Ad server Browsing advisor

Résolu
Bonjour,

Qqs soucis avec ad server Browsing advisor, qui m'ouvre des fenêtres intempestives. J'ai fait plusieurs scans mais, qui a éliminé pas mal de choses mais je ne pense pas que ce soit suffisant.
Quelle est la marche a suivre?

Merci :]
Configuration: Windows XP
Firefox 2.0.0.14

49 réponses

Résumé de la discussion

Le problème décrit concerne des fenêtres publicitaires intempestives liées à un ad server Browsing Advisor sur Windows XP et Firefox 2.0.0.14, malgré plusieurs scans et tentatives de nettoyage qui n'ont pas tout éliminé. Plusieurs outils ont été utilisés pour nettoyer le système, notamment OTMoveIt et HijackThis, qui ont déplacé et supprimé des fichiers et raccourcis indésirables, et ont réinitialisé les chemins StartUp et Run. Des éléments signalés dans les rapports concernent des entrées au démarrage et des composants d'outils réseau, notamment Wanadoo, Google Updater et Avast, ce qui suggère une vérification approfondie des programmes installés et de leurs services.

Bobot (l’IA à votre service)
  1. oui ^^
    et pour Sundbelt firewall aussi, il y a des tutaux très instructifs!

    Bye !!!
    1. De rien pour l'aide :)

      et bon surf !

      Je passe en résolu.

      ______________________________________________________________________

      A Lire

      -> http://www.commentcamarche.net/faq/sujet 8201 pirates attaquent

      -> https://sebsauvage.net/safehex.html#r_pourquoisecuriser

      -> http://www.commentcamarche.net/faq/sujet 9289 trojan comment ca marche

      -> https://forum.pcastuces.com/default.asp

      -> http://assiste.com.free.fr/p/abc/a/safe_cex.html

      ______________________________________________________________________

      Navigation sécurisée Avec Mozilla Firefox :

      -> Comparatif IE contre FF → http://www.infos-du-net.com/actualite/dossiers/11-firefox-internet-explorer.html

      -> Pourquoi utiliser FF ? → https://sebsauvage.net/logiciels/firefox.html

      > Téléchargement <


      -> https://forum.zebulon.fr/topic/69628-s%C3%A9curiser-un-peu-plus-firefox/ [ sécuriser FireFox ]

      Note :

      Il est important de garder IE car nombreux sont les logiciels qui ne fonctionnent qu'avec lui.

      ______________________________________________________________________

      Pour sécuriser - Facultatif - ( si tu ne les as pas encore ):
      ______________________________________________________________________

      ************ 1 ***********

      -> Spybot S&D (-> Scan passif + Résident )

      > Téléchargement <

      -> Tutorial : https://forums.cnetfrance.fr

      ************ 2 ***********

      -> Spyware blaster

      > Téléchargement <

      -> Tutorial : https://www.malekal.com/tutorial-spywareblaster/

      ************ 3 ***********

      -> SpywareGuard ( Ce logiciel complète très bien Spybot)

      > Téléchargement <

      -> Tutorial : https://www.zebulon.fr/dossiers/securite/47-spywareguard.html

      ______________________________________________________________________
      1. eh bien je ne pense pas avoir d'autre question et mis a part le petit pb de kerio (que je finirais bien par régler), ça me semble parfait :)

        Un grand et sincère merci pour ce suivi personnalisé!!
        Il y avait du boulot et je n'y serai jamais parvenue sans aide!! merci
        en tout cas shion-ares avait raison: j'étais entre de bonnes mains.

        Je vous recommande! XD

        ++

        Gaga
        1. Re ,

          ok :)

          Maintenant que ton PC n'est plus infecté, désactive ta "Restauration du système" puis réactive la, ce qui créer un point de restauration sain...

          Désactivation :
          Clique droit sur le "Poste de travail" > Propriétés > onglet "Restauration du système" > coche la case "Désactiver la Restauration du système sur tous les lecteurs"
          > Applique patiente jusqu’à ce que cela soit marqué "désactivé" puis Ok.

          Activation :
          Suivre le même chemin ; décoche la case "Désactiver la Restauration du système sur tous les lecteurs"
          > Applique attends que cela soit à nouveau sur "surveillance" puis Ok. Redémarre l'ordinateur.

          Tutorial :
          http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20020830101856924

          **********************************

          voila mon aide s'arrête la.

          Questions .?
          Soucis .?
          Autres .?

          A++
          1. ok c'est fait.

            Pour Kerio, je ne voudrais pas faire de bêtise en cliquant n'importe où.
            1. Re ,

              Supprime Toolscleaner.
              Supprime Tcleaner.txt


              Pour Kerio, tu n'as pas l'option ' autoriser ' ou ' refuser ' ?

              A++
              1. par contre, j'ai un autre souci depuis que j'ai téléchargé sunbelt personal firewall: il m'affiche constamment une fenêtre d'alerte. j'ai beau la fermer elle revient. Voici ce qui est marqué dans la fenêtre détail:

                Détails techniques sur l'intrusion :

                Application injectrice : c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe(new line)
                Description : Logitech LVPrcSrv Module.(new line)
                Version du fichier : 10.5.1.2027(new line)
                Produit : Logitech QuickCam(new line)
                Version du produit : 10.5.1.2027(new line)
                Créé le : 2007/2/6, 15:45:26(new line)
                Modifié le : 2007/2/6, 15:45:26(new line)
                Dernier accès le : 2008/6/13, 19:07:47

                Application cible : C:\WINDOWS\system32\HPZipm12.exe(new line)
                Description : PML Driver(new line)
                Version du fichier : 10, 1, 1, 5(new line)
                Produit : HP PML(new line)
                Version du produit : 10, 1, 1, 5(new line)
                Créé le : 2007/8/18, 15:01:39(new line)
                Modifié le : 2006/3/3, 19:03:10(new line)
                Dernier accès le : 2008/6/13, 19:10:43

                Adresse de l'injection : 0x00260000
                1. rapport tcleaner ok

                  -->- Recherche:

                  C:\_OtMoveIt: trouvé !
                  C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: trouvé !
                  C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
                  C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: trouvé !
                  C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
                  C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\Dss.exe: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\HijackThis.lnk: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\OtMoveIt2.exe: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\SDFIX: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\tar.exe: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\remove.reg: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\pskill.exe: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\LFiles.exe: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\gzip.exe: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\delsiri.cmd: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\delr.cmd: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\del3.cmd: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\del2.cmd: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\clean.cmd: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\cherche.cmd: trouvé !
                  C:\Documents and Settings\anne gaêlle\Bureau\SDFix\SDFIX: trouvé !
                  C:\Program Files\Trend Micro\HijackThis: trouvé !
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
                  C:\_OTMoveIt\MovedFiles\06132008_144429\Program Files\Navilog1: trouvé !
                  C:\_OTMoveIt\MovedFiles\06132008_144429\Program Files\Navilog1\Navilog1.bat: trouvé !

                  ---------------------------------
                  -->- Suppression:

                  C:\Documents and Settings\All Users\Bureau\Navilog1.lnk: supprimé !
                  C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
                  C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1\Navilog1.lnk: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\Dss.exe: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\HijackThis.lnk: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\OtMoveIt2.exe: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\tar.exe: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\remove.reg: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\pskill.exe: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\LFiles.exe: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\gzip.exe: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\delsiri.cmd: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\delr.cmd: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\del3.cmd: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\del2.cmd: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\clean.cmd: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\clean\cherche.cmd: supprimé !
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
                  C:\_OTMoveIt\MovedFiles\06132008_144429\Program Files\Navilog1\Navilog1.bat: supprimé !
                  C:\_OtMoveIt: supprimé !
                  C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
                  C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Navilog1: supprimé !
                  C:\Documents and Settings\anne gaêlle\Bureau\SDFIX: supprimé !
                  C:\Program Files\Trend Micro\HijackThis: supprimé !
                  1. Re

                    Supprime le fix.reg

                    Télécharge le pare-feu Kerio

                    Tutorial en cas de problèmes : https://kerio.probb.fr/f2-sunbelt-kerio-personal-firewall

                    ***********************************************

                    _Maintenant , nous allons supprimer les logiciels de désinfection que je t'ai fait téléchargé.
                    En effet , s'en servir est dangereux pour le pc si l'on ne s'y connais pas.
                    De plus ils sont mis régulièrement à jours.

                    → Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.

                    → Double clique sur ToolsCleaner2.exe >
                    → Clique sur .Recherche
                    → puis sur Suppression quand la liste est trouvée.
                    → Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                    (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                    Note : ton bureau RISQUE de disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

                    CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
                    Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

                    Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

                    Tuto : http://www.commentcamarche.net/faq/sujet 8341 toolscleaner suppression des fix de force brute ( merci espion3004 )

                    A+
                    1. ok c'est fait .

                      cependant je ne parviens pas à supprimer C:\Program Files\Java\jre1.5.0_06 ---> " impossible de supprimer jucheck.exe : Accès refusé. Vérifiez que le disque n'est pas plein ou protégé en écriture, et que le fichier n'est pas utilisé actuellement. "

                      ... y a t'il un autre moyen d'y parvenir?
                      1. Re !

                        Supprime ce dossier : C:\Program Files\Java\jre1.5.0_06

                        Met à jour JAVA --> https://www.java.com/fr/download/windows_manual.jsp?locale=fr&host=www.java.com:80 [ Version 6 update 6 ]

                        **************************

                        Ta version d'Adobe n'est pas à jour, télécharge la dernière , via ce site --> https://get2.adobe.com/reader/otherversions/

                        Bulletin de sécurité sur les versions Adobe 7.0.8 et antérieures :

                        https://www.adobe.com/support/security/bulletins/apsb07-01.html

                        **************************

                        a++
                        1. ok c'est fait, voici le rapport Hijackthis:

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 20:02:58, on 13/06/2008
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Windows Defender\MsMpEng.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\ehome\ehtray.exe
                          C:\WINDOWS\RTHDCPL.EXE
                          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\Program Files\QuickTime\qttask.exe
                          C:\Program Files\Windows Defender\MSASCui.exe
                          C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                          C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
                          C:\WINDOWS\system32\oopmagent.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Program Files\Messenger\msmsgs.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                          C:\WINDOWS\system32\WTablet\TabUserW.exe
                          C:\WINDOWS\arservice.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
                          C:\WINDOWS\eHome\ehRecvr.exe
                          C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
                          C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                          C:\WINDOWS\eHome\ehSched.exe
                          C:\WINDOWS\System32\FTRTSVC.exe
                          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
                          C:\PROGRA~1\Wanadoo\ComComp.exe
                          C:\WINDOWS\system32\nvsvc32.exe
                          C:\PROGRA~1\Wanadoo\Toaster.exe
                          C:\PROGRA~1\Wanadoo\Inactivity.exe
                          C:\PROGRA~1\Wanadoo\PollingModule.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\Tablet.exe
                          C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\WINDOWS\system32\dllhost.exe
                          C:\WINDOWS\system32\wscntfy.exe
                          C:\WINDOWS\eHome\ehmsas.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                          C:\PROGRA~1\Wanadoo\Watch.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                          C:\Program Files\Windows Live\Messenger\usnsvc.exe
                          c:\windows\system\hpsysdrv.exe
                          C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                          C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
                          C:\Program Files\Trend Micro\HijackThis\anne gaêlle.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Windows Media Player\wmplayer.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pixaco.com/hpdesktop/redirect.aspx?source=hp-preinstallation&countryid=FR
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                          O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                          O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
                          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                          O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                          O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                          O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                          O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
                          O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                          O4 - HKLM\..\Run: [ooquickpdfv7] "C:\WINDOWS\system32\oopmagent.exe"
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
                          O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                          O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
                          O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                          O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
                          O4 - Startup: Personal Player.lnk = C:\Program Files\Web Hottest Videos Personal Player\flash pro 8 fr_Web_Hottest_Videos_Personal_Player.exe
                          O4 - Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE
                          O4 - Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                          O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
                          O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                          O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
                          O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                          O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                          O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
                          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                          O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                          O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                          O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                          O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                          O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                          O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                          O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
                          1. Re ,

                            /!\ Manip crée spécialement pour cet utilisateur , ne pas reproduire chez soi ... /!\

                            Crée un nouveau document texte : clic droit de souris sur le bureau, "Nouveau"> "Document Texte". Ouvre-le et copie-colle dedans de ce qui est en citation en gras ci-dessous, (copie tout d'un trait) : ( y compris Regedit4, et la ligne vide en dessous )

                            REGEDIT4

                            [HKEY_USERS\S-1-5-21-1727379497-623443971-1452040563-1010\Software\Microsoft\Windows\Curre­ntVersion\Explorer\MountPoints2\{0d631688-1296-11dc-b465-0018f36de952}\Shell\Auto\command]­
                            @=-

                            [HKEY_USERS\S-1-5-21-1727379497-623443971-1452040563-1010\Software\Microsoft\Windows\Curre­ntVersion\Explorer\MountPoints2\{0d631688-1296-11dc-b465-0018f36de952}\Shell\AutoRun\comma­nd]
                            @=-


                            Puis "fichier" -> "enregistrer sous" :
                            dans : sur le bureau
                            Nom du fichier : fix.reg
                            Type de fichier : "tous les fichiers"
                            clique sur "enregistrer"

                            Cela doit ressembler à ça

                            Double clique sur fix.reg

                            → tu dois OBLIGATOIREMENT* avoir un message "voulez-vous vraiment ajouter les informations contenues dans ce fichier .reg au registre ?"
                            Si c'est bien le cas, clique sur "oui"

                            *Prevenir si le message n'apparait pas.

                            ******************************

                            reposte un rapport Hijackthis;
                            a++
                            1. Bonsoir!

                              voici le rapport OAD:

                              13/06/2008 ---- 19:37:25,14

                              ----------------------------------
                              §§§§§§ [AdobeR.exe] §§§§§§
                              ----------------------------------
                              [X] Registre

                              -------------- [ ] rapide
                              -- Fichier --- [ ] disque systeme
                              ------------- [X] complete

                              ********************
                              [Registre]
                              ********************

                              [HKEY_USERS\S-1-5-21-1727379497-623443971-1452040563-1010\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d631688-1296-11dc-b465-0018f36de952}\Shell\Auto\command]
                              @="AdobeR.exe e"

                              [HKEY_USERS\S-1-5-21-1727379497-623443971-1452040563-1010\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0d631688-1296-11dc-b465-0018f36de952}\Shell\AutoRun\command]
                              @="C:\\WINDOWS\\system32\\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e"

                              *******************
                              [Fichier]
                              *******************

                              *********************
                              [Même date]
                              *********************

                              Aucun fichier créé à la même date détecté

                              Outil Aide Diagnostic By !aur3n7 Version 1.1
                              ----------------------------------
                              §§§§§ Fin Rapport §§§§§
                              ----------------------------------
                              1. Re ,

                                Hijackthis ce trouve ici : C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\ANNEGAELLE.EXE

                                ***********************************************

                                → Relance hijackthis , en menu principal choisis ' Do a system scan only' Et fixe ces/cette ligne(s) : ( coche la case à leurs gauches )

                                R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                                O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
                                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')


                                Ferme toutes les fenêtres (hormis Hijackthis), y compris ton navigateur web.

                                → clique sur ' fixchecked '


                                ***********************************************


                                Télécharger OAD (Outil d'Aide au Diagnostic) < http://sosvirus.changelog.fr/OAD.exe >
                                → Enregistre-le sur ton bureau
                                → Lancer 'OAD.exe' en faisant un double clique sur le fichier
                                → Saisir la valeur recherchée -> ' AdobeR.exe ' ( fait un copier/coller )
                                → Type de recherche : sélectionner l'option 6 puis valide [entrée]
                                → OAD va maintenant rechercher le fichier.
                                → Laisse-le travailler jusqu'à ce qu'il en ait terminé.
                                → Suivant la taille des disques durs, cette recherche peut prendre plusieurs minutes.

                                ------------- Patienter. --------------

                                → Le rapport de recherche s'affichera automatiquement dès qu'il en aura terminé.
                                → Faire un copier/coller de ce rapport dans ton prochain post.

                                (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                Note: Certains Antivirus peuvent émettre une alerte lors du téléchargement / utilisation > ignore

                                A++

                                1. j'ai oublié le second rapport clean, le voici:

                                  13/06/2008 a 17:45:20,50

                                  *** Recherche des fichiers dans C:

                                  *** Recherche des fichiers dans C:\WINDOWS\

                                  *** Recherche des fichiers dans C:\WINDOWS\system32

                                  *** Recherche des fichiers dans C:\Program Files
                                  1. rapport dss:

                                    Deckard's System Scanner v20071014.68
                                    Run by anne gaêlle on 2008-06-13 17:44:09
                                    Computer is in Normal Mode.
                                    --------------------------------------------------------------------------------

                                    -- HijackThis (run as anne gaêlle.exe) -----------------------------------------

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 17:44:15, on 13/06/2008
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Windows Defender\MsMpEng.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\WINDOWS\ehome\ehtray.exe
                                    C:\WINDOWS\RTHDCPL.EXE
                                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    C:\Program Files\QuickTime\qttask.exe
                                    C:\Program Files\Windows Defender\MSASCui.exe
                                    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                                    C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                                    C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
                                    C:\WINDOWS\system32\oopmagent.exe
                                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    C:\Program Files\Messenger\msmsgs.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                                    C:\WINDOWS\system32\WTablet\TabUserW.exe
                                    C:\WINDOWS\arservice.exe
                                    C:\Program Files\Mozilla Firefox\firefox.exe
                                    C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
                                    C:\WINDOWS\eHome\ehRecvr.exe
                                    C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
                                    C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                                    C:\WINDOWS\eHome\ehSched.exe
                                    C:\WINDOWS\System32\FTRTSVC.exe
                                    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                    C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
                                    C:\PROGRA~1\Wanadoo\ComComp.exe
                                    C:\WINDOWS\system32\nvsvc32.exe
                                    C:\PROGRA~1\Wanadoo\Toaster.exe
                                    C:\PROGRA~1\Wanadoo\Inactivity.exe
                                    C:\PROGRA~1\Wanadoo\PollingModule.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\Tablet.exe
                                    C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    C:\WINDOWS\system32\dllhost.exe
                                    C:\WINDOWS\system32\wscntfy.exe
                                    C:\WINDOWS\eHome\ehmsas.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                    C:\PROGRA~1\Wanadoo\Watch.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                    c:\windows\system\hpsysdrv.exe
                                    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                                    C:\Documents and Settings\anne gaêlle\Bureau\dss.exe
                                    C:\PROGRA~1\TRENDM~1\HIJACK~1\ANNEGA~1.EXE

                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pixaco.com/hpdesktop/redirect.aspx?source=hp-preinstallation&countryid=FR
                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                                    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
                                    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                                    O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
                                    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                    O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                                    O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                                    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                                    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
                                    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
                                    O4 - HKLM\..\Run: [ooquickpdfv7] "C:\WINDOWS\system32\oopmagent.exe"
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    O4 - HKCU\..\Run: [WOOKIT] C:\Program Files\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
                                    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                                    O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
                                    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                    O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
                                    O4 - Startup: Personal Player.lnk = C:\Program Files\Web Hottest Videos Personal Player\flash pro 8 fr_Web_Hottest_Videos_Personal_Player.exe
                                    O4 - Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE
                                    O4 - Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe
                                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                                    O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
                                    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                                    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\shdocvw.dll
                                    O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                                    O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                                    O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
                                    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                                    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                                    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                                    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                                    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logishrd\lvmvfm\LVPrcSrv.exe
                                    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                    O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
                                    1. rapport clean en mode sans échec:

                                      Script execute en mode sans echec
                                      Rapport clean par Malekal_morte - http://www.malekal.com
                                      Script execute en mode sans echec 13/06/2008 a 17:32:30,76

                                      Microsoft Windows XP [version 5.1.2600]

                                      *** Suppression des fichiers dans C:

                                      *** Suppression des fichiers dans C:\WINDOWS\

                                      *** Suppression des fichiers dans C:\WINDOWS\system32

                                      *** Suppression des fichiers dans C:\Program Files

                                      *** Suppression des clefs du registre effectuee..
                                      *** Fin du rapport !
                                      • 1
                                      • 2
                                      • 3