A l'aide pour Win32:Vapsup-EB

Bonjour,je viens d'être infectée par Win32:Vapsup-EB. Avast n'arrive ni à le mettre en quarantaine, ni à le supprimer.
Il y en avait un autre qui apparemment aurait disparu.
En regardant sur le forum, j'ai vu qu'il fallait poster un hijackthis, alors j'ai fait comme tout le monde (bien que je ne sache pas ce que c'est) et voilà donc mon rapport.

Merci à la personne qui dechiffrera ce charabia pour moi et qui m'expliquera ce qu'il faut ensuite que je fasse.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:34:38, on 16/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ICO.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\Sony\VAIO Launcher\Launcher.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\cmd.exe
C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\vistasp1.exe
C:\WINDOWS\system32\cmd.exe
C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\software.php
C:\WINDOWS\system32\cmd.exe
C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\software.php
C:\WINDOWS\system32\cmd.exe
C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\software.php
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Documents and Settings\Utilisateur\Bureau\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [PDService.exe] C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [lphc3f8j0eaaa] C:\WINDOWS\system32\lphc3f8j0eaaa.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Packard Bell Data Secure] C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'Default user')
O4 - .DEFAULT User Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'Default user')
O4 - Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Transfert par Image Converter 2 - C:\Program Files\Sony\Image Converter 2\menu.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0D335865-9DA4-416E-A859-5867151EF83D}: NameServer = 86.64.145.140 84.103.237.140
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

--
End of file - 14263 bytes
Configuration: Windows XP
Internet Explorer 6.0

20 réponses

Résumé de la discussion

Une infection Win32:Vapsup-EB est signalée sur Windows XP et Avast ne parvient pas à la quarantaine ni à la supprimer, le rapport HijackThis étant partagé pour analyse. La réponse recommandée propose d’utiliser SDFix, de redémarrer en mode sans échec et d’exécuter RunThis.bat pour supprimer les services nuisibles et nettoyer le registre du système. Le processus implique de suivre les invites et de redémarrer, puis de partager le nouveau rapport HijackThis et le rapport SDFix pour une analyse plus approfondie. Des conseils complémentaires rappellent de mettre à jour Internet Explorer et Java, ainsi que d'effectuer des scans réguliers et de vérifier les mises à jour des divers logiciels pour prévenir les infections.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Impec ^^

    Content d'avoir pu te rendre service =)

    -->dernières choses importantes :

    Tu devrais mettre à jour IE ( tu as l'ancienne version 6 ) et Java ( des versions pas à jour ont des failles de sécurité...) .
    Je te conseille donc de les mettre à jour:
    *IE 7 ici

    *et pour la console Java :
    aller sur : Démarrer > Panneau de configuration > Icône Java > onglet Mise à jour > "Mettre à jour maintenant" > cocher la case "Automatiser la détection des mises à jour".

    **********************************************************

    Des infos intéressante pour toi et ton PC :

    => Comportement à adopter avec son PC : http://assiste.com.free.fr/p/abc/a/safe_cex.html

    => Surveillance :
    Effectue des scan réguliers de surveillance (une fois tous les 15 jours, par exemple) avec ton antivirus puis avec ton anti-spyware (après les avoir mis à jour bien sur !) et supprime ce qu'ils peuvent trouver (où mets en quarantaine, en pensant à la vider ultérieurement).

    =========================================================================

    => Afin d’éviter les autres failles de sécurité des différents programmes présents sur ton PC :

    Vérifie tes mises à jours des différents softs régulièrement ici et mets à jour ce qui ne l’est pas. https://www.flexera.com/products/operations/software-vulnerability-management.html
    -Tuto https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/
    -Autre possibilité, t'abonner gratuitement a "la lettre hebdomadaire de secuser.com" ici http://www.secuser.com/ a gauche en bas de page.

    =========================================================================

    => Rappel sur les principales causes d'infection :

    * L'utilisation de cracks ou keygens est à proscrire, de même que le surf sur les sites de téléchargement de ceux-ci :

    Les dangers des cracks : http://forum.malekal.com/ftopic893.php

    Le crack dans toute sa splendeur, journal d'une infection attendue :
    https://forum.zebulon.fr/topic/93281-pr%C3%A9vention-le-crack-dans-toute-sa-splendeur/

    * Le P2P ( l'utilisation de logiciels comme eMule, Sharazaa, LimeWire, Bit torrent):

    Les conséquences du P2P : https://forum.zebulon.fr/topic/85544-pr%C3%A9vention-le-p2p-et-ses-cons%C3%A9quences/

    Pourquoi éviter le P2P : http://www.speedweb1.org/forum-tesgaz/viewtopic.php?t=1793
    https://lexpansion.lexpress.fr/actualite-economique/

    * Prévention sur deux autres types d'infection d'actualité :

    MSN prévention : https://forum.zebulon.fr/topic/130590-infection-par-msn-ou-wlm/

    Infection par supports amovibles (clefs usb, flash, DD externes ..) https://forum.zebulon.fr/topic/131959-infections-par-supports-amovibles/
    https://forum.malekal.com/viewtopic.php?f=45&t=5544

    =========================================================================

    => Pour optimiser un peu ton PC

    * Gère tes services grâce à ces 2 liens
    http://speedweb1.free.fr/frames2.php?page=service3 et http://speedweb1.free.fr/frames2.php?page=service4

    * Utilise Zeb Utility de Sebdraluorg
    une application ne nécessitant pas d’installation, pour optimiser un poil ton pc. (merci a l ami Zebulon)
    Téléchargement : https://www.zebulon.fr/telechargements/utilitaires/optimisation/zeb-utility.html
    Tuto : https://www.zebulon.fr/dossiers/autres/58-zebutility.html

    =========================================================================
    ( merci le sioux )

    Voili, voilou ....

    Bonne continuation à toi ... :)

    A+

    0
    1. Apparemment tout va mieux!!!! Je lance avast une dernière fois juste au cas ou...

      Tu m'avais dit d'afficher les fichiers en cache dans le post n°6, est-ce qu'il faut que je fasse la manip inverse?

      Merci beaucoup pour ta précieuse aide, je n'y serais jamais arrivée seule. Tes indications étaient très simples et très précises.
      0
      1. Contributeur sécurité
        tiens moi au courant du scan et on conclura ... ;)
        0
      2. @sKe69Tout est ok. Encore une fois mille mercis pour ton aide.
        0
    2. Contributeur sécurité
      Par contre Malwarebyte's est tjs présent sur mon bureau, je l'enlève dans ajout et suppression de programme?

      De plus, dans C:/, j'ai plein de trucs et je ne sais pas si je dois les garder ou pas.(UNWISE.exe, Bootfond.bin, NTDETECT.com, et des fichiers SQM)


      Malwarebytes :tu gardes ( très utile pour scanner de temps en temps to PC )

      Et pour C:\ --> touches à rien alors ... si tu ne sait pas ce que c'est ...

      Fait ce-ci pour finir :

      Restauration système
      *Désactives ta restauration :
      Cliques droit sur poste de travail/propriétés/Restauration système/coche la case désactiver la restauration, appliquer, OK
      --->Redémarres ton PC
      *Réactives ta restauration :
      Cliques droit sur poste de travail/propriétés/Restauration système/décoche la case désactiver la restauration, appliquer, OK
      --->Redémarres ton PC

      Puis dis moi si tout est Ok pour toi maintenant , le PC va mieux non ?
      0
      1. Contributeur sécurité
        Salut,

        refais la manipe en mode sans échec et postes moi le nouveau rapport ....

        Comment aller en Mode sans échec
        1) Redémarre ton ordi
        2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
        3) Tu verras un écran avec options de démarrage apparaître
        4) Choisis la première option : Sans Échec, et valide avec "Entrée"
        5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
        ( ps : n'oublies pas , en mode sans échec , pas de connexion ! Donc copies ou imprimes bien la manipe ... )
        0
        1. Refaire la manip, oui mais laquelle? Relancer avast en mode sans échec?
          0
        2. Contributeur sécurité
          @Glorialaisses courrir ce que je t'eai posté , j'm'a suis trompé de personne lol !!!

          Reprenons :

          -> Pour éviter certaine alertes d'avast ( qui sont du au outils que l'on as utliser en fait ^^ ) , tu vas faire ce-ci :

          1- Télécharges ToolsCleaner (de A.Rothstein) sur ton Bureau.
          http://pc-system.fr/

          Déconnectes toi et fermes bien toutes tes applications en cours .

          Lances le .
          *Cliques sur Recherche et laisses le scan se terminer (cela peut être long).
          *Cliques sur Suppression pour finaliser.
          *Tu peux, si tu le souhaites, te servir des Options facultatives
          *Click sur "quitter" pour générer un rapport :
          ---> Postes le (TCleaner.txt), il se trouve à la racine de ton disque dur (C:\).

          Note : Ce petit soft va te nettoyer tout les trucs dont on c'est servi pour la désinfection ( tu n'en as plus besion ! ) .
          Supprimes tout les outils , dossiers ou rapports consernant la désinfection que Toolsclaener2 n'a pas supprimé .

          2- Télécharges : - CCleaner
          https://www.pcastuces.com/logitheque/ccleaner.htm
          Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
          Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).

          Un tuto ( aide ):
          http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

          ---> Utilisation:
          vas dans "nettoyeur" : fait analyse puis nettoyage
          et vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .

          ( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )

          3- Fais un scan antivirus en ligne, avec Internet Explorer et accepter l'ActiveX :
          https://www.bitdefender.fr/
          (pour le rapport ,qui est un doc IE , clik sur l'onglet "plus de détailles" : et à la fin du scan tu demandes à le sauvegarder sur ton bureau)

          --->fais un copier/coller et postes le rapport dans ta prochaine réponse ...

          Aide : En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
          Dans la nouvelle fenêtre, clique sur j’accepte .
          La fenêtre change encore, clique sur scanner .
          Les signatures se chargent, etc ...

          Tutoriel en images ici : http://pageperso.aol.fr/rginformatique/mapage/defender.htm (merci à Balltrap34 pour cette réalisation)
          Et ici : http://www.commentcamarche.net/faq/sujet 8872 scanner en ligne avec bitdefender

          0
        3. @sKe69Rapport de Toolcleaner
          -->- Recherche:

          C:\SmitFraudFix.exe: trouvé !
          C:\SDFIX: trouvé !
          C:\SmitFraudfix: trouvé !
          C:\Qoobox: trouvé !
          C:\Documents and Settings\Utilisateur\Bureau\SdFix.exe: trouvé !
          C:\Documents and Settings\Utilisateur\Bureau\ComboFix.exe: trouvé !
          C:\Documents and Settings\Utilisateur\Bureau\HijackThis.exe: trouvé !
          C:\Documents and Settings\Utilisateur\Recent\HijackThis.lnk: trouvé !

          ---------------------------------
          -->- Suppression:

          C:\SmitFraudFix.exe: supprimé !
          C:\Documents and Settings\Utilisateur\Bureau\SdFix.exe: supprimé !
          C:\Documents and Settings\Utilisateur\Bureau\ComboFix.exe: supprimé !
          C:\Documents and Settings\Utilisateur\Bureau\HijackThis.exe: supprimé !
          C:\Documents and Settings\Utilisateur\Recent\HijackThis.lnk: supprimé !
          C:\SDFIX: supprimé !
          C:\SmitFraudfix: supprimé !
          C:\Qoobox: supprimé !

          Ensuite j'ai lancé Ccleaner et j'ai effacé toutes les erreurs.
          Enfin j'ai lancé Bitdefender qui n'a rien trouvé.

          Par contre Malwarebyte's est tjs présent sur mon bureau, je l'enlève dans ajout et suppression de programme?

          De plus, dans C:/, j'ai plein de trucs et je ne sais pas si je dois les garder ou pas.(UNWISE.exe, Bootfond.bin, NTDETECT.com, et des fichiers SQM)
          0
      2. Contributeur sécurité
        C'est ce qui me semblais ... rien de grave , on réglera cela tout à l'heure ....=)
        0
        1. Le virus en question est: Win 32:KdCrypt(cryp) ,qui se trouve dans:
          - C:\Systeme Volume Information\-restore(28B95B92-4ADC-47B5-B9D3-0B42A08FD847)\RP455\A0049014.exe\SDFix\apps\cliptext.exe
          - C:\Documents and settings\Utilisateur\Bureau\SDFix.exe\SDFix\apps\cliptext.exe

          Impossible de les mettre en quarantaine ou de les supprimer, avast dit que l'opération n'est pas supportée par ce type d'archive.

          A tout à l'heure.
          0
          1. Contributeur sécurité
            " Avast n'arrive pas à supprimer les virus qu'il trouve " --> dis moi exactement les noms et informations sur ces virus ...

            Je ne suis pas dispo pour l'instant et je te dis à tout à l'heure .... Une fois chez moi on poursuivra ;)
            0
            1. Plus de nouvelles de sKe69 qui m'a beaucoup aidé jusqu'à ce matin. Quelqu'un peut-il prendre le relais? J'ai posté mon dernier log Combofix, et je suis toujours infectée. Merci beaucoup.
              0
              1. Avast n'arrive pas à supprimer les virus qu'il trouve: il n'arrive ni à les supprimer ni à les mettre en quarantaine. Il y a aussi le ver "other-malware gen".
                0
                1. Voici le rapport. Merci pour ton aide et pour le temps que tu me consacres.

                  ComboFix 08-07-15.4 - Utilisateur 2008-07-17 11:02:45.1 - NTFSx86
                  Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.236 [GMT 2:00]
                  Endroit: C:\Documents and Settings\Utilisateur\Bureau\ComboFix.exe
                  * Création d'un nouveau point de restauration

                  [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                  .

                  ((((((((((((((((((((((((((((( Fichiers créés 2008-06-17 to 2008-07-17 ))))))))))))))))))))))))))))))))))))
                  .

                  2008-07-16 21:15 . 2008-07-16 21:36 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                  2008-07-16 21:15 . 2008-07-16 21:15 <REP> d-------- C:\Documents and Settings\Utilisateur\Application Data\Malwarebytes
                  2008-07-16 21:15 . 2008-07-16 21:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                  2008-07-16 21:15 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
                  2008-07-16 21:15 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                  2008-07-16 20:53 . 2008-07-16 20:53 1,478,367 --a------ C:\SmitfraudFix.exe
                  2008-07-16 19:43 . 2008-07-16 19:44 <REP> d-------- C:\WINDOWS\ERUNT
                  2008-07-16 18:24 . 2005-07-13 13:56 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
                  2008-07-16 18:24 . 2005-07-13 13:56 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
                  2008-07-16 18:24 . 2005-07-13 12:01 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
                  2008-07-16 18:24 . 2005-07-21 16:38 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
                  2008-07-16 18:24 . 2005-07-13 15:35 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
                  2008-07-16 18:24 . 2005-07-21 16:38 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
                  2008-07-16 18:24 . 2005-07-13 15:46 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
                  2008-07-16 18:24 . 2005-07-13 15:40 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
                  2008-07-16 18:24 . 2005-07-13 15:31 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Sony Corporation
                  2008-07-16 18:24 . 2008-07-16 18:24 <REP> d-------- C:\Documents and Settings\Administrateur
                  2008-07-16 17:53 . 2008-07-16 20:05 <REP> d-------- C:\SDFix
                  2008-07-16 16:38 . 2008-07-16 16:38 7,168 --ahs---- C:\WINDOWS\Thumbs.db
                  2008-06-20 19:41 . 2008-06-20 19:41 247,808 -----c--- C:\WINDOWS\system32\dllcache\mswsock.dll
                  2008-06-20 12:44 . 2008-06-20 12:44 138,368 -----c--- C:\WINDOWS\system32\dllcache\afd.sys

                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2008-07-17 06:45 --------- d-----w C:\Program Files\Packard Bell Data Secure
                  2008-07-16 18:55 4,356 ----a-w C:\WINDOWS\system32\tmp.reg
                  2008-07-16 14:39 --------- d-----w C:\Program Files\eMule
                  2008-07-16 14:38 --------- d-----w C:\Program Files\SLD Codec Pack
                  2008-07-16 14:38 --------- d-----w C:\Program Files\Moodlogic HTML
                  2008-07-16 14:38 --------- d-----w C:\Program Files\Microsoft Works
                  2008-07-16 14:38 --------- d-----w C:\Program Files\Microsoft Picture It! 9
                  2008-07-02 11:33 82,432 ----a-w C:\WINDOWS\system32\IEDFix.C.exe
                  2008-07-01 05:11 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Sony Corporation
                  2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
                  2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
                  2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
                  2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
                  2008-06-18 11:20 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\dvdcss
                  2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
                  2008-06-08 08:08 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
                  2008-06-05 18:56 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
                  2008-06-05 18:56 --------- d-----w C:\Program Files\Windows Live
                  2008-06-05 18:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
                  2008-05-29 07:35 86,528 ----a-w C:\WINDOWS\system32\VACFix.exe
                  2008-05-23 16:21 81,920 ----a-w C:\WINDOWS\system32\404Fix.exe
                  2008-05-18 19:40 82,944 ----a-w C:\WINDOWS\system32\IEDFix.exe
                  2008-05-18 16:22 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\Image Zone Express
                  2008-05-18 16:03 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\Sony Corporation
                  2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
                  2008-04-21 06:57 670,720 ----a-w C:\WINDOWS\system32\wininet.dll
                  2005-12-22 10:10 0 ----a-w C:\Documents and Settings\Utilisateur\Application Data\wklnhst.dat
                  .

                  ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  REGEDIT4
                  *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
                  "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-22 23:17 68856]
                  "Packard Bell Data Secure"="C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe" [2006-06-20 15:15 2361856]
                  "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
                  "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "Apoint"="C:\Program Files\Apoint\Apoint.exe" [2003-11-07 10:21 114688]
                  "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-06-09 09:56 6746112]
                  "AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-04-29 07:56 45056]
                  "Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-06-29 07:33 114688]
                  "SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [2005-05-15 05:51 184320]
                  "ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 14:12 32768]
                  "VAIO Update 2"="C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-01-14 13:43 151552]
                  "PDService.exe"="C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe" [2004-07-06 14:15 40960]
                  "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-29 07:33 94208]
                  "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-29 07:33 77824]
                  "Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2005-03-03 22:47 483328]
                  "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-12-27 16:08 98304]
                  "SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2005-06-03 08:16 81920]
                  "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 01:19 79224]
                  "MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2007-03-27 11:07 190024]
                  "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48 36975]
                  "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-05-29 19:15 180269]
                  "Microsoft Works Update Detection"="C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-10 19:49 50688]
                  "%FP%Friendly fts.exe"="C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe" [2003-05-06 09:28 72192]
                  "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 03:41 49152]
                  "RTHDCPL"="RTHDCPL.EXE" [2005-06-29 06:25 14720000 C:\WINDOWS\RTHDCPL.EXE]
                  "Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 16:46 45056 C:\WINDOWS\system32\ico.exe]

                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]

                  C:\Documents and Settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
                  VAIO Launcher.lnk - C:\Program Files\Sony\VAIO Launcher\Launcher.exe [2005-12-21 19:16:48 778240]

                  C:\Documents and Settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
                  VAIO Launcher.lnk - C:\Program Files\Sony\VAIO Launcher\Launcher.exe [2005-12-21 19:16:48 778240]

                  C:\Documents and Settings\Default User\Menu D‚marrer\Programmes\D‚marrage\
                  VAIO Launcher.lnk - C:\Program Files\Sony\VAIO Launcher\Launcher.exe [2005-12-21 19:16:48 778240]

                  C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                  HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 05:21:22 288472]
                  Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
                  LUMIX Simple Viewer.lnk - C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2007-05-26 12:57:41 57344]

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
                  2005-05-20 17:42 73728 C:\WINDOWS\system32\VESWinlogon.dll

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                  "AppInit_DLLs"=MsgPlusLoader.dll

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                  "VIDC.dvsd"= C:\PROGRA~1\FICHIE~1\SONYSH~1\VideoLib\sonydv.dll
                  "msacm.l3acm"= l3codecp.acm

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
                  --a------ 2006-01-03 13:13 19495464 C:\Program Files\Skype\Phone\Skype.exe

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                  "EnableFirewall"= 0 (0x0)

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "C:\\Program Files\\eMule\\emule.exe"=
                  "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
                  "C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
                  "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
                  "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
                  "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                  "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

                  R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
                  R1 PrivateDisk;PrivateDisk;C:\WINDOWS\system32\Drivers\PrivateDiskM.sys [2004-07-06 14:07]
                  R2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe [2004-10-12 04:47]
                  R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
                  R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 18:55]
                  R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe [2004-10-12 03:40]
                  R3 PPPoEWin;PPPoEWin Miniport;C:\WINDOWS\system32\DRIVERS\PPPoEWin.SYS [2003-09-25 16:52]
                  S3 2e33dbca-5e2c-4d93-b519-ccac6a68b13f;2e33dbca-5e2c-4d93-b519-ccac6a68b13f;F:\Player\cds300.dll []
                  S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Program Files\Sony\Image Converter 2\IcVzMon.exe [2005-04-05 14:06]
                  S3 PALLADIA;Palladia 300/400 Usb Adsl Modem;C:\WINDOWS\system32\DRIVERS\usbiad.sys [2005-06-13 06:57]
                  S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 18:23]
                  S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
                  S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{02bbaad4-165b-11db-a594-0014a43e1e5a}]
                  \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL protector.exe
                  \Shell\infected\command - G:\protector.exe

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2bcb1d38-8cfe-11db-a5e6-5050506f4531}]
                  \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL protector.exe
                  \Shell\infected\command - protector.exe

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{962c0fc4-873b-11dc-a70a-5050506f4531}]
                  \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL protector.exe
                  \Shell\infected\command - G:\protector.exe

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ad33516e-fae1-11db-a65a-5050506f4531}]
                  \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL protector.exe
                  \Shell\infected\command - protector.exe

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ee1da675-77c7-11da-a48c-0014a43e1e5a}]
                  \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL protector.exe
                  \Shell\infected\command - protector.exe

                  *Newly Created Service* - PROCEXP90
                  .
                  - - - - ORPHANS REMOVED - - - -

                  MSConfigStartUp-BitTorrent - C:\Program Files\BitTorrent\bittorrent.exe

                  **************************************************************************

                  catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-07-17 11:05:27
                  Windows 5.1.2600 Service Pack 2 NTFS

                  Balayage processus cachés ...

                  Balayage caché autostart entries ...

                  Balayage des fichiers cachés ...

                  Scan terminé avec succès
                  Les fichiers cachés: 0

                  **************************************************************************
                  .
                  Temps d'accomplissement: 2008-07-17 11:07:16
                  ComboFix-quarantined-files.txt 2008-07-17 09:06:58

                  Pre-Run: 6,937,329,664 octets libres
                  Post-Run: 6,996,983,808 octets libres

                  185 --- E O F --- 2008-07-16 19:22:45
                  0
                  1. Et je suis aussi infectée par Win 32 Zlod-AWS et un ver. Désolée de poster les infos au compte goutte mais elles n'arrivent pas toutes en même temps et j'essaie de livrer le maximum d'infos (puisque c'est la seule chose que je sache faire). Merci
                    0
                    1. Contributeur sécurité
                      Salut,
                      Fais exactement ce-ci :

                      Télécharges ComboFix (par sUBs) sur ton Bureau (et pas ailleur !):
                      http://download.bleepingcomputer.com/sUBs/ComboFix.exe <--- clik droit sur ce lien et choisis "enregistrer la cible sous ... " : dans la fenêtre qui s'ouvre tape C-Fix et valide .

                      --------------------------------------------- [ ! ATTENTION ! ] ----------------------------------------------------------
                      !! déconnectes toi,fermes tes applications en cours et DESACTIVES TOUTES TES DEFENCES (anti-virus, guardes anti spy-ware, pare-feu) le temps de la manipe :
                      en effet , activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil ( voir planter le PC )...Tu les réactiveras donc après !!
                      --->Important : si tu rencontres des difficultés à ce niveau là, fais m'en part avant de poursuivre ...
                      Tuto ( aide ) ici : http://www.bleepingcomputer.com/combofix/fr/comment-utiliser­-combofix
                      ------------------------------------------------------------­------------------------------------------------------------­---------

                      Ensuite :
                      double-cliques C-Fix.exe ( = combofix.exe ) .

                      Appuyes sur la touche Y (Yes) pour démarrer le scan .

                      Attention : n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.
                      ---> si un message d'erreur windows apparait à un momment : clik sur la croix rouge en haut à droite de la fenêtre pour la fermer ( et pas sur autre chose ! sinon pas de rapport ... )

                      Le rapport sera crée dans: C:\Combofix.txt

                      Postes le rapport Combofix pour analyse ...
                      0
                      1. Bon apparemment non parce que avast vient encore de me detecter un virus du nom de win32 Krypt quelque chose.
                        Que puis-je faire? Merci
                        0
                        1. Voici le rapport de Malwarebyte's:

                          Malwarebytes' Anti-Malware 1.20
                          Version de la base de données: 930
                          Windows 5.1.2600 Service Pack 2

                          07:09:09 17/07/2008
                          mbam-log-7-17-2008 (07-09-09).txt

                          Type de recherche: Examen complet (C:\|D:\|F:\|)
                          Eléments examinés: 115647
                          Temps écoulé: 5 hour(s), 16 minute(s), 35 second(s)

                          Processus mémoire infecté(s): 0
                          Module(s) mémoire infecté(s): 0
                          Clé(s) du Registre infectée(s): 1
                          Valeur(s) du Registre infectée(s): 1
                          Elément(s) de données du Registre infecté(s): 2
                          Dossier(s) infecté(s): 0
                          Fichier(s) infecté(s): 5

                          Processus mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Module(s) mémoire infecté(s):
                          (Aucun élément nuisible détecté)

                          Clé(s) du Registre infectée(s):
                          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

                          Valeur(s) du Registre infectée(s):
                          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphc3f8j0eaaa (Trojan.FakeAlert) -> Quarantined and deleted successfully.

                          Elément(s) de données du Registre infecté(s):
                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
                          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                          Dossier(s) infecté(s):
                          (Aucun élément nuisible détecté)

                          Fichier(s) infecté(s):
                          C:\WINDOWS\system32\blphc3f8j0eaaa.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                          C:\WINDOWS\system32\lphc3f8j0eaaa.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                          C:\WINDOWS\system32\phc3f8j0eaaa.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                          C:\Documents and Settings\Utilisateur\Local Settings\Temp\.tt4.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
                          C:\Documents and Settings\Utilisateur\Local Settings\Temp\.ttD.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.

                          Et le nouvel hijackthis:

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 08:47:08, on 17/07/2008
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                          C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                          C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
                          C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                          C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                          C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                          C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                          C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
                          C:\Program Files\Apoint\Apoint.exe
                          C:\WINDOWS\RTHDCPL.EXE
                          C:\WINDOWS\system32\ICO.EXE
                          C:\WINDOWS\system32\igfxpers.exe
                          C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                          C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                          C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
                          C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
                          C:\WINDOWS\system32\hkcmd.exe
                          C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
                          C:\Program Files\QuickTime\qttask.exe
                          C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\Program Files\MessengerPlus! 3\MsgPlus.exe
                          C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                          C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
                          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
                          C:\Program Files\Messenger\msmsgs.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
                          C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
                          C:\Program Files\Sony\VAIO Launcher\Launcher.exe
                          C:\Program Files\Apoint\Apntex.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
                          C:\Program Files\Windows Live\Messenger\usnsvc.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                          C:\Documents and Settings\Utilisateur\Bureau\HiJackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL (file missing)
                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                          O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                          O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
                          O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                          O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                          O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                          O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
                          O4 - HKLM\..\Run: [PDService.exe] C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
                          O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                          O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                          O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                          O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O4 - HKCU\..\Run: [Packard Bell Data Secure] C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
                          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                          O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                          O4 - S-1-5-18 Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'SYSTEM')
                          O4 - .DEFAULT Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'Default user')
                          O4 - .DEFAULT User Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'Default user')
                          O4 - Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                          O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                          O8 - Extra context menu item: Transfert par Image Converter 2 - C:\Program Files\Sony\Image Converter 2\menu.htm
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
                          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O15 - Trusted Zone: *.sony-europe.com
                          O15 - Trusted Zone: *.sonystyle-europe.com
                          O15 - Trusted Zone: *.vaio-link.com
                          O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
                          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
                          O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
                          O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
                          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                          O17 - HKLM\System\CCS\Services\Tcpip\..\{0D335865-9DA4-416E-A859-5867151EF83D}: NameServer = 84.103.237.148 86.64.145.148
                          O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
                          O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                          O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
                          O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                          O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                          O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                          O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
                          O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
                          O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
                          O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe
                          O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                          O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                          O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                          O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                          O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                          O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                          O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
                          O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                          O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                          O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                          0
                          1. Voici le rapport de Malwarebyte's:

                            Malwarebytes' Anti-Malware 1.20
                            Version de la base de données: 930
                            Windows 5.1.2600 Service Pack 2

                            07:09:09 17/07/2008
                            mbam-log-7-17-2008 (07-09-09).txt

                            Type de recherche: Examen complet (C:\|D:\|F:\|)
                            Eléments examinés: 115647
                            Temps écoulé: 5 hour(s), 16 minute(s), 35 second(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 1
                            Valeur(s) du Registre infectée(s): 1
                            Elément(s) de données du Registre infecté(s): 2
                            Dossier(s) infecté(s): 0
                            Fichier(s) infecté(s): 5

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

                            Valeur(s) du Registre infectée(s):
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphc3f8j0eaaa (Trojan.FakeAlert) -> Quarantined and deleted successfully.

                            Elément(s) de données du Registre infecté(s):
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
                            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                            Dossier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Fichier(s) infecté(s):
                            C:\WINDOWS\system32\blphc3f8j0eaaa.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\lphc3f8j0eaaa.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            C:\WINDOWS\system32\phc3f8j0eaaa.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                            C:\Documents and Settings\Utilisateur\Local Settings\Temp\.tt4.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
                            C:\Documents and Settings\Utilisateur\Local Settings\Temp\.ttD.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.

                            Et le nouvel hijackthis:

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 08:47:08, on 17/07/2008
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                            C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                            C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
                            C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                            C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                            C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                            C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                            C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
                            C:\Program Files\Apoint\Apoint.exe
                            C:\WINDOWS\RTHDCPL.EXE
                            C:\WINDOWS\system32\ICO.EXE
                            C:\WINDOWS\system32\igfxpers.exe
                            C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                            C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                            C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
                            C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
                            C:\WINDOWS\system32\hkcmd.exe
                            C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
                            C:\Program Files\QuickTime\qttask.exe
                            C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            C:\Program Files\MessengerPlus! 3\MsgPlus.exe
                            C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
                            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                            C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                            C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
                            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                            C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
                            C:\Program Files\Messenger\msmsgs.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                            C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
                            C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
                            C:\Program Files\Sony\VAIO Launcher\Launcher.exe
                            C:\Program Files\Apoint\Apntex.exe
                            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
                            C:\Program Files\Windows Live\Messenger\usnsvc.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                            C:\Documents and Settings\Utilisateur\Bureau\HiJackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL (file missing)
                            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                            O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                            O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                            O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                            O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
                            O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                            O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                            O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                            O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
                            O4 - HKLM\..\Run: [PDService.exe] C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
                            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                            O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                            O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
                            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                            O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                            O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
                            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            O4 - HKCU\..\Run: [Packard Bell Data Secure] C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
                            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                            O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                            O4 - S-1-5-18 Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'SYSTEM')
                            O4 - .DEFAULT Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'Default user')
                            O4 - .DEFAULT User Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'Default user')
                            O4 - Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe
                            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                            O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                            O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                            O8 - Extra context menu item: Transfert par Image Converter 2 - C:\Program Files\Sony\Image Converter 2\menu.htm
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
                            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O15 - Trusted Zone: *.sony-europe.com
                            O15 - Trusted Zone: *.sonystyle-europe.com
                            O15 - Trusted Zone: *.vaio-link.com
                            O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
                            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
                            O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
                            O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
                            O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                            O17 - HKLM\System\CCS\Services\Tcpip\..\{0D335865-9DA4-416E-A859-5867151EF83D}: NameServer = 84.103.237.148 86.64.145.148
                            O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
                            O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
                            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                            O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
                            O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                            O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                            O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                            O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
                            O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
                            O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
                            O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe
                            O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                            O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                            O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                            O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                            O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                            O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                            O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
                            O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                            O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                            O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                            0
                            1. Contributeur sécurité
                              Ok ... j'avais un doute , mais rien de ce côter là ...

                              Fais ce-ci maitenant :

                              Télécharges MalwareByte's :
                              ici ftp://ftp.commentcamarche.com/download/mbam-setup.exe
                              ou ici : http://www.malwarebytes.org/mbam.php

                              Installes le ( choisis bien "francais" ; ne modifies pas les paramètres d'installe ) et mets le à jour .

                              Potasses le tuto pour te familiariser avec le prg : https://forum.pcastuces.com/sujet.asp?f=31&s=3
                              ( cela dis, il est très simple d'utilisation ).

                              Impératif : redémarres en mode sans échec :
                              Comment aller en Mode sans échec
                              1) Redémarres ton ordi
                              2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                              3) Tu verras un écran avec options de démarrage apparaître
                              4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                              5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                              (attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...)

                              Lances Malwarebyte's .

                              Fais un scan dit "complet" ( sélectionnes bien tout tes disks avant le scan ) et supprimes tout ce qu'il peut trouver :
                              --->une fois le scan terminé , click sur "résultat" : puis vérifies que tous les objets infectés soient validés, puis click sur " suppression " .

                              Redémarres ton PC ( mode normal ).

                              Postes le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes) accompagné d'un nouvel hijackthis ( fait en mode normal ) ...
                              0
                              1. Voici le rapport

                                SmitFraudFix v2.329

                                Rapport fait à 20:55:17,57, 16/07/2008
                                Executé à partir de C:\SmitfraudFix
                                OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                                Le type du système de fichiers est NTFS
                                Fix executé en mode normal

                                »»»»»»»»»»»»»»»»»»»»»»»» Process

                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                                C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
                                C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                                C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                                C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                                C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                                C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
                                C:\Program Files\Apoint\Apoint.exe
                                C:\Program Files\Apoint\Apntex.exe
                                C:\WINDOWS\RTHDCPL.EXE
                                C:\WINDOWS\system32\ICO.EXE
                                C:\WINDOWS\system32\igfxpers.exe
                                C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                                C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
                                C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
                                C:\WINDOWS\system32\hkcmd.exe
                                C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
                                C:\Program Files\QuickTime\qttask.exe
                                C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                C:\Program Files\MessengerPlus! 3\MsgPlus.exe
                                C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
                                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                                C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
                                C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
                                C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                C:\WINDOWS\system32\lphc3f8j0eaaa.exe
                                C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
                                C:\Program Files\Messenger\msmsgs.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
                                C:\Program Files\Sony\VAIO Launcher\Launcher.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                C:\WINDOWS\system32\wuauclt.exe
                                C:\WINDOWS\system32\igfxsrvc.exe
                                C:\WINDOWS\system32\wscntfy.exe
                                C:\SmitfraudFix\Policies.exe
                                C:\WINDOWS\system32\cmd.exe

                                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Utilisateur

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Utilisateur\Application Data

                                »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\UTILIS~1\Favoris

                                »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                                »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                                »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                                "Source"="About:Home"
                                "SubscribedURL"="About:Home"
                                "FriendlyName"="Ma page d'accueil"

                                »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                IEDFix
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                VACFix
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                404Fix
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                SrchSTS.exe by S!Ri
                                Search SharedTaskScheduler's .dll

                                »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                "AppInit_DLLs"="MsgPlusLoader.dll"

                                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                                "System"=""

                                »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                Description: WAN (PPP/SLIP) Interface
                                DNS Server Search Order: 84.103.237.143
                                DNS Server Search Order: 86.64.145.143

                                Description: WAN (PPP/SLIP) Interface
                                DNS Server Search Order: 192.168.1.1

                                HKLM\SYSTEM\CCS\Services\Tcpip\..\{0D335865-9DA4-416E-A859-5867151EF83D}: NameServer=84.103.237.143 86.64.145.143
                                HKLM\SYSTEM\CCS\Services\Tcpip\..\{7EED6C73-6C26-499A-96BC-1039312F873F}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS1\Services\Tcpip\..\{44225335-2F2D-4605-B777-2F1F42590ECC}: NameServer=80.10.246.1,80.10.246.132
                                HKLM\SYSTEM\CS2\Services\Tcpip\..\{0D335865-9DA4-416E-A859-5867151EF83D}: NameServer=84.103.237.143 86.64.145.143
                                HKLM\SYSTEM\CS2\Services\Tcpip\..\{7EED6C73-6C26-499A-96BC-1039312F873F}: DhcpNameServer=192.168.1.1
                                HKLM\SYSTEM\CS3\Services\Tcpip\..\{7EED6C73-6C26-499A-96BC-1039312F873F}: DhcpNameServer=192.168.1.1

                                »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                                »»»»»»»»»»»»»»»»»»»»»»»» Fin
                                0
                                1. Contributeur sécurité
                                  Ok ...

                                  1- Peux tu me reposter le rapport SDFix stp , il est imcomplet ^^ ( erreur de copier/coller )

                                  Une fois celui-ci reposté , fais ce qui suit :

                                  2- Avoir accès aux fichiers cachés :

                                  Vas dans Menu Démarrer->Poste de travail->Outils->Options des dossiers...->Affichage
                                  * "Afficher les fichiers et dossiers cachés" ---> coché
                                  * "Masquer les extensions des fichiers dont le type est connu" ---> décoché
                                  * "masquer les fichiers du système" ---> décoché
                                  ( tu remetteras les paramètres de départ une fois la désinfection terminée , pas avant ... )

                                  3- Télécharges SmitfraudFix (de S!Ri, balltrap34 et moe31 ) :
                                  http://siri.urz.free.fr/Fix/SmitfraudFix.exe

                                  IMPORTANT :
                                  !! Déconnectes toi, fermes toute tes applications et désactives tes défenses ( anti-virus ,anti-spyware,...) le temps de la manipe !!

                                  Installes le soft à la racine de C\ ( et pas ailleurs! --->"C\:SmitfraudFix.exe" ) .

                                  Tuto ( aide ) : http://siri.urz.free.fr/Fix/SmitfraudFix.php

                                  Utilisation ----> option 1 - Recherche :
                                  Double clique sur l'icône "Smitfraudfix.exe" et sélectionnes 1 pour créer un rapport des fichiers responsables de l'infection.

                                  Postes le rapport ( "rapport.txt" qui se trouve sous C\: ) et attends la suite .

                                  (Attention : process.exe est détecté par certains antivirus comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité.)
                                  0
                                  1. Excuse-moi, je n'ai pas fait attention. Le voici:

                                    [b]SDFix: Version 1.205 [/b]
                                    Run by Utilisateur on 16/07/2008 at 19:49

                                    Microsoft Windows XP [version 5.1.2600]
                                    Running From: C:\SDFix

                                    [b]Checking Services [/b]:

                                    Restoring Default Security Values
                                    Restoring Default Hosts File
                                    Restoring Default Desktop Wallpaper
                                    Restoring Default ScreenSaver value

                                    Rebooting

                                    [b]Checking Files [/b]:

                                    Trojan Files Found:

                                    C:\WINDOWS\SYSTEM32\PHC3F8~1.BMP - Deleted
                                    C:\WINDOWS\SYSTEM32\BLPHC3~1.SCR - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt1.tmp - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt1D4.tmp - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt1F9.tmp - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt1FE.tmp - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt2.tmp - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt215.tmp - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt221.tmp - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt2.tmp.vbs - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\vistasp1.exe.bat - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\software.php.bat - Deleted

                                    Removing Temp Files

                                    [b]ADS Check [/b]:

                                    [b]Final Check [/b]:

                                    catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                    Rootkit scan 2008-07-16 20:01:27
                                    Windows 5.1.2600 Service Pack 2 NTFS

                                    scanning hidden processes ...

                                    scanning hidden services & system hive ...

                                    scanning hidden registry entries ...

                                    scanning hidden files ...

                                    scan completed successfully
                                    hidden processes: 0
                                    hidden services: 0
                                    hidden files: 0

                                    [b]Remaining Services [/b]:

                                    Authorized Application Key Export:

                                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                                    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                                    "C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
                                    "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
                                    "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
                                    "C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
                                    "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
                                    "C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
                                    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
                                    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
                                    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                                    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

                                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                                    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                                    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                                    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

                                    [b]Remaining Files [/b]:

                                    File Backups: - C:\SDFix\backups\backups.zip

                                    [b]Files with Hidden Attributes [/b]:

                                    Fri 30 Dec 2005 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
                                    Wed 16 Jul 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\BIT1CE.tmp"
                                    Fri 9 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\71fa8e4b1f1c72b0e3a5d30a0a049f55\BIT12E.tmp"
                                    Sun 8 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\771350e502329b319ea4189fe126f571\BIT172.tmp"
                                    Sun 8 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ad213d081e2675ef87a62c73b8abf209\BIT171.tmp"
                                    Wed 16 Jul 2008 251,597 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\e09fe9fb23931659fee8175518ca0d14\BIT216.tmp"
                                    Wed 14 Jun 2006 258,560 ...H. --- "C:\Documents and Settings\Utilisateur\Mes documents\St Gallen\Summer Semester\CEMS\Management of Information and Communication Technology Concepts, Trends and Cases (CEMS)\~WRL0433.tmp"
                                    Wed 14 Jun 2006 258,560 ...H. --- "C:\Documents and Settings\Utilisateur\Mes documents\St Gallen\Summer Semester\CEMS\Management of Information and Communication Technology Concepts, Trends and Cases (CEMS)\~WRL0487.tmp"
                                    Wed 14 Jun 2006 259,072 ...H. --- "C:\Documents and Settings\Utilisateur\Mes documents\St Gallen\Summer Semester\CEMS\Management of Information and Communication Technology Concepts, Trends and Cases (CEMS)\~WRL1313.tmp"
                                    Wed 14 Jun 2006 258,560 ...H. --- "C:\Documents and Settings\Utilisateur\Mes documents\St Gallen\Summer Semester\CEMS\Management of Information and Communication Technology Concepts, Trends and Cases (CEMS)\~WRL1456.tmp"
                                    Wed 14 Jun 2006 259,072 ...H. --- "C:\Documents and Settings\Utilisateur\Mes documents\St Gallen\Summer Semester\CEMS\Management of Information and Communication Technology Concepts, Trends and Cases (CEMS)\~WRL1767.tmp"
                                    Wed 14 Jun 2006 258,560 ...H. --- "C:\Documents and Settings\Utilisateur\Mes documents\St Gallen\Summer Semester\CEMS\Management of Information and Communication Technology Concepts, Trends and Cases (CEMS)\~WRL2175.tmp"
                                    Thu 15 Jun 2006 288,768 ...H. --- "C:\Documents and Settings\Utilisateur\Mes documents\St Gallen\Summer Semester\CEMS\Management of Information and Communication Technology Concepts, Trends and Cases (CEMS)\~WRL2506.tmp"
                                    Wed 14 Jun 2006 259,072 ...H. --- "C:\Documents and Settings\Utilisateur\Mes documents\St Gallen\Summer Semester\CEMS\Management of Information and Communication Technology Concepts, Trends and Cases (CEMS)\~WRL2703.tmp"
                                    Wed 14 Jun 2006 260,096 ...H. --- "C:\Documents and Settings\Utilisateur\Mes documents\St Gallen\Summer Semester\CEMS\Management of Information and Communication Technology Concepts, Trends and Cases (CEMS)\~WRL3788.tmp"
                                    Tue 13 Jun 2006 258,560 ...H. --- "C:\Documents and Settings\Utilisateur\Mes documents\St Gallen\Summer Semester\CEMS\Management of Information and Communication Technology Concepts, Trends and Cases (CEMS)\~WRL4082.tmp"

                                    [b]Finished![/b]
                                    0
                                2. Contributeur sécurité
                                  Salut,

                                  Télécharges SDFix sur ton bureau :
                                  http://downloads.andymanchesta.com/RemovalTools/SDFix.exe.

                                  --->Double clique sur SDFix.exe et choisis "Install" .

                                  Puis une fois l'instale faite ,redémarre en mode sans échec .
                                  Comment aller en Mode sans échec :
                                  1) Redémarre ton ordi
                                  2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                                  3) Tu verras un écran avec options de démarrage apparaître
                                  4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                                  5) Choisis ton compte habituel, et non Administrateur (si besoin ... )

                                  Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                                  --->Tape Y pour lancer le script.
                                  Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire , donc :
                                  presses une touche pour redémarrer quand il te le sera demandé .

                                  Le PC va mettre du temps avant de démarrer ( c'est normale ), après le chargement du Bureau presses une touche lorsque "Finished" s'affiche .

                                  Le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier C:\SDFix sous le nom "Report.txt".
                                  Postes ce dernier dans ta prochaine réponse accompagné d'un nouveau rapport Hijakcthis pour analyse ...
                                  0
                                  1. Je vais essayer de faire ça mais pour l'instant j'ai du mal à installer SDFix.
                                    0
                                  2. @sKe69Voici mon rapport de SDFix, suivi du rapport de hijackthis

                                    [b]SDFix: Version 1.205 [/b]
                                    Run by Utilisateur on 16/07/2008 at 19:49

                                    Microsoft Windows XP [version 5.1.2600]
                                    Running From: C:\SDFix

                                    [b]Checking Services [/b]:

                                    Restoring Default Security Values
                                    Restoring Default Hosts File
                                    Restoring Default Desktop Wallpaper
                                    Restoring Default ScreenSaver value

                                    Rebooting

                                    [b]Checking Files [/b]:

                                    Trojan Files Found:

                                    C:\WINDOWS\SYSTEM32\PHC3F8~1.BMP - Deleted
                                    C:\WINDOWS\SYSTEM32\BLPHC3~1.SCR - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt1.tmp - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt1D4.tmp - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt1F9.tmp - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt1FE.tmp - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt2.tmp - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt215.tmp - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt221.tmp - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\.tt2.tmp.vbs - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\vistasp1.exe.bat - Deleted
                                    C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\software.php.bat - Deleted

                                    Rapport de Hijackthis

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 20:12:57, on 16/07/2008
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                                    C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
                                    C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                                    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                    C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                                    C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                                    C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
                                    C:\WINDOWS\system32\notepad.exe
                                    C:\WINDOWS\system32\wuauclt.exe
                                    C:\Program Files\Apoint\Apoint.exe
                                    C:\Program Files\Apoint\Apntex.exe
                                    C:\WINDOWS\RTHDCPL.EXE
                                    C:\WINDOWS\system32\ICO.EXE
                                    C:\WINDOWS\system32\igfxpers.exe
                                    C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                                    C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                    C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
                                    C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
                                    C:\WINDOWS\system32\hkcmd.exe
                                    C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
                                    C:\Program Files\QuickTime\qttask.exe
                                    C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    C:\Program Files\MessengerPlus! 3\MsgPlus.exe
                                    C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
                                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                    C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                                    C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe
                                    C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
                                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    C:\WINDOWS\system32\lphc3f8j0eaaa.exe
                                    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
                                    C:\Program Files\Messenger\msmsgs.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                    C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
                                    C:\Program Files\Sony\VAIO Launcher\Launcher.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                    C:\Documents and Settings\Utilisateur\Bureau\HiJackThis.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL (file missing)
                                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                                    O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                                    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
                                    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                                    O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                                    O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                                    O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
                                    O4 - HKLM\..\Run: [PDService.exe] C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
                                    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                                    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                                    O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                    O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
                                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
                                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                                    O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\Friendly Technologies\BroadbandAccess\fts.exe"
                                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    O4 - HKLM\..\Run: [lphc3f8j0eaaa] C:\WINDOWS\system32\lphc3f8j0eaaa.exe
                                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    O4 - HKCU\..\Run: [Packard Bell Data Secure] C:\Program Files\Packard Bell Data Secure\PBDataSecure.exe
                                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
                                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                    O4 - S-1-5-18 Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'SYSTEM')
                                    O4 - .DEFAULT Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'Default user')
                                    O4 - .DEFAULT User Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe (User 'Default user')
                                    O4 - Startup: VAIO Launcher.lnk = C:\Program Files\Sony\VAIO Launcher\Launcher.exe
                                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                    O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                                    O8 - Extra context menu item: Transfert par Image Converter 2 - C:\Program Files\Sony\Image Converter 2\menu.htm
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
                                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O15 - Trusted Zone: *.sony-europe.com
                                    O15 - Trusted Zone: *.sonystyle-europe.com
                                    O15 - Trusted Zone: *.vaio-link.com
                                    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
                                    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
                                    O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
                                    O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
                                    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                    O17 - HKLM\System\CCS\Services\Tcpip\..\{0D335865-9DA4-416E-A859-5867151EF83D}: NameServer = 84.103.237.143 86.64.145.143
                                    O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
                                    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
                                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
                                    O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
                                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                    O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
                                    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
                                    O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
                                    O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\VAIO Entertainment\VzTaskScheduler.exe
                                    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                                    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                                    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                                    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                                    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                                    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                                    O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
                                    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                                    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                                    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                                    0
                                  3. @GloriaDe plus, quand l'ordi reste inactif pendant plus de 10 min, l'écran devient bleu et un message en anglais annonce que le pc a un problème et d'autres choses que je n'ai pas comprises.
                                    0