Win32:Spyware-gen

Bonjour à tous,
Depuis quelques jours je suis embêtée par un trojan et j'avoue avoir besoin d'un petit coup de main : )
Avast m'a signaler à plusieurs reprise que j'étais infectée par le Trojan Win32:Spyware-gen. Je le met donc en quarantaine et le jour suivant quand je lance le pc j'ai de nouveau le message d'alerte..
Parait il que les mettre en quarantaine ne les dérange pas donc je viens chercher de l'aide ^^
J'ai fais des recherches virus avec Avast, utiliser Ad-Aware, Spybot, Malwarebyte, Regsupreme (Je pense pas pouvoir trouver énormément d'autre chose à faire ^^)
Après recherche ça semble être un truc relativement courant comme problème et le conseil numéro un est de copier / coller le rapport fait avec HijackThis c'est donc ce que je vais faire :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:20:25, on 15/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nTrayFw.exe
E:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
E:\Program Files\Diskeeper\DkService.exe
C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
E:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
E:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - E:\Program Files\FlashGet\jccatch.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - E:\Program Files\FlashGet\getflash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [nTrayFw] C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nTrayFw.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Tout télécharger avec FlashGet - E:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Télécharger avec FlashGet - E:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\windows\servicepackfiles\i386\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\windows\servicepackfiles\i386\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - E:\Program Files\Diskeeper\DkService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

--
End of file - 8525 bytes

En espérant que quelqu'un puisse m'apporter son aide. : )
Configuration: Windows XP
Firefox 3.0.1

38 réponses

Résumé de la discussion

Une infection par le Trojan Win32:Spyware-gen est signalée par Avast et ces alertes se reproduisent après quarantaine, entraînant l’examen du log HijackThis et la recherche de solutions adaptées. Des solutions proposées incluent la publication du rapport malware, puis l’utilisation d’un outil comme SDFix en mode sans échec et un redémarrage pour effectuer le nettoyage plus en profondeur. D’autres intervenants suggèrent aussi de vérifier les programmes et services listés dans le log et de s’appuyer sur des scans complémentaires via Ad-Aware, Spybot et Malwarebytes pour éviter les remèdes insuffisants. Le fil rappelle également qu’un log HijackThis peut être très volumineux et qu’un extrait ciblé ou l’identification des éléments suspects peut accélérer l’aide.

Bobot (l’IA à votre service)
  1. Je pense m'arrêter la..

    Voila le moment des remerciements :

    Lawrent_999 et Chiquitine29 : MERCI pour tout ! Vous avez pris un très long moment pour m'aider, tenter de nombreuses choses pour qu'enfin je me débarasse de tout ça..
    Merci encore ; )
    0
    1. C est sur que formater reglera tout

      perso c est que je fais si g un soucis , meme avec mes quelques connaissances dans le domaine ..

      a toi de voir

      sinon fait un scan complet avec avast en mode sans echec
      0
      1. [b]SDFix: Version 1.216 [/b]
        Run by Nevaeh_ on 15/08/2008 at 23:37

        Microsoft Windows XP [version 5.1.2600]
        Running From: C:\SDFix

        [b]Checking Services [/b]:

        Restoring Default Security Values
        Restoring Default Hosts File

        Rebooting

        [b]Checking Files [/b]:

        No Trojan Files Found

        Removing Temp Files

        [b]ADS Check [/b]:

        [b]Final Check [/b]:

        catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-08-15 23:42:47
        Windows 5.1.2600 Service Pack 2 NTFS

        scanning hidden processes ...

        scanning hidden services & system hive ...

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000272b00026]
        "0016b832df72"=hex:79,b7,21,2a,a6,ff,19,74,4d,b4,a7,5b,d1,c6,50,03
        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
        "s1"=dword:47bc8618
        "s2"=dword:cfa7361b
        "h0"=dword:00000002

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
        "h0"=dword:00000000
        "ujdew"=hex:a2,0c,0f,d7,f3,05,16,f1,0b,ee,d7,fd,a6,e8,22,62,e2,87,16,0b,0d,..

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
        "h0"=dword:00000001
        "khjeh"=hex:0a,ae,a1,64,78,36,9f,d0,39,a3,b9,20,42,66,f6,a7,1b,6e,7a,fe,4f,..
        "p0"="E:\Program Files\DAEMON Tools\"

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
        "a0"=hex:20,01,00,00,d9,48,26,b8,f6,64,2a,03,39,14,68,e6,27,39,5d,e9,ef,..
        "khjeh"=hex:20,85,50,7a,aa,a4,39,6e,6d,b1,f4,ef,f1,70,71,38,2f,83,38,92,39,..

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
        "khjeh"=hex:e9,34,42,e0,8f,9c,13,54,7d,79,99,81,3d,b1,67,bb,33,fd,bf,af,c3,..

        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
        "khjeh"=hex:0e,45,40,1b,cd,98,a2,0b,b7,c9,6a,53,81,e3,1c,5f,4a,32,33,ad,3e,..
        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\000272b00026]
        "0016b832df72"=hex:79,b7,21,2a,a6,ff,19,74,4d,b4,a7,5b,d1,c6,50,03
        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
        "h0"=dword:00000000
        "ujdew"=hex:a2,0c,0f,d7,f3,05,16,f1,0b,ee,d7,fd,a6,e8,22,62,e2,87,16,0b,0d,..
        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
        "h0"=dword:00000001
        "khjeh"=hex:0a,ae,a1,64,78,36,9f,d0,39,a3,b9,20,42,66,f6,a7,1b,6e,7a,fe,4f,..
        "p0"="E:\Program Files\DAEMON Tools\"

        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
        "a0"=hex:20,01,00,00,d9,48,26,b8,f6,64,2a,03,39,14,68,e6,27,39,5d,e9,ef,..
        "khjeh"=hex:20,85,50,7a,aa,a4,39,6e,6d,b1,f4,ef,f1,70,71,38,2f,83,38,92,39,..

        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
        "khjeh"=hex:e9,34,42,e0,8f,9c,13,54,7d,79,99,81,3d,b1,67,bb,33,fd,bf,af,c3,..

        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
        "khjeh"=hex:0e,45,40,1b,cd,98,a2,0b,b7,c9,6a,53,81,e3,1c,5f,4a,32,33,ad,3e,..

        scanning hidden registry entries ...

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
        "TracesProcessed"=dword:00000000
        "TracesSuccessful"=dword:00000000
        "LastTraceFailure"=dword:00000000

        scanning hidden files ...

        scan completed successfully
        hidden processes: 0
        hidden services: 0
        hidden files: 0

        [b]Remaining Services [/b]:

        Authorized Application Key Export:

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "E:\\Program Files\\ABC\\abc.exe"="E:\\Program Files\\ABC\\abc.exe:*:Enabled:abc"
        "E:\\Program Files\\eMule\\emule.exe"="E:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
        "C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
        "E:\\Norton\\mIRC\\mirc.exe"="E:\\Norton\\mIRC\\mirc.exe:*:Enabled:mIRC"
        "E:\\Program Files\\FlashGet\\flashget.exe"="E:\\Program Files\\FlashGet\\flashget.exe:*:Enabled:Flashget"
        "C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
        "C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
        "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
        "E:\\Program Files\\iTunes\\iTunes.exe"="E:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
        "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
        "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
        "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
        "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
        "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

        [b]Remaining Files [/b]:

        [b]Files with Hidden Attributes [/b]:

        Fri 20 Aug 2004 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
        Fri 20 Aug 2004 1,667,584 ..SH. --- "C:\WINDOWS\ServicePackFiles\i386\msmsgs.exe"
        Wed 11 Apr 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"

        [b]Finished![/b]

        C'est pas un scoop j'y comprend rien mais la phrase No Trojan Files Found me plait pas mal : )
        Le seul hic c'est la recherche Avast que je viens de faire pour voir si j'avais droit au même genre de message et .. non :s
        Il trouve toujours le fameux trz machin !

        Je me dit que le mieux serait sans doute un formatage non ? Alors certe j'aime pas ça c'est long etc, mais peut être que cela est la meilleur solution :( J'aimerais bien ton avis la dessus : )
        0
        1. * Télécharge SDFix depuis ce lien : http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
          * Enregistre SDFix sur ton bureau
          * Double-clique sur l'icone SDFix
          * Une fenêtre s'ouvre, laisse les options telles quelles puis clique sur le bouton InstallSDFix .

          Pour la suite le nettoyage se fait en mode sans échec.

          Pour redémarrer en mode sans échec :

          * Redémarre ton PC, avant le logo Windows et après le changement du premier écran
          * Tapote sur la touche F8, un menu va apparaître, choisis Mode sans échec et appuie sur la touche entrée du clavier.
          * Pour plus d'informations, voir la page comment redémarrer en mode sans échec

          * Une fois en mode sans échec, clique sur le menu Démarrer puis Exécuter et colle la commande suivant :
          C:\SDFix\RunThis.bat
          * Cliquez sur OK.
          * Une fenêtre noire s'ouvre vous donnant la version du Fix.
          * Appuyez sur la touche Y (pour yes) du clavier et appuyez sur Entrée

          *A ce moment le bureau (Menu Démarrer etc.) va disparaître.

          * Le Fix commence son travail, cela peut durer une trentaines de minutes
          * Une fois les opérations de nettoyage effectuées... SDFix signale que l'ordinateur doit être redémarré :

          >>>The PC Will now restart

          * Appuie sur une touche du clavier

          * L'ordinateur va redémarrer normalement.
          * Avant d'arriver sur le bureau, une nouvelle fenêtre de SDFix va s'ouvrir. Ca peut durer cinq minutes...

          >> Le rapport SDFix s'ouvre alors fais un copier coller et envoi le.
          0
          1. Me revoila,
            donc lorsque je fais une recherche de virus avec Avast il trouve systématiquement le fichier :
            C:\WINDOWS\System32\trz.tmp
            je le met en quarantaine (faute de pouvoir le supprimer) et lors de la recherche suivante il le retrouve mais avec un nom très légèrement différent : trz16; trz17; trz7B; trz1E; ...
            Le point positif c'est qu'il ne me parle plus du fichier el32.dll qui m'embêtait au départ (il est dans ma zone de quarantaine)
            N'empêche ça m'embête bien :(

            Je rajoute un truc, un peu plus tôt Lawrent_999 en m'aidant m'a signaler que je risquais de ne plus voir mon bureau lors de l'utilisation de ComboFix et sur le coup tout se passait bien mais depuis à chaque reboot le bureau ne s'affiche pas et je dois faire ce qu'il m'avait dit : CTRL + ALT + SUPPR --> Nouveau -> explorer
            Aurais-tu une solution également pour ceci ?

            C'est horrible à quelle point je ne sais rien faire ^^'
            0
            1. non ce n est pas sur le rapport refais le scan pour voir (avast)
              0
              1. et l'extra.txt

                Deckard's System Scanner v20071014.68
                Extra logfile - please post this as an attachment with your post.
                --------------------------------------------------------------------------------

                -- System Information ----------------------------------------------------------

                Microsoft Windows XP Professionnel (build 2600) SP 2.0
                Architecture: X86; Language: French

                CPU 0: Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz
                CPU 1: Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz
                Percentage of Memory in Use: 26%
                Physical Memory (total/avail): 2046.48 MiB / 1504.99 MiB
                Pagefile Memory (total/avail): 3428.62 MiB / 2978.03 MiB
                Virtual Memory (total/avail): 2047.88 MiB / 1926.45 MiB

                A: is Removable (Unformatted)
                C: is Fixed (NTFS) - 19.53 GiB total, 9.16 GiB free.
                D: is CDROM (No Media)
                E: is Fixed (NTFS) - 213.35 GiB total, 43.4 GiB free.
                F: is CDROM (No Media)
                G: is CDROM (No Media)

                \\.\PHYSICALDRIVE0 - SAMSUNG SP2504C - 232.88 GiB - 2 partitions
                \PARTITION0 (bootable) - Système de fichiers installable - 19.53 GiB - C:
                \PARTITION1 - Système de fichiers installable - 213.35 GiB - E:

                -- Security Center -------------------------------------------------------------

                AUOptions is disabled.
                Windows Internal Firewall is disabled.

                AntiVirusDisableNotify is set.
                FirewallDisableNotify is set.
                UpdatesDisableNotify is set.

                FW: ActiveArmor Firewall v1.0 (NVIDIA Corporation)
                AV: avast! antivirus 4.8.1229 [VPS 080815-0] v4.8.1229 (ALWIL Software)

                [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
                "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

                [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
                "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                "E:\\Program Files\\ABC\\abc.exe"="E:\\Program Files\\ABC\\abc.exe:*:Enabled:abc"
                "E:\\Program Files\\eMule\\emule.exe"="E:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
                "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                "C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
                "E:\\Norton\\mIRC\\mirc.exe"="E:\\Norton\\mIRC\\mirc.exe:*:Enabled:mIRC"
                "E:\\Program Files\\FlashGet\\flashget.exe"="E:\\Program Files\\FlashGet\\flashget.exe:*:Enabled:Flashget"
                "C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
                "C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
                "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
                "E:\\Program Files\\iTunes\\iTunes.exe"="E:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
                "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
                "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

                -- Environment Variables -------------------------------------------------------

                ALLUSERSPROFILE=C:\Documents and Settings\All Users
                APPDATA=C:\Documents and Settings\Nevaeh_\Application Data
                CLASSPATH=.;C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
                CLIENTNAME=Console
                CommonProgramFiles=C:\Program Files\Fichiers communs
                COMPUTERNAME=NEVAEH
                ComSpec=C:\WINDOWS\system32\cmd.exe
                FP_NO_HOST_CHECK=NO
                HOMEDRIVE=C:
                HOMEPATH=\Documents and Settings\Nevaeh_
                LOGONSERVER=\\NEVAEH
                MOZ_CRASHREPORTER_DATA_DIRECTORY=C:\Documents and Settings\Nevaeh_\Application Data\Mozilla\Firefox\Crash Reports
                MOZ_CRASHREPORTER_RESTART_ARG_0=C:\Program Files\Mozilla Firefox\firefox.exe
                MOZ_CRASHREPORTER_STRINGS_OVERRIDE=C:\Program Files\Mozilla Firefox\crashreporter-override.ini
                NUMBER_OF_PROCESSORS=2
                OS=Windows_NT
                Path=C:\Program Files\Mozilla Firefox;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;E:\PROGRA~1\DISKEE~1;E:\Program Files\QuickTime\QTSystem
                PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                PROCESSOR_ARCHITECTURE=x86
                PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 6, GenuineIntel
                PROCESSOR_LEVEL=6
                PROCESSOR_REVISION=0f06
                ProgramFiles=C:\Program Files
                PROMPT=$P$G
                QTJAVA=C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip
                SESSIONNAME=Console
                SystemDrive=C:
                SystemRoot=C:\WINDOWS
                TEMP=C:\DOCUME~1\Nevaeh_\LOCALS~1\Temp
                TMP=C:\DOCUME~1\Nevaeh_\LOCALS~1\Temp
                USERDOMAIN=NEVAEH
                USERNAME=Nevaeh_
                USERPROFILE=C:\Documents and Settings\Nevaeh_
                windir=C:\WINDOWS
                __COMPAT_LAYER=EnableNXShowUI

                -- User Profiles ---------------------------------------------------------------

                Nevaeh_ [I](admin)/I
                Administrateur [I](new local, admin)/I

                -- Add/Remove Programs ---------------------------------------------------------

                --> C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
                --> C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                --> E:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
                --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                ABC (remove only) --> E:\Program Files\ABC\Uninstall.exe
                Ad-Aware --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
                Adobe Flash Player 9 ActiveX --> C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
                Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                Adobe Photoshop 7.0.1 --> C:\WINDOWS\ISUN040C.EXE -f"E:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"E:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
                Adobe Reader 7.0.9 - Français --> MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A70900000002}
                Apple Mobile Device Support --> MsiExec.exe /I{6D22289D-ED59-4F97-B636-2111EC64F5D4}
                Apple Software Update --> MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
                Archiveur WinRAR --> E:\Program Files\WinRAR\uninstall.exe
                Assistant de connexion Windows Live --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
                ASUS Gamer OSD --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}\setup.exe" -l0x9 -removeonly
                ATI - Utilitaire de désinstallation du logiciel --> C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
                ATI Catalyst Control Center --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{055EE59D-217B-43A7-ABFF-507B966405D8}\setup.exe" -l0x4e49
                ATI Display Driver --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
                ATI Parental Control & Encoder --> MsiExec.exe /I{9862B19F-4CAD-4EED-920F-2F378D84393F}
                avast! Antivirus --> C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
                AVIVO Codecs --> MsiExec.exe /X{C941F1F1-25B3-4DF5-83E6-888C51A1AAB6}
                Bonjour --> MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
                BS.Player FREE powered by AdVantage --> "E:\Program Files\Webteh\BSplayer\uninstall.exe"
                BSPlayer --> "E:\Program Files\Webteh\BSplayer\uninstall.exe"
                Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch --> C:\Program Files\InstallShield Installation Information\{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}\setup.exe -runfromtemp -l0x0409
                CamStudio 2.02 Fr --> "E:\Program Files\CamStudio\unins000.exe"
                Catalyst Control Center - Branding --> MsiExec.exe /I{4893A35F-0A23-48EC-8E74-24969244D6F2}
                Catalyst Control Center - Branding --> MsiExec.exe /I{4FC31A14-3D58-4F8F-85DA-EB3EBC771252}
                CCleaner (remove only) --> "E:\Program Files\CCleaner\uninst.exe"
                Combined Community Codec Pack 2007-02-22 --> "E:\Program Files\Combined Community Codec Pack\unins000.exe"
                Correctif pour Windows XP (KB914440) --> "C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
                Correctif pour Windows XP (KB935448) --> "C:\WINDOWS\$NtUninstallKB935448$\spuninst\spuninst.exe"
                Correctif Windows XP - KB873339 --> C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
                Correctif Windows XP - KB885835 --> C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
                Correctif Windows XP - KB885836 --> C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
                Correctif Windows XP - KB886185 --> C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
                Correctif Windows XP - KB888302 --> C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
                Correctif Windows XP - KB890859 --> "C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
                Correctif Windows XP - KB891781 --> C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
                DirectVobSub (remove only) --> "e:\Program Files\DirectVobSub\uninstall.exe"
                Diskeeper 2008 Pro Premier --> MsiExec.exe /X{67A48ED5-0B6A-470A-995C-B8F1942E8AB9}
                DivX Codec --> E:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
                DivX Content Uploader --> E:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
                DivX Converter --> E:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
                DivX Player --> E:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
                DivX Web Player --> E:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
                eMule --> "E:\Program Files\eMule\Uninstall.exe"
                ffdshow (remove only) --> "e:\Program Files\Matroska Pack\ffdshow\uninstall.exe"
                FlashGet 1.9.6.1073 --> E:\Program Files\FlashGet\uninst.exe
                Fraps (remove only) --> "E:\Fraps\uninstall.exe"
                Google Earth --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x40c -removeonly
                Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"
                Haali Media Splitter --> "e:\Program Files\Matroska Pack\haali\uninstall.exe"
                Hamachi 1.0.2.2 --> E:\Hamachi\uninstall.exe
                High Definition Audio Driver Package - KB888111 --> "C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
                HijackThis 2.0.2 --> "E:\HijackThis\HijackThis.exe" /uninstall
                Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                HP USB Disk Storage Format Tool --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}\Setup.exe" -l0x9
                iPod for Windows 2006-01-10 --> C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{3D047C15-C859-45F7-81CE-F2681778069B} /l1036
                iTunes --> MsiExec.exe /I{B0A88235-FDF0-4DCD-88A0-D78EA2D03AB9}
                Java(TM) SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
                JMB36X Raid Configurer --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}\setup.exe" -l0x40c -removeonly
                Kaspersky Internet Security 6.0 --> MsiExec.exe /I{D0DCD54F-C829-41A5-AF32-71E632BB0E2C}
                Kit d'installation --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9C650676-CDDB-42C0-8D11-3EEB7F791F99}\setup.exe" -l0x40c -eth
                Malwarebytes' Anti-Malware --> "E:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                Matroska Pack --> e:\Program Files\Matroska Pack\uninstall.exe
                Messenger Plus! Live --> "C:\Program Files\MSN Messenger\Messenger Plus! Live\Uninstall.exe"
                Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
                Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                Microsoft Works 2000 --> MsiExec.exe /I{A3088CD2-612B-11D3-AF43-00C04F443448}
                mIRC --> "E:\Norton\mIRC\mirc.exe" -uninstall
                Mise à jour de sécurité pour Lecteur Windows Media (KB911564) --> "C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734) --> "C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398) --> "C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB893756) --> "C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB896358) --> "C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB896423) --> "C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB896428) --> "C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB899587) --> "C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB899591) --> "C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB900725) --> "C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB901017) --> "C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB901214) --> "C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB902400) --> "C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB904706) --> "C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB905414) --> "C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB905749) --> "C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB908519) --> "C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB911562) --> "C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB911927) --> "C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB913580) --> "C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB914388) --> "C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB914389) --> "C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB917344) --> "C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB917422) --> "C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB917953) --> "C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB918118) --> "C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB918439) --> "C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB919007) --> "C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB920213) --> "C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB920670) --> "C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB920683) --> "C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB920685) --> "C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB922819) --> "C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB923191) --> "C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB923414) --> "C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB923694) --> "C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB923980) --> "C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB924191) --> "C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB924270) --> "C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB924496) --> "C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB924667) --> "C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB925902) --> "C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB926247) --> "C:\WINDOWS\$NtUninstallKB926247$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB926255) --> "C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB926436) --> "C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB927779) --> "C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB927802) --> "C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB928090) --> "C:\WINDOWS\$NtUninstallKB928090$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB928255) --> "C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB928843) --> "C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB929969) --> "C:\WINDOWS\$NtUninstallKB929969$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB930178) --> "C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB931261) --> "C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB931768) --> "C:\WINDOWS\$NtUninstallKB931768$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB931784) --> "C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
                Mise à jour de sécurité pour Windows XP (KB932168) --> "C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB894391) --> "C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB898461) --> "C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB900485) --> "C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB904942) --> "C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB908531) --> "C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB910437) --> "C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB911280) --> "C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB916595) --> "C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB920872) --> "C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB922582) --> "C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB927891) --> "C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB930916) --> "C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
                Mise à jour pour Windows XP (KB931836) --> "C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe"
                Mozilla Firefox (3.0.1) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                Navilog1 3.6.3 --> "C:\Program Files\Navilog1\unins000.exe"
                Nero Suite --> C:\Program Files\Fichiers communs\Nero\Uninstall\setup.exe /uninstall ExtraUninstallID=""
                NVIDIA Drivers --> C:\WINDOWS\System32\nvuide.exe UninstallGUI
                NVIDIA ForceWare Network Access Manager --> C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1F6423DE-7959-4178-80E0-023C7EAA5347} /l1036
                PhotoFiltre Studio --> "E:\Program Files\PhotoFiltre Studio\Uninst.exe"
                Pro Evolution Soccer 6 --> C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{EBB794ED-D282-4334-92FB-254481EFF514} /l1036
                QuickTime --> MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
                RealPlayer --> C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
                Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x40c -removeonly
                RegSupreme 1.2 --> "E:\Program Files\RegSupreme\unins000.exe"
                Skype™ 3.5 --> MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
                Spybot - Search & Destroy --> "E:\Program Files\Spybot - Search & Destroy\unins001.exe"
                Spybot - Search & Destroy 1.5.2.20 --> "C:\WINDOWS\unins000.exe"
                Steam --> E:\Steam\UNWISE.EXE E:\Steam\INSTALL.LOG
                StreamPlug Player --> c:\Program Files\Cedelia\StreamPlug\StreamPlug Player.exe --uninstall
                Subtitle Workshop 2.51 --> "E:\Program Files\Subtitle Workshop\uninstall.exe"
                TeamSpeak 2 RC2 --> "e:\Program Files\Teamspeak2_RC2\unins000.exe"
                VideoLAN VLC media player 0.8.6i --> E:\Program Files\VideoLAN\VLC\uninstall.exe
                Winamp (remove only) --> "e:\Program Files\Winamp\UninstWA.exe"
                Windows Live installer --> MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
                Windows Live Messenger --> MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
                Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                World of Warcraft --> C:\Program Files\Fichiers communs\Blizzard Entertainment\World of Warcraft\Uninstall.exe
                Wow Cartographe 1.07 --> E:\Program Files\WowCartographe\uninst.exe

                -- Application Event Log -------------------------------------------------------

                Event Record #/Type15085 / Error
                Event Submitted/Written: 08/15/2008 10:38:23 PM
                Event ID/Source: 8 / crypt32
                Event Description:
                Échec de la récupération de la mise à jour automatique du numéro de séquence de la liste racine tierce partie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> avec l'erreur : Le serveur spécifié ne peut pas exécuter l'opération demandée.

                Event Record #/Type15084 / Error
                Event Submitted/Written: 08/15/2008 10:38:07 PM
                Event ID/Source: 8 / crypt32
                Event Description:
                Échec de la récupération de la mise à jour automatique du numéro de séquence de la liste racine tierce partie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> avec l'erreur : Le serveur spécifié ne peut pas exécuter l'opération demandée.

                Event Record #/Type15083 / Error
                Event Submitted/Written: 08/15/2008 10:38:07 PM
                Event ID/Source: 8 / crypt32
                Event Description:
                Échec de la récupération de la mise à jour automatique du numéro de séquence de la liste racine tierce partie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> avec l'erreur : Le serveur spécifié ne peut pas exécuter l'opération demandée.

                Event Record #/Type15082 / Error
                Event Submitted/Written: 08/15/2008 10:38:07 PM
                Event ID/Source: 8 / crypt32
                Event Description:
                Échec de la récupération de la mise à jour automatique du numéro de séquence de la liste racine tierce partie à partir de : <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> avec l'erreur : Cette opération s'est terminée car le délai d'attente a expiré.

                Event Record #/Type15079 / Success
                Event Submitted/Written: 08/15/2008 10:33:42 PM
                Event ID/Source: 12001 / usnjsvc
                Event Description:
                The Messenger Sharing USN Journal Reader service started successfully.

                -- Security Event Log ----------------------------------------------------------

                No Errors/Warnings found.

                -- System Event Log ------------------------------------------------------------

                Event Record #/Type39818 / Error
                Event Submitted/Written: 08/15/2008 09:53:46 PM
                Event ID/Source: 7022 / Service Control Manager
                Event Description:
                Le service ForceWare Intelligent Application Manager (IAM) est en attente de démarrage.

                Event Record #/Type39814 / Warning
                Event Submitted/Written: 08/15/2008 09:52:03 PM
                Event ID/Source: 1003 / Dhcp
                Event Description:
                Votre ordinateur n'a pas pu renouveler son adresse à partir du réseau (à partir
                du serveur DHCP) pour la carte réseau dont l'adresse réseau est 001A921CC2B7. Il s'est
                produit l'erreur suivante :
                %%1223.
                Votre ordinateur va continuer à essayer d'obtenir sa propre adresse auprès du
                serveur d'adresse réseau (DHCP).

                Event Record #/Type39779 / Error
                Event Submitted/Written: 08/15/2008 09:19:40 PM
                Event ID/Source: 7022 / Service Control Manager
                Event Description:
                Le service ForceWare Intelligent Application Manager (IAM) est en attente de démarrage.

                Event Record #/Type39759 / Error
                Event Submitted/Written: 08/15/2008 09:15:54 PM
                Event ID/Source: 1501 / SNMP
                Event Description:
                Le service SNMP a rencontré une erreur lors de la configuration des transports entrants.\n
                Le transport IP a été abandonné.

                Event Record #/Type39739 / Error
                Event Submitted/Written: 08/15/2008 09:14:44 PM
                Event ID/Source: 10005 / DCOM
                Event Description:
                DCOM a reçu l'erreur "%%1084" lors de la mise en route du service EventSystem avec les arguments ""
                pour démarrer le serveur :
                {1BE1F766-5536-11D1-B726-00C04FB926AF}

                -- End of Deckard's System Scanner: finished at 2008-08-15 22:38:57 ------------
                0
                1. ça a été mis en quarantaine voir même supprimé mais alors pourquoi avoir encore des alertes lors des recherches virus ? C'est juste une question parce que des fois j'ai l'impression de voir des trucs étranges, c'est histoire d'être moine bête ^^

                  Voici donc le rapport main.txt :

                  Deckard's System Scanner v20071014.68
                  Run by Nevaeh_ on 2008-08-15 22:37:04
                  Computer is in Normal Mode.
                  --------------------------------------------------------------------------------

                  -- System Restore --------------------------------------------------------------

                  Successfully created a Deckard's System Scanner Restore Point.

                  -- Last 5 Restore Point(s) --
                  46: 2008-08-15 20:37:08 UTC - RP100 - Deckard's System Scanner Restore Point
                  45: 2008-08-15 17:40:43 UTC - RP99 - ComboFix created restore point
                  44: 2008-08-15 11:49:02 UTC - RP98 - Point de vérification système
                  43: 2008-08-13 16:27:02 UTC - RP97 - Point de vérification système
                  42: 2008-08-11 17:16:25 UTC - RP96 - Point de vérification système

                  -- First Restore Point --
                  1: 2008-06-11 17:54:55 UTC - RP55 - Point de vérification système

                  Backed up registry hives.
                  Performed disk cleanup.

                  -- HijackThis (run as Nevaeh_.exe) ---------------------------------------------

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 22:37:48, on 15/08/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\WINDOWS\ATKKBService.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  E:\Program Files\Diskeeper\DkService.exe
                  C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
                  C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
                  C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
                  C:\WINDOWS\system32\PnkBstrA.exe
                  C:\WINDOWS\system32\PnkBstrB.exe
                  C:\WINDOWS\System32\snmp.exe
                  C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
                  C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
                  C:\WINDOWS\explorer.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\WINDOWS\system32\rundll32.exe
                  C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nTrayFw.exe
                  E:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  E:\Program Files\iPod\bin\iPodService.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Windows Live\Messenger\usnsvc.exe
                  C:\Documents and Settings\Nevaeh_\Bureau\dss.exe
                  E:\PROGRA~1\HIJACK~1\Nevaeh_.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                  O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - E:\Program Files\FlashGet\jccatch.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
                  O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - E:\Program Files\FlashGet\getflash.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                  O4 - HKLM\..\Run: [nTrayFw] C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nTrayFw.exe
                  O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                  O8 - Extra context menu item: &Tout télécharger avec FlashGet - E:\Program Files\FlashGet\jc_all.htm
                  O8 - Extra context menu item: &Télécharger avec FlashGet - E:\Program Files\FlashGet\jc_link.htm
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                  O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                  O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\Program Files\FlashGet\FlashGet.exe
                  O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\Program Files\FlashGet\FlashGet.exe
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\windows\servicepackfiles\i386\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\windows\servicepackfiles\i386\msmsgs.exe
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                  O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Diskeeper - Diskeeper Corporation - E:\Program Files\Diskeeper\DkService.exe
                  O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
                  O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
                  O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
                  O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
                  O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
                  0
                  1. il les a mis en quarantaine ... donc c good

                    mais nous nous l avions supprimé :

                    C:\WINDOWS\system32\el32.dll NOT unregistered.
                    C:\WINDOWS\system32\el32.dll moved successfully

                    on peux verifier si tu veux :

                    Télécharge sur ton bureau DSS (ex Comboscan) de Deckard:

                    http://deckard.geekstogo.com/dss.exe

                    (choisis enregistrer, puis Bureau comme emplacement)

                    Ferme toutes les applications en cours.

                    Double-clic sur DSS.exe pour lancer l'outil.

                    Une fenêtre s'ouvre, invitant à fermer toutes les applications, clique sur OK.

                    A la fin de l'analyse, une fenêtre s'ouvre, clique sur OK.

                    Le rapport main.txt va s'afficher, copie le dans ta prochaine réponse.
                    Si un rapport complémentaire a été créé ( extra.txt ), poste le aussi dans ta réponse.

                    Les rapports sont ici :
                    (!) C:\Deckard\System Scanner\main.txt
                    (!) C:\Deckard\System Scanner\extra.txt

                    (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                    0
                    1. Je viens aux nouvelles avec 2 détections :

                      http://img239.imageshack.us/img239/7439/infectionjk7.jpg
                      0
                      1. D'abord le rapport hijackthis :

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 21:49:26, on 15/08/2008
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\WINDOWS\ATKKBService.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe
                        E:\Program Files\Diskeeper\DkService.exe
                        C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
                        C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
                        C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
                        C:\WINDOWS\system32\PnkBstrA.exe
                        C:\WINDOWS\system32\PnkBstrB.exe
                        C:\WINDOWS\System32\snmp.exe
                        C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
                        C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
                        C:\WINDOWS\explorer.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\WINDOWS\system32\rundll32.exe
                        C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nTrayFw.exe
                        E:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        E:\Program Files\iPod\bin\iPodService.exe
                        C:\Program Files\Windows Live\Messenger\usnsvc.exe
                        E:\Program Files\HijackThis\HijackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                        O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - E:\Program Files\FlashGet\jccatch.dll
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
                        O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - E:\Program Files\FlashGet\getflash.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                        O4 - HKLM\..\Run: [nTrayFw] C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nTrayFw.exe
                        O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                        O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                        O8 - Extra context menu item: &Tout télécharger avec FlashGet - E:\Program Files\FlashGet\jc_all.htm
                        O8 - Extra context menu item: &Télécharger avec FlashGet - E:\Program Files\FlashGet\jc_link.htm
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                        O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                        O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\Program Files\FlashGet\FlashGet.exe
                        O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - E:\Program Files\FlashGet\FlashGet.exe
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\windows\servicepackfiles\i386\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\windows\servicepackfiles\i386\msmsgs.exe
                        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                        O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                        O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                        O23 - Service: Diskeeper - Diskeeper Corporation - E:\Program Files\Diskeeper\DkService.exe
                        O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcAppFlt.exe
                        O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\Apache Group\Apache2\bin\apache.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcIp.exe
                        O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\PROGRA~1\NVIDIA~1\NETWOR~1\bin\nSvcLog.exe
                        O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
                        O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
                        0
                        1. refais un scan hijackthis et post le rapport stp et dis moi si t as encore des souis
                          0
                          1. Search Navipromo version 3.6.3 commencé le 15/08/2008 à 21:30:58,07

                            !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                            !!! Postez ce rapport sur le forum pour le faire analyser !!!
                            !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                            Outil exécuté depuis C:\Program Files\navilog1
                            Session actuelle : "Nevaeh_"

                            Mise à jour le 09.08.2008 à 18h00 par IL-MAFIOSO

                            Microsoft Windows XP [version 5.1.2600]
                            Internet Explorer : 6.0.2900.2180
                            Système de fichiers : NTFS

                            Recherche executé en mode normal

                            *** Recherche Programmes installés ***

                            *** Recherche dossiers dans "C:\WINDOWS" ***

                            *** Recherche dossiers dans "C:\Program Files" ***

                            *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                            *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                            *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                            *** Recherche dossiers dans "C:\Documents and Settings\Nevaeh_\applic~1" ***

                            *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

                            *** Recherche dossiers dans "C:\Documents and Settings\Nevaeh_\locals~1\applic~1" ***

                            *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

                            *** Recherche dossiers dans "C:\Documents and Settings\Nevaeh_\menudm~1\progra~1" ***

                            *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***

                            *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                            pour + d'infos : http://www.gmer.net

                            *** Recherche avec GenericNaviSearch ***
                            !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                            !!! A vérifier impérativement avant toute suppression manuelle !!!

                            * Recherche dans "C:\WINDOWS\system32" *

                            * Recherche dans "C:\Documents and Settings\Nevaeh_\locals~1\applic~1" *

                            * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

                            *** Recherche fichiers ***

                            *** Recherche clés spécifiques dans le Registre ***

                            *** Module de Recherche complémentaire ***
                            (Recherche fichiers spécifiques)

                            1)Recherche nouveaux fichiers Instant Access :

                            2)Recherche Heuristique :

                            * Dans "C:\WINDOWS\system32" :

                            * Dans "C:\Documents and Settings\Nevaeh_\locals~1\applic~1" :

                            * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :

                            3)Recherche Certificats :

                            Certificat Egroup absent !
                            Certificat Electronic-Group absent !
                            Certificat Montorgueil absent !
                            Certificat OOO-Favorit absent !
                            Certificat Sunny-Day-Design-Ltd absent !

                            4)Recherche fichiers connus :

                            *** Analyse terminée le 15/08/2008 à 21:33:23,90 ***
                            0
                            1. Alors alors,
                              Chiquitine29 voila le rapport avec OTmoveit

                              LoadLibrary failed for C:\WINDOWS\system32\el32.dll
                              C:\WINDOWS\system32\el32.dll NOT unregistered.
                              C:\WINDOWS\system32\el32.dll moved successfully.
                              C:\fixwareout\FindT moved successfully.
                              C:\fixwareout moved successfully.
                              C:\WINDOWS\el.ini moved successfully.

                              OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08152008_212748


                              et celui avec navilog ça vient dans le message suivant ; )
                              0
                              1. Juste pour dire que je viens de voir le message de Chiquitine29,
                                je vais tester tout ça ; )
                                0
                                1. Comme on pouvait s'y attendre au vu de comment ça se passe depuis le début :
                                  Problème ^^
                                  donc, en MSE je ne peux pas aller supprimer les fichiers en quarantaine
                                  Initialisation des fichiers de la zone de quarantaine
                                  L'action a été accomplie avec des erreurs !


                                  En plus de ça depuis tout à l'heure, chaque fois que je reboot le bureau ne s'affiche pas et je dois faire CTRL + ALT + SUPPR --> explorer

                                  Je me dit que je vais jamais m'en débarrasser de ce problème :(
                                  0
                                  1. Salut

                                    pour aider :

                                    télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau.
                                    double-clique sur OTMoveIt.exe pour le lancer.
                                    Assure toi que la case Unregister Dll's and Ocx's soit bien cochée
                                    copie la liste qui se trouve en gras ci-dessous,
                                    et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                                    C:\WINDOWS\system32\el32.dll
                                    C:\fixwareout
                                    C:\WINDOWS\el.ini


                                    clique sur MoveIt! pour lancer la suppression.
                                    le résultat apparaitra dans le cadre "Results".
                                    clique sur Exit pour fermer.
                                    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                                    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes

                                    ensuite :

                                    Fais un clic droit sur ce lien : (IL-MAFIOSO)
                                    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
                                    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
                                    Ensuite double clique sur navilog1.exe pour lancer l'installation.
                                    Une fois l'installation terminée, le fix s'exécutera automatiquement.
                                    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

                                    Laisse-toi guider. Au menu principal, choisis 1 et valides.
                                    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

                                    Patiente jusqu'au message :
                                    *** Analyse Termine le ..... ***
                                    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
                                    Copie-colle l'intégralité dans une réponse. Referme le blocnote.
                                    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

                                    Tuto: http://www.malekal.com/Adware.Magic_Control.php

                                    .
                                    0
                                    1. Bon, redémarre en mode sans echec
                                      Puis tu ouvres ton anti virus avast
                                      Tu vas dans la zone de quarantaine et tu supprimes tous les fichiers
                                      Ensuite, tu ferme avast, tu vides la corbeille puis tu redémarre normalement
                                      Ensuite refais une analyse avec avast et dis moi quoi stp
                                      0
                                      • 1
                                      • 2