Virus

Résolu
Bonjour,
voila mon probleme mon anti virys avast a detecter un win 32 d apres se que j ai lue se serais un virus g j ai demander a avast de le suprimer il a fait mes depuit mon pc ram et la aujourd huit il se mes a sonnet comment si on brancher une perifisie et con la debranche et cela sen arret pourriez vous m aider on en parle beaucoup sur le cite mes je n y connet pas grand chose merci d avance
Configuration: Windows XP
Firefox 3.0.1

45 réponses

Résumé de la discussion

Une détection Avast signale un Win32 sur un PC sous Windows XP, accompagnée de ralentissements et d’un comportement anormal lors du branchement et du débranchement de périphériques. Plusieurs contributeurs préconisent de supprimer le programme potentiellement indésirable C:\Program Files\AskTBar, puis d’opérer en mode sans échec et de vérifier un rapport HijackThis pour cibler les éléments à enlever. Des outils tels que Malwarebytes' Anti-Malware et Avira Antivirus ont été utilisés, avec des détections et des éléments supprimés dans le registre, et des rapports indiquant des adware comme MyWebSearch et Agent. En cas de persistance, des outils de nettoyage supplémentaires comme OTMoveIt ou l’édition manuelle du registre ont été proposés pour sécuriser la suppression et éviter les réinfections.

Bobot (l’IA à votre service)
  1. Contributeur
    Bonjour

    oui surement tu peux le mettre toujours afficher en faisant clique droit sur ta arre de tache ensuite personnaliser et tu le recherche et tu mets en toujours afficher

    @+
    0
    1. bonsoir
      il y a 2 jour il ma demander le numero de clé c normal
      et zone alarme me dit quand (pas anti virus detecter) pour quoi
      0
  2. Contributeur
    Pour moi ton PC est propre

    Bye ;)
    0
    1. bonjour merci pour tout et @+
      0
    2. ses normal que le symbol en ba a droite s enléve merci
      0
  3. Contributeur
    Bonsoir

    Oui c'est la preuve qu'il te protège et qu'il ne laisse aucune modification se faire sans ton accord :)

    @+
    0
    1. bonsoir
      ok merci je pence que l on en a fini ou il y a autre chose a faire
      0
  4. bonjour
    g installer zone alarme c normal qu il me demande des autorisations a chaques foit merci
    0
    1. Contributeur
      Bonsoir

      non un seul parefeu sur ton PC
      si tu en instale un autre celui de windows va normalement se désactivé de lui même mais à toi de vérifier qu'il soit bien désactivé
      si ce n'est pas le cas tu le désactive toi même ;)
      0
      1. Contributeur
        Bonjour
        Bien sur Windows intègre son propre parefeu
        Mais ce n'est pas ce que l'on fait de mieux

        @+
        0
        1. bonjour
          donc si je comprend bien il faut que je supprime celui que g actuellement pour installer l autre ou il faut que je le metre en supplement
          0
      2. Contributeur
        Spybot n'est pas un parefeu
        regarde ici
        http://www.swl1f.net/viewtopic.php?f=14&t=178&sid=1833263a59d2a9987faf3d217538619c

        @+
        0
        1. je voulais savoir si sur mon pc il n y avait pas un parefeu d origine
          0
      3. bonjour comment connetre mon parefeu
        spybot et bon
        aussi non g fait tout se que tu ma dit
        0
        1. Contributeur
          Bonjour

          Relance HijackThis et clique sur "Do a system scan only"
          Ensuite recherche ces lignes et coches les cases

          R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (file missing)
          O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (file missing)
          O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
          O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)

          Une fois coché, ferme toutes les fenêtres et applications et clique sur "Fix checked"

          Télécharge ATF Cleaner par Atribune. <== Tu pourras garder ce logiciel pour une utilisation régulière.
          http://www.atribune.org/ccount/click.php?id=1

          Double-clique ATF-Cleaner.exe afin de lancer le programme.
          Sous l'onglet Main, choisis : Select All
          Clique sur le bouton Empty Selected

          Si tu utilises le navigateur Firefox :

          Clique Firefox au haut et choisis : Select All
          Clique le bouton Empty Selected
          NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

          Si tu utilises le navigateur Opera :


          Clique Opera au haut et choisis : Select All
          Clique le bouton Empty Selected
          NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

          Clique Exit, du menu principal, afin de fermer le programme.
          Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.

          ensuite ce logiciel va t'aider a supprimer les outils utiliser

          Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.
          http://pc-system.fr/

          Double clique sur ToolsCleaner2.exe >
          puis Recherche
          et sur Suppression
          Note : ton bureau va disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

          CTRL+ALT+SUPP
          pour ouvrir le Gestionnaire des tâches.
          Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

          Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

          ensuite fait ceci (IMPORTANT)

          * Désactivation :

          Cliquer droit sur le "Poste de travail" > Propriétés > onglet "Restauration du système" > cocher la case "Désactiver la Restauration du système sur tous les lecteurs"
          > Appliquer patiente jusqu a que cela soit marqué "désactivée" puis Ok.

          * Activation :
          Suivre le même chemin ; décocher la case "Désactiver la Restauration du système sur tous les lecteurs"
          > Appliquer attends que cela soit a nouveau sur "surveillance" puis Ok. Redémarrer l'ordinateur..

          Pense aussi à faire tes mises à jours régulièrement

          Windows update : ==> ici =>http://www.update.microsoft.com/windowsupdate/v6/default.aspx
          Java : ==> ici => https://www.java.com/fr/download/

          Ces mises à jours sont très importantes pour la sécurité de ton PC.

          N'installe qu'un seul parefeu !!
          et bien sur qu'un antivirus

          N'oublie pas de faire régulièrement les mises à jour de tes logiciels avant chaque scan.

          * Tu peux aussi utiliser ces logiciels de sécurité

          Malwarebytes => C'est un anti-malwares gratuit et en français, tu devras une fois installer le lancer périodiquement pour contrôler ton PC.
          Un tuto pour le télécharger et son installation => Ici => http://www.swl1f.net/viewtopic.php?f=14&t=68

          Spyware Terminator => C'est un anti-spyware gratuit et en français, Il travaillera automatiquement grâce à son module résident, tu pourras le programmer pour effectuer un scan journalier.
          Un tuto pour le télécharger et son installation => Ici => http://www.swl1f.net/viewtopic.php?f=14&t=66

          * Ensuite quelques conseils
          L'infection de ton pc peut se faire de différente façon, voici en quelques lignes plusieurs points à éviter. ==> ici =>http://www.swl1f.net/viewtopic.php?f=14&t=67

          * le navigateur

          Essaye le navigateur Firefox plus sur/securisé qu IE
          Firefox n'utilise pas le dangereux protocole ActiveX
          * Téléchargement: ==> Firefox => http://www.mozilla-europe.org/fr/products/firefox/
          * Tutorial pour le sécuriser: ==> ici =>https://forum.zebulon.fr/topic/69628-s%C3%A9curiser-un-peu-plus-firefox/

          Important
          Surfez avec les droits administrateurs sur le net te rend vulnérable, il faut donc utiliser un autre compte que celui de l'administrateur


          * Pour que ton pc retrouve un peu de jeunesse
          * Pense a lancer une petite défragmentation.
          * Utilise CCleaner régulièrement.
          * Gère tes services grâce a ces 2 liens
          ==> ici => http://speedweb1.free.fr/frames2.php?page=service3 et ==> ici => http://speedweb1.free.fr/frames2.php?page=service4
          * Utilise Zeb Utility
          une application ne nécessitant pas d’installation, pour optimiser un poil ton pc. (merci a l ami Zebulon)
          Téléchargement : ==> ici ==> https://www.zebulon.fr/telechargements/utilitaires/optimisation/zeb-utility.html
          Tuto : ==> ici => https://www.zebulon.fr/dossiers/autres/58-zebutility.html

          Et pour finir

          Dénonce ton infection pour faire condamner les auteurs.

          Crée un message pour faire avancer les choses sur Malware-Complaints, nous devons être les plus nombreux possibles, alors rends compte de ton infection

          - Voir les règles du forum : ==> ici => https://malwarecomplaints.info/
          - Après t'être enregistré à l'aide du bouton en haut se nommant "Register"
          Si tu as plus de 13 ans, choisir : "I Agree to these terms and am over or exactly 13 years of age"
          Si tu as moins, clique sur : "I Agree to these terms and am under 13 years of age"

          Tu as alors sous forme de liste un sujet par type d'infection (Look2Me, Smitfraud, SpywareQuake etc..).

          * malwarecomplaints => https://malwarecomplaints.info/

          Si le malware que tu as eu n'apparaît pas dans la liste, ou si tu ne sais pas par quoi tu étais infecté(e), crée un message dans le sujet Autres infections
          conforme au règle du forum (age, ville, département etc..)

          Indique aussi le nom du Forum qui t'a aidé

          * Tuto => http://www.malekal.com/malwarecomplaints.html

          @+

          0
          1. Contributeur
            Bonsoir oui un c'est le logiciel d'installation et l'autre le raccourci pour l'utilisation de l'antivirus

            As tu encore des soucis
            poste un nouveau HijackThis stp
            0
            1. Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 12:29, on 2008-09-20
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16705)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              C:\WINDOWS\system32\IoctlSvc.exe
              C:\WINDOWS\system32\HPZipm12.exe
              C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
              C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
              C:\program files\steam\steam.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
              C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
              C:\Program Files\Lphant\eLePhantClient.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (file missing)
              R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              R3 - URLSearchHook: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLph1.dll
              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLph1.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL (file missing)
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
              O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL (file missing)
              O3 - Toolbar: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLph1.dll
              O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
              O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
              O4 - HKCU\..\Run: [PC SpeedScan Pro] C:\Program Files\Ascentive\PC SpeedScan Pro\PCSpeedScan.exe -m
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
              O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
              O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
              0
          2. Contributeur
            Bonsoir
            oui c'est ce AsKTBar qu'il faut virer
            0
            1. bonjour c fait mes sur mon bureau g 2 antivir un qui se nomme antivir pe classic et l autre antivir_workst c normal
              0
          3. bonjour tu parle du programme C:\Programm FILES\AsKTBar si si c sa je le trouve ou g essayer avec recherche mes sa me dit que le programme n ai pas axesible g etait dans disque c g trouver un programme qui se nomme AsKTBar mes je ne suis pas sur que c le bon
            0
            1. Contributeur
              Bonsoir

              tu ne répond pas à mes question si tu ne le fait pas je ne peux pas t'aider
              0
              1. Contributeur
                Tu n'as pas suivis mes instructions
                0
                1. pourquoi
                  0
                2. Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 10:57, on 2008-09-16
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\WINDOWS\system32\IoctlSvc.exe
                  C:\WINDOWS\system32\HPZipm12.exe
                  C:\WINDOWS\system32\slserv.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                  C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Program Files\Lphant\eLePhantClient.exe
                  C:\Program Files\Steam\Steam.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
                  R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                  R3 - URLSearchHook: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLph1.dll
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLph1.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                  O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
                  O3 - Toolbar: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLph1.dll
                  O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                  O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                  O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
                  0
              2. Contributeur
                Bonsoir

                recherche et supprime C:\Program Files\AskTBar
                si i ne veut pas en mode normal fait le en mode sans échec
                reposte un nouveau rapport HijackThis stp
                1
                1. Avira AntiVir Personal
                  Report file date: 2008-09-15 21:51

                  Scanning for 1616739 virus strains and unwanted programs.

                  Licensed to: Avira AntiVir PersonalEdition Classic
                  Serial number: 0000149996-ADJIE-0001
                  Platform: Windows XP
                  Windows version: (Service Pack 3) [5.1.2600]
                  Boot mode: Normally booted
                  Username: SYSTEM
                  Computer name: OMAR-A699CC6AAD

                  Version information:
                  BUILD.DAT : 8.1.0.331 16934 Bytes 2008-08-12 11:46:00
                  AVSCAN.EXE : 8.1.4.7 315649 Bytes 2008-06-26 08:57:53
                  AVSCAN.DLL : 8.1.4.0 40705 Bytes 2008-05-26 07:56:40
                  LUKE.DLL : 8.1.4.5 164097 Bytes 2008-06-12 12:44:19
                  LUKERES.DLL : 8.1.4.0 12033 Bytes 2008-05-26 07:58:52
                  ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 2007-07-18 10:33:34
                  ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 2008-06-24 13:54:15
                  ANTIVIR2.VDF : 7.0.6.153 3341312 Bytes 2008-09-12 19:48:29
                  ANTIVIR3.VDF : 7.0.6.161 67072 Bytes 2008-09-15 19:48:30
                  Engineversion : 8.1.1.28
                  AEVDF.DLL : 8.1.0.5 102772 Bytes 2008-02-25 09:58:21
                  AESCRIPT.DLL : 8.1.0.70 319866 Bytes 2008-09-15 19:48:34
                  AESCN.DLL : 8.1.0.23 119156 Bytes 2008-07-10 12:44:49
                  AERDL.DLL : 8.1.1.1 397683 Bytes 2008-09-15 19:48:33
                  AEPACK.DLL : 8.1.2.1 364917 Bytes 2008-07-15 12:58:35
                  AEOFFICE.DLL : 8.1.0.23 196987 Bytes 2008-09-15 19:48:33
                  AEHEUR.DLL : 8.1.0.51 1397111 Bytes 2008-09-15 19:48:32
                  AEHELP.DLL : 8.1.0.15 115063 Bytes 2008-07-10 12:44:48
                  AEGEN.DLL : 8.1.0.36 315764 Bytes 2008-09-15 19:48:31
                  AEEMU.DLL : 8.1.0.7 430452 Bytes 2008-07-31 08:33:21
                  AECORE.DLL : 8.1.1.11 172406 Bytes 2008-09-15 19:48:31
                  AEBB.DLL : 8.1.0.1 53617 Bytes 2008-07-10 12:44:48
                  AVWINLL.DLL : 1.0.0.12 15105 Bytes 2008-07-09 08:40:05
                  AVPREF.DLL : 8.0.2.0 38657 Bytes 2008-05-16 09:28:01
                  AVREP.DLL : 8.0.0.2 98344 Bytes 2008-09-15 19:48:30
                  AVREG.DLL : 8.0.0.1 33537 Bytes 2008-05-09 11:26:40
                  AVARKT.DLL : 1.0.0.23 307457 Bytes 2008-02-12 08:29:23
                  AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 2008-06-12 12:27:49
                  SQLITE3.DLL : 3.3.17.1 339968 Bytes 2008-01-22 17:28:02
                  SMTPLIB.DLL : 1.2.0.23 28929 Bytes 2008-06-12 12:49:40
                  NETNT.DLL : 8.0.0.1 7937 Bytes 2008-01-25 12:05:10
                  RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 2008-06-12 13:48:07
                  RCTEXT.DLL : 8.0.52.0 86273 Bytes 2008-06-27 13:34:37

                  Configuration settings for the scan:
                  Jobname..........................: Complete system scan
                  Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                  Logging..........................: low
                  Primary action...................: interactive
                  Secondary action.................: ignore
                  Scan master boot sector..........: on
                  Scan boot sector.................: on
                  Boot sectors.....................: C:,
                  Process scan.....................: on
                  Scan registry....................: on
                  Search for rootkits..............: off
                  Scan all files...................: Intelligent file selection
                  Scan archives....................: on
                  Recursion depth..................: 20
                  Smart extensions.................: on
                  Macro heuristic..................: on
                  File heuristic...................: medium

                  Start of the scan: 2008-09-15 21:51

                  The scan of running processes will be started
                  Scan process 'avscan.exe' - '1' Module(s) have been scanned
                  Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                  Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'avguard.exe' - '1' Module(s) have been scanned
                  Scan process 'sched.exe' - '1' Module(s) have been scanned
                  Scan process 'NMIndexStoreSvr.exe' - '1' Module(s) have been scanned
                  Scan process 'alg.exe' - '1' Module(s) have been scanned
                  Scan process 'NMIndexingService.exe' - '1' Module(s) have been scanned
                  Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
                  Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
                  Scan process 'NMBgMonitor.exe' - '1' Module(s) have been scanned
                  Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                  Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
                  Scan process 'ashDisp.exe' - '1' Module(s) have been scanned
                  Scan process 'ADeck.exe' - '1' Module(s) have been scanned
                  Scan process 'explorer.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'slserv.exe' - '1' Module(s) have been scanned
                  Scan process 'HPZipm12.exe' - '1' Module(s) have been scanned
                  Scan process 'IoctlSvc.exe' - '1' Module(s) have been scanned
                  Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
                  Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                  Scan process 'ashServ.exe' - '1' Module(s) have been scanned
                  Scan process 'aswUpdSv.exe' - '1' Module(s) have been scanned
                  Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                  Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
                  Scan process 'lsass.exe' - '1' Module(s) have been scanned
                  Scan process 'services.exe' - '1' Module(s) have been scanned
                  Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                  Scan process 'csrss.exe' - '1' Module(s) have been scanned
                  Scan process 'smss.exe' - '1' Module(s) have been scanned
                  37 processes with 37 modules were scanned

                  Starting master boot sector scan:
                  Master boot sector HD0
                  [INFO] No virus was found!
                  Master boot sector HD1
                  [INFO] No virus was found!
                  [WARNING] System error [21]: Le périphérique n'est pas prêt.
                  Master boot sector HD2
                  [INFO] No virus was found!
                  [WARNING] System error [21]: Le périphérique n'est pas prêt.
                  Master boot sector HD3
                  [INFO] No virus was found!
                  [WARNING] System error [21]: Le périphérique n'est pas prêt.
                  Master boot sector HD4
                  [INFO] No virus was found!
                  [WARNING] System error [21]: Le périphérique n'est pas prêt.

                  Start scanning boot sectors:
                  Boot sector 'C:\'
                  [INFO] No virus was found!

                  Starting to scan the registry.
                  The registry was scanned ( '50' files ).

                  Starting the file scan:

                  Begin scan in 'C:\'
                  C:\pagefile.sys
                  [WARNING] The file could not be opened!
                  C:\System Volume Information\_restore{D52835CC-1FBB-4076-AF89-59408F19F3F4}\RP149\A0054516.exe
                  [DETECTION] Is the TR/Shutdowner.OA Trojan
                  [NOTE] The file was moved to '48fec10b.qua'!

                  End of the scan: 2008-09-15 22:19
                  Used time: 28:19 Minute(s)

                  The scan has been done completely.

                  3996 Scanning directories
                  174635 Files were scanned
                  1 viruses and/or unwanted programs were found
                  0 Files were classified as suspicious:
                  0 files were deleted
                  0 files were repaired
                  1 files were moved to quarantine
                  0 files were renamed
                  1 Files cannot be scanned
                  174633 Files not concerned
                  1214 Archives were scanned
                  5 Warnings
                  1 Notes

                  bonsoir scan efectuer avec Antivir par contre je n arrive pas a enlever icone avast en bas a droite mes il n est plus actif car il y a un sans interdie dessu antivir fait il des alerte pour les virus et les mise a jour
                  0
              3. Contributeur
                Pour vérif fait un nouveau HijackThis stp
                0
                1. Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 18:08, on 2008-09-15
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\WINDOWS\system32\IoctlSvc.exe
                  C:\WINDOWS\system32\slserv.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\program files\steam\steam.exe
                  C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                  C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Lphant\eLePhantClient.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
                  R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                  R3 - URLSearchHook: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLph1.dll
                  O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLph1.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                  O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
                  O3 - Toolbar: LphantBar Toolbar - {6b284373-1765-4464-a587-80fbc2b2eefa} - C:\Program Files\LphantBar\tbLph1.dll
                  O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                  O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                  O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
                  0
              4. Contributeur
                Oui je pense que avast n'as rien a voir avec antivir si tu as lu tu doit savoir ce que j'en pense :)
                Mais bien sur à toi de voir :)

                si tu as encore des soucis ?
                c'est à toi de ma le dire !
                0
                1. je te demandé si mon rapport etait cline car comme je te les deja dit je ne suis pas un pro par contre pour anti v je vais le testé sa ne me coute rien
                  0
              5. Contributeur
                Je te conseil de lire ceci tu en décideras toi même

                http://www.swl1f.net/viewtopic.php?f=14&t=59

                @+
                0
                1. pourquoi tu ve que je prenne celui la moi g avast prof tu trouve quil né pas assait bon et pour mon probleme il est resolus ou quoi merci
                  0
              6. Contributeur
                Télécharge OTMoveIt (de OldTimer) sur ton Bureau.
                http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
                clic double sur OTMoveIt.exe pour le lancer.
                copie la liste qui se trouve en citation ci-dessous,
                et colle-la dans le cadre de gauche de OTMoveIt :
                Paste List of Files/Folders to be moved.

                C:\WINDOWS\hpoins07.dat 
                C:\WINDOWS\hpoins07.dat.temp 
                EmptyTemp
                

                clique sur MoveIt! pour lancer la suppression.
                le résultat apparaîtra dans le cadre Results.
                clique sur Exit pour fermer.
                poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                il te sera peut-être demandé de faire redémarrer le PC pour achever la suppression.

                0
                1. C:\WINDOWS\hpoins07.dat moved successfully.
                  C:\WINDOWS\hpoins07.dat.temp moved successfully.
                  < EmptyTemp >
                  File delete failed. C:\DOCUME~1\omar\LOCALS~1\Temp\etilqs_of4xtQ4wwjGLhKtR84bC scheduled to be deleted on reboot.
                  File delete failed. C:\WINDOWS\temp\JET7B0C.tmp scheduled to be deleted on reboot.
                  File delete failed. C:\WINDOWS\temp\JET7C15.tmp scheduled to be deleted on reboot.
                  File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_4e4.dat scheduled to be deleted on reboot.
                  File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
                  Temp folders emptied.
                  IE temp folders emptied.
                  File/Folder not found.

                  OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 09132008_125415

                  Files moved on Reboot...
                  File C:\DOCUME~1\omar\LOCALS~1\Temp\etilqs_of4xtQ4wwjGLhKtR84bC not found!
                  File C:\WINDOWS\temp\JET7B0C.tmp not found!
                  File C:\WINDOWS\temp\JET7C15.tmp not found!
                  File C:\WINDOWS\temp\Perflib_Perfdata_4e4.dat not found!
                  File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
                  0
              • 1
              • 2
              • 3