Rapport hijackthis correct??help svp

Résolu
Bonjour,
déjà merci pour tout vos conseils,voilà je viens de faire une analyse hijackthis en suivant vos conseils mais j'arrive pas à déchiffrer cette langue,est-ce que quelqu'un peut m'aider s'il vous plait,dites moi s'il est sain ou pas et ce que je devrais faire,partout j'ai lu que je devais le poster pour le faire analyser par des pros,en l'occurrence vous,alors le voila

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 04:04:07, on 03/11/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\adslTV\adsltv.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553550000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
O23 - Service: stllssvr - Unknown owner - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)

--
End of file - 8355 bytes

Merci les mecs(et/ou les filles) vous êtes sympa de me repondre
Configuration: Windows Vista
Firefox 3.0.3

27 réponses

Résumé de la discussion

Une demande d'aide porte sur l'interprétation d'un fichier de log HijackThis sous Windows Vista, afin de déterminer s'il est sain ou s'il indique une infection et quelles actions entreprendre. Des conseils préconisent l'utilisation d'outils antimalware externes; Malwarebytes' Anti-Malware est recommandé pour lancer une analyse et nettoyer les menaces, puis copier le rapport d'analyse dans la réponse. D'autres interventions suggèrent des actions complémentaires: mise à jour de Java, utilisation d'un outil de désinstallation Norton, et vérification de résultats par des analyses d'Avira ou d'autres suites pour confirmer l'absence d'infections. En parallèle, des utilisateurs expriment leur gratitude lorsque ces étapes leur permettent d'atténuer le problème et d'obtenir des rapports détaillés qui documentent l'état du système.

Bobot (l’IA à votre service)
  1. Modérateur
    C'est vraiment un second disque dur ou une autre partition ?
    1. En faite c'était mon 1er disque dur,un jour j'ai changé la résolution de l'écran parce que ça avait changé tout seul,ensuite l'ordi a affiché input not supported dans un ecran noir,je ne pouvais plus rien faire,j'ai appuyé sur toutes les touches du clavier ça ne répondait plus,alor j'ai éteint et éssayé de redémarrer mais en vain en mode sans echec,etc,mais rien,on m'a dit que ça pouvait pouvait être le disque dur donc j'en ai racheté un,j'ai placé celui qui fonctionnait plus en second disque dur pour pouvoir récuperer mes fichiers,je le vois dans le poste de travail,mais je ne peux pas l'ouvrir,il me dit accès refusé,j'ai tout essayé même de le remettre en numéro 1 mais toujours rien.
  2. Modérateur
    Comment ça "un disque dur inaccessible" ?
    1. Bah je vois mon second disque dur dans le poste de travail
      mais quand j'essaie d'y accéder il me dit "F\ n'est pas accessible.accès refusé"
  3. Modérateur
    Essaie de le réinstaller pour voir :
    http://www.mozilla-europe.org/fr/firefox/
    1. Voilà je l'ai réinstallé,je verrais s'il plante encore.

      Bon dernière chose,tu as vu l'autre question que j'ai posté concernant un disque dur inaccessible?
      As-tu une idée de ce que ça peut-être ?
  4. Modérateur
    T'as essayé de le réinstaller ?
    1. Non pas encore ça a commencé il y quelques jours alors qu'avant y avait pas de soucis mais si c'est pas dangereux pour l'ordi c'est pas grave
  5. Modérateur
    "Bah je pense que tu es plus apte que moi à dire si j'ai encore des soucis ou pas "
    ---> Je ne peux pas savoir si tu as des écrans bleus, des programmes qui plantent, des alertes de virus, etc...
    1. Oui c'est sûr mais je parlais des rapports de hijackthis et mbam,pour le reste je pense qu'il y a pas trop de problème,
      ou alors si tu pouvais m'expliquer vite fait pourquoi firefox n'arrète pas de planter quand je le ferme
  6. Bah je pense que tu es plus apte que moi à dire si j'ai encore des soucis ou pas
    après avoir vu le rapport de MBAM et celui la de hijackthis :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 03:43:15, on 04/11/2008
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v8.00 (8.00.6001.18241)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\hp\support\hpsysdrv.exe
    C:\WINDOWS\RtHDVCpl.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\WINDOWS\System32\hkcmd.exe
    C:\WINDOWS\System32\igfxpers.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\explorer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.msn.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.msn.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O13 - Gopher Prefix:
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553550000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O23 - Service: Intel(R) Alert Service (AlertService) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
    O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: Intel DH Service (IntelDHSvcConf) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe
    O23 - Service: Intel(R) Software Services Manager (ISSM) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Intel(R) Viiv(TM) Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
    O23 - Service: Intel(R) Application Tracker (MCLServiceATL) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
    O23 - Service: Intel(R) Remoting Service (Remote UI Service) - Intel(R) Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
    O23 - Service: stllssvr - Unknown owner - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
    1. Modérateur
      ---> Poste un nouveau rapport HijackThis.

      Encore des soucis ?
      1. Merci d'avoir répondu,alors voilà le rapport d'analyse

        Malwarebytes' Anti-Malware 1.30
        Version de la base de données: 1361
        Windows 6.0.6001 Service Pack 1

        04/11/2008 03:29:49
        mbam-log-2008-11-04 (03-29-49).txt

        Type de recherche: Examen rapide
        Eléments examinés: 45497
        Temps écoulé: 3 minute(s), 39 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 0
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 0

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        (Aucun élément nuisible détecté)
        1. Modérateur
          ---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
          ---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
          ---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
          ---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
          ---> Sélectionne Exécuter un examen rapide.
          ---> Clique sur Rechercher. L'analyse démarre.

          A la fin de l'analyse, un message s'affiche :

          L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.

          ---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
          ---> Ferme tes navigateurs.
          Si des malwares ont été détectés, clique sur Afficher les résultats.
          ---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
          ---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
          1. Voila ce que donne l'analyse avira

            Avira AntiVir Personal
            Report file date: lundi 3 novembre 2008 05:40

            Scanning for 1002747 virus strains and unwanted programs.

            Licensed to: Avira AntiVir PersonalEdition Classic
            Serial number: 0000149996-ADJIE-0001
            Platform: Windows Vista
            Windows version: (Service Pack 1) [6.0.6001]
            Boot mode: Normally booted
            Username: SYSTEM
            Computer name: PC-DE-KEVIN

            Version information:
            BUILD.DAT : 8.2.0.334 16933 Bytes 16/10/2008 14:55:00
            AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 09:57:53
            AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 08:56:40
            LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 13:44:19
            LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 08:58:52
            ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 04:37:01
            ANTIVIR1.VDF : 7.1.0.21 130560 Bytes 31/10/2008 04:37:02
            ANTIVIR2.VDF : 7.1.0.22 2048 Bytes 31/10/2008 04:37:02
            ANTIVIR3.VDF : 7.1.0.27 30208 Bytes 02/11/2008 04:37:03
            Engineversion : 8.2.0.10
            AEVDF.DLL : 8.1.0.6 102772 Bytes 14/10/2008 11:05:56
            AESCRIPT.DLL : 8.1.1.9 319867 Bytes 03/11/2008 04:37:12
            AESCN.DLL : 8.1.1.3 123252 Bytes 14/10/2008 11:05:56
            AERDL.DLL : 8.1.1.2 438644 Bytes 12/09/2008 07:06:02
            AEPACK.DLL : 8.1.2.4 369014 Bytes 14/10/2008 11:05:56
            AEOFFICE.DLL : 8.1.0.29 196988 Bytes 03/11/2008 04:37:10
            AEHEUR.DLL : 8.1.0.63 1479032 Bytes 03/11/2008 04:37:09
            AEHELP.DLL : 8.1.1.2 115062 Bytes 14/10/2008 11:05:56
            AEGEN.DLL : 8.1.0.42 319861 Bytes 03/11/2008 04:37:06
            AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 11:05:56
            AECORE.DLL : 8.1.2.9 172407 Bytes 03/11/2008 04:37:05
            AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 11:05:56
            AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 09:40:05
            AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 10:28:01
            AVREP.DLL : 8.0.0.2 98344 Bytes 03/11/2008 04:37:03
            AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 12:26:40
            AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 09:29:23
            AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 13:27:49
            SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 18:28:02
            SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 13:49:40
            NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 13:05:10
            RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 14:48:07
            RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 14:34:37

            Configuration settings for the scan:
            Jobname..........................: Complete system scan
            Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
            Logging..........................: low
            Primary action...................: interactive
            Secondary action.................: ignore
            Scan master boot sector..........: on
            Scan boot sector.................: on
            Boot sectors.....................: C:, D:, F:, G:,
            Process scan.....................: on
            Scan registry....................: on
            Search for rootkits..............: off
            Scan all files...................: Intelligent file selection
            Scan archives....................: on
            Recursion depth..................: 20
            Smart extensions.................: on
            Macro heuristic..................: on
            File heuristic...................: medium

            Start of the scan: lundi 3 novembre 2008 05:40

            The scan of running processes will be started
            Scan process 'avscan.exe' - '1' Module(s) have been scanned
            Scan process 'avcenter.exe' - '1' Module(s) have been scanned
            Scan process 'avgnt.exe' - '1' Module(s) have been scanned
            Scan process 'avguard.exe' - '1' Module(s) have been scanned
            Scan process 'sched.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'VSSVC.exe' - '1' Module(s) have been scanned
            Scan process 'firefox.exe' - '1' Module(s) have been scanned
            Scan process 'taskeng.exe' - '1' Module(s) have been scanned
            Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
            Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
            Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
            Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'MSCamS32.exe' - '1' Module(s) have been scanned
            Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
            Scan process 'IAANTmon.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'GoogleUpdaterService.exe' - '1' Module(s) have been scanned
            Scan process 'DQLWinService.exe' - '1' Module(s) have been scanned
            Scan process 'sidebar.exe' - '1' Module(s) have been scanned
            Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
            Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
            Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned
            Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
            Scan process 'ehtray.exe' - '1' Module(s) have been scanned
            Scan process 'igfxsrvc.exe' - '1' Module(s) have been scanned
            Scan process 'sidebar.exe' - '1' Module(s) have been scanned
            Scan process 'jusched.exe' - '1' Module(s) have been scanned
            Scan process 'igfxpers.exe' - '1' Module(s) have been scanned
            Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
            Scan process 'IAAnotif.exe' - '1' Module(s) have been scanned
            Scan process 'taskeng.exe' - '1' Module(s) have been scanned
            Scan process 'RtHDVCpl.exe' - '1' Module(s) have been scanned
            Scan process 'hpsysdrv.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
            Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
            Scan process 'explorer.exe' - '1' Module(s) have been scanned
            Scan process 'dwm.exe' - '1' Module(s) have been scanned
            Scan process 'ashServ.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'audiodg.exe' - '0' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'winlogon.exe' - '1' Module(s) have been scanned
            Scan process 'lsm.exe' - '1' Module(s) have been scanned
            Scan process 'lsass.exe' - '1' Module(s) have been scanned
            Scan process 'services.exe' - '1' Module(s) have been scanned
            Scan process 'csrss.exe' - '1' Module(s) have been scanned
            Scan process 'wininit.exe' - '1' Module(s) have been scanned
            Scan process 'csrss.exe' - '1' Module(s) have been scanned
            Scan process 'smss.exe' - '1' Module(s) have been scanned
            63 processes with 63 modules were scanned

            Starting master boot sector scan:
            Master boot sector HD0
            [INFO] No virus was found!
            Master boot sector HD1
            [INFO] No virus was found!
            Master boot sector HD2
            [INFO] No virus was found!
            [WARNING] System error [21]: Le périphérique n'est pas prêt.
            [INFO] Please restart the search with Administrator rights
            Master boot sector HD3
            [INFO] No virus was found!
            [WARNING] System error [21]: Le périphérique n'est pas prêt.
            [INFO] Please restart the search with Administrator rights
            Master boot sector HD4
            [INFO] No virus was found!
            [WARNING] System error [21]: Le périphérique n'est pas prêt.
            [INFO] Please restart the search with Administrator rights
            Master boot sector HD5
            [INFO] No virus was found!
            [WARNING] System error [21]: Le périphérique n'est pas prêt.
            [INFO] Please restart the search with Administrator rights

            Start scanning boot sectors:
            Boot sector 'C:\'
            [INFO] No virus was found!
            Boot sector 'D:\'
            [INFO] No virus was found!
            Boot sector 'F:\'
            [INFO] No virus was found!
            Boot sector 'G:\'
            [INFO] No virus was found!

            Starting to scan the registry.
            The registry was scanned ( '39' files ).

            Starting the file scan:

            Begin scan in 'C:\' <HP>
            C:\pagefile.sys
            [WARNING] The file could not be opened!
            C:\ProgramData\Microsoft\Windows\WER\ReportArchive\Report2010a84b\Report.cab
            [0] Archive type: CAB (Microsoft)
            --> kcjnrh.exe.xor
            [1] Archive type: HIDDEN
            --> MEM\AV00024b73.AV$
            [DETECTION] Is the TR/Dropper.Gen Trojan
            [NOTE] The file was moved to '497e8323.qua'!
            C:\WINDOWS\System32\drivers\sptd.sys
            [WARNING] The file could not be opened!
            Begin scan in 'D:\' <RECOVERY>
            Begin scan in 'F:\' <HP>
            F:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch3.zip
            [DETECTION] Contains suspicious code GEN/PwdZIP
            [NOTE] The detection was classified as suspicious.
            [NOTE] The file was moved to '49658d06.qua'!
            F:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch75.zip
            [DETECTION] Contains suspicious code GEN/PwdZIP
            [NOTE] The detection was classified as suspicious.
            [NOTE] The file was moved to '49658d10.qua'!
            F:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch76.zip
            [DETECTION] Contains suspicious code GEN/PwdZIP
            [NOTE] The detection was classified as suspicious.
            [NOTE] The file was moved to '49658d17.qua'!
            F:\ProgramData\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch77.zip
            [DETECTION] Contains suspicious code GEN/PwdZIP
            [NOTE] The detection was classified as suspicious.
            [NOTE] The file was moved to '49658d27.qua'!
            F:\ProgramData\Spybot - Search & Destroy\Recovery\SpywareSecure3.zip
            [DETECTION] Contains suspicious code GEN/PwdZIP
            [NOTE] The detection was classified as suspicious.
            [NOTE] The file was moved to '49878d48.qua'!
            F:\ProgramData\Spybot - Search & Destroy\Recovery\SpywareSecure6.zip
            [DETECTION] Contains suspicious code GEN/PwdZIP
            [NOTE] The detection was classified as suspicious.
            [NOTE] The file was moved to '49878d89.qua'!
            Begin scan in 'G:\' <Recovery>

            End of the scan: lundi 3 novembre 2008 06:52
            Used time: 1:12:10 Hour(s)

            The scan has been done completely.

            37370 Scanning directories
            626139 Files were scanned
            1 viruses and/or unwanted programs were found
            6 Files were classified as suspicious:
            0 files were deleted
            0 files were repaired
            7 files were moved to quarantine
            0 files were renamed
            2 Files cannot be scanned
            626130 Files not concerned
            3409 Archives were scanned
            6 Warnings
            7 Notes
            1. Modérateur
              "C'est le même logiciel sauf qu'il est en français?Je dois le télecharger et l'installer et enlever l'autre ?"
              ---> Oui et oui.

              "je dois le mettre en quarantaine ou le supprimer carrément ?"
              ---> Mets-le en quarantaine pour l'instant.

              A la fin du scan, tu pourras récupérer un rapport, poste-le ici.
              1. Merci d'abord pour ton aide.
                C'est le même logiciel sauf qu'il est en français?Je dois le télecharger et l'installer et enlever l'autre ?
                Et une dernière,comme avira vient de trouver un virus ou logiciel malveillant qui commençait par "windows32...."
                je suppose que c'est un virus,je dois le mettre en quarantaine ou le supprimer carrément ?
                1. Modérateur
                  Oui.
                  1. Voila j'ai installé avira et désinstallé avast,on peut avoir la traduction à l'heure actuel ?
                    Et j'ai donc lancé le 1er scanner qui m'indique déjà 5 warning,ce sont des fichiers infectés ?
                2. Dans ce cas je dois télecharger antivir ensuite desinstaller avast et rompre la connection internet ?
                  1. Modérateur
                    "Je dois desactiver avast ?"
                    ---> Non, le désinstaller carrément, ne jamais avoir deux antivirus sur le même PC.
                    1. ouai c'est ce que je me disais aussi après avoir lu ton profil lol pour les avis matériel astuces et compagnie,donc je le télecharge et comment ça se passe?Je dois désactiver avast ?Et pour finir la traduction française est-elle disponible maintenant ?
                      • 1
                      • 2