Rapport hisjackthis

Bonjour,
je souhaiterais que quelqu'un regarde mon rapport parce que mon pc "freeze" depuis quelques semaines malgré les mises à jour des pilotes, scan antivirus , spyware etc

merci à vous bonne journée

StartupList report, 26/10/2008, 15:09:27
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP3 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16735)
* Using default options
* Including empty and uninteresting sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Savescreen\Savescreen.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\imapi.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\notepad.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\sophie.SOPHIE-3E35C239\Menu Démarrer\Programmes\Démarrage]
Gestionnaire Internet.lnk = C:\Program Files\Wanadoo\GestMAJ.exe

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage]
agenda.LNK = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

Savescreen = C:\Program Files\Savescreen\Savescreen.exe
SoundMAXPnP = C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
SoundMAX = "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
WOOWATCH = C:\PROGRA~1\Wanadoo\Watch.exe
WOOTASKBARICON = C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
avast! = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz = nwiz.exe /install
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

msnmsgr = "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
WOOKIT = C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

--------------------------------------------------

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINDOWS\system32\mshta.exe "%1" %*

--------------------------------------------------

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

--------------------------------------------------

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

--------------------------------------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\ssmypics.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------

Enumerating Browser Helper Objects:

AcroIEHelperStub - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
EoRezoBHO - (no file) - {64F56FC1-1272-44CD-BA6E-39723696E350}
(no name) - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
(no name) - (no file) - {7E853D72-626A-48EC-A868-BA8D5E23E045}

--------------------------------------------------

Enumerating Task Scheduler jobs:

ashQuick.job

--------------------------------------------------

Enumerating Download Program Files:

[FavImport Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\ImportAx.dll
CODEBASE = https://onedrive.live.com/?id=favorites

[WUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\wuweb.dll
CODEBASE = http://www.update.microsoft.com/...

[MUWebControl Class]
InProcServer32 = C:\WINDOWS\system32\muweb.dll
CODEBASE = http://www.update.microsoft.com/...

[Windows Live Photo Upload Control]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll
CODEBASE = http://lamaregrand.spaces.live.com/PhotoUpload/MsnPUpld.cab

[Java Plug-in 1.6.0_07]
InProcServer32 = C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

[F-Secure Online Scanner 3.3]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\fscax.dll
CODEBASE = https://www.f-secure.com/en/home/support

[Java Plug-in 1.6.0_07]
InProcServer32 = C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

[Java Plug-in 1.6.0_07]
InProcServer32 = C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx
CODEBASE = http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
Protocol #1: C:\WINDOWS\system32\mswsock.dll
Protocol #2: C:\WINDOWS\system32\mswsock.dll
Protocol #3: C:\WINDOWS\system32\mswsock.dll
Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS\system32\mswsock.dll
Protocol #7: C:\WINDOWS\system32\mswsock.dll
Protocol #8: C:\WINDOWS\system32\mswsock.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll
Protocol #12: C:\WINDOWS\system32\mswsock.dll
Protocol #13: C:\WINDOWS\system32\mswsock.dll
Protocol #14: C:\WINDOWS\system32\mswsock.dll
Protocol #15: C:\WINDOWS\system32\mswsock.dll
Protocol #16: C:\WINDOWS\system32\mswsock.dll
Protocol #17: C:\WINDOWS\system32\mswsock.dll
Protocol #18: C:\WINDOWS\system32\mswsock.dll
Protocol #19: C:\WINDOWS\system32\mswsock.dll
Protocol #20: C:\WINDOWS\system32\mswsock.dll
Protocol #21: C:\WINDOWS\system32\mswsock.dll

--------------------------------------------------

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll

--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

--------------------------------------------------

End of report, 16 763 bytes
Report generated in 0,047 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Configuration: Windows XP
Firefox 3.0.3

15 réponses

  1. Ben tu sais, tu peux déjà voir par toi-même. Tu débranches les périphériques inutiles au démarrage et tu testes. Tu laisses une barrette et ton DD et vois si tu as toujours des problèmes.
    0
    1. je pense aussi à un conflit quelconque dans le pc mais j'ignore lequel, j'ai fais des recherches sur google mais plein de personnes rencontrent des problèmes de "freeze" , je pense que je vais faire appel à un professionnel qui verra peut etre dans la tour si tout est ok merci quand meme
      0
      1. Lance un nettoyage complet de ton pc: CCleaner, Reg cleaner, défragmentation...

        Voici un tuto: http://www.infos-du-net.com/actualite/dossiers/59-15-logiciels-gratuits.html
        0
        1. rien de detecte a priori ce n est pas une infection plus un probleme avec l ordi.

          as tu vu dans rapport et solutions aux problemes.
          0
          1. Malwarebytes' Anti-Malware 1.30
            Version de la base de données: 1323
            Windows 5.1.2600 Service Pack 3

            26/10/2008 17:15:21
            mbam-log-2008-10-26 (17-15-21).txt

            Type de recherche: Examen complet (C:\|)
            Eléments examinés: 162102
            Temps écoulé: 33 minute(s), 59 second(s)

            Processus mémoire infecté(s): 0
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 0
            Valeur(s) du Registre infectée(s): 0
            Elément(s) de données du Registre infecté(s): 0
            Dossier(s) infecté(s): 0
            Fichier(s) infecté(s): 0

            Processus mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Valeur(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Elément(s) de données du Registre infecté(s):
            (Aucun élément nuisible détecté)

            Dossier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Fichier(s) infecté(s):
            (Aucun élément nuisible détecté)
            0
            1. j'y arrive pas ça m'énerve alors je pense que je vais me tourner vers un professionnel , merci pour votre aide
              bonne soirée
              0
              1. Ok! Alors teste un scan complet de MBAM en mode sans échec.
                0
                1. la mise à jour à été faite vendredi et j'ai bien les derniers drivers
                  0
                  1. Ou une mise à jour du pilote de carte graphique, peut-être...
                    0
                    1. c est bien possible aussi mais voyons ce que te trouve mbam.

                      les mise a jour qui ne sont pas importante je ne les installe pas.
                      0
                  2. a priori rien sur le hijack.

                    as tu essaye celui la , il en vaut la peine.

                    Telecharges malwares bytes anti malwares : egalement tres util sur pb de pub mais pas tous malheureusement

                    Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                    Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
                    fais comme indique,mise a jour , scan complet en mode sans echec et les rapports.

                    garde le et lance un scan tout les mois comme indique.

                    si tu as ad aware tu peux desinstalle car il ne reconnait plus grand chose.

                    c est possible egalement le fait que ton pc soit instable a cause de different programmes ou je ne sais quoi d autre.
                    0
                    1. et celui là :

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 14:52:30, on 26/10/2008
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16735)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\System32\FTRTSVC.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Savescreen\Savescreen.exe
                      C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                      C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                      C:\WINDOWS\system32\RUNDLL32.EXE
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
                      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                      C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                      C:\PROGRA~1\Wanadoo\ComComp.exe
                      C:\PROGRA~1\Wanadoo\Toaster.exe
                      C:\PROGRA~1\Wanadoo\Inactivity.exe
                      C:\PROGRA~1\Wanadoo\PollingModule.exe
                      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                      C:\PROGRA~1\Wanadoo\Watch.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\Program Files\Windows Live\Messenger\usnsvc.exe
                      C:\WINDOWS\system32\mmc.exe
                      C:\WINDOWS\system32\imapi.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                      O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O4 - HKLM\..\Run: [Savescreen] C:\Program Files\Savescreen\Savescreen.exe
                      O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                      O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O4 - Startup: Gestionnaire Internet.lnk = C:\Program Files\Wanadoo\GestMAJ.exe
                      O4 - Global Startup: agenda.LNK = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
                      O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                      O8 - Extra context menu item: Ajouter à &Windows Live Favorites - https://onedrive.live.com/?id=favorites
                      O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
                      O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                      O16 - DPF: {03B39B10-9AB9-4DBB-8189-7F76E0CE5F3F} (FavImport Class) - https://onedrive.live.com/?id=favorites
                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
                      O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://lamaregrand.spaces.live.com/PhotoUpload/MsnPUpld.cab
                      O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{D0AA2200-52BC-44CC-91F8-A9C163C9EF05}: NameServer = 80.10.246.130 81.253.149.10
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                      O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
                      0
                      1. je comprend pas.ton rapport ne m indique pas grand chose , il m est inutil si quelqu un a la solution. merci.

                        tu as bien fait: do a scan and save a logfile?si tu regardes les autres questions du forum securite, un hijack ne correspond pas du tout au tien.
                        1
                        1. c'est bien la dernière version que j'ai , je l'ai télécharger sur le même lien que tu m'as donné

                          StartupList report, 26/10/2008, 15:08:46
                          StartupList version: 1.52.2
                          Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
                          Detected: Windows XP SP3 (WinNT 5.01.2600)
                          Detected: Internet Explorer v7.00 (7.00.6000.16735)
                          * Using default options
                          ==================================================

                          Running processes:

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\System32\FTRTSVC.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\nvsvc32.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Savescreen\Savescreen.exe
                          C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                          C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                          C:\WINDOWS\system32\RUNDLL32.EXE
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
                          C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                          C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
                          C:\PROGRA~1\Wanadoo\ComComp.exe
                          C:\PROGRA~1\Wanadoo\Toaster.exe
                          C:\PROGRA~1\Wanadoo\Inactivity.exe
                          C:\PROGRA~1\Wanadoo\PollingModule.exe
                          C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                          C:\PROGRA~1\Wanadoo\Watch.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Program Files\Windows Live\Messenger\usnsvc.exe
                          C:\WINDOWS\system32\imapi.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                          C:\Program Files\Internet Explorer\iexplore.exe

                          --------------------------------------------------

                          Listing of startup folders:

                          Shell folders Startup:
                          [C:\Documents and Settings\sophie.SOPHIE-3E35C239\Menu Démarrer\Programmes\Démarrage]
                          Gestionnaire Internet.lnk = C:\Program Files\Wanadoo\GestMAJ.exe

                          Shell folders Common Startup:
                          [C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage]
                          agenda.LNK = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
                          DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe

                          --------------------------------------------------

                          Checking Windows NT UserInit:

                          [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          UserInit = C:\WINDOWS\system32\userinit.exe,

                          --------------------------------------------------

                          Autorun entries from Registry:
                          HKLM\Software\Microsoft\Windows\CurrentVersion\Run

                          Savescreen = C:\Program Files\Savescreen\Savescreen.exe
                          SoundMAXPnP = C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
                          SoundMAX = "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
                          WOOWATCH = C:\PROGRA~1\Wanadoo\Watch.exe
                          WOOTASKBARICON = C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                          avast! = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                          nwiz = nwiz.exe /install
                          NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

                          --------------------------------------------------

                          Autorun entries from Registry:
                          HKCU\Software\Microsoft\Windows\CurrentVersion\Run

                          msnmsgr = "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                          WOOKIT = C:\PROGRA~1\Wanadoo\GestMaj.exe GestionnaireInternet.exe
                          ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe

                          --------------------------------------------------

                          Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

                          Shell=*INI section not found*
                          SCRNSAVE.EXE=*INI section not found*
                          drivers=*INI section not found*

                          Shell & screensaver key from Registry:

                          Shell=Explorer.exe
                          SCRNSAVE.EXE=C:\WINDOWS\system32\ssmypics.scr
                          drivers=*Registry value not found*

                          Policies Shell key:

                          HKCU\..\Policies: Shell=*Registry key not found*
                          HKLM\..\Policies: Shell=*Registry value not found*

                          --------------------------------------------------

                          Enumerating Browser Helper Objects:

                          AcroIEHelperStub - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
                          EoRezoBHO - (no file) - {64F56FC1-1272-44CD-BA6E-39723696E350}
                          (no name) - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
                          (no name) - (no file) - {7E853D72-626A-48EC-A868-BA8D5E23E045}

                          --------------------------------------------------

                          Enumerating Task Scheduler jobs:

                          ashQuick.job

                          --------------------------------------------------

                          Enumerating Download Program Files:

                          [FavImport Class]
                          InProcServer32 = C:\WINDOWS\Downloaded Program Files\ImportAx.dll
                          CODEBASE = https://onedrive.live.com/?id=favorites

                          [WUWebControl Class]
                          InProcServer32 = C:\WINDOWS\system32\wuweb.dll
                          CODEBASE = http://www.update.microsoft.com/...

                          [MUWebControl Class]
                          InProcServer32 = C:\WINDOWS\system32\muweb.dll
                          CODEBASE = http://www.update.microsoft.com/...

                          [Windows Live Photo Upload Control]
                          InProcServer32 = C:\WINDOWS\Downloaded Program Files\MsnPUpld.dll
                          CODEBASE = http://lamaregrand.spaces.live.com/PhotoUpload/MsnPUpld.cab

                          [F-Secure Online Scanner 3.3]
                          InProcServer32 = C:\WINDOWS\Downloaded Program Files\fscax.dll
                          CODEBASE = https://www.f-secure.com/en/home/support

                          [Shockwave Flash Object]
                          InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx
                          CODEBASE = http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

                          --------------------------------------------------

                          Enumerating ShellServiceObjectDelayLoad items:

                          PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
                          CDBurn: C:\WINDOWS\system32\SHELL32.dll
                          WebCheck: C:\WINDOWS\system32\webcheck.dll
                          SysTray: C:\WINDOWS\system32\stobject.dll
                          WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll

                          --------------------------------------------------
                          End of report, 6 921 bytes
                          Report generated in 0,031 seconds

                          Command line options:
                          /verbose - to add additional info on each section
                          /complete - to include empty sections and unsuspicious data
                          /full - to include several rarely-important sections
                          /force9x - to include Win9x-only startups even if running on WinNT
                          /forcent - to include WinNT-only startups even if running on Win9x
                          /forceall - to include all Win9x and WinNT startups, regardless of platform
                          /history - to list version history only
                          0
                          1. tu as une ancienne version du hijack, desinstalle le et ensuite installe cette nouvelle version.

                            telecharge cela:util pour voir ce que peut etre l infection et agir ensuite.

                            http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

                            installe le normallement comme tout autre programme dans c/programme/...............
                            clique sur do a scan and save a logfile, tu obtiens un rapport que tu colles.
                            parfois alerte comme quoi, sans la fonction administrateur le rapport ne peut pas etre complet .
                            a ce moment relance hijack avec un clique droit sur le raccourci et executer en tant qu administrateur.
                            1