Pub intempestives

Résolu
Bonjour,
Je suis encore infesté par les pubs, j'ai pris les devant et fait un rapport avec Hijackthis que voici :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:47:52, on 18/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\apps\ABoard\ABoard.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
D:\belkin\bin\btwdins.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
D:\belkin\BTTray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\OFFICE One6.5\OFFICE One Clock\ooneclockv65.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
D:\belkin\BTSTAC~1.EXE
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - D:\Free Download Manager\iefdmcks.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [EasyAntivirus] C:\Program Files\EasyAntivirus\bin\ClamTray.exe --logon
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: OFFICE One Clock v6.5.lnk = C:\Program Files\OFFICE One6.5\OFFICE One Clock\ooneclockv65.exe
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - D:\belkin\btsendto_ie_ctx.htm
O8 - Extra context menu item: Envoyer à &Bluetooth - D:\belkin\btsendto_ie_ctx.htm
O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://D:\Free Download Manager\dlall.htm
O8 - Extra context menu item: Télécharger avec Free Download Manager - file://D:\Free Download Manager\dllink.htm
O8 - Extra context menu item: Télécharger les tous avec Free Download Manager - file://D:\Free Download Manager\dlselected.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\belkin\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\belkin\btsendto_ie.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\The Nightshift Code\Images\stg_drm.ocx
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Venice\Images\armhelper.ocx
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\belkin\bin\btwdins.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

--
End of file - 10189 bytes
Configuration: Windows XP
Firefox 2.0.0.12

32 réponses

Résumé de la discussion

Pubs persistantes et signes d’infection apparaissent malgré des outils de sécurité, et le rapport HijackThis est utilisé pour identifier les composants suspects sur le système Windows XP. Des indications solides préconisent l’utilisation de Navilog1 en mode sans échec et la désactivation temporaire des protections comme UAC et la protection en temps réel d’Antivirus, pour obtenir un rapport fiable. Si Navilog ne donne pas de solution, l’usage de SmitFraudFix en mode sans échec et le nettoyage des éléments identifiés dans le rapport peuvent être envisagés. D'autres retours indiquent que certains composants publicitaires disparaissent après nettoyage, mais que des éléments résiduels comme des barres d'outils ou des scripts persistent et nécessitent une vérification continue.

Bobot (l’IA à votre service)
  1. naivlog ne fonctionne tjs pas, mais c'est bon je n'ai plus de pubs !
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 08:26:11, on 24/03/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      D:\belkin\bin\btwdins.exe
      c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
      C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
      C:\apps\ABoard\ABoard.exe
      c:\APPS\HIDSERVICE\HIDSERVICE.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
      C:\apps\ABoard\AOSD.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
      C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
      C:\WINDOWS\system32\ctfmon.exe
      D:\belkin\BTTray.exe
      C:\Program Files\OFFICE One6.5\OFFICE One Clock\ooneclockv65.exe
      c:\APPS\Powercinema\Kernel\TV\CLSched.exe
      D:\belkin\BTSTAC~1.EXE
      C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Windows Live\Mail\wlmail.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Trend Micro\HijackThis\scanner.exe.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
      O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - D:\Free Download Manager\iefdmcks.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [EasyAntivirus] C:\Program Files\EasyAntivirus\bin\ClamTray.exe --logon
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: BTTray.lnk = ?
      O4 - Global Startup: OFFICE One Clock v6.5.lnk = C:\Program Files\OFFICE One6.5\OFFICE One Clock\ooneclockv65.exe
      O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - D:\belkin\btsendto_ie_ctx.htm
      O8 - Extra context menu item: Envoyer à &Bluetooth - D:\belkin\btsendto_ie_ctx.htm
      O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://D:\Free Download Manager\dlall.htm
      O8 - Extra context menu item: Télécharger avec Free Download Manager - file://D:\Free Download Manager\dllink.htm
      O8 - Extra context menu item: Télécharger les tous avec Free Download Manager - file://D:\Free Download Manager\dlselected.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
      O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\belkin\btsendto_ie.htm
      O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\belkin\btsendto_ie.htm
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
      O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Charm Tale 2 - Mermaid Lagoon\Images\stg_drm.ocx
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
      O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
      O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Venice\Images\armhelper.ocx
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - D:\belkin\bin\btwdins.exe
      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
      O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
      O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
      O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: MysqlInventime - Unknown owner - C:\Apps\INVENT~1\mysql\bin\mysqld-nt.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
      O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
      1. Contributeur sécurité
        salut boodha ,pour la scan en ligne :

        E - Scan online avec BitDefender

        Fais ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X;

        la barre anti-popup du SP2 (en haut) va se mettre à clignoter,
        clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
        Une fois qu'il a terminé colle le rapport ici stp
        https://www.bitdefender.com/toolbox/
        Copie/Colle le rapport
        http://www.malekal.com/tutorial_BitDefender_AntiSpyware.php
        https://kerio.probb.fr/
        http://pageperso.aol.fr/rginformatique/mapage/defender.htm
        1. tout est ok maintenant, je te remercie pour ton aide ! et merci combofix !
          1. On tâtonne, on tâtonne grrrr

            Toujours des pubs ?

            Envoie un nouveau rapport HJ
            1. ===================== COMBOFIX ========================

              Combofix

              Installer ComboFix sur le bureau
              Note :
              Le serveur de téléchargement peut être en surcharge et renvoyer une page d'erreur. Il faut insister.


              • Se déconnecter d'internet
              • Désactiver seulement pendant l'utilisation de ComboFix, la protection de l'antivirus et de l'antispyware ceux-ci pouvant entraver le bon fonctionnement de combofix
              • Fermer toutes les applications en cours
              • Double-click sur l'icône qui s'est installé sur le bureau
              • Appuyer sur la touche 1 puis sur entrée:
              • Laisser Combofix travailler sans se servir de la machine.
              • Si ComboFix a besoin de redémarrer la machine, laisser faire.
              • Réactiver la protection de l'antivirus et de l'antispyware

              • Copier/Coller le rapport généré dans le bloc-note dans le prochain message
              (Ce fichier est automatiquement généré et enregistré sous C:\Combofix.txt)
              1. ComboFix 08-03-23.2 - Michelle 2008-03-23 20:19:11.4 - NTFSx86
                Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.406 [GMT 1:00]
                Endroit: D:\Documents and Settings\Michelle\Bureau\ComboFix.exe
                .

                ((((((((((((((((((((((((((((( Fichiers créés 2008-02-23 to 2008-03-23 ))))))))))))))))))))))))))))))))))))
                .

                2008-03-23 18:48 . 2008-03-23 18:48 <REP> d-------- C:\WINDOWS\LastGood
                2008-03-23 18:47 . 2008-03-23 18:47 <REP> d-------- D:\Documents and Settings\Michelle\Application Data\ATI
                2008-03-23 18:47 . 2008-03-23 18:47 <REP> d-------- D:\Documents and Settings\All Users\Application Data\ATI
                2008-03-23 18:33 . 2008-03-23 18:33 <REP> d-------- C:\Program Files\MSXML 6.0
                2008-03-23 18:31 . 2008-03-23 18:31 <REP> d-------- C:\Program Files\MSBuild
                2008-03-23 18:28 . 2008-03-23 18:33 <REP> d-------- C:\WINDOWS\system32\XPSViewer
                2008-03-23 18:28 . 2008-03-23 18:28 <REP> d-------- C:\Program Files\Reference Assemblies
                2008-03-23 18:27 . 2008-03-23 18:40 <REP> d-------- C:\WINDOWS\system32\fr-fr
                2008-03-23 18:27 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
                2008-03-23 17:45 . 2008-03-23 18:11 <REP> d-------- C:\Program Files\Lopxp
                2008-03-23 15:32 . 2008-03-23 15:32 <REP> d-------- D:\Documents and Settings\Michelle\Application Data\ma-config.com
                2008-03-23 15:32 . 2008-03-23 15:32 <REP> d-------- C:\Program Files\ma-config.com
                2008-03-23 12:23 . 2008-03-23 12:23 0 --a------ C:\WINDOWS\ativpsrm.bin
                2008-03-23 12:18 . 2004-08-03 22:59 95,360 --a------ C:\WINDOWS\system32\drivers\SET76.tmp
                2008-03-23 12:02 . 2008-03-23 12:02 <REP> d-------- D:\Documents and Settings\Michelle\Application Data\Uniblue
                2008-03-23 11:18 . 2007-01-18 13:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
                2008-03-19 13:33 . 2008-03-19 13:33 <REP> d-------- D:\Documents and Settings\Michelle\Application Data\My Games
                2008-03-19 12:59 . 2008-03-19 12:59 <REP> d-------- D:\Documents and Settings\All Users\Application Data\RTL Winter Sports 2008
                2008-03-19 09:00 . 2008-03-19 09:20 <REP> d-------- C:\Program Files\RegCleaner
                2008-03-19 08:22 . 2008-03-19 08:22 <REP> d-------- D:\Documents and Settings\Michelle\Application Data\Malwarebytes
                2008-03-19 08:22 . 2008-03-19 08:22 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Malwarebytes
                2008-03-19 08:22 . 2008-03-19 08:22 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                2008-03-18 11:35 . 2008-03-18 11:35 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
                2008-03-18 11:01 . 2008-03-18 11:01 <REP> d-------- D:\Documents and Settings\NetworkService\Application Data\Webroot
                2008-03-18 10:25 . 2008-03-18 10:25 <REP> d-------- D:\Documents and Settings\All Users\Application Data\Avira
                2008-03-18 10:25 . 2008-03-18 10:25 <REP> d-------- C:\Program Files\Avira
                2008-03-17 13:13 . 2008-03-18 17:24 <REP> d-------- C:\Program Files\Charma_at
                2008-03-17 13:05 . 2008-03-17 13:11 <REP> d-------- C:\Program Files\LegendOfElDorado_at
                2008-03-15 13:37 . 2008-03-16 08:26 <REP> d-------- C:\Program Files\GoldMinerVegas_at
                2008-03-13 13:32 . 2008-03-13 13:32 <REP> d--hs---- C:\WINDOWS\ftpcache
                2008-03-11 10:51 . 2008-03-11 10:51 <REP> d-------- C:\Program Files\Common Files
                2008-02-26 22:52 . 2008-02-26 23:00 202 --a------ C:\WINDOWS\cdplayer.ini
                2008-02-26 04:12 . 2008-02-26 04:12 372,736 --a------ C:\WINDOWS\system32\ATIDEMGX.dll
                2008-02-26 03:59 . 2008-02-26 03:59 9,797,632 --a------ C:\WINDOWS\system32\atioglx2.dll
                2008-02-26 03:41 . 2008-02-26 03:41 3,107,788 --a------ C:\WINDOWS\system32\ativvaxx.dat
                2008-02-26 03:41 . 2008-02-26 03:41 3,107,788 --a------ C:\WINDOWS\system32\ativva5x.dat
                2008-02-26 03:41 . 2008-02-26 03:41 887,724 --a------ C:\WINDOWS\system32\ativva6x.dat
                2008-02-26 03:29 . 2008-02-26 03:29 46,080 --a------ C:\WINDOWS\system32\amdpcom32.dll
                2008-02-26 03:19 . 2008-02-26 03:19 167,936 --a------ C:\WINDOWS\system32\atiok3x2.dll

                .
                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2008-03-23 19:19 --------- d-----w D:\Documents and Settings\Michelle\Application Data\Free Download Manager
                2008-03-23 19:13 --------- d-----w C:\Program Files\Navilog1
                2008-03-23 14:37 --------- d--h--w C:\Program Files\InstallShield Installation Information
                2008-03-23 11:20 --------- d-----w C:\Program Files\ATI Technologies
                2008-03-23 10:31 --------- d-----w C:\Program Files\a-squared Anti-Malware
                2008-03-17 12:11 --------- d-----w C:\Program Files\Pogo FR
                2008-03-13 13:42 --------- d---a-w D:\Documents and Settings\All Users\Application Data\TEMP
                2008-03-11 08:55 --------- d-----w C:\Program Files\Defenza
                2008-03-09 12:49 --------- d-----w C:\Program Files\Spyware Doctor
                2008-03-09 12:46 --------- d-----w C:\Program Files\Hitman Pro
                2008-03-09 08:44 --------- d-----w D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                2008-03-09 07:57 --------- d-----w C:\Program Files\SpywareBlaster
                2008-03-09 07:55 74,240 ----a-w C:\WINDOWS\system32\drivers\iksyssec.sys
                2008-03-09 07:55 56,832 ----a-w C:\WINDOWS\system32\drivers\iksysflt.sys
                2008-03-08 06:47 --------- d-----w C:\Program Files\Java
                2008-03-04 13:18 --------- d-----w C:\Program Files\Fichiers communs\Adobe
                2008-02-26 18:24 --------- d-----w D:\Documents and Settings\Michelle\Application Data\vlc
                2008-02-26 05:51 2,863,616 ----a-w C:\WINDOWS\system32\drivers\ati2mtag.sys
                2008-02-26 05:51 2,863,616 ----a-w C:\WINDOWS\system32\dllcache\ati2mtag.sys
                2008-02-26 03:10 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
                2008-02-26 03:10 299,520 ----a-w C:\WINDOWS\system32\ati2dvag.dll
                2008-02-26 03:02 172,032 ----a-w C:\WINDOWS\system32\atipdlxx.dll
                2008-02-26 03:02 126,976 ----a-w C:\WINDOWS\system32\Oemdspif.dll
                2008-02-26 03:01 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
                2008-02-26 03:01 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
                2008-02-26 03:01 126,976 ----a-w C:\WINDOWS\system32\ati2evxx.dll
                2008-02-26 03:00 520,192 ----a-w C:\WINDOWS\system32\ati2evxx.exe
                2008-02-26 02:58 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
                2008-02-26 02:49 3,176,480 ----a-w C:\WINDOWS\system32\ati3duag.dll
                2008-02-26 02:41 1,755,264 ----a-w C:\WINDOWS\system32\ativvaxx.dll
                2008-02-26 02:25 393,216 ----a-w C:\WINDOWS\system32\atikvmag.dll
                2008-02-26 02:23 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
                2008-02-26 02:22 49,152 ----a-w C:\WINDOWS\system32\drivers\ati2erec.dll
                2008-02-26 02:21 5,439,488 ----a-w C:\WINDOWS\system32\atioglxx.dll
                2008-02-26 02:16 520,192 ----a-w C:\WINDOWS\system32\ati2cqag.dll
                2008-02-25 20:05 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
                2008-02-19 15:40 --------- d-----w D:\Documents and Settings\All Users\Application Data\PlayFirst
                2008-02-19 15:12 --------- d-----w D:\Documents and Settings\All Users\Application Data\MonteCristo
                2008-02-14 07:29 --------- d-----w D:\Documents and Settings\All Users\Application Data\QB9 S.R.L
                2008-02-02 12:12 --------- d-----w D:\Documents and Settings\Michelle\Application Data\Sonic
                2008-01-25 06:51 --------- d-----w C:\Program Files\Messenger Plus! Live
                2008-01-11 05:36 44,544 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
                2007-12-22 12:50 71 ----a-w C:\Program Files\ETIQ.TXT
                2007-12-10 19:43 32 ----a-w D:\Documents and Settings\All Users\Application Data\ezsid.dat
                2007-09-23 07:56 774,144 ----a-w C:\Program Files\RngInterstitial.dll
                .

                ((((((((((((((((((((((((((((( snapshot@2008-03-23_19.54.30,15 )))))))))))))))))))))))))))))))))))))))))
                .
                + 2008-03-23 19:04:40 860,160 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\f187e672d236454e90c6970a93df783c\AspNetMMCExt.ni.dll
                + 2008-03-23 19:04:21 434,176 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\[u]0/u7a304a4660bb4478b54a00d73b1efbb\ComSvcConfig.ni.exe
                + 2008-03-23 19:04:41 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\3e04b852c1880c46943c7665c6c69a45\CustomMarshalers.ni.dll
                + 2008-03-23 19:04:40 15,360 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\dfsvc\73f3853290b01d46a946b6c8adb69fec\dfsvc.ni.exe
                + 2008-03-23 19:04:42 880,640 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\8d9412c3a0af9b448d59e68eb1733e5a\Microsoft.Build.Engine.ni.dll
                + 2008-03-23 19:04:24 405,504 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\c2579038cbd1634689b397a4403b9dbd\Microsoft.Transactions.Bridge.Dtc.ni.dll
                + 2008-03-23 19:04:24 1,069,056 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\e0b25dfbaba09843a8f3dab0630f83a9\Microsoft.Transactions.Bridge.ni.dll
                + 2008-03-23 19:04:43 1,724,416 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\4ae01b025b5f2e48ad86904180361afc\Microsoft.VisualBasic.ni.dll
                + 2008-03-23 19:04:45 1,576,960 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\b546204845b0f4499323f3f75c3385c1\PresentationBuildTasks.ni.dll
                + 2008-03-23 19:04:24 139,264 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\5129372330554047a1c08a37962085e9\ServiceModelReg.ni.exe
                + 2008-03-23 19:04:25 286,720 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\61f21f9e77510549ad4bb30d996df08e\SMDiagnostics.ni.dll
                + 2008-03-23 19:04:25 323,584 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\SMSvcHost\34a7ed8c3b9b144c94938c6073b63ebf\SMSvcHost.ni.exe
                + 2008-03-23 19:04:47 262,144 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\sysglobl\2026c6486d7ab140917ea8841e964404\sysglobl.ni.dll
                + 2008-03-23 19:03:55 237,568 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\ff9d4235467030499a2e8b3c0b49d51c\System.IdentityModel.Selectors.ni.dll
                + 2008-03-23 19:03:54 995,328 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\80f1cb6e94b97e48a25bbcab6b5ca1e6\System.IdentityModel.ni.dll
                + 2008-03-23 19:03:55 425,984 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.IO.Log\fcb726bdd26de840a77adb5a12483c24\System.IO.Log.ni.dll
                + 2008-03-23 19:03:58 2,371,584 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\a975e9d7e5e4834f9244b18a10dbf104\System.Runtime.Serialization.ni.dll
                + 2008-03-23 19:04:20 17,506,304 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\65027743acfe4f489bbcaee8ee006273\System.ServiceModel.ni.dll
                + 2008-03-23 19:04:47 2,043,904 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Speech\6244e5d858366644b907f015fe9982d3\System.Speech.ni.dll
                + 2008-03-23 19:04:50 2,310,144 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\f8054f1246ba5a4a9086ad785df3ddf9\System.Web.Mobile.ni.dll
                + 2008-03-23 19:04:51 483,328 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationClient\42b70a670f78054c96ad60b58e2c0a76\UIAutomationClient.ni.dll
                + 2008-03-23 19:04:52 1,122,304 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\4348b5a74d9f0b4faa871c01fab0b04c\UIAutomationClientsideProviders.ni.dll
                + 2008-03-23 19:04:53 245,760 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\d8cc51035ae0da42a0582db06c51759e\WindowsFormsIntegration.ni.dll
                + 2008-03-23 19:04:26 380,928 ----a-w C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\WsatConfig\54b726c83509994dbe8fefcb6970ca15\WsatConfig.ni.exe
                .
                ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                REGEDIT4
                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
                "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-01 10:14 68856]
                "Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
                "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
                "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
                "ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 10:31 24576]
                "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
                "EasyAntivirus"="C:\Program Files\EasyAntivirus\bin\ClamTray.exe" [2005-11-24 16:49 53248]
                "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-03-18 10:26 249896]
                "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-11-22 01:58 180269]
                "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-22 01:53 98304]
                "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 12:17 61440]

                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]

                D:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                BTTray.lnk - D:\belkin\BTTray.exe [2006-06-07 17:05:38 553021]
                OFFICE One Clock v6.5.lnk - C:\Program Files\OFFICE One6.5\OFFICE One Clock\ooneclockv65.exe [2007-07-31 10:08:26 257536]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                "DisableMonitoring"=dword:00000001

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                "DisableMonitoring"=dword:00000001

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                "C:\\APPS\\skype\\Phone\\Skype.exe"=
                "C:\\WINDOWS\\system32\\dpvsetup.exe"=
                "C:\\WINDOWS\\system32\\rundll32.exe"=
                "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                "C:\\Program Files\\Sony Ericsson\\Update Service\\Update Service.exe"=
                "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

                R2 Machnm32;Machnm32 Driver;C:\WINDOWS\System32\Machnm32.sys [2003-08-13 00:27]
                R2 X4HSX32;X4HSX32;C:\Program Files\Player Metaboli\X4HSX32.Sys [2006-12-13 09:34]
                R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2006-04-11 19:36]
                R3 snpstd2;GE 98067 MiniCam Pro;C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-12-16 18:14]
                S3 AdWatchDrv;AW Realtime Driver;C:\WINDOWS\system32\drivers\AWRTPD.sys []
                S3 ProcMonitor;Process Monitor;C:\Program Files\EasyAntivirus\bin\ProcObsrv.sys [2005-10-05 11:37]
                S3 ultradfg;ultradfg;C:\WINDOWS\system32\DRIVERS\ultradfg.sys [2007-12-05 07:27]
                S3 XDva019;XDva019;C:\WINDOWS\system32\XDva019.sys []

                .
                Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
                "2008-03-23 18:30:00 C:\WINDOWS\Tasks\Configurer mon PC.job"
                - C:\Apps\SMP\PCSETUP.EXE
                "2008-03-23 09:53:00 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1185871944.job"
                - D:\HP\Digital Imaging\Bin\hpqfrucl.exe4-I
                .
                **************************************************************************

                catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-03-23 20:20:06
                Windows 5.1.2600 Service Pack 2 NTFS

                Balayage processus cachés ...

                Balayage caché autostart entries ...

                Balayage des fichiers cachés ...

                Scan terminé avec succès
                Les fichiers cachés: 0

                **************************************************************************

                [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MysqlInventime]
                "ImagePath"="C:\Apps\INVENT~1\mysql\bin\mysqld-nt --defaults-file=C:\Apps\Inventime\mysql\my.ini MysqlInventime"
                .
                Temps d'accomplissement: 2008-03-23 20:20:28
                ComboFix-quarantined-files.txt 2008-03-23 19:20:26
                ComboFix2.txt 2008-03-23 18:54:45
                ComboFix3.txt 2007-12-10 19:21:41
                .
                2008-03-23 16:52:11 --- E O F ---
            2. Sun Mar 23 19:19:48 2008
              EliBagle v11.18 (c)2008 S.G.H. / Satinfo S.L.
              ----------------------------------------------
              Lista de Acciones (por Acción Directa):

              Sun Mar 23 19:19:59 2008
              EliBagle v11.18 (c)2008 S.G.H. / Satinfo S.L.
              ----------------------------------------------
              Lista de Acciones (por Exploración):
              Explorando Unidad C:\

              Nº Total de Directorios: 6102
              Nº Total de Ficheros: 57484
              Nº de Ficheros Analizados: 11605
              Nº de Ficheros Infectados: 0
              Nº de Ficheros Limpiados: 0

              Sun Mar 23 19:26:27 2008
              EliBagle v11.18 (c)2008 S.G.H. / Satinfo S.L.
              ----------------------------------------------
              Lista de Acciones (por Exploración):
              Explorando Unidad D:\

              Nº Total de Directorios: 4236
              Nº Total de Ficheros: 42032
              Nº de Ficheros Analizados: 1764
              Nº de Ficheros Infectados: 0
              Nº de Ficheros Limpiados: 0
              1. On va essayer ça (Merci à GreenDay)

                Télécharge ELIBAGLA en bas de cette page:
                ==> http://www.zonavirus.com/datos/descargas/95/elibagla.asp
                Lance Elibagla en double cliquant dessus.
                assure toi que le bouton "Eliminar Ficheros Automaticamente" soit coché.
                Vérifie que C:\ soit sélectionné dans Unidad (ou la partition contenant ton OS).
                Clique sur le bouton Explorar.
                à la fin poste le rapport C:\infoSat.txt
                1. On a un problème là.

                  Je demande de l'aide. (Ca peut prendre un moment).
                  1. oui j'ai bien compris, j'ai bien double-cliqué dessus, il s'est lanceé j'ai tapé 1 puis entrée, ensuite il s'est fermé ! même chose en mode sans échec.
                    1. Alors tu dois avoir sur le bureau une Icône carré blanc avec 2 roues formant un engrenage. Avec en dessous Lopxp.

                      C'est la dessus-que tu dois double-clicker pour lancer LopFix.
                      1. Tu l'as téléchargé sur ton bureau ?
                        1. même problème qu'avec navilog, il se lance et dès que j'entre 1 + entrée, il se ferme directement, même chose en mode sans échec !
                        2. oui il est sur mon bureau
                      2. impossible de lancer lopxp il refuse de s'installer, j'ai rebooter comme c'était écrit et relancer l'application mais rien à faire ça marche pas !
                        1. Bon, on continue

                          ==================== LOPXP ======================

                          LOP XP
                          1ere phase

                          Télécharger Lopxp

                          • Double-click sur Lopxpsetup.exe pour lancer l'installation
                          • Au menu, choisir l'option 1
                          • Patienter un peu
                          • Copier/Coller le rapport dans la prochaine réponse
                          • 1
                          • 2