Virus malware

Bonjour,
j'ai attrapper un virus aujourd'hui je crois du moins et j'ai essayer de m'en débarasser avec les conaissance que j'ai mais sa n'a rien donner j'ai plein de page d'antiviruse qui s'ouvre et des pages de cul aussi c'est vraiment fatiguant quand tu te trouve sur internet tes couper au 10 seconde bon j'ai faite marcher mon anti virus antivir personnalEdition classic
voici le raport :
Avira AntiVir Personal
Report file date: 7 mai 2008 16:36

Scanning for 1255113 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: Administrateur
Computer name: USER_AUTO

Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 2008-04-09 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 2008-04-16 13:16:22
AVSCAN.DLL : 8.1.1.0 53505 Bytes 2008-04-16 13:16:22
LUKE.DLL : 8.1.2.9 151809 Bytes 2008-04-16 13:16:23
LUKERES.DLL : 8.1.2.1 12033 Bytes 2008-04-16 13:16:23
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 2007-07-18 19:27:15
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 2008-03-07 03:29:50
ANTIVIR2.VDF : 7.0.4.0 1554432 Bytes 2008-05-05 13:09:07
ANTIVIR3.VDF : 7.0.4.12 50688 Bytes 2008-05-07 13:08:38
Engineversion : 8.1.0.37
AEVDF.DLL : 8.1.0.5 102772 Bytes 2008-04-16 13:16:24
AESCRIPT.DLL : 8.1.0.28 233851 Bytes 2008-04-30 13:12:35
AESCN.DLL : 8.1.0.15 119157 Bytes 2008-04-30 13:12:34
AERDL.DLL : 8.1.0.20 418165 Bytes 2008-04-25 13:11:25
AEPACK.DLL : 8.1.1.4 364918 Bytes 2008-04-29 13:12:22
AEOFFICE.DLL : 8.1.0.18 192890 Bytes 2008-04-18 13:12:57
AEHEUR.DLL : 8.1.0.21 1196407 Bytes 2008-04-30 13:12:33
AEHELP.DLL : 8.1.0.14 115063 Bytes 2008-04-18 13:12:48
AEGEN.DLL : 8.1.0.18 299381 Bytes 2008-04-25 13:11:22
AEEMU.DLL : 8.1.0.5 430450 Bytes 2008-04-16 13:16:24
AECORE.DLL : 8.1.0.27 168310 Bytes 2008-04-18 13:12:33
AVWINLL.DLL : 1.0.0.7 14593 Bytes 2008-04-16 13:16:22
AVPREF.DLL : 8.0.0.1 25857 Bytes 2008-04-16 13:16:22
AVREP.DLL : 7.0.0.1 155688 Bytes 2007-04-16 18:16:24
AVREG.DLL : 8.0.0.0 30977 Bytes 2008-04-16 13:16:22
AVARKT.DLL : 1.0.0.23 307457 Bytes 2008-04-16 13:16:21
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 2008-04-16 13:16:21
SQLITE3.DLL : 3.3.17.1 339968 Bytes 2008-04-16 13:16:24
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 2008-04-16 13:16:24
NETNT.DLL : 8.0.0.1 7937 Bytes 2008-04-16 13:16:23
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 2008-04-16 13:16:18
RCTEXT.DLL : 8.0.32.0 86273 Bytes 2008-04-16 13:16:18

Configuration settings for the scan:
Jobname..........................: Local Drives
Configuration file...............: c:\program files\avira\antivir personaledition classic\alldrives.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, A:, E:, D:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: All files
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: 7 mai 2008 16:36

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
Scan process 'iPodService.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'kpf4ss.exe' - '1' Module(s) have been scanned
Scan process 'SMAgent.exe' - '1' Module(s) have been scanned
Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
Scan process 'Brmfrmps.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'SPUVolumeWatcher.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'VirusHeat 4.4.exe' - '1' Module(s) have been scanned
Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
Scan process 'sbsm.exe' - '1' Module(s) have been scanned
Scan process 'scm.exe' - '1' Module(s) have been scanned
Scan process 'reader_sl.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
Scan process 'igfxtray.exe' - '1' Module(s) have been scanned
Scan process 'sbmntr.exe' - '1' Module(s) have been scanned
Scan process 'scit.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'brss01a.exe' - '1' Module(s) have been scanned
Scan process 'brsvc01a.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
45 processes with 45 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
[WARNING] Le périphérique n'est pas prêt.

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'A:\'
[INFO] In the drive 'A:\' no data medium is inserted!
Boot sector 'E:\'
[INFO] In the drive 'E:\' no data medium is inserted!

Starting to scan the registry.
The registry was scanned ( '31' files ).

Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\527631\527631.dll
[DETECTION] Is the Trojan horse TR/BHO.DM
[NOTE] The file was deleted!
Begin scan in 'A:\'
Search path A:\ could not be opened!
Le périphérique n'est pas prêt.

Begin scan in 'E:\'
Search path E:\ could not be opened!
Le périphérique n'est pas prêt.

Begin scan in 'D:\'
Search path D:\ could not be opened!
Le périphérique n'est pas prêt.

End of the scan: 7 mai 2008 17:32
Used time: 56:29 min

The scan has been done completely.

5389 Scanning directories
213547 Files were scanned
1 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
1 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
213546 Files not concerned
964 Archives were scanned
2 Warnings
1 Notes

j'ai aussi fait un scan avec hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:58:06, on 2008-05-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\NetProject\scit.exe
C:\Program Files\NetProject\sbmntr.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\NetProject\scm.exe
C:\Program Files\NetProject\sbsm.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Documents and Settings\Administrateur\Mes documents\marie\kpf4ss.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Administrateur\Mes documents\marie\kpf4gui.exe
C:\Documents and Settings\Administrateur\Mes documents\marie\kpf4gui.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Administrateur\Mes documents\marie\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = https://internetsearchservice.com/
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = https://internetsearchservice.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://internetsearchservice.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://internetsearchservice.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://internetsearchservice.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://internetsearchservice.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://internetsearchservice.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://internetsearchservice.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: 527631 helper - {54160F28-994B-48DD-8D83-1B2F6B9EB054} - C:\WINDOWS\system32\527631\527631.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - C:\Program Files\NetProject\sbmdl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [PKR Pal] "C:\Program Files\PKR\pkrpal.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Hope Draw Obj Funk] C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW\01 admin.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [cdrom vga] C:\DOCUME~1\ADMINI~1\APPLIC~1\REALDA~1\Film each.exe
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe
O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\NetProject\sbmntr.exe
O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.getietool.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.getietool.com/redirect.php (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://buffy.en.musique.free.fr
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O22 - SharedTaskScheduler: delayingly - {e89fa8e9-5c0b-45f6-a70e-f7b177bcd193} - C:\WINDOWS\system32\rtmipr.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Documents and Settings\Administrateur\Mes documents\marie\kpf4ss.exe

--
End of file - 8987 bytes

je sais pas si vous pouvez m'aider du moins jespere ;) merci
Configuration: Windows XP
Internet Explorer 7.0

31 réponses

Résumé de la discussion

Infection potentielle détectée sur un poste Windows XP avec des fenêtres intrusives et des pages web non désirées, apparaissant après des symptômes de ralentissement et de navigation perturbée. L'analyse Avira AntiVir PersonalEdition Classic a détecté un seul élément malveillant et en a supprimé un fichier; le rapport évoque notamment le Trojan TR/BHO.DM et des modules associés. Le journal HijackThis révèle de nombreuses entrées suspectes dans les clés de registre et des programmes au démarrage, incluant des composants liés à des barres d'outils, des services et des DLL. Des éléments supplémentaires indiquent des redirections de recherche et des composants Google Updater, iPod et Adobe, suggérant une infection multi-composants nécessitant une démarche de nettoyage approfondie sans indication claire de résolution.

Bobot (l’IA à votre service)
  1. rapport virtumonde :

    [05/09/2008, 19:28:48] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Administrateur\Bureau\VirtumundoBeGone.exe" )
    [05/09/2008, 19:28:59] - Detected System Information:
    [05/09/2008, 19:28:59] - Windows Version: 5.1.2600, Service Pack 2
    [05/09/2008, 19:28:59] - Current Username: Administrateur (Admin)
    [05/09/2008, 19:28:59] - Windows is in NORMAL mode.
    [05/09/2008, 19:28:59] - Searching for Browser Helper Objects:
    [05/09/2008, 19:28:59] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
    [05/09/2008, 19:28:59] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
    [05/09/2008, 19:28:59] - BHO 3: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Programme d'aide de l'Assistant de connexion Windows Live)
    [05/09/2008, 19:28:59] - BHO 4: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
    [05/09/2008, 19:28:59] - BHO 5: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
    [05/09/2008, 19:28:59] - Finished Searching Browser Helper Objects
    [05/09/2008, 19:28:59] - Finishing up...
    [05/09/2008, 19:28:59] - Nothing found! Exiting...

    [05/09/2008, 19:30:01] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Administrateur\Bureau\VirtumundoBeGone.exe" )
    [05/09/2008, 19:30:16] - Detected System Information:
    [05/09/2008, 19:30:16] - Windows Version: 5.1.2600, Service Pack 2
    [05/09/2008, 19:30:16] - Current Username: Administrateur (Admin)
    [05/09/2008, 19:30:16] - Windows is in NORMAL mode.
    [05/09/2008, 19:30:16] - Searching for Browser Helper Objects:
    [05/09/2008, 19:30:16] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
    [05/09/2008, 19:30:16] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
    [05/09/2008, 19:30:17] - BHO 3: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Programme d'aide de l'Assistant de connexion Windows Live)
    [05/09/2008, 19:30:17] - BHO 4: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
    [05/09/2008, 19:30:17] - BHO 5: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
    [05/09/2008, 19:30:17] - Finished Searching Browser Helper Objects
    [05/09/2008, 19:30:17] - Finishing up...
    [05/09/2008, 19:30:17] - Nothing found! Exiting...

    rapport hijackthis :

    Logfile of HijackThis v1.99.1
    Scan saved at 19:33:39, on 2008-05-09
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16640)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\brsvc01a.exe
    C:\WINDOWS\system32\brss01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\Brmfrmps.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
    C:\Program Files\iPod\bin\iPodService.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/?gws_rd=ssl
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [Hope Draw Obj Funk] C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW\01 admin.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [cdrom vga] C:\DOCUME~1\ADMINI~1\APPLIC~1\REALDA~1\Film each.exe
    O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
    O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O15 - Trusted Zone: http://buffy.en.musique.free.fr
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    0
    1. je sais pas si tu voulais le rapport de défragmentation donc je te le laisse :

      Volume (C:)
      Taille du volume = 36,16 Go
      Taille de cluster = 4 Ko
      Espace utilisé = 19,86 Go
      Espace libre = 16,30 Go
      Pourcentage d'espace libre = 45 %

      Fragmentation du volume
      Fragmentation totale = 0 %
      Fragmentation de fichiers = 0 %
      Fragmentation de l'espace libre = 0 %

      Fragmentation de fichiers
      Total de fichiers = 39 462
      Taille moyenne de fichier = 695 Ko
      Total de fichiers fragmentés = 2
      Total de fragments en trop = 402
      Nombre moyen de fragments par fichier = 1,01

      Fragmentation du fichier paginé
      Taille du fichier paginé = 384 Mo
      Total de fragments = 1

      Fragmentation de dossier
      Total de dossiers = 5 136
      Dossiers fragmentés = 1
      Fragments de dossiers en trop = 0

      Fragmentation de la table de fichiers principale (MFT)
      Taille totale de la MFT = 73 Mo
      Nombre d'enregistrements dans la MFT = 44 685
      Pourcentage d'utilisation de la MFT = 59 %
      Total de fragments dans la MFT = 2

      --------------------------------------------------------------------------------
      Fragments Taille du fichierFichiers qui ne peuvent pas être défragmentés
      Aucun
      0
      1. ok et ta pas passé virtumonde ? mets le rapport aussi de ça stp

        bizz
        0
    2. je l'ai déja c'est juste une abitude d'aller sur IEje vais essayer de me réabituer avec firefox
      0
      1. ok ben oui tu n'a aimé firefox ou quoi ^^

        lance ceci stp :
        Télécharge VirtumundoBegone sur le bureau:
        http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

        Double clique ensuite sur VirtumundoBeGone.exe et suis les instructions.
        Une fois terminé, redémarre et poste le rapport VBG.TXT créé sur le bureau dans ta prochaine réponse avec un nouveau rapport HijackThis.

        Ne t'inquiète pas si tu vois un message Ecran bleu "Erreur fatale", c'est normal et attendu

        op au boulot ^^

        bizz
        0
    3. re

      défragmenter: démarer > tous les prog > accessoires > outils systeme>défragmenteur de disque

      passe Ccleaner souvent

      aussi en gardant internet explo biensur ,télécharge firefox ici :

      http://www.mozilla-europe.org/fr/products/firefox/

      teste le et tu sera au paradis ^^ si cela te convient pas malgés qu'il soit ++++ sur de surfer par là dis moi ok mais please teste le ,tu risque rien , t'en fait pas

      bises
      0
      1. ouais j'ai ccleaner et je navigue avec IE
        comment on fait une défragmentation?
        pour ce qui est des logiciel j'ai mieu pas toucher a ceux que je connais pas lol les autres je les utilise généralement
        0
        1. bon en faite ça plutot l'air de s'arranger j'ai plus de fenetre qui s'ouvre et j'ai pu tout plein d'anti virus qui s'installe automatique mais la mon ordi est lente vraiment lente
          0
          1. salut

            bon on avance alors

            as tu ccleaner ?

            tu navigue avec IE ou autre ?

            faire 1 défragmentation serait bien + regarde dans ajout/sup programes et vire les logiciels qui te serve a rien et bouffe de la place .....

            bises
            0
        2. sinon je sais pas si sa peu etre utile mais j'ai fait un analyse avec AVG anti spyware voici le raport :
          ---------------------------------------------------------
          AVG Anti-Spyware - Rapport d'analyse
          ---------------------------------------------------------

          + Créé à: 18:33:56 2008-05-08

          + Résultat de l'analyse:

          C:\Program Files\AntiSpywareShield\AntiSpywareShield0.dll -> Adware.BraveSentry : Ignoré.
          C:\Program Files\AntiSpywareShield\AntiSpywareShield1.dll -> Adware.BraveSentry : Ignoré.
          C:\Program Files\AntiSpywareShield\AntiSpywareShield3.dll -> Adware.BraveSentry : Ignoré.
          C:\System Volume Information\_restore{BFEE5266-B250-43AF-9BC5-128465A384FE}\RP43\A0003340.dll -> Adware.BraveSentry : Ignoré.
          C:\System Volume Information\_restore{BFEE5266-B250-43AF-9BC5-128465A384FE}\RP43\A0003341.dll -> Adware.BraveSentry : Ignoré.
          C:\System Volume Information\_restore{BFEE5266-B250-43AF-9BC5-128465A384FE}\RP43\A0003342.dll -> Adware.BraveSentry : Ignoré.
          C:\System Volume Information\_restore{BFEE5266-B250-43AF-9BC5-128465A384FE}\RP43\A0003366.dll -> Adware.BraveSentry : Ignoré.
          C:\System Volume Information\_restore{BFEE5266-B250-43AF-9BC5-128465A384FE}\RP43\A0003370.dll -> Adware.BraveSentry : Ignoré.
          C:\System Volume Information\_restore{BFEE5266-B250-43AF-9BC5-128465A384FE}\RP43\A0003371.dll -> Adware.BraveSentry : Ignoré.
          [3716] C:\Program Files\AntiSpywareShield\AntiSpywareShield1.dll -> Adware.BraveSentry : Ignoré.
          C:\Program Files\AntiSpywareShield\AntiSpywareShield0.ad -> Adware.DrAntispy : Ignoré.
          C:\System Volume Information\_restore{BFEE5266-B250-43AF-9BC5-128465A384FE}\RP42\A0002158.dll -> Not-A-Virus.Adware.E404 : Ignoré.
          C:\VundoFix Backups\ljjkige.dll.bad -> Not-A-Virus.Adware.Virtumonde : Ignoré.
          C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\2DDDQ79W\install_en[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.au : Ignoré.
          C:\Documents and Settings\Administrateur\Application Data\Sun\Java\Deployment\cache\6.0\39\2b76b6a7-36a6ae56 -> Not-A-Virus.ExploitByteVerify : Ignoré.
          C:\Documents and Settings\Administrateur\Application Data\Sun\Java\Deployment\cache\6.0\49\7a6af5f1-75c5163a -> Not-A-Virus.ExploitByteVerify : Ignoré.
          :mozilla.56:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\4f8wq8wa.default\cookies.txt -> TrackingCookie.2o7 : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@3.adbrite[1].txt -> TrackingCookie.Adbrite : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@adbrite[1].txt -> TrackingCookie.Adbrite : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@stats.adbrite[1].txt -> TrackingCookie.Adbrite : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@rotator.adjuggler[2].txt -> TrackingCookie.Adjuggler : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@rotator.dex.adjuggler[2].txt -> TrackingCookie.Adjuggler : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@www.adobe[2].txt -> TrackingCookie.Adobe : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@adrevolver[2].txt -> TrackingCookie.Adrevolver : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@media.adrevolver[2].txt -> TrackingCookie.Adrevolver : Ignoré.
          :mozilla.25:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\4f8wq8wa.default\cookies.txt -> TrackingCookie.Atdmt : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@atdmt[2].txt -> TrackingCookie.Atdmt : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@www.belstat[1].txt -> TrackingCookie.Belstat : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@bluestreak[1].txt -> TrackingCookie.Bluestreak : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@dbbsrv[1].txt -> TrackingCookie.Dbbsrv : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@dealtime[1].txt -> TrackingCookie.Dealtime : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@stat.dealtime[2].txt -> TrackingCookie.Dealtime : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@estat[1].txt -> TrackingCookie.Estat : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@fastclick[1].txt -> TrackingCookie.Fastclick : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@findwhat[1].txt -> TrackingCookie.Findwhat : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@hit.gemius[1].txt -> TrackingCookie.Gemius : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@searchportal.information[2].txt -> TrackingCookie.Information : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@server.iad.liveperson[3].txt -> TrackingCookie.Liveperson : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@image.masterstats[1].txt -> TrackingCookie.Masterstats : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@overture[2].txt -> TrackingCookie.Overture : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@revenue[2].txt -> TrackingCookie.Revenue : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@revsci[1].txt -> TrackingCookie.Revsci : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@serving-sys[2].txt -> TrackingCookie.Serving-sys : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@counter9.sextracker[1].txt -> TrackingCookie.Sextracker : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@sextracker[2].txt -> TrackingCookie.Sextracker : Ignoré.
          :mozilla.58:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\4f8wq8wa.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.
          :mozilla.59:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\4f8wq8wa.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.
          :mozilla.60:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\4f8wq8wa.default\cookies.txt -> TrackingCookie.Smartadserver : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@smartadserver[1].txt -> TrackingCookie.Smartadserver : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@statcounter[1].txt -> TrackingCookie.Statcounter : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@tacoda[2].txt -> TrackingCookie.Tacoda : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@login.tracking101[1].txt -> TrackingCookie.Tracking101 : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@trafficmp[1].txt -> TrackingCookie.Trafficmp : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Ignoré.
          :mozilla.61:C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\4f8wq8wa.default\cookies.txt -> TrackingCookie.Weborama : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@free.wegcash[2].txt -> TrackingCookie.Wegcash : Ignoré.
          C:\Documents and Settings\Administrateur\Cookies\administrateur@xxxcounter[1].txt -> TrackingCookie.Xxxcounter : Ignoré.

          Fin du rapport

          1
          1. bravo!!!!!!!!!!!! jtai mis du jaune^^ bonne initiative +++++deta part je matte apres g vu engros mais occupée ,jereviens

            biz
            0
        3. je suis du québec c'est peut etre pour sa que ça marque 17:35 il est seulement 18:30 la
          0
          1. en revoila un nouveau :
            Logfile of HijackThis v1.99.1
            Scan saved at 18:21:35, on 2008-05-08
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16640)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\brsvc01a.exe
            C:\WINDOWS\system32\brss01a.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            C:\Program Files\NetProject\scit.exe
            C:\Program Files\NetProject\sbmntr.exe
            C:\WINDOWS\system32\igfxtray.exe
            C:\WINDOWS\system32\hkcmd.exe
            C:\Program Files\NetProject\sbsm.exe
            C:\Program Files\NetProject\scm.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\WINDOWS\system32\Brmfrmps.exe
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
            C:\Documents and Settings\Administrateur\Mes documents\marie\kpf4ss.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\Documents and Settings\Administrateur\Mes documents\marie\kpf4gui.exe
            C:\Documents and Settings\Administrateur\Mes documents\marie\kpf4gui.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\iTunes\iTunes.exe
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\distnoted.exe
            C:\WINDOWS\system32\sol.exe
            C:\WINDOWS\system32\cisvc.exe
            C:\WINDOWS\system32\cidaemon.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
            C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
            C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

            R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = https://internetsearchservice.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = https://internetsearchservice.com/
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://internetsearchservice.com/
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://internetsearchservice.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://internetsearchservice.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://internetsearchservice.com/
            R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://internetsearchservice.com/
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://internetsearchservice.com/
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: 527631 helper - {54160F28-994B-48DD-8D83-1B2F6B9EB054} - C:\WINDOWS\system32\527631\527631.dll (file missing)
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - C:\Program Files\NetProject\sbmdl.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKLM\..\Run: [PKR Pal] "C:\Program Files\PKR\pkrpal.exe" -osboot
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
            O4 - HKLM\..\Run: [Hope Draw Obj Funk] C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW\01 admin.exe
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [cdrom vga] C:\DOCUME~1\ADMINI~1\APPLIC~1\REALDA~1\Film each.exe
            O4 - HKCU\..\Run: [AntiSpywareShield] C:\Program Files\AntiSpywareShield\AntiSpywareShield.exe
            O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
            O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
            O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
            O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.getietool.com/redirect.php (file missing)
            O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.getietool.com/redirect.php (file missing)
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O11 - Options group: [INTERNATIONAL] International*
            O15 - Trusted Zone: http://buffy.en.musique.free.fr
            O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
            O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
            O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
            O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
            O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
            O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
            O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
            O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Documents and Settings\Administrateur\Mes documents\marie\Ares\chatServer.exe
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
            O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
            O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
            O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Documents and Settings\Administrateur\Mes documents\marie\kpf4ss.exe

            0
            1. re

              ton rapport est de 17h35 ,ta pas 1 tout nouveau,allez ca dur 1 mn ^^
              0
              1. bon ok le raport hijackthis :

                --Logfile of HijackThis v1.99.1
                Scan saved at 17:37:08, on 2008-05-08
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16640)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\brsvc01a.exe
                C:\WINDOWS\system32\brss01a.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                C:\Program Files\NetProject\scit.exe
                C:\Program Files\NetProject\sbmntr.exe
                C:\WINDOWS\system32\igfxtray.exe
                C:\WINDOWS\system32\hkcmd.exe
                C:\Program Files\NetProject\sbsm.exe
                C:\Program Files\NetProject\scm.exe
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\AntiSpywareShield\AntiSpywareShield.exe
                C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\WINDOWS\system32\Brmfrmps.exe
                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                C:\Documents and Settings\Administrateur\Mes documents\marie\kpf4ss.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\iPod\bin\iPodService.exe
                C:\Documents and Settings\Administrateur\Mes documents\marie\kpf4gui.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Documents and Settings\Administrateur\Mes documents\marie\kpf4gui.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\Program Files\iTunes\iTunes.exe
                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe
                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\distnoted.exe
                C:\WINDOWS\system32\sol.exe
                C:\Documents and Settings\Administrateur\Bureau\VundoFix.exe
                C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

                R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = https://internetsearchservice.com/
                R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = https://internetsearchservice.com/
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://internetsearchservice.com/
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://internetsearchservice.com/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://internetsearchservice.com/
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://internetsearchservice.com/
                R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://internetsearchservice.com/
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://internetsearchservice.com/
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: 527631 helper - {54160F28-994B-48DD-8D83-1B2F6B9EB054} - C:\WINDOWS\system32\527631\527631.dll (file missing)
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - C:\Program Files\NetProject\sbmdl.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                O4 - HKLM\..\Run: [PKR Pal] "C:\Program Files\PKR\pkrpal.exe" -osboot
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                O4 - HKLM\..\Run: [Hope Draw Obj Funk] C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW\01 admin.exe
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [cdrom vga] C:\DOCUME~1\ADMINI~1\APPLIC~1\REALDA~1\Film each.exe
                O4 - HKCU\..\Run: [AntiSpywareShield] C:\Program Files\AntiSpywareShield\AntiSpywareShield.exe
                O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
                O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
                O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.getietool.com/redirect.php (file missing)
                O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.getietool.com/redirect.php (file missing)
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O11 - Options group: [INTERNATIONAL] International*
                O15 - Trusted Zone: http://buffy.en.musique.free.fr
                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
                O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                O20 - Winlogon Notify: WgaLogon - WgaLogon.dll (file missing)
                O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Documents and Settings\Administrateur\Mes documents\marie\Ares\chatServer.exe
                O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
                O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
                O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Documents and Settings\Administrateur\Mes documents\marie\kpf4ss.exe

                mais je vois pas grand changement en faite sauf que j'arrive plus a aller sur mon site préférer lol

                Seul dieu le sait mais le diable s'en doute 
                L'enfer est paver de bonne intension
                Etre ather c'est accepter tout et tout le monde, etre croyant c'est ce couper du reste du monde 
                0
                1. ben je vien de redémarrer la est ce que je doit relancer vundofix la je sais plus la lol
                  0
                  1. lol tu peux ca coute rien ^^ sinon dis moi si tu vois des changements ou pas + 1 nouveau rapport hijack stp ,

                    bizz
                    0
                2. le raport de vundofix:

                  VundoFix V7.0.3

                  Scan started at 02:09:50 2008-03-25

                  Listing files found while scanning....

                  C:\windows\system32\ddayx.dll
                  C:\WINDOWS\system32\ljjkige.dll
                  C:\windows\system32\qpqss.ini
                  C:\windows\system32\qpqss.ini2
                  C:\windows\system32\ssqpq.dll
                  C:\windows\system32\xyadd.ini
                  C:\windows\system32\xyadd.ini2

                  Beginning removal...

                  Attempting to delete C:\windows\system32\ddayx.dll
                  C:\windows\system32\ddayx.dll Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\ljjkige.dll
                  C:\WINDOWS\system32\ljjkige.dll Could not be deleted.

                  Attempting to delete C:\windows\system32\qpqss.ini
                  C:\windows\system32\qpqss.ini Has been deleted!

                  Attempting to delete C:\windows\system32\qpqss.ini2
                  C:\windows\system32\qpqss.ini2 Has been deleted!

                  Attempting to delete C:\windows\system32\ssqpq.dll
                  C:\windows\system32\ssqpq.dll Has been deleted!

                  Attempting to delete C:\windows\system32\xyadd.ini
                  C:\windows\system32\xyadd.ini Has been deleted!

                  Attempting to delete C:\windows\system32\xyadd.ini2
                  C:\windows\system32\xyadd.ini2 Has been deleted!

                  Performing Repairs to the registry.
                  Done!

                  Beginning removal...

                  Performing Repairs to the registry.
                  Done!

                  VundoFix V7.0.3

                  Scan started at 11:57:09 2008-03-25

                  Listing files found while scanning....

                  No infected files were found.

                  VundoFix V7.0.3

                  Scan started at 12:29:14 2008-03-25

                  Listing files found while scanning....

                  No infected files were found.

                  VundoFix V7.0.3

                  Scan started at 22:33:27 2008-03-26

                  Listing files found while scanning....

                  No infected files were found.

                  VundoFix V7.0.3

                  Scan started at 11:04:00 2008-03-29

                  Listing files found while scanning....

                  No infected files were found.

                  Beginning removal...

                  VundoFix V7.0.3

                  Scan started at 13:33:38 2008-03-29

                  Listing files found while scanning....

                  C:\windows\system32\ddayx.dll
                  C:\WINDOWS\system32\ljjkige.dll
                  C:\windows\system32\vtutq.dll
                  C:\windows\system32\xyadd.ini
                  C:\windows\system32\xyadd.ini2

                  Beginning removal...

                  Attempting to delete C:\windows\system32\ddayx.dll
                  C:\windows\system32\ddayx.dll Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\ljjkige.dll
                  C:\WINDOWS\system32\ljjkige.dll Could not be deleted.

                  Attempting to delete C:\windows\system32\vtutq.dll
                  C:\windows\system32\vtutq.dll Could not be deleted.

                  Attempting to delete C:\windows\system32\xyadd.ini
                  C:\windows\system32\xyadd.ini Has been deleted!

                  Attempting to delete C:\windows\system32\xyadd.ini2
                  C:\windows\system32\xyadd.ini2 Has been deleted!

                  Performing Repairs to the registry.
                  Done!

                  Beginning removal...

                  Attempting to delete C:\WINDOWS\system32\ljjkige.dll
                  C:\WINDOWS\system32\ljjkige.dll Has been deleted!

                  Performing Repairs to the registry.
                  Done!

                  VundoFix V7.0.3

                  Scan started at 15:12:11 2008-03-29

                  Listing files found while scanning....

                  No infected files were found.

                  VundoFix V7.0.3

                  Scan started at 16:19:40 2008-03-29

                  Listing files found while scanning....

                  C:\windows\system32\ddayx.dll
                  C:\WINDOWS\system32\ljjkige.dll
                  C:\windows\system32\qtutv.ini
                  C:\windows\system32\qtutv.ini2
                  C:\windows\system32\vtutq.dll
                  C:\windows\system32\xyadd.ini
                  C:\windows\system32\xyadd.ini2

                  Beginning removal...

                  Attempting to delete C:\windows\system32\ddayx.dll
                  C:\windows\system32\ddayx.dll Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\ljjkige.dll
                  C:\WINDOWS\system32\ljjkige.dll Could not be deleted.

                  Attempting to delete C:\windows\system32\qtutv.ini
                  C:\windows\system32\qtutv.ini Has been deleted!

                  Attempting to delete C:\windows\system32\qtutv.ini2
                  C:\windows\system32\qtutv.ini2 Has been deleted!

                  Attempting to delete C:\windows\system32\vtutq.dll
                  C:\windows\system32\vtutq.dll Could not be deleted.

                  Attempting to delete C:\windows\system32\xyadd.ini
                  C:\windows\system32\xyadd.ini Has been deleted!

                  Attempting to delete C:\windows\system32\xyadd.ini2
                  C:\windows\system32\xyadd.ini2 Has been deleted!

                  Performing Repairs to the registry.
                  Done!

                  Beginning removal...

                  Attempting to delete C:\WINDOWS\system32\ljjkige.dll
                  C:\WINDOWS\system32\ljjkige.dll Has been deleted!

                  Attempting to delete C:\windows\system32\vtutq.dll
                  C:\windows\system32\vtutq.dll Has been deleted!

                  Performing Repairs to the registry.
                  Done!

                  VundoFix V7.0.3

                  Scan started at 23:31:06 2008-03-30

                  Listing files found while scanning....

                  No infected files were found.

                  VundoFix V7.0.3

                  Scan started at 16:57:16 2008-04-15

                  Listing files found while scanning....

                  No infected files were found.

                  VundoFix V7.0.3

                  Scan started at 23:03:23 2008-04-21

                  Listing files found while scanning....

                  No infected files were found.

                  VundoFix V7.0.3

                  Scan started at 18:09:18 2008-05-07

                  Listing files found while scanning....

                  No infected files were found.

                  VundoFix V7.0.3

                  Scan started at 16:42:37 2008-05-08

                  Listing files found while scanning....

                  No infected files were found.

                  Beginning removal...
                  0
                  1. re

                    super le vundo

                    t'as redemarré et testé apres ça?
                    0
                3. je pense que sa n'apas donner grand chose lol je me suis lever avec une vingtaine de page ouvert et un virus détecter
                  0
                  1. salut

                    lance stp ceci :

                    Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
                    http://www.atribune.org/ccount/click.php?id=4
                    Double-clique VundoFix.exe afin de le lancer.

                    Clique sur le bouton Scan for Vundo.
                    Lorsque le scan est complété, clique sur le bouton Remove Vundo.
                    Une invite te demandera si tu veux supprimer les fichiers, clique YES
                    Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
                    Tu verras une invite qui t'annonce que ton PC va s'éteindre ("shutdown") ; clique OK
                    Démarre ton PC à nouveau.
                    Copie/colle le rapport (c:\vundofix.txt) dans ta réponse

                    bises
                    0
                4. ok

                  on poursuit demain,taleur enfin......!!!!bonnenuit à toi ,enfin beaux reves

                  bises
                  0
                  1. j'ai un peu moins de pub mais a peine

                    ps : je vais me coucher je re demain
                    0
                    1. re

                      ok déjà c bien

                      vois tu du changement sur ton ordi ou pas encore,dis si c pareil , ok?
                      0
                      1. le raport de clean:
                        Script execute en mode sans echec
                        Rapport clean par Malekal_morte - http://www.malekal.com
                        Script execute en mode sans echec 2008-05-07 a 23:00:00,09

                        Microsoft Windows XP [version 5.1.2600]

                        *** Suppression des fichiers dans C:

                        *** Suppression des fichiers dans C:\WINDOWS\

                        *** Suppression des fichiers dans C:\WINDOWS\system32

                        *** Suppression des fichiers dans C:\Program Files

                        *** Suppression des clefs du registre effectuee..
                        *** Fin du rapport !
                        0
                        • 1
                        • 2