Virus sans aucun solution

Bonjour,

depuis quelque semaine j'ai un verus sur mon ordinateur que je n'arrive plus a m'en debarasser malgré l'utilisation de plusieurs utilities de scan anti virus comme spywarefoctor ou lavasoft adawre
.

j'ai pris une snapshot de l'alert que l'anitivirus ESET NOD32 m'envoie tous les 5 minute :
http://www.4wfi.com/sshot-20.png

le problem si que dés cette alerte, le navigateur se bloque pour 5 minute et ma connection adsl montre un voulme de transmission de donné maximum alors que je transmis ne rien du tous.
je pense que ce virus collecte des information et l'envoie tous les 5 minutes.

.
Configuration: Windows XP
Internet Explorer 7.0

27 réponses

Résumé de la discussion

Un utilisateur signale une infection suspectée sur Windows XP, avec ESET NOD32 qui émet des alertes récurrentes et un navigateur bloqué toutes les cinq minutes, soupçonnant une exfiltration de données. Plusieurs utilitaires de détection n'ont pas éliminé le problème, et des captures d'écran d'alertes et des journaux montrent des composants potentiellement malveillants dans le démarrage et les processus. Les éléments répertoriés lors du diagnostic incluent des BHO et des services suspects, des programmes comme Ad-Aware et des outils d'exploit, suggérant une infection complexe et un démarrage global. D'autres éléments mentionnés incluent des fichiers DLL mal identifiés et des entrées de registre potentiellement modifiées, indiquant la nécessité d'outils spécialisés et d'un nettoyage approfondi hors ligne.

Bobot (l’IA à votre service)
  1. ok

    fais ça aussi

    Télécharge cet outil de SiRi:

    http://siri.urz.free.fr/RHosts.php

    Double cliquer dessus pour l'exécuter

    et cliquer sur " Restore original Hosts "

    ps : c est normal que rien ne se passe

    et redémarre le pc
    1. ouyi les alerts continue l'un deux le message est
      le site a été bloquer
      http://undkredit.info/bot.php/users=01254540000000
      ip adress 58.65.237.17:80
      1. ce fichier s accroche

        réouvre hijackthis
        fais scan only
        coches cette lignes :

        O2 - BHO: (no name) - {ACC51D34-1F0C-452F-AD37-6817A32DD737} - C:\WINDOWS\system32\dpla.dll

        et clic sur fix checked

        ensuite redémarre le pc (important) et refais un scan hijackthis et post le rapport stp
        1. LoadLibrary failed for C:\WINDOWS\system32\dpla.dll
          C:\WINDOWS\system32\dpla.dll NOT unregistered.
          File move failed. C:\WINDOWS\system32\dpla.dll scheduled to be moved on reboot.

          OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07102008_225724

          Files moved on Reboot...
          LoadLibrary failed for C:\WINDOWS\system32\dpla.dll
          C:\WINDOWS\system32\dpla.dll NOT unregistered.
          File move failed. C:\WINDOWS\system32\dpla.dll scheduled to be moved on reboot.
          1. Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 22:59:07, on 10/07/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16574)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\hkcmd.exe
            C:\WINDOWS\SOUNDMAN.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\AutoMate 6\AMTS.exe
            C:\Program Files\AutoMate 6\AMEM.exe
            C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
            C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
            C:\Program Files\Free Download Manager\fdm.exe
            C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
            C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\Notepad++\notepad++.exe
            C:\PROGRA~1\MSNGAM~1\Windows\zclientm.exe
            C:\Program Files\Offline Explorer Enterprise\OE.exe
            C:\Program Files\FileZilla\FileZilla.exe
            C:\WINDOWS\system32\NOTEPAD.EXE
            C:\WINDOWS\system32\NOTEPAD.EXE
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
            C:\Program Files\Crazy Browser\Crazy Browser.exe
            C:\WINDOWS\system32\ctfmon.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: (no name) - {ACC51D34-1F0C-452F-AD37-6817A32DD737} - C:\WINDOWS\system32\dpla.dll
            O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
            O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
            O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
            O4 - HKLM\..\Run: [AutoMate6] C:\Program Files\AutoMate 6\AMEM.exe
            O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
            O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
            O4 - HKLM\..\Run: [smtpsrv] C:\Program Files\Local SMTP Server Pro\SMTPServer.exe
            O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
            O4 - HKLM\..\RunOnce: [OTScanIt] C:\OTMoveIt2.exe
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
            O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
            O4 - Global Startup: Action Manager 32.lnk = C:\Program Files\ScannerU\AM32.exe
            O4 - Global Startup: DSLMON.lnk = ?
            O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
            O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
            O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
            O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
            O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
            O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
            O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
            O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
            O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
            O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
            O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
            O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
            O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
            O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
            O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
            O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
            O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
            O17 - HKLM\System\CCS\Services\Tcpip\..\{58B2C714-81CC-4F8C-8472-851B66BFF439}: NameServer = 212.217.0.3 196.217.246.210
            O17 - HKLM\System\CS1\Services\Tcpip\..\{58B2C714-81CC-4F8C-8472-851B66BFF439}: NameServer = 212.217.0.3 196.217.246.210
            O18 - Filter: text/plain - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urunon.dll
            O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
            O23 - Service: AutoMate 6 (AutoMate6) - Network Automation, Inc. - C:\Program Files\AutoMate 6\AMTS.exe
            O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
            O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
            O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
            O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
            1. réouvre hijackthis
              fais scan only
              coche ces lignes :

              O2 - BHO: (no name) - {ACC51D34-1F0C-452F-AD37-6817A32DD737} - C:\WINDOWS\system32\dpla.dll

              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RESEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

              tu les coches et tu clic sur fix checked

              ensuite :

              double-clique sur OTMoveIt.exe pour le lancer.
              copie la liste qui se trouve en gras ci-dessous,
              et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

              C:\WINDOWS\system32\dpla.dll

              clique sur MoveIt! pour lancer la suppression.
              le résultat apparaitra dans le cadre "Results".
              clique sur Exit pour fermer.
              poste le rapport situé dans C:\_OTMoveIt\MovedFiles. + un nouveau rapport hijackthis stp

              il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

              toujours des alertes ??
              1. le rapport hijackthis

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 22:29:42, on 10/07/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\hkcmd.exe
                C:\WINDOWS\SOUNDMAN.EXE
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\AutoMate 6\AMTS.exe
                C:\Program Files\AutoMate 6\AMEM.exe
                C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Free Download Manager\fdm.exe
                C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                C:\WINDOWS\system32\wuauclt.exe
                C:\Program Files\Notepad++\notepad++.exe
                C:\PROGRA~1\MSNGAM~1\Windows\zclientm.exe
                C:\Program Files\Offline Explorer Enterprise\OE.exe
                C:\Program Files\Crazy Browser\Crazy Browser.exe
                C:\Program Files\FileZilla\FileZilla.exe
                C:\WINDOWS\system32\NOTEPAD.EXE
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: (no name) - {ACC51D34-1F0C-452F-AD37-6817A32DD737} - C:\WINDOWS\system32\dpla.dll
                O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
                O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
                O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
                O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                O4 - HKLM\..\Run: [AutoMate6] C:\Program Files\AutoMate 6\AMEM.exe
                O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                O4 - HKLM\..\Run: [smtpsrv] C:\Program Files\Local SMTP Server Pro\SMTPServer.exe
                O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
                O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RESEAU')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                O4 - Global Startup: Action Manager 32.lnk = C:\Program Files\ScannerU\AM32.exe
                O4 - Global Startup: DSLMON.lnk = ?
                O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
                O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
                O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
                O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
                O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
                O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
                O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
                O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
                O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                O17 - HKLM\System\CCS\Services\Tcpip\..\{58B2C714-81CC-4F8C-8472-851B66BFF439}: NameServer = 212.217.0.3 196.217.246.210
                O17 - HKLM\System\CS1\Services\Tcpip\..\{58B2C714-81CC-4F8C-8472-851B66BFF439}: NameServer = 212.217.0.3 196.217.246.210
                O18 - Filter: text/plain - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urunon.dll
                O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                O23 - Service: AutoMate 6 (AutoMate6) - Network Automation, Inc. - C:\Program Files\AutoMate 6\AMTS.exe
                O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
                O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
                O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
                1. ok ça donne quoi de ton coté ??

                  refais un scan hijackthis et post le rapport stp
                  1. le rapport nod32 (eset)

                    C:\pagefile.sys - error opening
                    C:\WINDOWS\system32\config\system.LOG - error opening
                    C:\WINDOWS\system32\config\software.LOG - error opening
                    C:\WINDOWS\system32\config\default.LOG - error opening
                    C:\WINDOWS\system32\config\SAM.LOG - error opening
                    C:\WINDOWS\system32\config\SECURITY.LOG - error opening
                    C:\WINDOWS\system32\config\SECURITY - error opening
                    C:\WINDOWS\system32\config\SOFTWARE - error opening
                    C:\WINDOWS\system32\config\SYSTEM - error opening
                    C:\WINDOWS\system32\config\DEFAULT - error opening
                    C:\WINDOWS\system32\config\SAM - error opening
                    C:\WINDOWS\system32\drivers\gvvmnjrv.dat - error opening
                    C:\WINDOWS\system32\drivers\sptd.sys - error opening
                    C:\WINDOWS\vf_hip\chrome.manifest » MIME - is OK (internal scanning not performed)
                    C:\WINDOWS\SoftwareDistribution\Download\f3f2705b5fdfd9264b7123a2d283e06d\update\eula.txt » MIME - is OK (internal scanning not performed)
                    C:\WINDOWS\SoftwareDistribution\Download\5f51a5d334ac80a2988bd8848bc695cb\update\eula.txt » MIME - is OK (internal scanning not performed)
                    C:\WINDOWS\SoftwareDistribution\Download\7c43cf31471ac5c8600409a70e40c22f\update\eula.txt » MIME - is OK (internal scanning not performed)
                    C:\WINDOWS\SoftwareDistribution\Download\3785f1ad0230e231b0e7dc1f4bb81cd1\update\eula.txt » MIME - is OK (internal scanning not performed)
                    C:\WINDOWS\SoftwareDistribution\Download\edcc3f7164a381fb0912c47bc6b94ca4\update\eula.txt » MIME - is OK (internal scanning not performed)
                    C:\WINDOWS\SoftwareDistribution\Download\d3c181d971d83bacdf1ae12100584248\update\eula.txt » MIME - is OK (internal scanning not performed)
                    C:\WINDOWS\SoftwareDistribution\Download\60ed62953e03ee5bf235cba11ef6e53b\BIT7C.tmp » CAB » _sfx_0009._p - archive damaged - the file could not be extracted.
                    C:\WINDOWS\SoftwareDistribution\Download\60ed62953e03ee5bf235cba11ef6e53b\BIT7C.tmp » CAB » _sfx_0005._p - archive damaged - the file could not be extracted.
                    C:\WINDOWS\SoftwareDistribution\Download\60ed62953e03ee5bf235cba11ef6e53b\BIT7C.tmp » CAB » _sfx_0003._p - archive damaged - the file could not be extracted.
                    C:\WINDOWS\SoftwareDistribution\Download\60ed62953e03ee5bf235cba11ef6e53b\BIT7C.tmp » CAB » _sfx_0008._p - archive damaged - the file could not be extracted.
                    C:\WINDOWS\SoftwareDistribution\Download\60ed62953e03ee5bf235cba11ef6e53b\BIT7C.tmp » CAB » _sfx_0001._p - archive damaged - the file could not be extracted.
                    C:\WINDOWS\SoftwareDistribution\Download\60ed62953e03ee5bf235cba11ef6e53b\BIT7C.tmp » CAB » _sfx_0000._p - archive damaged - the file could not be extracted.
                    C:\WINDOWS\SoftwareDistribution\Download\60ed62953e03ee5bf235cba11ef6e53b\BIT7C.tmp » CAB » _sfx_0006._p - archive damaged - the file could not be extracted.
                    C:\WINDOWS\SoftwareDistribution\Download\60ed62953e03ee5bf235cba11ef6e53b\BIT7C.tmp » CAB » _sfx_0012._p - archive damaged - the file could not be extracted.
                    C:\WINDOWS\SoftwareDistribution\Download\60ed62953e03ee5bf235cba11ef6e53b\BIT7C.tmp » CAB » _sfx_0007._p - archive damaged - the file could not be extracted.
                    C:\WINDOWS\SoftwareDistribution\Download\60ed62953e03ee5bf235cba11ef6e53b\BIT7C.tmp » CAB » _sfx_0011._p - archive damaged - the file could not be extracted.
                    C:\WINDOWS\SoftwareDistribution\Download\60ed62953e03ee5bf235cba11ef6e53b\BIT7C.tmp » CAB » _sfx_0004._p - archive damaged - the file could not be extracted.
                    C:\WINDOWS\SoftwareDistribution\Download\60ed62953e03ee5bf235cba11ef6e53b\BIT7C.tmp » CAB » _sfx_0002._p - archive damaged - the file could not be extracted.
                    C:\WINDOWS\SoftwareDistribution\Download\60ed62953e03ee5bf235cba11ef6e53b\BIT7C.tmp » CAB » _sfx_0010._p - archive damaged - the file could not be extracted.
                    C:\WINDOWS\SoftwareDistribution\Download\06119f7f007fbf3388fb7f012fd2ce49\update\eula.txt » MIME - is OK (internal scanning not performed)
                    C:\WINDOWS\SoftwareDistribution\Download\fde0566446f6dd640c536f419fe1216a\update\eula.txt » MIME - is OK (internal scanning not performed)
                    C:\WINDOWS\SoftwareDistribution\Download\c8f95ed251aedea843abb9ea5b1a52d3\update\eula.txt » MIME - is OK (internal scanning not performed)
                    C:\WINDOWS\SoftwareDistribution\Download\46faa4cd5c82200be099d1b1e8a12eed\update\eula.txt » MIME - is OK (internal scanning not performed)
                    C:\WINDOWS\SoftwareDistribution\Download\287a58cb69d3630207800fd4dd011739\update\eula.txt » MIME - is OK (internal scanning not performed)
                    C:\WINDOWS\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}\eula.txt » MIME - is OK (internal scanning not performed)
                    C:\WINDOWS\$hf_mig$\KB898461\update\eula.txt » MIME - is OK (internal scanning not performed)
                    C:\Documents and Settings\NetworkService\ntuser.dat.LOG - error opening
                    C:\Documents and Settings\NetworkService\NTUSER.DAT - error opening
                    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - error opening
                    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat - error opening
                    C:\Documents and Settings\LocalService\ntuser.dat.LOG - error opening
                    C:\Documents and Settings\LocalService\NTUSER.DAT - error opening
                    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - error opening
                    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat - error opening
                    C:\Documents and Settings\Administrateur\ntuser.dat.LOG - error opening
                    C:\Documents and Settings\Administrateur\ntuser.dat - error opening
                    C:\Documents and Settings\Administrateur\Local Settings\Temp\wutftjqn.dat - error opening
                    C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - error opening
                    C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat - error opening
                    C:\Documents and Settings\Administrateur\Local Settings\Application Data\Identities\{7D5C7F1F-B996-4B4D-A618-E659AFA7F637}\Microsoft\Outlook Express\Boîte de réception.dbx » DBX - is OK (internal scanning not performed)
                    C:\Documents and Settings\Administrateur\Local Settings\Application Data\Identities\{7D5C7F1F-B996-4B4D-A618-E659AFA7F637}\Microsoft\Outlook Express\Brouillons.dbx » DBX - is OK (internal scanning not performed)
                    C:\Documents and Settings\Administrateur\Mes documents\Computer.mht » MIME - is OK (internal scanning not performed)
                    C:\Documents and Settings\Administrateur\Mes documents\TigerDirect.mht » MIME - is OK (internal scanning not performed)
                    C:\Program Files\Fichiers communs\DFX\Skins\Obsidian\Obsidian.exe » NSIS - bad archive
                    C:\Program Files\Fichiers communs\DFX\Skins\Obsidian_mini\Obsidian_mini.exe » NSIS - bad archive
                    C:\Program Files\Fichiers communs\DFX\Skins\SoundFX\SoundFX.exe » NSIS - bad archive
                    C:\Program Files\Windows Media Player\eula.txt » MIME - is OK (internal scanning not performed)
                    C:\Program Files\SlimBrowser\sbrowser.chm » CHM » /replace.js » MIME - is OK (internal scanning not performed)
                    C:\Program Files\Siber Systems\AI RoboForm\license-es.txt » MIME - is OK (internal scanning not performed)
                    C:\Program Files\Siber Systems\AI RoboForm\license-it.txt » MIME - is OK (internal scanning not performed)
                    C:\Program Files\RSS Submit\submitok\www.poupeebarbie.com____61____StrategicBoard.HTML » MIME - is OK (internal scanning not performed)
                    C:\Program Files\Nvu\chrome\installed-chrome.txt » MIME - is OK (internal scanning not performed)
                    C:\Program Files\Nero\Nero Core\CDI\CDI_VCD.CFG » MIME - is OK (internal scanning not performed)
                    C:\Program Files\Free Download Manager\Firefox\extension\chrome.manifest » MIME - is OK (internal scanning not performed)
                    C:\Program Files\AllSubmitter\cacheallsubmitter\google.com.mht » MIME - is OK (internal scanning not performed)
                    C:\Program Files\Real\RealPlayer\browserrecord\chrome.manifest » MIME - is OK (internal scanning not performed)
                    C:\Program Files\Netscape\Navigator 9\chrome\browser.manifest » MIME - is OK (internal scanning not performed)
                    C:\Program Files\Netscape\Navigator 9\chrome\comm.manifest » MIME - is OK (internal scanning not performed)
                    C:\Program Files\Netscape\Navigator 9\chrome\pippki.manifest » MIME - is OK (internal scanning not performed)
                    C:\Program Files\Netscape\Navigator 9\chrome\toolkit.manifest » MIME - is OK (internal scanning not performed)
                    C:\Program Files\Qualcomm\Eudora\private_mails.mbx » MIME - is OK (internal scanning not performed)
                    C:\Program Files\Local SMTP Server Pro\readme.txt » MIME - is OK (internal scanning not performed)
                    C:\System Volume Information\_restore{97145BD0-F5A6-4741-9358-52118D4BDE5C}\RP252\A0084696.manifest » MIME - is OK (internal scanning not performed)
                    C:\System Volume Information\_restore{97145BD0-F5A6-4741-9358-52118D4BDE5C}\RP261\A0086737.exe - probably a variant of Win32/Spy.Agent.NET trojan - cleaned by deleting - quarantined
                    D:\Program Files\Softomate\ToolbarStudio\schema\help\desc_button_command.txt » MIME - is OK (internal scanning not performed)
                    D:\Program Files\Softomate\ToolbarStudio\schema\help\desc_commands_shellexecute_notfound.txt » MIME - is OK (internal scanning not performed)
                    D:\Program Files\Softomate\ToolbarStudio\schema\help\desc_commands_webjump_newwin.txt » MIME - is OK (internal scanning not performed)
                    D:\Program Files\Softomate\ToolbarStudio\schema\help\desc_commands_webjump_parseevents.txt » MIME - is OK (internal scanning not performed)
                    D:\Program Files\Softomate\ToolbarStudio\schema\help\desc_item_command.txt » MIME - is OK (internal scanning not performed)
                    D:\Program Files\_bounces\05def.txt » MIME - is OK (internal scanning not performed)
                    D:\Program Files\_bounces\06def.txt » MIME - is OK (internal scanning not performed)
                    D:\Program Files\_bounces\07def.txt » MIME - is OK (internal scanning not performed)
                    D:\Program Files\_bounces\08def.txt » MIME - is OK (internal scanning not performed)
                    D:\Program Files\_bounces\09def.txt » MIME - is OK (internal scanning not performed)
                    D:\Program Files\_bounces\11def.txt » MIME - is OK (internal scanning not performed)
                    D:\Program Files\_bounces\12def.txt » MIME - is OK (internal scanning not performed)
                    1. le rapport de clean

                      Script execute en mode sans echec
                      Rapport clean par Malekal_morte - http://www.malekal.com
                      Script execute en mode sans echec 10/07/2008 a 13:30:43,76

                      Microsoft Windows XP [version 5.1.2600]

                      *** Suppression des fichiers dans C:

                      *** Suppression des fichiers dans C:\WINDOWS\

                      *** Suppression des fichiers dans C:\WINDOWS\system32

                      *** Suppression des fichiers dans C:\Program Files
                      tentative de suppression de C:\PROGRA~1\PERFEC~1\

                      *** Suppression des clefs du registre effectuee..
                      1. -> Redémarre en mode sans échec :

                        Comment redémarrer en mode sans echec?

                        Tu redemarre le pc et tapote la touche F8 des le début de l allumage sans t´arrêter.
                        Une fenêtre sur fond noir va s’ouvrir, tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                        Une fois sur le bureau si il n y a pas toutes les couleurs et autres c´est normal!
                        Ps : si F8 ne marche pas utilise la touche F5.

                        -> Une fois en mode sans echec, ouvre le dossier que tu auvais crée et click sur clean.cmd et choisis l'option 2.

                        -> Redémarre normalement et poste le rapport de clean.

                        ensuite je voudras que tu fasse un scan complet de ta machine avec nod32 (eset) et que tu envoi le rapport sur le forum stp

                        @+
                        1. voici le rapport

                          10/07/2008 a 13:05:29,85

                          *** Recherche des fichiers dans C:

                          *** Recherche des fichiers dans C:\WINDOWS\

                          *** Recherche des fichiers dans C:\WINDOWS\system32

                          *** Recherche des fichiers dans C:\Program Files
                          C:\PROGRA~1\PERFEC~1\ FOUND
                          1. OK

                            réouvre malewarebyte
                            va sur quarantaine
                            supprime tout

                            ensuite

                            Télécharge clean.zip, de Malekal
                            http://www.malekal.com/download/clean.zip

                            (1) Dézippe-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.

                            (2) Ouvre le dossier clean qui se trouve sur ton bureau, et double-clic sur clean.cmd

                            une fenêtre noire va apparaître pendant un instant, laisse la ouverte.

                            (3) Choisis l'option 1 puis patiente
                            Poste le rapport obtenu

                            pour retrouver le rapport : double clique sur > C > double clique sur " rapport_clean txt.
                            et copie/colle le sur ta prochaine réponse .

                            Ne passe pas à l'option 2 sans notre avis !
                            1. je m'excuse pour le retard depuis hier

                              voici le log

                              Malwarebytes' Anti-Malware 1.20
                              Database version: 935
                              Windows 5.1.2600 Service Pack 2

                              00:16:05 10/07/2008
                              mbam-log-7-10-2008 (00-16-05).txt

                              Scan type: Full Scan (C:\|D:\|)
                              Objects scanned: 441967
                              Time elapsed: 1 hour(s), 30 minute(s), 38 second(s)

                              Memory Processes Infected: 0
                              Memory Modules Infected: 0
                              Registry Keys Infected: 0
                              Registry Values Infected: 4
                              Registry Data Items Infected: 0
                              Folders Infected: 0
                              Files Infected: 1

                              Memory Processes Infected:
                              (No malicious items detected)

                              Memory Modules Infected:
                              (No malicious items detected)

                              Registry Keys Infected:
                              (No malicious items detected)

                              Registry Values Infected:
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Delete on reboot.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Delete on reboot.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Delete on reboot.
                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Delete on reboot.

                              Registry Data Items Infected:
                              (No malicious items detected)

                              Folders Infected:
                              (No malicious items detected)

                              Files Infected:
                              D:\software\Trial-Reset_v3[1].0_RC9\Plugins\SlySoft.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
                              1. ok

                                on continue :

                                Telecharge malwarebytes

                                -> http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                                Tu l´instale; le programme va se mettre automatiquement a jour.

                                Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

                                Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

                                Puis click sur "rechercher".

                                Laisse le scanner le pc...

                                Si des elements on ete trouvés > click sur supprimer la selection.

                                si il t´es demandé de redemarrer > click sur "yes".

                                A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

                                Copie et colle le rapport stp.

                                ps : les rapport sont aussi rangé dans l onglet rapport/log
                                1. lorsque je clique sur move it le program me repond C:\WINDOWS\system32\dpla.dll n'est pas une image windows valide

                                  voici un log du program apres redemarage

                                  File/Folder not found.
                                  File move failed. C:\WINDOWS\system32\dpla.dll scheduled to be moved on reboot.
                                  File/Folder not found.

                                  OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07092008_221338

                                  Files moved on Reboot...
                                  LoadLibrary failed for C:\WINDOWS\system32\dpla.dll
                                  C:\WINDOWS\system32\dpla.dll NOT unregistered.
                                  File move failed. C:\WINDOWS\system32\dpla.dll scheduled to be moved on reboot.

                                  voici le nouveau hijackthis:

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 22:30:09, on 09/07/2008
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\AutoMate 6\AMTS.exe
                                  C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                                  C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                                  C:\WINDOWS\Explorer.EXE
                                  C:\WINDOWS\notepad.exe
                                  C:\WINDOWS\system32\hkcmd.exe
                                  C:\WINDOWS\SOUNDMAN.EXE
                                  C:\Program Files\AutoMate 6\AMEM.exe
                                  C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                                  C:\Program Files\Local SMTP Server Pro\SMTPServer.exe
                                  C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
                                  C:\WINDOWS\system32\wuauclt.exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\Program Files\Messenger\msmsgs.exe
                                  C:\Program Files\Free Download Manager\fdm.exe
                                  C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                                  C:\Program Files\Crazy Browser\Crazy Browser.exe
                                  C:\WINDOWS\system32\NOTEPAD.EXE
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: (no name) - {ACC51D34-1F0C-452F-AD37-6817A32DD737} - C:\WINDOWS\system32\dpla.dll
                                  O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
                                  O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
                                  O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
                                  O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                  O4 - HKLM\..\Run: [AutoMate6] C:\Program Files\AutoMate 6\AMEM.exe
                                  O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                                  O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                  O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                                  O4 - HKLM\..\Run: [smtpsrv] C:\Program Files\Local SMTP Server Pro\SMTPServer.exe
                                  O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
                                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                  O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
                                  O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
                                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RESEAU')
                                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                  O4 - Global Startup: Action Manager 32.lnk = C:\Program Files\ScannerU\AM32.exe
                                  O4 - Global Startup: DSLMON.lnk = ?
                                  O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
                                  O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
                                  O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                                  O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
                                  O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
                                  O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
                                  O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
                                  O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
                                  O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                  O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                                  O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
                                  O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                                  O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                                  O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                                  O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                                  O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                                  O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                                  O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                  O17 - HKLM\System\CCS\Services\Tcpip\..\{58B2C714-81CC-4F8C-8472-851B66BFF439}: NameServer = 212.217.0.3 196.217.246.210
                                  O17 - HKLM\System\CS1\Services\Tcpip\..\{58B2C714-81CC-4F8C-8472-851B66BFF439}: NameServer = 212.217.0.3 196.217.246.210
                                  O18 - Filter: text/plain - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urunon.dll
                                  O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                  O23 - Service: AutoMate 6 (AutoMate6) - Network Automation, Inc. - C:\Program Files\AutoMate 6\AMTS.exe
                                  O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
                                  O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                  O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
                                  O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
                                  1. * Télécharge OTMoveIt2 (de Old_Timer) sur ton bureau : http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe

                                    n´y touche pas

                                    redemarre en mode sans echec:

                                    Comment redémarrer en mode sans echec?

                                    Tu redemarre le pc et tapote la touche F8 des le début de l allumage sans t´arrêter.
                                    Une fenêtre sur fond noir va s’ouvrir, tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                                    capture d´ecran : http://www.coupdepoucepc.com/
                                    Une fois sur le bureau si il n y a pas toutes les couleurs et autres c´est normal!
                                    Ps : si F8 ne marche pas utilise la touche F5.

                                    Note : en mode sans echec tu n´auras plus acces au net alors imprime ou copie les instructions ci dessous dans un fichier texte que tu pourras consulter a souhait
                                    une fois en mode sans echec.

                                    Fix.reg

                                    Ouvre le bloc-notes (click droit sur le bureau > dans l´arborescence choisie nouveau et nouveau fichier texte) et fais un copier coller de ce qui est en citation ci-dessous (copie tout d'un trait-sans les barres(x)) :

                                    XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
                                    REGEDIT4

                                    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ACC51D34-1F0C-452F-AD37-6817A32DD737}]

                                    XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
                                    Note : Regedit4 est sur la premiere ligne dans le bloc note et il y a une ligne blanche a la fin.
                                    Puis click sur "fichier"/"enregistrer sous" :
                                    dans : sur le bureau
                                    Nom du fichier : fix.reg
                                    Type de fichier : "tous les fichiers"
                                    clique sur "enregistrer"

                                    ca doit ressembler a ca une fois enrregistré :

                                    http://img520.imageshack.us/img520/4251/screenshot005ps2.png

                                    double clique sur fix.reg => tu dois obligatoirement avoir un message "voulez-vous vraiment ajouter les informations contenues dans ce fichier .reg au registre ?"
                                    Si c'est bien le cas, clique sur "oui"

                                    * Double-clique sur OTMoveIt.exe pour lancer le programme,
                                    * Copie la liste de fichiers ou de dossiers ci-dessous et colle-la dans la fenêtre du programme "Paste Custom List of Files/Folders to Move" :

                                    C:\WINDOWS\system32\dpla.dll

                                    * Clique sur MoveIt! pour lancer la suppression,
                                    * Le résultat appraraîtra dans le cadre Results.
                                    * Clique sur Exit pour fermer le programme.
                                    * Poste le rapport qui est situé ici : C:\\\_OTMoveIt\MovedFiles
                                    * Il te sera peut-être demandé de redémarrer ton PC. Dans ce cas, clique sur Yes.

                                    Redemarre normalement et post le rapport de ot_move it ici stp ainsi qu´un nouveau rapport hijack this.

                                    1. et HijackThis

                                      Logfile of Trend Micro HijackThis v2.0.2
                                      Scan saved at 21:26:06, on 09/07/2008
                                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                                      MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                                      Boot mode: Normal

                                      Running processes:
                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\Program Files\AutoMate 6\AMTS.exe
                                      C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                                      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                                      C:\WINDOWS\system32\hkcmd.exe
                                      C:\WINDOWS\SOUNDMAN.EXE
                                      C:\Program Files\AutoMate 6\AMEM.exe
                                      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                                      C:\WINDOWS\system32\ctfmon.exe
                                      C:\Program Files\Free Download Manager\fdm.exe
                                      C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                                      C:\WINDOWS\system32\taskmgr.exe
                                      C:\WINDOWS\system32\wuauclt.exe
                                      C:\WINDOWS\explorer.exe
                                      C:\WINDOWS\system32\notepad.exe
                                      C:\Program Files\Crazy Browser\Crazy Browser.exe
                                      C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
                                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                      O2 - BHO: (no name) - {ACC51D34-1F0C-452F-AD37-6817A32DD737} - C:\WINDOWS\system32\dpla.dll
                                      O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
                                      O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
                                      O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
                                      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                                      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                      O4 - HKLM\..\Run: [AutoMate6] C:\Program Files\AutoMate 6\AMEM.exe
                                      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                                      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                                      O4 - HKLM\..\Run: [smtpsrv] C:\Program Files\Local SMTP Server Pro\SMTPServer.exe
                                      O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
                                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                      O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
                                      O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
                                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RESEAU')
                                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                      O4 - Global Startup: Action Manager 32.lnk = C:\Program Files\ScannerU\AM32.exe
                                      O4 - Global Startup: DSLMON.lnk = ?
                                      O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
                                      O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
                                      O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                                      O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
                                      O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
                                      O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
                                      O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
                                      O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
                                      O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
                                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                      O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                                      O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
                                      O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                                      O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                                      O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                                      O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                                      O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                                      O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                                      O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                      O17 - HKLM\System\CCS\Services\Tcpip\..\{58B2C714-81CC-4F8C-8472-851B66BFF439}: NameServer = 212.217.0.3 196.217.246.210
                                      O17 - HKLM\System\CS1\Services\Tcpip\..\{58B2C714-81CC-4F8C-8472-851B66BFF439}: NameServer = 212.217.0.3 196.217.246.210
                                      O18 - Filter: text/plain - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urunon.dll
                                      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                      O23 - Service: AutoMate 6 (AutoMate6) - Network Automation, Inc. - C:\Program Files\AutoMate 6\AMTS.exe
                                      O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
                                      O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                      O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
                                      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
                                      1. et HijackThis

                                        Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 21:26:06, on 09/07/2008
                                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                                        MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                        C:\WINDOWS\system32\spoolsv.exe
                                        C:\Program Files\AutoMate 6\AMTS.exe
                                        C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                                        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                                        C:\WINDOWS\system32\hkcmd.exe
                                        C:\WINDOWS\SOUNDMAN.EXE
                                        C:\Program Files\AutoMate 6\AMEM.exe
                                        C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                                        C:\WINDOWS\system32\ctfmon.exe
                                        C:\Program Files\Free Download Manager\fdm.exe
                                        C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                                        C:\WINDOWS\system32\taskmgr.exe
                                        C:\WINDOWS\system32\wuauclt.exe
                                        C:\WINDOWS\explorer.exe
                                        C:\WINDOWS\system32\notepad.exe
                                        C:\Program Files\Crazy Browser\Crazy Browser.exe
                                        C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
                                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                        O2 - BHO: (no name) - {ACC51D34-1F0C-452F-AD37-6817A32DD737} - C:\WINDOWS\system32\dpla.dll
                                        O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
                                        O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
                                        O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
                                        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                                        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                        O4 - HKLM\..\Run: [AutoMate6] C:\Program Files\AutoMate 6\AMEM.exe
                                        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                                        O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                        O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                                        O4 - HKLM\..\Run: [smtpsrv] C:\Program Files\Local SMTP Server Pro\SMTPServer.exe
                                        O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
                                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                        O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
                                        O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
                                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RESEAU')
                                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                        O4 - Global Startup: Action Manager 32.lnk = C:\Program Files\ScannerU\AM32.exe
                                        O4 - Global Startup: DSLMON.lnk = ?
                                        O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
                                        O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
                                        O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                                        O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
                                        O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
                                        O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
                                        O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
                                        O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
                                        O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
                                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                        O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                                        O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
                                        O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                                        O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                                        O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                                        O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                                        O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                                        O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                                        O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                        O17 - HKLM\System\CCS\Services\Tcpip\..\{58B2C714-81CC-4F8C-8472-851B66BFF439}: NameServer = 212.217.0.3 196.217.246.210
                                        O17 - HKLM\System\CS1\Services\Tcpip\..\{58B2C714-81CC-4F8C-8472-851B66BFF439}: NameServer = 212.217.0.3 196.217.246.210
                                        O18 - Filter: text/plain - {DC186800-657F-11D4-B0B5-0050BABFC904} - C:\WINDOWS\system32\urunon.dll
                                        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                        O23 - Service: AutoMate 6 (AutoMate6) - Network Automation, Inc. - C:\Program Files\AutoMate 6\AMTS.exe
                                        O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
                                        O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                        O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
                                        O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
                                        • 1
                                        • 2