Télécharge et installe CCleaner :
                    https://forums.cnetfrance.fr
                    Sur le site, clique sur > Download latest version et laisse-toi guider.
                    Ne coche pas "Ajouter la barre d' outils Yahoo".
                    Laisse-le s’ installer tel que …

                    Télécharge OTMoveIt (de Old_Timer) sur ton bureau...
                    http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

                    Redémarre le PC en mode sans échec :
                    http://forum.telecharger.01net.com/forum/
                    (méthode F8 de préférence)

                    --------------------------------------------
                    Tu n' auras pas accès à Internet pendant le "mode sans échec".
                    Aussi, copie/colle la procédure dans un fichier texte (word) et mets-la sur le
                    "bureau" pour l' avoir à ta disposition.
                    --------------------------------------------

                    Ferme toutes les fenêtres et applications.
                    Relance HijackThis et clique sur > Do a system scan only puis, coche les
                    cases devant les lignes qui suivent (et uniquement ces lignes), si tjrs présentes :

                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" –start
                    O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                    O4 - Global Startup: QuickSet.lnk = ?
                    O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                    O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll (file missing)

                    Puis, clique sur > Fix checked et valide par « Yes ». Referme HijackThis.

                    Double-clique sur OTMoveIt.exe pour le lancer.
                    Assure toi que la case "Unregister Dll's and Ocx's" soit bien cochée !!!
                    Copie le texte qui se trouve dans l'encadré ci-dessous et colle-le dans le cadre
                    de gauche de OTMoveIt nommé Paste List of Files/Folders to be moved.

                    C:\Windows\OEM02Mon.exe


                    Clique sur MoveIt! pour lancer la suppression.
                    Lorsque un résultat apparaît dans le cadre Results, clique sur Exit.
                    Redémarre ton PC.
                    Copie-colle le rapport dans ta réponse :
                    Il est situé sur --> C:\_OTMoveIt\MovedFiles.

                    Lance CCleaner ...
                    Clique sur > Analyse > Lancer le nettoyage, puis sur OK dans la fenêtre qui s' affiche.
                    (re)Lance le nettoyage et (re)confirme par OK.

                    A++
                    0
                    1. Hé bin c'est assez bizarre , mon pc était ralentit uniquement pour le streaming ! je devais attendre quasiment 1 a 2minute pour n'importe quelle video ou musique..l'affichage des pages était toujours rapide , les tests de bande passante aussi , j'ai fait une restauration systeme et c'est rentré dans l'orde! mais je ne sais vraiment pas a cause de quoi mon pc était ralentit..et surtout uniquement pour le streaming..
                      voici le log :
                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 13:07:19, on 04/12/2007
                      Platform: Windows Vista (WinNT 6.00.1904)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16546)
                      Boot mode: Normal

                      Running processes:
                      C:\Windows\system32\Dwm.exe
                      C:\Windows\Explorer.EXE
                      C:\Windows\system32\taskeng.exe
                      C:\Program Files\Windows Defender\MSASCui.exe
                      C:\Program Files\DellTPad\Apoint.exe
                      C:\Windows\OEM02Mon.exe
                      C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                      C:\Windows\System32\rundll32.exe
                      C:\Program Files\DellTPad\ApMsgFwd.exe
                      C:\Windows\System32\rundll32.exe
                      C:\Windows\System32\rundll32.exe
                      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                      C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
                      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                      C:\Windows\ehome\ehtray.exe
                      C:\Program Files\DellTPad\HidFind.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Program Files\DellTPad\Apntex.exe
                      C:\Windows\ehome\ehmsas.exe
                      C:\Program Files\Digital Line Detect\DLG.exe
                      C:\Program Files\Dell\QuickSet\quickset.exe
                      C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                      C:\Windows\System32\mobsync.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                      O1 - Hosts: ::1 localhost
                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: IeMonitorBho Class - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
                      O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                      O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
                      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                      O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
                      O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                      O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
                      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
                      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
                      O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                      O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      O4 - Global Startup: QuickSet.lnk = ?
                      O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                      O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                      O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
                      O9 - Extra button: Casino-On-Net - {3015DB92-158E-4b77-9020-85C8E311FBB5} - C:\PROGRA~1\CASINO~1\casino.exe
                      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                      O13 - Gopher Prefix:
                      O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.euro.dell.com/systemprofiler/SysPro.CAB
                      O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
                      O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                      O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
                      O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll (file missing)
                      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
                      O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
                      O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                      O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                      O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
                      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                      0
                      1. Refais un log Hijackthis
                        Stp

                        Quels sont les symptômes de ton pc?
                        0
                        1. Salut , voila le rapport ! :

                          Antivirus Version Dernière mise à jour Résultat
                          AhnLab-V3 2007.12.4.1 2007.12.04 -
                          AntiVir 7.6.0.34 2007.12.04 -
                          Authentium 4.93.8 2007.12.04 -
                          Avast 4.7.1074.0 2007.12.03 -
                          AVG 7.5.0.503 2007.12.04 -
                          BitDefender 7.2 2007.12.04 -
                          CAT-QuickHeal 9.00 2007.12.03 -
                          ClamAV 0.91.2 2007.12.04 -
                          DrWeb 4.44.0.09170 2007.12.04 -
                          eSafe 7.0.15.0 2007.12.03 -
                          eTrust-Vet 31.3.5349 2007.12.04 -
                          Ewido 4.0 2007.12.03 -
                          FileAdvisor 1 2007.12.04 -
                          Fortinet 3.14.0.0 2007.12.04 -
                          F-Prot 4.4.2.54 2007.12.04 -
                          F-Secure 6.70.13030.0 2007.12.04 -
                          Ikarus T3.1.1.12 2007.12.04 -
                          Kaspersky 7.0.0.125 2007.12.04 -
                          McAfee 5176 2007.12.03 -
                          Microsoft 1.3007 2007.12.03 -
                          NOD32v2 2699 2007.12.03 -
                          Norman 5.80.02 2007.12.03 -
                          Panda 9.0.0.4 2007.12.03 -
                          Prevx1 V2 2007.12.04 Heuristic: Suspicious Hijacker
                          Rising 20.21.10.00 2007.12.04 -
                          Sophos 4.24.0 2007.12.04 -
                          Sunbelt 2.2.907.0 2007.12.01 -
                          Symantec 10 2007.12.04 -
                          TheHacker 6.2.9.148 2007.12.03 -
                          VBA32 3.12.2.5 2007.12.03 -
                          VirusBuster 4.3.26:9 2007.12.03 -
                          Webwasher-Gateway 6.0.1 2007.12.04 -
                          Information additionnelle
                          File size: 36864 bytes
                          MD5: 23242fd6c7d4c61807e84fd3a79248c4
                          SHA1: 3214ff50dc3f98ba8fcebcdc8854f770e8ea0bbe
                          PEiD: -
                          Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PX5=FD17F7CC0030E108906400A182BC7F00DB9CE8D1
                          0
                          1. Slt

                            Rends toi sur http://www.virustotal.com/flash/index_en.html
                            Clique sur "Parcourir..." et cherche EXACTEMENT le fichier en gras :

                            C:\Windows\OEM02Mon.exe

                            Attends que le rectangle soit vert (à droite) et clique sur "Send".

                            Une fois le scan terminé, copie/colle le rapport sur le forum.

                            0
                            1. re , ne trouvant pas de solution j'ai effectué une restauration systeme ce qui a résolu le problème , mais s'il s'agissait d'un malware ou autre il est toujours sur le pc n'est ce pas? merçi pour votre aide
                              0
                              1. Salut marie merçi pour ta réponse (y en a qui se lèvent tot) , voila les rapports :

                                Script executed in Safe Mode
                                Rapport clean par Malekal_morte - http://www.malekal.com
                                Script executed in Safe Mode 03/12/2007 a 12:22:04,95

                                Microsoft Windows [version 6.0.6000]

                                *** Suppression C:

                                *** Suppression C:\Windows\
                                tentative de suppression de C:\Windows\UnGins.exe

                                *** Suppression C:\Windows\system32
                                tentative de suppression de C:\Windows\system32\wininit.exe
                                Impossible de supprimer C:\Windows\system32\wininit.exe
                                tentative de suppression de C:\Windows\system32\wininit.exe
                                Impossible de supprimer C:\Windows\system32\wininit.exe

                                *** Suppression C:\Program Files

                                *** Deletion of the registry keys successful..
                                *** End of the report !

                                SmitFraudFix v2.257

                                Scan done at 12:30:18,83, 03/12/2007
                                Run from C:\Users\Kam\Desktop\SmitfraudFix
                                OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                                The filesystem type is NTFS
                                Fix run in safe mode

                                »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                                !!!Attention, following keys are not inevitably infected!!!

                                SrchSTS.exe by S!Ri
                                Search SharedTaskScheduler's .dll

                                »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                127.0.0.1 localhost
                                ::1 localhost

                                »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                                S!Ri's WS2Fix: LSP not Found.

                                »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                                GenericRenosFix by S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                HKLM\SYSTEM\CCS\Services\Tcpip\..\{41EFE59C-E81A-415C-9692-EF14BD714CBE}: DhcpNameServer=192.168.1.1 0.0.0.0
                                HKLM\SYSTEM\CS1\Services\Tcpip\..\{41EFE59C-E81A-415C-9692-EF14BD714CBE}: DhcpNameServer=192.168.1.1 0.0.0.0
                                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

                                »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                                !!!Attention, following keys are not inevitably infected!!!

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                                »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                                Registry Cleaning done.

                                »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                                !!!Attention, following keys are not inevitably infected!!!

                                SrchSTS.exe by S!Ri
                                Search SharedTaskScheduler's .dll

                                »»»»»»»»»»»»»»»»»»»»»»»» End

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 12:33:59, on 03/12/2007
                                Platform: Windows Vista (WinNT 6.00.1904)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16546)
                                Boot mode: Safe mode

                                Running processes:
                                C:\Windows\explorer.exe
                                C:\Windows\notepad.exe
                                C:\Windows\System32\mobsync.exe
                                C:\Windows\system32\wbem\unsecapp.exe
                                C:\Windows\system32\NOTEPAD.EXE
                                C:\Windows\system32\NOTEPAD.EXE
                                C:\Users\Kam\Desktop\HijackThis.exe

                                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer fourni par Dell
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                O1 - Hosts: ::1 localhost
                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
                                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                O2 - BHO: IeMonitorBho Class - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
                                O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                                O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
                                O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
                                O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
                                O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                                O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
                                O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
                                O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
                                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
                                O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                O4 - Global Startup: QuickSet.lnk = ?
                                O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                                O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
                                O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
                                O9 - Extra button: Casino-On-Net - {3015DB92-158E-4b77-9020-85C8E311FBB5} - C:\PROGRA~1\CASINO~1\casino.exe
                                O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O13 - Gopher Prefix:
                                O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
                                O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll (file missing)
                                O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
                                O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
                                O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                                O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
                                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
                                O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
                                O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                                0
                                1. Ok

                                  On continue

                                  Redémarre ton PC en mode sans échec :
                                  Redémarre en mode sans échec (Pour cela : démarrer le PC en tapotant sur la touche F8 du clavier jusqu'à ce que le menu des options avancées de Windows apparaisse puis avec les touches fléchées du clavier, sélectionner Mode sans échec puis appuyer sur la touche Entrée...)
                                  Double-clic sur clean. Cela va ouvrir une fenêtre noire.
                                  Un menu va apparaître, choisis l'option 2 en appuyant sur la touche 2 de ton clavier.
                                  Clean va travailler.
                                  Un rapport Va etre généré, envoie le moi dans ta prochaine réponse !

                                  Démarre en mode sans échec :
                                  Pour cela, tu tapotes la touche F8 ((Si F8 ne marche pas utilise la touche F5)).
                                  dès le début de l’allumage du pc sans t’arrêter.
                                  Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                                  Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                                  ----------------------------------------------------------------------------
                                  Relance le programme Smitfraud,
                                  Cette fois choisit l’option 2,
                                  répond oui à tous ;
                                  Sauvegarde le rapport,
                                  Redémarre en mode normal,
                                  Copie/colle le rapport sauvegardé sur le forum

                                  Un log Hijackthis dans la foulée
                                  0
                                  1. Re salut , voila le rapport clean :

                                    02/12/2007 a 23:51:48,22

                                    *** Recherche C:

                                    *** Recherche C:\Windows\
                                    C:\Windows\UnGins.exe FOUND

                                    *** Recherche C:\Windows\system32
                                    C:\Windows\system32\wininit.exe FOUND
                                    C:\Windows\system32\wininit.exe FOUND

                                    *** Recherche C:\Program Files
                                    *** End of the report !

                                    et celui de smidfraudfix :

                                    SmitFraudFix v2.257

                                    Scan done at 0:03:17,38, 03/12/2007
                                    Run from C:\Windows\System32\SmitfraudFix
                                    OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                                    The filesystem type is NTFS
                                    Fix run in normal mode

                                    »»»»»»»»»»»»»»»»»»»»»»»» Process

                                    C:\Windows\system32\csrss.exe
                                    C:\Windows\system32\wininit.exe
                                    C:\Windows\system32\csrss.exe
                                    C:\Windows\system32\services.exe
                                    C:\Windows\system32\lsass.exe
                                    C:\Windows\system32\lsm.exe
                                    C:\Windows\system32\winlogon.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\SLsvc.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                    C:\Windows\System32\spoolsv.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\taskeng.exe
                                    C:\Windows\system32\Dwm.exe
                                    C:\Windows\Explorer.EXE
                                    C:\Program Files\Windows Defender\MSASCui.exe
                                    C:\Program Files\DellTPad\Apoint.exe
                                    C:\Windows\OEM02Mon.exe
                                    C:\Program Files\Java\jre1.6.0\bin\jusched.exe
                                    C:\Program Files\DellTPad\ApMsgFwd.exe
                                    C:\Program Files\DellTPad\HidFind.exe
                                    C:\Windows\System32\rundll32.exe
                                    C:\Windows\System32\rundll32.exe
                                    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                                    C:\Windows\System32\rundll32.exe
                                    C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe
                                    C:\Windows\ehome\ehtray.exe
                                    C:\Program Files\Windows Media Player\wmpnscfg.exe
                                    C:\Program Files\Digital Line Detect\DLG.exe
                                    C:\Program Files\DellTPad\Apntex.exe
                                    C:\Windows\ehome\ehmsas.exe
                                    C:\Program Files\Dell\QuickSet\quickset.exe
                                    C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
                                    C:\Windows\system32\aestsrv.exe
                                    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                                    C:\Program Files\Microsoft LifeCam\MSCamS32.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\STacSV.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\system32\SearchIndexer.exe
                                    C:\Windows\system32\DRIVERS\xaudio.exe
                                    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                    C:\Windows\system32\taskeng.exe
                                    C:\Program Files\Windows Media Player\wmpnetwk.exe
                                    C:\Windows\system32\wbem\wmiprvse.exe
                                    C:\Windows\System32\mobsync.exe
                                    C:\Windows\system32\wbem\unsecapp.exe
                                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                    C:\Program Files\Mozilla Firefox\firefox.exe
                                    C:\Windows\system32\conime.exe
                                    C:\Windows\system32\taskeng.exe
                                    C:\Windows\servicing\TrustedInstaller.exe
                                    C:\Windows\system32\NOTEPAD.EXE
                                    C:\Windows\system32\cmd.exe
                                    C:\Windows\system32\SearchProtocolHost.exe
                                    C:\Windows\system32\wbem\wmiprvse.exe
                                    C:\Windows\system32\SearchFilterHost.exe

                                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Kam

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Kam\Application Data

                                    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Kam\FAVORI~1

                                    »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                                    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                                    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                                    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                                    !!!Attention, following keys are not inevitably infected!!!

                                    SrchSTS.exe by S!Ri
                                    Search SharedTaskScheduler's .dll

                                    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                                    !!!Attention, following keys are not inevitably infected!!!

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                    "AppInit_DLLs"="C:\\PROGRA~1\\KASPER~1\\KASPER~1.0\\r3hook.dll,C:\\PROGRA~1\\KASPER~1\\KASPER~1.0\\adialhk.dll"
                                    "LoadAppInit_DLLs"=dword:00000001

                                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                                    !!!Attention, following keys are not inevitably infected!!!

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                                    »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                    Description: Intel(R) Wireless WiFi Link 4965AGN
                                    DNS Server Search Order: 192.168.1.1
                                    DNS Server Search Order: 0.0.0.0

                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{41EFE59C-E81A-415C-9692-EF14BD714CBE}: DhcpNameServer=192.168.1.1 0.0.0.0
                                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{41EFE59C-E81A-415C-9692-EF14BD714CBE}: DhcpNameServer=192.168.1.1 0.0.0.0
                                    HKLM\SYSTEM\CS2\Services\Tcpip\..\{41EFE59C-E81A-415C-9692-EF14BD714CBE}: DhcpNameServer=192.168.1.1 0.0.0.0
                                    HKLM\SYSTEM\CS3\Services\Tcpip\..\{41EFE59C-E81A-415C-9692-EF14BD714CBE}: DhcpNameServer=192.168.1.1 0.0.0.0
                                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                                    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                                    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

                                    »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                                    »»»»»»»»»»»»»»»»»»»»»»»» End

                                    Merçi je vais voir ce que je peux faire avec ces rundll....bonne nuit :))
                                    0
                                    1. J'ai remarqué un truc, c'est qu'il y a plein de "RUNDLL32.EXE" qui sont en tâche en arrière-plan.
                                      C'est un peu louche, et c'est rarement utilisé par le système.
                                      Essaye de tuer ces trois processus.
                                      0
                                      1. Un peu de lecture
                                        http://www.commentcamarche.net/processus/rundll32 exe.php3
                                        0
                                    2. Re

                                      Télécharge sur ton bureau : http://www.malekal.com/download/clean.zip
                                      Tuto
                                      http://mickael.barroux.free.fr/securite/clean.php
                                      Une fois sur le bureau, tu fais un clic droit sur ton fichier clean.zip et dans le menu déroulant, tu clics sur extrait tout ou extraire ici.
                                      Cela va créer un dossier clean.
                                      Double-clic sur ce dossier clean, tu y trouveras dedans plusieurs fichiers.
                                      Double-clic sur clean. Cela va ouvrir une fenêtre noire.
                                      Un menu va apparaître, choisis l'option 1 en appuyant sur la touche 1 de ton clavier.
                                      Clean va travailler.
                                      Un rapport Va etre généré, colle le contenu entier ici.

                                      (- Où est le rapport clean ? : « Poste de travail » / double clic sur disque « C / » double-clic sur « rapport_clean.txt » et « copier/coller le contenu » sur le forum. )

                                      Télécharge SmitfraudFix
                                      Utilitaire de S!Ri: Moe et balltrap34
                                      http://siri.urz.free.fr/Fix/SmitfraudFix.php
                                      et télécharge SmitfraudFix.exe.

                                      Regarde le tuto

                                      Exécute le en choisissant l’option 1,
                                      il va générer un rapport
                                      Copie/colle le sur le poste stp.

                                      Bon courage
                                      A++

                                      0
                                      1. Ok merçi ! n'avais je pas desactivé l'UAC? en allant dans comptes utilistateurs je pouvais uniquement cocher la case pour activer le controle..
                                        Voici le rapport :

                                        Search Navipromo version 3.3.6 commencé le 02/12/2007 à 18:25:10,44

                                        Outil exécuté depuis C:\Program Files\navilog1
                                        Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO

                                        Microsoft Windows Vista 6.0.6000
                                        Internet Explorer : 7.0.6000.16546

                                        *** Recherche Programmes installés ***

                                        *** Recherche dossiers dans C:\Windows ***

                                        *** Recherche dossiers dans C:\Program Files ***

                                        *** Recherche dossiers dans C:\ProgramData ***

                                        *** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***

                                        *** Recherche dossiers dans C:\USERS\KAM\APPDATA\ROAMING\MICROS~1\WINDOWS\STARTM~1\PROGRAMS ***

                                        *** Recherche dossiers dans C:\Users\Kam\AppData\Local\virtualstore\Program Files ***

                                        *** Recherche dossiers dans C:\Users\Kam\AppData\Roaming ***

                                        *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                                        pour + d'infos : http://www.gmer.net

                                        Aucun fichier trouvé dans :

                                        - C:\Users\Kam\AppData\Local\Microsoft
                                        - C:\Users\Kam\AppData\Local\virtualstore\windows\system32
                                        - C:\Users\Kam\AppData\Local

                                        *** Recherche avec GenericNaviSearch ***
                                        !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                                        !!! A vérifier impérativement avant toute suppression manuelle !!!

                                        * Recherche dans C:\Windows\system32 *

                                        * Recherche dans C:\Users\Kam\AppData\Local\Microsoft *

                                        * Recherche dans C:\Users\Kam\AppData\Local\virtualstore\windows\system32 *

                                        * Recherche dans C:\Users\Kam\AppData\Local *

                                        *** Recherche fichiers ***

                                        *** Recherche clés spécifiques dans le Registre ***

                                        *** Module de Recherche complémentaire ***
                                        (Recherche fichiers spécifiques)

                                        1)Recherche fichiers connus:

                                        2)Recherche Heuristique :

                                        3)Recherche Certificats :

                                        Certificat Egroup absent !

                                        *** Analyse terminée le 02/12/2007 à 18:26:17,31 ***
                                        0
                                        • 1
                                        • 2