BureauTrojan.Win32.BlackBird

Résolu
Bonjour,
mon ordinator ete atacè par le virus Trojan malgre le deux antivirus y instoler ( avast et spybot ), virus ce manifester par le fenetre publisiter de PCclinerqui n'est pas aretè de c'ouvrir sur le bureau. J'ai reusi de resudre cet problem avec Spy Sweeper, mais apre ca j'ai retruvè l'aplication dant mes "Documents and Settings" qui ce s'apelle "BureauTrojan.Win32.BlackBird" et je n'arive pas le suprimer car un message s'afiche : "Impossible de suprimer BureauTrojan.Win32.BlackBird: cette ressource est utilisée par une autre person ou un autre programme. fermez les programme susceptible d'utiliser le fichier et essayez à nouveau."
Comant je peux resudre cette problem?
Merci
Configuration: Windows XP
Internet Explorer 7.0

27 réponses

Résumé de la discussion

Le fil expose une infection par le Trojan BureauTrojan.Win32.BlackBird sur Windows XP, dont l’apparition se manifeste par une fenêtre publicitaire bloquant le bureau et un fichier suspect réclamant suppression impossible. Plusieurs conseils recommandent d’utiliser Malwarebytes’ Anti-Malware pour un balayage approfondi, de le mettre à jour, puis de détruire ou mettre en quarantaine les éléments détectés afin d’éradiquer les composants tenaces. Des échanges évoquent aussi la cohabitation d’antivirus tels Avast, Spybot et Spy Sweeper, et la possibilité de changer d’outils ou d’ajouter un pare-feu intégré pour limiter les dysfonctionnements. En dernier lieu, des conseils portent sur des outils complémentaires et des méthodes pour nettoyer les paramètres du navigateur et les entrées de démarrage sans recourir au formatage.

Bobot (l’IA à votre service)
  1. Salut
    J'ai demandè de concail dans un boutique informatique - ils ont dit que ce possible que c'est windows a bloque l'axer aux applicatien et comme on a souprimè le reste des composent il n'y a plus de moien d'y acseder ???
    Est-ce que c'est resonable ???
    0
    1. Bonjour !
      Apre 9h de scanage kaspersky à delitè encor 2 troyane dant le restor failes et ce tout.
      L'aplicatien "BureauTrojan.Win32.BlackBird" n'a pas bugè de sa plas, mais mon ordi est beaucoup plus propre que aven-ca se sur.
      Si il y a un solutien pour virer ce "BureauTrojan.Win32.BlackBird" ( par prancipe) je serai vremen content.
      De tout le fassone un grande merci pour tous les consailes !!!!!!
      0
      1. et t'en fais pas a chaque probleme= solution

        tu apprends en même temps^^

        on va y arriver va

        bizz
        0
    2. Bonsoir !
      J'ai instoler le Kasperskiy vertion d'evaluatien.
      Avon fair ca j'ai du desinstaler avast et je fais avec lui le dernier gros scane en demarage - de coup ce lui qui a corige pluser problemes. Maintenant je fais le scane de +/- 8 heur avec Kasper, pour le memant il n'a rien truvè à par que il conseder SDFix et Navilog comme virus. Comme il termine de scaner je comunicrais le resultat.
      Bon nuit.
      0
      1. re normal navilog enerve les antivirus t'inquiete

        ok goood night a toi

        bises
        0
    3. salut

      non non n'achete rien ! il t'as rien viré?
      0
      1. Bonjiur !
        j'ai fais un scaner onlayne et voilà... Kasperskiy a trouvè des chos. Je cole le rapport ici.
        Est-ce que avec la version d'évalation de kaspersky on peut corriger le problem ou il faux acheter vertion complet ?
        Merci.

        Monday, April 28, 2008 6:34:30 AM
        Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
        Kaspersky Online Scanner version: 5.0.98.0
        Kaspersky Anti-Virus database last update: 27/04/2008
        Kaspersky Anti-Virus database records: 727908

        Scan Settings
        Scan using the following antivirus database extended
        Scan Archives true
        Scan Mail Bases true

        Scan Target My Computer
        C:\
        D:\

        Scan Statistics
        Total number of scanned objects 93133
        Number of viruses found 5
        Number of infected objects 13
        Number of suspicious objects 0
        Duration of the scan process 04:45:02

        Infected Object Name Virus Name Last Action
        C:\Documents and Settings\All Users\Application Data\Nero\Nero8\Nero BackItUp\Cache\NeroBackItUpScheduler3.log Object is locked skipped

        C:\Documents and Settings\andrei\Application Data\Webroot\Spy Sweeper\Logs\080428002031.ses Object is locked skipped

        C:\Documents and Settings\andrei\Bureau\Navilog1.exe/file10 Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

        C:\Documents and Settings\andrei\Bureau\Navilog1.exe Inno: infected - 1 skipped

        C:\Documents and Settings\andrei\Cookies\index.dat Object is locked skipped

        C:\Documents and Settings\andrei\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

        C:\Documents and Settings\andrei\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

        C:\Documents and Settings\andrei\Local Settings\Historique\History.IE5\index.dat Object is locked skipped

        C:\Documents and Settings\andrei\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

        C:\Documents and Settings\andrei\Mes documents\Downloads\winzip111.rar/winzip111/Setup.exe Infected: Trojan-Downloader.Win32.Agent.mgw skipped

        C:\Documents and Settings\andrei\Mes documents\Downloads\winzip111.rar RAR: infected - 1 skipped

        C:\Documents and Settings\andrei\ntuser.dat Object is locked skipped

        C:\Documents and Settings\andrei\ntuser.dat.LOG Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS03CADDCA-7702-4A99-AC34-699E1E8DB306.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS057CE7BD-84E9-45C9-9AA8-2E4391ACE19A.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS079FC2FA-CD6F-44FF-BAAC-3EA33A067185.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS07FF26F1-0404-4536-86F5-CB4A7268B093.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS083B68B0-8E71-40C6-BA80-ED06B1E286CA.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0988E228-BDC9-435C-9663-1E1CEBB64289.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS09B0467C-FE14-472F-B57A-766FEEE04467.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0AB9579A-A2B5-4420-B090-C351669359A6.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0E917095-4074-4DFC-BEF4-6CDB50447BDB.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS0F817771-856D-4730-9D36-9B9D84E297F1.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS110BBA87-2135-430F-955B-40D3E94A407F.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS14ECA0AE-9FDC-45FA-B1D0-EC64D92DE9E4.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS19ED9665-E429-42BE-BD8C-7898B169AB62.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS1F9B1394-B187-465B-974F-F783356D1B43.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2215858B-C39F-4FB5-8670-409165C7B37C.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS23B6AAA2-5782-4C68-9CA7-1D11615D0550.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2407AAF3-C017-45E6-8B3F-BC13D3DD53CA.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS25C6B20A-F83E-4C5E-920F-D46EBAA5B84B.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS27ED5CE4-DADE-48CA-AE65-6D75D6A24D1C.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2C7EB7F8-84EB-47C8-BEAC-3515C15AC6E9.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2D6F10EC-9307-4ABB-A84D-20A05DAA9C6D.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS2FD477BD-F8B6-46AC-B1BC-1864C3936F3C.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3442A3B7-89EF-4B3A-BBDD-844E0A7726EA.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3456DCCA-F2EF-488E-ABDB-F9EF11B5F2AA.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3459A0AC-8C72-4D7C-AAB3-962B46A221A9.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3693A4B4-A812-4425-A3F8-7F91933371E5.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS39108DF1-01BA-4464-B1A4-BE5911F95E05.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3DE6ABE8-A46E-4AB3-81EF-BEBDD826A9E3.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3EFAF410-CE64-4C83-AB22-A145264331D6.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS3FD5D88E-511A-4ACE-A9A3-92F4EF10E2AD.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS45A9C1E2-E8CF-447F-B3CE-18A75E994F30.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS47D5B001-067A-4649-AF47-A33D5D6F5352.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS48B69CD0-3F03-4A81-A52F-26A91158F94F.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4B56F742-376C-442C-99B6-366E2DE496E2.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4D675FB9-4C22-4A78-A508-D8D12B3E9E3F.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS4E576D14-2E81-43B1-B59C-33A47486A6B7.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS51A9A8A3-C8A0-4C20-A5C8-6AC8865EC742.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS54073ECD-0504-4A8A-812C-B92187D653DA.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5BD14BC8-9183-4F58-95E6-45DB38B3175E.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS5E7F62B6-8459-400B-A59C-DC0A95A3692F.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS659189F3-E8BC-4B7C-85A4-02FB265DECE4.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6A4EE364-534D-4EAD-884D-3A422653F9A4.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS6FED50C3-4033-451B-86C8-8CDA818CDE14.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7166F05F-1262-4D0E-8D40-5659DFCA9F84.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS72A94EBC-B77D-4EF7-BF37-99394D48744D.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS73109831-B2FB-4F74-9708-5B281B1FC2B4.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS739BE5F4-114B-44D1-AA09-4EE44AF7C20E.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS7E2761A4-FB92-4E48-A762-5AB48CEF726A.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS862D3A94-82FA-4ACB-8A43-468702AF9DF5.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8651A8E9-1194-4445-A6A6-562A801C5938.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8B1A9842-A887-40C7-996C-1D8E081FC1C5.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8E2D723C-BF45-4BDF-BADA-775D1BA0391D.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS8ED359D3-A650-4518-9276-ED65CFAFFB8F.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS903AF19B-AB92-42EF-8B85-0AB06F328E64.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9286AABE-A274-4288-841A-CA0AEF867DCF.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS96100B60-3758-4BAD-9755-E31D7F0AF897.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS99963F7C-FFD4-438A-8F7C-EE9E71517E8D.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9B2181A5-D045-474D-A5AD-40C60B73F554.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9C6F6FCE-C16C-4DB8-B64C-4A40C1EF9BF5.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9D4B2445-040D-407B-A33E-CD9754BB050F.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMS9DC1EADB-1F70-4CFE-AE2A-6DD859D5149E.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA2C66518-6971-4073-AF8D-A8F8E2F20AF5.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA4849A93-2CFE-4EDA-AD8E-D1917BE9536B.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSA52F773A-590A-48FC-B677-777E15F64902.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAC7B6AD4-54D8-41FD-BE92-96C2B2172F5C.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSACE77B01-8892-4B94-B250-7A8C31100551.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAE25BD7F-6769-4E92-B712-D7E6BE70B568.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSAEE2808D-61E5-404F-8BE1-FD211122343B.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSB2A75B87-CB96-446E-8F7F-EEA17FE09966.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC09C962F-DB9A-47FB-B6B1-03B9225F2D53.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC1B2668C-5931-47C2-B84B-5F0A094309B7.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC2B53AC0-AD47-489D-A5F4-7B796A8818B2.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC5AD9A83-386A-41CB-9FBF-6918B61BBB59.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSC7E131B4-ED3D-4754-AA5B-C7F2C3E898A1.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCAB4AC0B-D620-4AAE-A6B3-F4561CD52DE4.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCD518C76-346D-43DC-8A26-0424048C409B.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSCF073E5A-5B43-4CED-8D6E-AADA4BF91D8E.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD006CB3D-BA20-4E5B-8A51-C5651C9AFEB9.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD127BAC7-B023-48A0-9DF3-70900179B635.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD2B3C31A-5E85-4923-82B4-B6ECD4B29691.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD689774D-B1F3-4A50-BAA2-2579A1E683B0.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSD8842929-1470-4BD4-AAFF-16BA9C05A6C3.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSDDA3DC9A-EE91-4E44-AEAB-FBF2B0EE03A0.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE0503B25-5956-487B-881C-D2A48D1C5C3B.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSE565051B-2159-4271-9386-6120FE9D92D3.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSEECF532B-1BDA-4F4A-A27A-B5D4E6621F9F.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF15FB877-6EF2-4782-9D4A-B4A9DACD74AE.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF58BA22D-28FF-4550-9365-8ED9C94A64D6.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSMSF9578B72-2F4E-4ADE-9AE1-BBF5FE414661.tmp Object is locked skipped

        C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

        C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

        C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

        C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped

        C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

        C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

        C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

        C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

        C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

        C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

        C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

        C:\Program Files\AskTBar\bar\1.bin\A5POPSWT.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.az skipped

        C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.az skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\debug.log Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\debug.log.idx Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\error.log Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\error.log.idx Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\hips.log Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\hips.log.idx Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\ids.log Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\ids.log.idx Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\network.log Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\network.log.idx Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\system.log Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\system.log.idx Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\warning.log Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\warning.log.idx Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\web.log Object is locked skipped

        C:\Program Files\Kerio\Personal Firewall 4\logs\web.log.idx Object is locked skipped

        C:\Program Files\Navilog1\reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

        C:\Program Files\Nero\Nero8\Nero BackItUp\BIU1.txt Object is locked skipped

        C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped

        C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped

        C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped

        C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped

        C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP414\A0085524.dll Infected: not-a-virus:AdWare.Win32.Vapsup.dan skipped

        C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP414\A0085525.dll Infected: not-a-virus:AdWare.Win32.Vapsup.dan skipped

        C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP418\A0088517.exe/file10 Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

        C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP418\A0088517.exe Inno: infected - 1 skipped

        C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP418\A0088519.exe Infected: Backdoor.Win32.Hupigon.bnca skipped

        C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP418\A0088522.exe Infected: Backdoor.Win32.Hupigon.bnca skipped

        C:\System Volume Information\_restore{9AEDEF4B-1977-4657-B854-EFDB21259CFF}\RP418\change.log Object is locked skipped

        C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

        C:\WINDOWS\SchedLgU.Txt Object is locked skipped

        C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

        C:\WINDOWS\Sti_Trace.log Object is locked skipped

        C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

        C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

        C:\WINDOWS\system32\config\Antiviru.evt Object is locked skipped

        C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

        C:\WINDOWS\system32\config\DEFAULT Object is locked skipped

        C:\WINDOWS\system32\config\default.LOG Object is locked skipped

        C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

        C:\WINDOWS\system32\config\SAM Object is locked skipped

        C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

        C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

        C:\WINDOWS\system32\config\SECURITY Object is locked skipped

        C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

        C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped

        C:\WINDOWS\system32\config\software.LOG Object is locked skipped

        C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

        C:\WINDOWS\system32\config\SYSTEM Object is locked skipped

        C:\WINDOWS\system32\config\system.LOG Object is locked skipped

        C:\WINDOWS\system32\h323log.txt Object is locked skipped

        C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

        C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

        C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

        C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

        C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

        C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

        C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

        C:\WINDOWS\wiadebug.log Object is locked skipped

        C:\WINDOWS\wiaservc.log Object is locked skipped

        C:\WINDOWS\WindowsUpdate.log Object is locked skipped

        Scan process completed.
        0
        1. Merci !
          Kaspersky ce pour demain - j'afichrais le resultas.
          0
          1. ok!!! no soucy^^ bonne soirée à toi

            bizoux
            0
        2. Apre le scan rapide de Malwarebyte il n'y a aucun viruse etais detecter sur mon ordi - donc je le bien netouier : un grand merci à FunnyGirl !

          Mais le problem initiale est reste sont rezolution: l'aplication "BureauTrojan.Win32.BlackBird" reste dant le C:/Documents and Settings/user/

          j'aimrai bien savoire si un jour je pourais de c'en debarassai et quelle manere ???

          et auci si quelqun me peut doner le concaile quelle formule de protection et mailer,
          pour resudre mon problem j'ai telecharge un paque de antispaywere et je ne sais pas que je vais desinstaler et qui garder.

          maintenant j'ai SpyBot, Avast, SpySweeper et en plus je viene d'instaler le Malwarebytes' Anti-Malware, CCleaner et HijackThis

          je ponse que je vais ramplasser Avast par Antivir, est-ce que c'est une bon idée?

          Je remercie à tous ces qui pouent me repondre à tous ces question !!!
          0
          1. franchement avast ,antivir ,sont telechargeable n'importe quand!1 conseil telecharge la version d'évalation de kaspersky ici :

            http://www.01men.com/contenu/4483/01men_telecharger-logiciels-windows-Securite/33637-kaspersky-internet-security

            dans ce cas ,i tu veux le mettre ( c'est ce que j'ai et pas de souci) dis le car il possede son propre parefeu et kério serait inutile + il faudrait désinstaller antivir
            0
          2. @Utilisateur anonymeOK ! Merci pour le concail antivirus.

            Et que ce que tu ponse pour "BureauTrojan.Win32.BlackBird" - je dois reformater le disque ou je peux le lesser comme il est?
            0
          3. @O10eynan reformate pas pour si peu ! as tu mis kaspersky?
            pour le reste je vais demander conseil ok !?
            0
        3. Bon, on va tous recomonser...
          Entre tempe j'ai suprimè tous les fichiers dant les carontines de Avast, Spy Sweewer et Malwarebytes;

          renetoiler avec CCliner;

          analiser et netoiler avec leSDFif en mode sans echec et enrigistrer le rapporte

          analiser avec Hijack et enrigistrer le rpporte

          nouvaux redemarer l'ordi en mod sans echec et esseer voir ce fichie on detailes : il est proteger - aucun modificatien autriser, je n'ai pas reussie coche le case "autorise le soupretion" et tout ce genre de modifikation le information qui se truve sur cet aplication est :

          C:\WINDOWS>dir
          RépertoirevdeC:\WINDOWS
          SYSTEM<DIR> 03-01-95
          WIN COM 22 087 03-01-95
          WIN INI 11 728 03-01-95
          welcom EXE 19 539 03-01-95

          et encore le lien qui est attache à lui:

          % SYSTEMROOT%\system32\CONFIG.NT

          je ne sais pas si ce utile, cette information?

          Je coles les deux derniers raporte que j'ai erigistrè par SDFix et Hijack

          Je vais scaner avec Malwarebytes et je vais coler le rezultas.

          merci de tous tes reponses à mes problemes !!!!

          Par SDFix :

          [b]SDFix: Version 1.175 /b
          Run by andrei on dim. 27/04/2008 at 18:58

          Microsoft Windows XP [version 5.1.2600]
          Running From: C:\DOCUME~1\andrei\Bureau\SDFix\SDFix

          [b]Checking Services /b:

          Restoring Windows Registry Values
          Restoring Windows Default Hosts File

          Rebooting

          [b]Checking Files /b:

          No Trojan Files Found

          Removing Temp Files

          [b]ADS Check /b:

          [b]Final Check /b:

          catchme 0.3.1353.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,

          http://www.gmer.net
          Rootkit scan 2008-04-27 19:18:44
          Windows 5.1.2600 Service Pack 2 NTFS

          scanning hidden processes ...

          scanning hidden services & system hive ...

          scanning hidden registry entries ...

          scanning hidden files ...

          scan completed successfully
          hidden processes: 0
          hidden services: 0
          hidden files: 0

          [b]Remaining Services /b:

          Authorized Application Key Export:

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\param

          eters\firewallpolicy\standardprofile\authorizedapplications\list]
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabl

          ed:@xpsp2res.dll,-22019"
          "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program

          Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
          "C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program

          Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network

          Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
          "C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvse

          tup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
          "C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll3

          2.exe:*:Enabled:Ex‚cuter une DLL en tant qu'application"
          "C:\\Program Files\\ICQ6\\ICQ.exe"="C:\\Program

          Files\\ICQ6\\ICQ.exe:*:Enabled:ICQ6"
          "C:\\Program Files\\Real\\RealOne Player\\realplay.exe"="C:\\Program

          Files\\Real\\RealOne Player\\realplay.exe:*:Enabled:RealOne Player"
          "C:\\Program Files\\eMule\\emule.exe"="C:\\Program

          Files\\eMule\\emule.exe:*:Enabled:eMule"
          "C:\\Program Files\\Fichiers communs\\Ahead\\Nero

          Web\\SetupX.exe"="C:\\Program Files\\Fichiers communs\\Ahead\\Nero

          Web\\SetupX.exe:*:Enabled:Nero ProductSetup"
          "C:\\Documents and Settings\\andrei\\Local Settings\\Temp\\Nero

          Web\\SetupXu.exe"="C:\\Documents and Settings\\andrei\\Local

          Settings\\Temp\\Nero Web\\SetupXu.exe:*:Enabled:Nero ProductSetup"
          "C:\\Program Files\\Fichiers communs\\Nero\\Nero

          Web\\SetupX.exe"="C:\\Program Files\\Fichiers communs\\Nero\\Nero

          Web\\SetupX.exe:*:Enabled:Nero ControlCenter"
          "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program

          Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
          "C:\\Program Files\\DNA\\btdna.exe"="C:\\Program

          Files\\DNA\\btdna.exe:*:Enabled:DNA"
          "C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program

          Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
          "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program

          Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
          "C:\\Program Files\\Kerio\\Personal Firewall 4\\kpf4gui.exe"="C:\\Program

          Files\\Kerio\\Personal Firewall 4\\kpf4gui.exe:*:Enabled:Kerio Personal Firewall 4

          - GUI"

          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\param

          eters\firewallpolicy\domainprofile\authorizedapplications\list]
          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabl

          ed:@xpsp2res.dll,-22019"
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network

          Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

          [b]Remaining Files /b:

          File Backups: - C:\DOCUME~1\andrei\Bureau\SDFix\SDFix\backups\backups.zip

          [b]Files with Hidden Attributes /b:

          Sun 29 May 2005 193 A.SHR --- "C:\BOOT.BAK"
          Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search &

          Destroy\SDUpdate.exe"
          Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search &

          Destroy\SpybotSD.exe"
          Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search &

          Destroy\TeaTimer.exe"
          Fri 30 Aug 2002 57,344 A..HR --- "C:\WINDOWS\system32\sol.exe"
          Sun 22 Jul 2007 4,348 A.SH. --- "C:\Documents and Settings\All

          Users\DRM\DRMv1.bak"
          Tue 17 Oct 2006 304,736 A..H. --- "C:\Program Files\Canon\MP Navigator

          3.0\Maint.exe"
          Tue 17 Oct 2006 61,440 A..H. --- "C:\Program Files\Canon\MP Navigator

          3.0\uinstrsc.dll"
          Thu 18 Jan 2007 0 A.SH. --- "C:\Documents and Settings\All

          Users\DRM\Cache\Indiv01.tmp"
          Sun 19 Nov 2006 624,640 ...H. --- "C:\Documents and Settings\andrei\Application

          Data\Microsoft\Word\~WRL0221.tmp"
          Sun 7 May 2006 1,699,840 ...H. --- "C:\Documents and Settings\andrei\Application

          Data\Microsoft\Word\~WRL1598.tmp"
          Sun 19 Nov 2006 620,544 ...H. --- "C:\Documents and Settings\andrei\Application

          Data\Microsoft\Word\~WRL1698.tmp"
          Fri 17 Nov 2006 638,976 ...H. --- "C:\Documents and Settings\andrei\Application

          Data\Microsoft\Word\~WRL2793.tmp"

          [b]Finished!/b

          Et hijack

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 19:28:51, on 27/04/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16640)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\system32\CTsvcCDA.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
          C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
          C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
          C:\WINDOWS\System32\nvsvc32.exe
          C:\WINDOWS\system32\IoctlSvc.exe
          C:\WINDOWS\system32\slserv.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
          C:\WINDOWS\system32\MsPMSPSv.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
          C:\Program Files\Winamp\winampa.exe
          C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\WINDOWS\System32\WLTRAY.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
          C:\WINDOWS\system32\LVCOMSX.EXE
          C:\Program Files\Logitech\Video\LogiTray.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\Logitech\Video\FxSvr2.exe
          C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe
          C:\Program Files\Windows Media Player\WMPNSCFG.exe
          C:\Program Files\WinZip\WZQKPICK.EXE
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\WINDOWS\system32\wscntfy.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
          O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
          O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [U.S. Robotics Wireless Manager UI] C:\WINDOWS\System32\WLTRAY
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
          O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
          O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
          O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe"
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
          O4 - HKCU\..\Run: [Creative MediaSource Go] "C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe" /SCB
          O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\microsoft office\Office\OSA9.EXE
          O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
          O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O14 - IERESET.INF: START_PAGE_URL=https://www.proximus.be/pickx
          O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) -
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
          O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
          O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
          O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
          O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
          0
          1. CClinere m'a corigè quelque centain problemes mais la mudite aplicatione reste sur sa plas son bouger !
            Est-ce il ya d'autre moienne pour le fair disparetre ou on peut vivre avec son que elle se revail un jour ?
            0
            1. re

              1) Imprime ou copie surbloc note ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

              2) Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton bureau à partir de ce lien :

              https://www.malwarebytes.com/

              3) A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

              4) Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

              5) Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

              6) MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue. La fenêtre principale de MBAM s'affiche :

              7) Dans l'onglet analyse, vérifie que "Exécuter une analyse rapide" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

              8) MBAM analyse ton ordinateur. L'analyse peut prendre un certain teps. Il suffit de vérifier de temps en temps son avancement.

              9) A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

              10) Si des malwares ont été détectés, leur liste s'affiche.
              En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

              11) MBAM va ouvrir le bloc-notes et y copier le rapport d'analyse. Ferme le bloc-note. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

              12) Ferme MBAN en cliquant sur Quitter.
              0
          2. Je suis arivè au stade apre analyse - dant la marge gauche que deux icone "Windows" et "Application" !
            Commant je peux retruver "Erreurs"
            0
            1. re

              oui ccleaner tu le télécharge mais il ne vas pas te virer le trojan mais logiciel a avoir et a utiliser régulierement

              *Ccleaner (gratuit)
              Téléchargement :
              https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
              Tuto :
              https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

              Lors de l’installation, [décoche] l’option qui t’installerait la barre Yahoo !

              ¤ Lance CCleaner.

              Suppression des fichiers temporaires

              Va dans la section "Options" situé dans la marge gauche. Décoche Avancé. Retourne ensuite dans la section "Nettoyeur"
              Fais bien attention de cocher toutes ces cases dans la marge gauche (Internet Explorer/Windows Explorer/Système)
              • Clique sur Analyse
              • Patiente le temps du scan, qui peut prendre un peu de temps si c'est la première fois.
              • Une fois le scan terminé, clique sur Lancer le Nettoyage

              Suppression des incohérence du registre

              • Clique sur l'icône Erreurs situés dans la marge à gauche.
              • Puis clique sur Analyser les erreurs
              • Patiente pendant que CCleaner scan ton registre.
              • Une fois le scan terminé, coche toutes les entrèes qu'il t'aura trouvée.
              • Tu peux cliquer ensuite sur Corriger les erreurs.

              Si tu n'est pas sur de ce que tu fais, tu peux choisir de sauvegarder les entrées cochées pour les restaurer ultérieurement
              0
              1. J'ai deja instolè kerio.
                Mais mon fames dossie BureauTrojan.Win32.BlackBird est toujour la et je ne peux pas le souprimer. Sour l'autre forom j'ai vue de consail d'instoler CCleaner - est-ce que sera utille ?
                0
                1. salut

                  nan celui de windows est 1 passoire ,mets kério plutot

                  bises
                  0
                  1. J'ai vue dant le rapporte encor ca :

                    O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup

                    Est-ce que il doit y etre ou c'est mieux le suprimer ?

                    Et je verifier - le fichie avec troyan restait sur ca plas pour le memant - est-ce que c'est normal a ce stad là ?

                    Merci beaucoup!
                    0
                    1. Bonjur !

                      Normalmo j'ai utilisè le parefeu windows pardefaux - est-ce que ce n'ete pas asser?

                      Et en fin voilà le rapporte Hijack :

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 9:44:25, on 27/04/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\CTsvcCDA.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                      C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
                      C:\Program Files\Winamp\winampa.exe
                      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\WINDOWS\SOUNDMAN.EXE
                      C:\WINDOWS\System32\WLTRAY.exe
                      C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\WINDOWS\system32\LVCOMSX.EXE
                      C:\WINDOWS\System32\nvsvc32.exe
                      C:\Program Files\Logitech\Video\LogiTray.exe
                      C:\WINDOWS\system32\IoctlSvc.exe
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                      C:\WINDOWS\system32\slserv.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                      C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe
                      C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                      C:\Program Files\WinZip\WZQKPICK.EXE
                      C:\WINDOWS\system32\MsPMSPSv.exe
                      C:\Program Files\Logitech\Video\FxSvr2.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
                      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                      O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
                      O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
                      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                      O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [U.S. Robotics Wireless Manager UI] C:\WINDOWS\System32\WLTRAY
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
                      O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                      O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
                      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
                      O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                      O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
                      O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
                      O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe"
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\cdas50.exe" /minimize
                      O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
                      O4 - HKCU\..\Run: [Creative MediaSource Go] "C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe" /SCB
                      O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\microsoft office\Office\OSA9.EXE
                      O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
                      O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O14 - IERESET.INF: START_PAGE_URL=https://www.proximus.be/pickx
                      O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) -
                      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                      O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
                      O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                      O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
                      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                      O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
                      O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                      0
                      1. Bonjur !

                        Normalmo j'ai utilisè le parefeu windows pardefaux - est-ce que ce n'ete pas asser?

                        Et en fin voilà le rapporte Hijack :

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 9:44:25, on 27/04/2008
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\CTsvcCDA.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
                        C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                        C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
                        C:\Program Files\Winamp\winampa.exe
                        C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                        C:\WINDOWS\SOUNDMAN.EXE
                        C:\WINDOWS\System32\WLTRAY.exe
                        C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\WINDOWS\system32\LVCOMSX.EXE
                        C:\WINDOWS\System32\nvsvc32.exe
                        C:\Program Files\Logitech\Video\LogiTray.exe
                        C:\WINDOWS\system32\IoctlSvc.exe
                        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                        C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                        C:\WINDOWS\system32\slserv.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe
                        C:\Program Files\Windows Media Player\WMPNSCFG.exe
                        C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                        C:\Program Files\WinZip\WZQKPICK.EXE
                        C:\WINDOWS\system32\MsPMSPSv.exe
                        C:\Program Files\Logitech\Video\FxSvr2.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\Program Files\Kerio\Personal Firewall 4\kpf4gui.exe
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
                        O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                        O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
                        O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
                        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                        O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [U.S. Robotics Wireless Manager UI] C:\WINDOWS\System32\WLTRAY
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
                        O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                        O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
                        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
                        O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                        O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
                        O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
                        O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe"
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\cdas50.exe" /minimize
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
                        O4 - HKCU\..\Run: [Creative MediaSource Go] "C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe" /SCB
                        O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\microsoft office\Office\OSA9.EXE
                        O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                        O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
                        O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O14 - IERESET.INF: START_PAGE_URL=https://www.proximus.be/pickx
                        O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) -
                        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                        O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall 4\kpf4ss.exe
                        O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                        O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
                        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                        O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                        O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
                        O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                        0
                        1. Et le rapporte de hijackThis:

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 2:43:44, on 27/04/2008
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\system32\CTsvcCDA.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                          C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\System32\nvsvc32.exe
                          C:\WINDOWS\system32\IoctlSvc.exe
                          C:\WINDOWS\system32\slserv.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                          C:\WINDOWS\system32\MsPMSPSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\WINDOWS\system32\notepad.exe
                          C:\Program Files\Winamp\winampa.exe
                          C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          C:\WINDOWS\SOUNDMAN.EXE
                          C:\WINDOWS\System32\WLTRAY.exe
                          C:\Program Files\QuickTime\qttask.exe
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\WINDOWS\system32\LVCOMSX.EXE
                          C:\Program Files\Logitech\Video\LogiTray.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                          C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe
                          C:\Program Files\Windows Media Player\WMPNSCFG.exe
                          C:\Program Files\WinZip\WZQKPICK.EXE
                          C:\Documents and Settings\andrei\Local Settings\Application Data\YouTube\Uploader\youtubeuploader.exe
                          C:\Program Files\Logitech\Video\FxSvr2.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll
                          O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                          O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
                          O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
                          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                          O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [U.S. Robotics Wireless Manager UI] C:\WINDOWS\System32\WLTRAY
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
                          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                          O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                          O4 - HKLM\..\Run: [StopSignSsTsMon] "Rundll32.exe" "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
                          O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
                          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
                          O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                          O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
                          O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
                          O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe"
                          O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [CyberDefender Early Detection Center] "C:\Program Files\CyberDefender\AntiSpyware\cdas50.exe" /minimize
                          O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
                          O4 - HKCU\..\Run: [Creative MediaSource Go] "C:\Program Files\Creative\MediaSource\Go\CTCMSGo.exe" /SCB
                          O4 - HKCU\..\Run: [owlzbdtb] C:\WINDOWS\system32\rypujmlq.exe
                          O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
                          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                          O4 - Startup: YouTube Uploader.lnk = C:\Documents and Settings\andrei\Local Settings\Application Data\YouTube\Uploader\youtubeuploader.exe
                          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\microsoft office\Office\OSA9.EXE
                          O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
                          O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O14 - IERESET.INF: START_PAGE_URL=https://www.proximus.be/pickx
                          O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) -
                          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
                          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                          O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                          O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
                          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                          O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\FICHIE~1\SONYSH~1\AVLib\Sptisrv.exe
                          O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                          0
                          1. re

                            1/pas de parefeu ! installe kério ici :
                            http://kerio.probb.fr/logiciels-et-tutoriels-f6/tutoriel-sunbelt-personal-firewall-45916-ex-kerio-t248.htm
                            suis le instructions pour le configurer

                            2/maintenant relance hijack et clic sur do a scan only, coche ces lignes puis clic sur fix

                            -C:\Documents and Settings\andrei\Local Settings\Application Data\YouTube\Uploader\youtubeuploader.exe
                            -O4 - HKLM\..\Run: [StopSignSsTsMon] "Rundll32.exe" "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
                            -O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
                            -O4 - HKCU\..\Run: [owlzbdtb] C:\WINDOWS\system32\rypujmlq.exe
                            -O4 - Startup: YouTube Uploader.lnk = C:\Documents and Settings\andrei\Local Settings\Application Data\YouTube\Uploader\youtubeuploader.exe

                            3/ redemarre ton pc et reposte 1 nouvel hijack

                            apres tout ça , je matte tout ça taleur , car hs

                            bises et bonne nuit
                            0
                        2. Voici deja le rapport de SDFix:
                          Je vais commanser le scane avec Hijackthis, mais je ne pas compris que c'est que je dois fair avec le derniere deux lien de paqeperso et cybersecuriti - auci fair le scaning ?
                          Merci!

                          [b]SDFix: Version 1.175 [/b]
                          Run by andrei on dim. 27/04/2008 at 01:58

                          Microsoft Windows XP [version 5.1.2600]
                          Running From: C:\DOCUME~1\andrei\Bureau\SDFix\SDFix

                          [b]Checking Services [/b]:

                          Restoring Windows Registry Values
                          Restoring Windows Default Hosts File

                          Rebooting

                          [b]Checking Files [/b]:

                          Trojan Files Found:

                          C:\Documents and Settings\andrei\Local Settings\Temp\aax77.tmp.exe - Deleted
                          C:\Documents and Settings\andrei\Local Settings\Temp\aax9D.tmp.exe - Deleted
                          C:\Documents and Settings\andrei\Local Settings\Temp\aaxF.tmp.exe - Deleted

                          Removing Temp Files

                          [b]ADS Check [/b]:

                          [b]Final Check [/b]:

                          catchme 0.3.1353.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2008-04-27 02:18:17
                          Windows 5.1.2600 Service Pack 2 NTFS

                          scanning hidden processes ...

                          scanning hidden services & system hive ...

                          scanning hidden registry entries ...

                          scanning hidden files ...

                          scan completed successfully
                          hidden processes: 0
                          hidden services: 0
                          hidden files: 0

                          [b]Remaining Services [/b]:

                          Authorized Application Key Export:

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                          "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
                          "C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
                          "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                          "C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
                          "C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Ex‚cuter une DLL en tant qu'application"
                          "C:\\Program Files\\ICQ6\\ICQ.exe"="C:\\Program Files\\ICQ6\\ICQ.exe:*:Enabled:ICQ6"
                          "C:\\Program Files\\Real\\RealOne Player\\realplay.exe"="C:\\Program Files\\Real\\RealOne Player\\realplay.exe:*:Enabled:RealOne Player"
                          "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
                          "C:\\Program Files\\Fichiers communs\\Ahead\\Nero Web\\SetupX.exe"="C:\\Program Files\\Fichiers communs\\Ahead\\Nero Web\\SetupX.exe:*:Enabled:Nero ProductSetup"
                          "C:\\Documents and Settings\\andrei\\Local Settings\\Temp\\Nero Web\\SetupXu.exe"="C:\\Documents and Settings\\andrei\\Local Settings\\Temp\\Nero Web\\SetupXu.exe:*:Enabled:Nero ProductSetup"
                          "C:\\Program Files\\Fichiers communs\\Nero\\Nero Web\\SetupX.exe"="C:\\Program Files\\Fichiers communs\\Nero\\Nero Web\\SetupX.exe:*:Enabled:Nero ControlCenter"
                          "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
                          "C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
                          "C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
                          "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

                          [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                          "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                          "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

                          [b]Remaining Files [/b]:

                          File Backups: - C:\DOCUME~1\andrei\Bureau\SDFix\SDFix\backups\backups.zip

                          [b]Files with Hidden Attributes [/b]:

                          Sun 29 May 2005 193 A.SHR --- "C:\BOOT.BAK"
                          Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
                          Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
                          Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
                          Fri 30 Aug 2002 57,344 A..HR --- "C:\WINDOWS\system32\sol.exe"
                          Sun 22 Jul 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
                          Tue 17 Oct 2006 304,736 A..H. --- "C:\Program Files\Canon\MP Navigator 3.0\Maint.exe"
                          Tue 17 Oct 2006 61,440 A..H. --- "C:\Program Files\Canon\MP Navigator 3.0\uinstrsc.dll"
                          Thu 18 Jan 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
                          Sun 19 Nov 2006 624,640 ...H. --- "C:\Documents and Settings\andrei\Application Data\Microsoft\Word\~WRL0221.tmp"
                          Sun 7 May 2006 1,699,840 ...H. --- "C:\Documents and Settings\andrei\Application Data\Microsoft\Word\~WRL1598.tmp"
                          Sun 19 Nov 2006 620,544 ...H. --- "C:\Documents and Settings\andrei\Application Data\Microsoft\Word\~WRL1698.tmp"
                          Fri 17 Nov 2006 638,976 ...H. --- "C:\Documents and Settings\andrei\Application Data\Microsoft\Word\~WRL2793.tmp"

                          [b]Finished![/b]
                          0
                          • 1
                          • 2