Cheval de troie ????

Bonjour,
voila j'ai depuis quelques temps un gros soucis avec mon pc qui rame pour acceder a internet .
j'ai fait des tas d'analyses avec toutes sortes de logiciels

et aucuns ne me trouve d'infection .

n'ayant trouvè aucunes solutions depuuis pour regler mon probleme je suis allè voir un commerçant specialisè en informatique celui ci me dis que j'ai un cheval de troie , et que la seule solution et de tout reinstaller formater .

je ne suis pas tres content de cette solution car j'ai un boulot enorme pour tout reinstaller et je ne suis pas sur de ne rien perdre .

auriez vous une solution efficasse pour trouver s'il y a , ce cheval de troie et le supprimer ?

merci a tous
Configuration: Windows XP
Firefox 2.0.0.14

25 réponses

  1. tu peux essayer.

    sinon regarde voir si tu as un soucis de connections .
    tu ouvre internet explorer et tu tape le code 192.168.1.1 à la place de la page d'accueil.

    Il va te demander un nom d'utilisateur ce sera admin
    et le mot de passe admin

    ensuite tu peux voir si tu es bien connecté.
    0
    1. oui je l'avais installè aussi au cas ou

      je pense a un truc comme j'ai 2 disques durs et 4 partitions , je vais installer un system sur une partition et voir comment il se comporte a l'acces internet au moins je serai fixè sur la carte mere ou sur mon autre system qui rame .

      qu'en pense tu ?
      0
      1. as tu installer le logiciel orange pour ta connections?

        car dès fois ça fais ramer.
        0
        1. "orange " eux aussi me disent que le probleme ne viens pas d'eux .

          mon pc est encore sous garantie il a pas un an .achetè via le net et montè par mes soins .

          je vais voir avec un pote si je peux le connecter chez lui pour voir si le probleme persiste .

          deja je sais qu'il n'est pas infectè
          0
          1. et bien tu peux être sur et certain que tu n'est pas infecté.

            le problème vient d'ailleurs.

            je te souhaites bon courage et tiens moi au courant.

            Tu es chez quel fournisseur d'accès?
            0
            1. C:\Combofix: trouvé !
              C:\Qoobox: trouvé !
              C:\Documents and Settings\freddy\Bureau\ComboFix.exe: trouvé !
              C:\Documents and Settings\freddy\Bureau\Nouveau dossier\SdFix.exe: trouvé !
              C:\Documents and Settings\freddy\Bureau\Nouveau dossier\SDFIX: trouvé !
              C:\Documents and Settings\freddy\Bureau\SAUVEGARDE AVANT FORMATAGE\HijackThis.exe: trouvé !

              je me doutais qu'il n'y avait pas d'infection c'est pourquoi je n'ai pas formatè de suite .

              mais je voulais en etre sur !

              le probleme ne viens pas de ma fiche ethernet , car je l'ai aussi installè en wi fi pour tester et le probleme etait le meme .
              aussi celui avec qui je communique actuellement et un 2eme pc bien moins performant mais il est en wi fi et il fonctionne tres bien .

              celui qui rame est en cable ethernet actuellement .mais si je le met en wi fi il rame aussi .

              moi j'ai pensè a la carte mere mais ont me dis que ca ne viens pas d'elle !!!
              0
              1. bon je ne vois pas de virus en ce qui concerne ta connexion regarde peut etre au niveau de ta prise de téléphone c'est peut etre de la que viens le problème.

                télécharge ToolsCleaner sur ton PC.
                une fois installé tu fais recherche et ensuite tu fais suppression.
                Un rapport va être généré envois le moi.

                Tu n'est pas infecté.
                0
                1. j'ai nettoyè avec ccleaner . et retentè de me connecter au web , mais la connection est toujours aussi lente

                  vois tu des infections dans les rapports ??
                  0
                  1. bien on va nettoyer ta base de registre

                    télécharge CCleaner sur ton ordinateur.

                    voici le tuto regarde le et lis tout:
                    https://forums.cnetfrance.fr

                    nettoies ta base de registre correctement et dis moi si tu as des améliorations.
                    0
                    1. voici les rapports

                      [b]SDFix: Version 1.185 [/b]
                      Run by freddy on 2008-05-23 at 20:20

                      Microsoft Windows XP [version 5.1.2600]
                      Running From: C:\DOCUME~1\freddy\Bureau\SDFix

                      [b]Checking Services [/b]:

                      Restoring Windows Registry Values
                      Restoring Windows Default Hosts File

                      Rebooting

                      [b]Checking Files [/b]:

                      No Trojan Files Found

                      Removing Temp Files

                      [b]ADS Check [/b]:

                      [b]Final Check [/b]:

                      catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2008-05-23 20:25:07
                      Windows 5.1.2600 Service Pack 2 NTFS

                      scanning hidden processes ...

                      scanning hidden services & system hive ...

                      scanning hidden registry entries ...

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                      "AppInit_DLLs"="sockspy.dll"
                      "DeviceNotSelectedTimeout"="15"
                      "GDIProcessHandleQuota"=dword:00002710
                      "Spooler"="yes"
                      "swapdisk"=""
                      "TransmissionRetryTimeout"="90"
                      "USERProcessHandleQuota"=dword:00002710

                      scanning hidden files ...

                      scan completed successfully
                      hidden processes: 0
                      hidden services: 0
                      hidden files: 0

                      [b]Remaining Services [/b]:

                      Authorized Application Key Export:

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                      "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
                      "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
                      "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                      "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

                      [b]Remaining Files [/b]:

                      File Backups: - C:\DOCUME~1\freddy\Bureau\SDFix\backups\backups.zip

                      [b]Files with Hidden Attributes [/b]:

                      Mon 30 Jul 2007 5,388,088 A..H. --- "C:\Program Files\Picasa2\setup.exe"
                      Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
                      Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
                      Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
                      Fri 5 Oct 2007 52,224 ..SHR --- "C:\Program Files\The Free Toolbar\Setup.exe"
                      Tue 17 Apr 2007 71,168 ..SHR --- "C:\Program Files\Mio Technology\MioSync\Setup.exe"
                      Sat 9 Jul 2005 16,384 A.SHR --- "C:\Program Files\Mio Technology\MioSync\_Setup.dll"
                      Mon 7 Apr 2008 71,168 ..SHR --- "C:\Program Files\Mio Technology\SpeedCAM Tool\Setup.exe"
                      Sat 9 Jul 2005 16,384 A.SHR --- "C:\Program Files\Mio Technology\SpeedCAM Tool\_Setup.dll"
                      Mon 6 Aug 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
                      Wed 7 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\BIT20.tmp"
                      Mon 15 Oct 2007 857 ...HR --- "C:\Documents and Settings\freddy\Application Data\SecuROM\UserData\securom_v7_01.bak"
                      Wed 24 Oct 2007 162,241 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0c421e9c03c15e3b0c16f1599b67ef6e\download\BIT9A.tmp"
                      Mon 2 Oct 2006 4,908,960 A..H. --- "C:\Documents and Settings\freddy\Bureau\SAUVEGARDE AVANT FORMATAGE\SAUVEGARDE MES DOCUMENTS\logiciels istallŠs\Picasa2\setup.exe"

                      [b]Finished![/b]

                      .............................................................................................................................................................

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 20:28, on 2008-05-23
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                      C:\Program Files\ewido anti-spyware 4.0\guard.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                      C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
                      C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                      C:\Program Files\Softwin\BitDefender10\vsserv.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\WINDOWS\system32\notepad.exe
                      C:\Program Files\Google\Gmail Notifier\gnotify.exe
                      C:\Program Files\Analog Devices\Core\smax4pnp.exe
                      C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                      C:\WINDOWS\system32\RUNDLL32.EXE
                      C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
                      C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
                      C:\Program Files\Softwin\BitDefender10\bdmcon.exe
                      C:\Program Files\Softwin\BitDefender10\bdagent.exe
                      C:\Program Files\ASUS\AI Remote\AiRc.exe
                      C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
                      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
                      C:\WINDOWS\system32\LVCOMSX.EXE
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\ASUS\AI Remote\AiRemote.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                      C:\Program Files\Logitech\SetPoint\SetPoint.exe
                      C:\Program Files\Mio Technology\MioSync\mioSync.exe
                      C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
                      C:\Documents and Settings\freddy\Bureau\SAUVEGARDE AVANT FORMATAGE\HiJackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
                      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                      O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
                      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
                      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
                      O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
                      O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                      O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
                      O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\System32\JMRaidSetup.exe boot
                      O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
                      O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
                      O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
                      O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
                      O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
                      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
                      O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.24\AsRunHelp.exe
                      O4 - HKLM\..\Run: [ASUS ASAP USB] C:\Program Files\ASUS\ASAP\asapusb.exe
                      O4 - HKLM\..\Run: [Ai Remote Help] "C:\Program Files\ASUS\AI Remote\AiRc.exe"
                      O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe"
                      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                      O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                      O4 - Global Startup: MioSync.lnk = C:\Program Files\Mio Technology\MioSync\mioSync.exe
                      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                      O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
                      O14 - IERESET.INF: START_PAGE_URL=https://www.google.fr/?gws_rd=ssl
                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                      O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                      O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                      O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                      O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTServ.exe
                      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
                      O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                      O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
                      O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                      0
                      1. ok au depart il m'a affichè un message d'erreur puis il est reparti et là me demande d'attendre
                        0
                        1. Appuie sur Y pour commencer le processus de nettoyage. il faut taper "y" en majuscule et entrèe ??
                          0
                          1. ok,

                            Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau:
                            http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
                            Guide d'utilisation :
                            http://mickael.barroux.free.fr/securite/sdfix.php

                            Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :

                            * Redémarre ton ordinateur
                            * Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
                            * A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
                            * Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
                            * Choisis ton compte.

                            Déroule la liste des instructions ci-dessous :

                            * Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et double clique sur RunThis.bat pour lancer le script.
                            * Appuie sur Y pour commencer le processus de nettoyage.
                            * Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                            * Appuie sur une touche pour redémarrer le PC.
                            * Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                            * Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                            * Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
                            * Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                            * Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum.

                            N.B.:
                            - Le fichier SDFIX_README.htm (dans le dossier SDFix) contient la liste des malwares pris en compte par l'outil.
                            - Andy fait plusieurs mises à jour, souvent plus d'une par jour... N'hésitez donc pas à demander de télécharger une nouvelle version lorsque le nettoyage dure et que l'outil ne semble pas tout voir.

                            + nouveau rapport hijackthis.
                            0
                            1. bon ben il a passè le disque "c" et il analyse l 'autre disque dur . donc il semblerai qu'il ne vois pas d'infections .....
                              0
                              1. ok oui je l'ai installè il y a pas une semaine et j'ai bien fait la mise a jour .il est en train d'analyser là ,en mode ss echecs
                                0
                                1. n'oubli pas de le mettre à jour avant de lancer le scan.
                                  0
                                  1. oui celui là je l'ai installè il y a peut de temps je vais le lançer a nouveau

                                    je reviens
                                    0
                                    1. Télécharge MalwareByte's Anti-Malware sur ton Bureau.

                                      https://www.majorgeeks.com/files/details/malwarebytes_anti_malware.html

                                      Installe-le en double-cliquant sur le fichier Download_mbam-setup.exe.

                                      Une fois l'installation et la mise à jour effectuées, redémarre en mode sans échec.

                                      * Exécute maintenant MalwareByte's Anti-Malware. Si cela n'est pas déjà fait, sélectionne "Exécuter un examen complet".
                                      * Afin de lancer la recherche, clic sur"Rechercher".
                                      * Une fois le scan terminé, une fenêtre s'ouvre, clic sur OK. Deux possibilités s'offrent à toi :

                                      -- si le programme n'a rien trouvé, appuie sur OK. Un rapport va apparaître, ferme-le.
                                      -- si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.
                                      REMARQUE : Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.


                                      tuto sur MBMA:http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
                                      0
                                      1. voici les rapports et merci beaucoup de ton aide

                                        ComboFix 08-05-21.3 - freddy 2008-05-23 18:11:44.1 - NTFSx86 MINIMAL
                                        Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1768 [GMT 2:00]
                                        Endroit: C:\Documents and Settings\freddy\Bureau\ComboFix.exe

                                        [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                                        .

                                        (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                        .

                                        .
                                        ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                                        .

                                        -------\Legacy_NWSAPAGENT
                                        -------\Service_NwSapAgent

                                        ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-23 to 2008-05-23 ))))))))))))))))))))))))))))))))))))
                                        .

                                        2008-05-23 18:00 . 2008-05-23 18:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
                                        2008-05-23 17:58 . 2008-05-23 18:16 <REP> d-------- C:\Program Files\Trojan Remover
                                        2008-05-23 17:58 . 2008-05-23 17:58 <REP> d-------- C:\Documents and Settings\freddy\Application Data\Simply Super Software
                                        2008-05-23 17:58 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
                                        2008-05-23 17:58 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
                                        2008-05-08 10:32 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
                                        2008-05-08 10:32 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                                        2008-05-03 22:09 . 2008-05-08 10:32 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                                        2008-05-03 22:09 . 2008-05-03 22:09 <REP> d-------- C:\Documents and Settings\freddy\Application Data\Malwarebytes
                                        2008-05-03 22:09 . 2008-05-03 22:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                                        2008-05-03 16:47 . 2008-05-03 16:47 <REP> d-------- C:\Program Files\SAGEM
                                        2008-05-03 16:44 . 2005-12-22 14:45 493,440 --a------ C:\WINDOWS\system32\drivers\WlanBZ64.SYS
                                        2008-05-03 16:44 . 2005-12-22 14:45 402,432 --a------ C:\WINDOWS\system32\drivers\WlanBZXP.sys
                                        2008-05-03 16:44 . 2005-12-22 14:45 25,214 --a------ C:\WINDOWS\WLANUTL.ICO
                                        2008-05-03 16:43 . 2005-06-17 10:27 379,456 --a------ C:\WINDOWS\system32\drivers\WlanUIG.sys
                                        2008-05-03 12:26 . 2008-05-03 12:27 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
                                        2008-05-03 12:25 . 2008-05-03 12:25 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
                                        2008-05-03 09:25 . 2008-05-03 10:02 <REP> d-------- C:\WINDOWS\BDOSCAN8
                                        2008-05-02 21:22 . 2008-05-02 21:23 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
                                        2008-05-02 20:19 . 2008-05-02 20:19 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
                                        2008-05-02 19:24 . 2008-05-02 19:24 <REP> d-------- C:\Program Files\Sun

                                        .
                                        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                        .
                                        2008-05-23 16:09 44,418 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
                                        2008-05-06 20:13 --------- d-----w C:\Program Files\Wanadoo
                                        2008-05-03 16:02 0 ----a-w C:\WINDOWS\system32\drivers\lvuvc.hs
                                        2008-05-03 14:47 --------- d--h--w C:\Program Files\InstallShield Installation Information
                                        2008-05-03 10:27 --------- d-----w C:\Documents and Settings\freddy\Application Data\Lavasoft
                                        2008-05-03 10:26 --------- d-----w C:\Program Files\Lavasoft
                                        2008-05-02 19:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                                        2008-05-02 17:24 --------- d-----w C:\Program Files\Java
                                        2008-04-30 20:49 --------- d-----w C:\Documents and Settings\freddy\Application Data\MSN6
                                        2008-04-27 20:49 --------- d-----w C:\Program Files\ewido anti-spyware 4.0
                                        2008-04-17 16:42 --------- d-----w C:\Program Files\Macrogaming
                                        2008-04-08 10:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\LogiShrd
                                        2008-04-08 10:37 --------- d-----w C:\Program Files\Fichiers communs\Logitech
                                        2008-04-08 10:37 --------- d-----w C:\Program Files\Fichiers communs\logishrd
                                        2008-04-08 10:37 --------- d-----w C:\Documents and Settings\freddy\Application Data\InstallShield
                                        2008-04-07 17:54 --------- d-----w C:\Program Files\Mio Technology
                                        2008-04-01 10:01 --------- d-----w C:\Program Files\eMule
                                        2008-03-31 16:50 --------- d-----w C:\Program Files\DivX
                                        2008-03-30 06:07 --------- d--h--r C:\Documents and Settings\freddy\Application Data\yahoo!
                                        2008-03-23 15:26 --------- d-----w C:\Program Files\BallClock3D
                                        2007-12-23 23:53 40,768 ----a-w C:\Documents and Settings\freddy\Application Data\GDIPFONTCACHEV1.DAT
                                        2007-10-14 17:01 1 ----a-w C:\Documents and Settings\freddy\SI.bin
                                        2007-07-28 15:15 8,192 ----a-w C:\Program Files\dmfafr39.Ock
                                        2007-07-28 15:15 4,096 ----a-w C:\Program Files\dmfafr39.Dlk
                                        2006-06-23 06:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe
                                        .

                                        ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                                        .
                                        .
                                        REGEDIT4
                                        *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                        "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
                                        "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-05 11:36 68856]
                                        "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

                                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                        "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-03-22 04:50 8425472]
                                        "{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="C:\Program Files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 23:48 479232]
                                        "SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 10:22 155648]
                                        "SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-10-05 14:25 868352]
                                        "SetDefPrt"="C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe" [2005-01-26 18:02 49152]
                                        "PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 19:17 57393]
                                        "nwiz"="nwiz.exe" [2007-03-22 04:50 1622016 C:\WINDOWS\system32\nwiz.exe]
                                        "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-03-22 04:50 81920]
                                        "NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
                                        "JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 14:44 36864]
                                        "JMB36X Configure"="C:\WINDOWS\System32\JMRaidSetup.exe" [2006-10-30 14:44 1953792]
                                        "IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 19:30 40960]
                                        "DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-10-04 12:38 163840]
                                        "ControlCenter3"="C:\Program Files\Brother\ControlCenter3\brctrcen.exe" [2006-06-29 12:18 77824]
                                        "BrMfcWnd"="C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-06-28 07:46 622592]
                                        "BDMCon"="C:\Program Files\Softwin\BitDefender10\bdmcon.exe" [2008-05-02 14:39 290816]
                                        "BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [2008-05-02 14:39 69632]
                                        "AsusStartupHelp"="C:\Program Files\ASUS\AASP\1.00.24\AsRunHelp.exe" [2006-12-29 03:54 363008]
                                        "ASUS ASAP USB"="C:\Program Files\ASUS\ASAP\asapusb.exe" [2007-01-10 11:55 384512]
                                        "Ai Remote Help"="C:\Program Files\ASUS\AI Remote\AiRc.exe" [2007-01-19 14:24 3347456]
                                        "Ai Nap"="C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe" [2007-01-11 23:39 1423360]
                                        "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [ ]
                                        "LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-09-01 14:04 221184]
                                        "TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2007-03-16 13:44 296544]

                                        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                        "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 16:09 15360]

                                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
                                        "UIHost"="C:\\WINDOWS\\system32\\logonui.exe"

                                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
                                        c:\program files\fichiers communs\logitech\bluetooth\LBTWlgn.dll 2007-11-15 10:10 72208 c:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTWLgn.dll

                                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                                        "AppInit_DLLs"=sockspy.dll

                                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                                        "vidc.dvsd"= pdvcodec.dll

                                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                                        Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

                                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
                                        @=""

                                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
                                        --a------ 2007-06-16 01:15 366400 C:\Program Files\Picasa2\PicasaMediaDetector.exe

                                        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                                        "DisableMonitoring"=dword:00000001

                                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                                        "EnableFirewall"= 0 (0x0)

                                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                        "%windir%\\system32\\sessmgr.exe"=
                                        "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
                                        "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
                                        "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
                                        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                        "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                                        "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

                                        R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 10:21]
                                        R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 10:21]
                                        R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2006-10-31 05:10]
                                        R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
                                        S3 brfilt;Pilote de filtre Brother MFC;C:\WINDOWS\system32\Drivers\Brfilt.sys [2001-08-17 21:12]
                                        S3 BrFiltLo;Pilote de filtre inférieur de stockage de masse Brother USB;C:\WINDOWS\system32\DRIVERS\BrFiltLo.sys [2001-08-17 21:12]
                                        S3 BrFiltUp;Pilote de filtre supérieur de stockage de masse Brother USB;C:\WINDOWS\system32\DRIVERS\BrFiltUp.sys [2001-08-17 21:12]
                                        S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 12:50]
                                        S3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;C:\WINDOWS\system32\Drivers\BrSerIf.sys [2006-01-18 22:44]
                                        S3 BrSerWDM;Pilote série WDM Brother;C:\WINDOWS\system32\Drivers\BrSerWdm.sys [2001-08-17 21:12]
                                        S3 BrUsbMdm;Brother MFC USB modem télécopieur uniquement;C:\WINDOWS\system32\Drivers\BrUsbMdm.sys [2001-08-17 21:12]
                                        S3 BrUsbScn;Pilote de scanneur Brother MFC USB;C:\WINDOWS\system32\Drivers\BrUsbScn.sys [2001-08-17 21:12]
                                        S3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\WINDOWS\system32\Drivers\BrUsbSer.sys [2006-01-19 03:17]
                                        S3 LVPrcMon;Logitech LVPrcMon Driver;C:\WINDOWS\system32\drivers\LVPrcMon.sys [2005-09-01 14:11]
                                        S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
                                        S3 ZDCndis5;ZDCndis5 Protocol Driver;C:\WINDOWS\system32\ZDCndis5.SYS []
                                        Stop Pending2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe" [2007-04-26 10:21]

                                        .
                                        Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
                                        "2008-05-23 15:56:56 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"

                                        .................................................................................................................................................

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 18:24, on 2008-05-23
                                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                                        MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                        C:\WINDOWS\system32\spoolsv.exe
                                        c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                                        C:\WINDOWS\Explorer.EXE
                                        C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                                        C:\Program Files\ewido anti-spyware 4.0\guard.exe
                                        C:\WINDOWS\system32\nvsvc32.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                                        C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                                        C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
                                        C:\Program Files\Google\Gmail Notifier\gnotify.exe
                                        C:\Program Files\Analog Devices\Core\smax4pnp.exe
                                        C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                                        C:\WINDOWS\system32\RUNDLL32.EXE
                                        C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
                                        C:\Program Files\Softwin\BitDefender10\bdmcon.exe
                                        C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
                                        C:\Program Files\Softwin\BitDefender10\bdagent.exe
                                        C:\Program Files\ASUS\AI Remote\AiRc.exe
                                        C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe
                                        C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
                                        C:\Program Files\ASUS\AI Remote\AiRemote.exe
                                        C:\WINDOWS\system32\LVCOMSX.EXE
                                        C:\WINDOWS\system32\ctfmon.exe
                                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                        C:\Program Files\Logitech\SetPoint\SetPoint.exe
                                        C:\Program Files\Mio Technology\MioSync\mioSync.exe
                                        C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
                                        C:\Program Files\Softwin\BitDefender10\vsserv.exe
                                        C:\Documents and Settings\freddy\Bureau\SAUVEGARDE AVANT FORMATAGE\HiJackThis.exe

                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                        O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
                                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
                                        O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                        O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                        O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
                                        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                        O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
                                        O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                                        O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
                                        O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe
                                        O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                                        O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
                                        O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\System32\JMRaidSetup.exe boot
                                        O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
                                        O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
                                        O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
                                        O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
                                        O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
                                        O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
                                        O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.24\AsRunHelp.exe
                                        O4 - HKLM\..\Run: [ASUS ASAP USB] C:\Program Files\ASUS\ASAP\asapusb.exe
                                        O4 - HKLM\..\Run: [Ai Remote Help] "C:\Program Files\ASUS\AI Remote\AiRc.exe"
                                        O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe"
                                        O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
                                        O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
                                        O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
                                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                                        O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                                        O4 - Global Startup: MioSync.lnk = C:\Program Files\Mio Technology\MioSync\mioSync.exe
                                        O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                        O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
                                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
                                        O14 - IERESET.INF: START_PAGE_URL=https://www.google.fr/?gws_rd=ssl
                                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                                        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                                        O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                        O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                                        O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
                                        O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
                                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTServ.exe
                                        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
                                        O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
                                        O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                        O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                                        O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
                                        O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                                        0
                                        • 1
                                        • 2