Mon PC rame ++

Bonjour,

Mon PC met beaucoup de temps pour passer d'une page à une autre (jusqu'à 1 minute) sur internet ainsi que pour accomplir les opérations que je lui demande. J'ai défragmenter et nettoyer le disque mais cela ne sert à rien.
Merci d'avance pour l'aide que vous pourrez m'apporter.
Configuration: Windows XP
Firefox 3.0.5

32 réponses

Résumé de la discussion

Le ralentissement du PC se manifeste par des chargements web retardés et des opérations qui prennent jusqu'à une minute, malgré des tentatives de défragmentation et de nettoyage du disque. Plusieurs analyses indiquent l'absence d'infection détectée par Malwarebytes et Avast, ce qui implique que le ralentissement ne provient pas d'un malware évident et nécessite des outils de diagnostic supplémentaires. La réponse principale conseille d'utiliser DiagHelp pour réaliser un diagnostic approfondi, en téléchargeant DiagHelp.zip, extrayant le contenu et lançant go.cmd, puis en suivant les options pour obtenir un fichier resultat.txt. Des messages ultérieurs évoquent aussi une influence possible de la connexion réseau (ADSL/Livebox) et proposent de tester le débit pour différencier goulot d'étranglement réseau et symptômes locaux.

Bobot (l’IA à votre service)
  1. Modérateur
    En effet,
    Voilà un autre lien qui fonctionne :
    http://download.registry-clean.net/download/registry-defrag.exe
    1. Modérateur
      On va procéder à une défragmentation de la base de registre pour gagner en rapidité !

      = = = =>>> Télécharge l'utilitaire ici <<<= = = =

      Double-clique sur le fichier téléchargé pour lancer l'installation. Lorsque l'écran intitulé Licence Agreement apparait, coche I accept the Agreement pour accepter la licence puis clique sur le bouton Next.

      A la fin de l'installation, le programme se lance.

      Analyse du registre:
      Clique sur le bouton Analyse Registry pour lancer l'analyse.

      A la fin de l'analyse, un mini rapport vous indique le pourcentage de fragmentation du registre:

      Si le pourcentage de fragmentation est trop important, clique sur le bouton Compact/Defrag Registry pour lancer la défragmentation.

      A la fin du processus, ton ordinateur doit être redémarré.
      1. A priori le lien de téléchargement est mort car message "404 page not found"
    2. Modérateur
      Ce sont des faux positifs : ce ne sont pas des fichiers infectieux.
      1. Modérateur
        C'est une fausse alerte : désactive avast et retélécharge le !
        Essaye ceci également :
        http://www.freedrweb.com/&prev=/search%3Fq%3Ddr%2Bweb%26hl%3Dfr%26sa%3DG&usg=ALkJrhiRIJLcGeCMKYHqbJzpyxiBXIvx6Q%27 target='_blank' rel='nofollow'>http://209.85.135.104/... et : regseeker pour nettoyer profondément.
        Défragmente ton disque dur.
        https://www.01net.com/telecharger/windows/Utilitaire/systeme/fiches/29399.html
        1. Fausse alerte...
          Voici une partie du rapport d'avaast après le scan :

          "28/12/2008 18:10:47 1230484247 SYSTEM 1464 Sign of "Win32:Trojan-gen {Other}" has been found in "http://www.malekal.com/download/DiagHelp.zip\DiagHelp\FilesInfoCmd.exe" file.
          28/12/2008 18:52:15 1230486735 SYSTEM 1352 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\LEMAIRE CHRISTIAN\Bureau\DiagHelp\DiagHelp\FilesInfoCmd.exe" file.
          28/12/2008 18:56:49 1230487009 SYSTEM 1352 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\LEMAIRE CHRISTIAN\Bureau\DiagHelp\DiagHelp\FilesInfoCmd.exe" file.
          28/12/2008 18:57:15 1230487035 SYSTEM 1352 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\LEMAIRE CHRISTIAN\Bureau\DiagHelp\DiagHelp\FilesInfoCmd.exe" file.
          28/12/2008 18:57:31 1230487051 SYSTEM 1352 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\LEMAIRE CHRISTIAN\Bureau\DiagHelp\DiagHelp\FilesInfoCmd.exe" file.
          28/12/2008 20:55:54 1230494154 LEMAIRE CHRISTIAN 3236 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\LEMAIRE CHRISTIAN\Bureau\DiagHelp.zip\DiagHelp\FilesInfoCmd.exe" file.
          28/12/2008 21:10:44 1230495044 LEMAIRE CHRISTIAN 3236 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\LEMAIRE CHRISTIAN\Local Settings\Application Data\Mozilla\Firefox\Profiles\oywjoee0.default\Cache\0DCABA69d01\DiagHelp\FilesInfoCmd.exe" file. "

          Est ce vraiment une alerte?
      2. Modérateur
        - Télécharge DiagHelp.zip sur ton bureau - Tuto : http://www.malekal.com/DiagHelp/DiagHelp.php
        - Ne double-clic pas dessus !! Fais un clic droit sur le fichier et extraire tout
        - Un nouveau dossier chercher va être créé DiagHelp
        - Ouvre le et double-clic sur go.cmd (le .cmd peut ne pas apparaître)
        - Une fenêtre va s'ouvrir, choisis l'option 1
        - L'analyse va commencer, ceci peut durer quelques minutes, laisse faire et appuie sur une touche quand on te le demande.

        ATTENTION : pendant l'analyse, après le rapport catchme, il te sera demandé d'appuyer sur une touche afin de poursuivre le scan, suis bien les instructions à l'écran !

        - A la fin de l'analyse, il peut-être (pas obligatoire) demandé de redemanderl'ordinateur... Une fois l'ordinateur redémarré le rapport va apparaître sur le bloc-note.. Ce dernier se trouve sur C:\resultat.txt
        - Copie/colle le contenu du bloc-note qui s'ouvre, pour cela :
        -- Dans le bloc-note, cliquez sur le menu Edition / Selectionner tout
        -- A nouveau menu Edition / copier
        -- Dans un nouveau message ici, faire un clic droit / coller
        1. Décidément, rien ne va... en téléchargeant DiagHelp je me suis récupérer un "Win 32 : Trojan-gen(other).

          J'ai décompresser le fichier etc... et lorsque je fais l'option 1 dans la fenêtre noire il y a un message me disant que le fichier en question est introuvable et que je dois renouveler l'opération. Je l'ai refait à plusieurs reprises et Avaast me fait apparaitre le trojan pdt que je fait l'opération que tu me demandes...
      3. Modérateur
        Est-ce que tu rames après une certaine manioulation, un certain téléchargement ?
        Combien de place te reste-t-il sur ton disque dur ?

        *************************************

        Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur le Bureau.

        http://images.malwareremoval.com/random/RSIT.exe

        * Double-clique sur RSIT.exe pour le lancer.

        * Une première fenêtre s'ouvre, clique alors sur Continue (Disclaimer).

        * Si la dernière version de HijackThis n'est pas détectée sur ton PC, RSIT le téléchargera et te demandera d'accepter la licence.

        * Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

        * Poste le contenu de log.txt (c'est celui qui apparait à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).
        1. Mon PC continue de ramer en passant les pages sur internet ainsi que dans les applications que je lui demande comme la recherche de fichiers par ex.

          Voici le rapport :

          Logfile of random's system information tool 1.05 (written by random/random)
          Run by LEMAIRE CHRISTIAN at 2008-12-28 16:11:36
          Microsoft Windows XP Édition familiale Service Pack 3
          System drive C: has 51 GB (69%) free of 73 GB
          Total RAM: 502 MB (18% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 16:12:21, on 28/12/2008
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Unable to get Internet Explorer version!
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Java\jre6\bin\jqs.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
          C:\Program Files\Securitoo\Controle Parental\bin\optproxy.exe
          C:\Program Files\Spyware Doctor\pctsAuxs.exe
          C:\Program Files\Spyware Doctor\pctsSvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Spyware Doctor\pctsTray.exe
          C:\WINDOWS\System32\alg.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\system32\hkcmd.exe
          C:\Program Files\Analog Devices\Core\smax4pnp.exe
          C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
          C:\Program Files\Dell\Media Experience\DMXLauncher.exe
          C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
          C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
          C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
          C:\WINDOWS\system32\dla\tfswctrl.exe
          C:\Program Files\Real\RealPlayer\RealPlay.exe
          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
          C:\Program Files\Orange\Systray\SystrayApp.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\Program Files\EoRezo\EoEngine.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\TomTom HOME 2\HOMERunner.exe
          C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
          C:\Program Files\OpenOffice.org 3\program\soffice.exe
          C:\Program Files\OpenOffice.org 3\program\soffice.bin
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\WINDOWS\system32\dlbtcoms.exe
          C:\Documents and Settings\LEMAIRE CHRISTIAN\Bureau\RSIT.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\Documents and Settings\LEMAIRE CHRISTIAN\Bureau\LEMAIRE CHRISTIAN.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
          O2 - BHO: EoBho - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
          O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
          O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
          O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
          O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
          O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
          O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
          O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
          O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
          O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
          O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
          O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
          O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
          O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
          O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/FR/install.cab
          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
          O23 - Service: Securitoo Control Parental (OPTENET_FILTER) - Securitoo - C:\Program Files\Securitoo\Controle Parental\bin\optproxy.exe
          O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
          O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
          O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
      4. Modérateur
        Suis cette procédure pour supprimer toutes les traces de Norton :
        = = = =>>> En cliquant ici <<<= = = =
        Tu ne fais bien entendu pas l'étape 3 de la réinstallation.

        Tu ne l'as probablement pas correctement fait la dernière fois.
        1. Normalement ça y est.
      5. Modérateur
        Pourquoi, tu le télécharge bien sur le site donné ?
        Un message d'erreur ?
        Comment procèdes-tu ?
        1. Petite erreur de ma part, le nom du fichier à télécharger ne correspondant pas à l'exemple donné sur le site de téléchargement de Java que je n'avais pas oser faire la manip. mais maintenant ça y est... Java est téléchargé. Je suis un peu méfiante avec les téléchargements...
      6. Modérateur
        Dans l'ajout/Suppression de programmes, désinstalle ça :
        Java 2 Runtime Environment, SE v1.4.2_03
        Et versions antérieures si présentes

        ********************************

        Met Java à jour sur ce lien :
        https://www.java.com/fr/download/
        1. Bonsoir,

          J'ai désinstallé Java mais pas moyen de le mettre à jour. que puis je faire?
      7. Modérateur
        Ok.

        Télécharge Random’s System Information Tool (RSIT) de random/random et enregistre l’exécutable sur le Bureau.

        = = = = >>> En cliquant ici <<< = = = =

        * Double-clique sur RSIT.exe pour le lancer.

        * Une première fenêtre s’ouvre, clique alors sur Continue (Disclaimer).

        * Si la dernière version de HijackThis n’est pas détectée sur ton PC, RSIT le téléchargera et te demandera d’accepter la licence.

        * Lorsque l’analyse sera terminée, deux fichiers texte s’ouvriront (probablement avec le bloc-notes).

        * Poste le contenu de log.txt (c’est celui qui apparaît à l’écran) ainsi que de info.txt (que tu verras dans la barre des tâches).
        1. En voici un :

          Logfile of random's system information tool 1.05 (written by random/random)
          Run by LEMAIRE CHRISTIAN at 2008-12-27 01:06:26
          Microsoft Windows XP Édition familiale Service Pack 3
          System drive C: has 51 GB (70%) free of 73 GB
          Total RAM: 502 MB (14% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 01:06:59, on 27/12/2008
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Unable to get Internet Explorer version!
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
          C:\Program Files\Securitoo\Controle Parental\bin\optproxy.exe
          C:\Program Files\Spyware Doctor\pctsAuxs.exe
          C:\Program Files\Spyware Doctor\pctsSvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\hkcmd.exe
          C:\Program Files\Analog Devices\Core\smax4pnp.exe
          C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
          C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
          C:\Program Files\Dell\Media Experience\DMXLauncher.exe
          C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
          C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
          C:\WINDOWS\system32\dla\tfswctrl.exe
          C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
          C:\Program Files\Real\RealPlayer\RealPlay.exe
          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
          C:\Program Files\Orange\Systray\SystrayApp.exe
          C:\Program Files\Spyware Doctor\pctsTray.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\TomTom HOME 2\HOMERunner.exe
          C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
          C:\WINDOWS\system32\dlbtcoms.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Documents and Settings\LEMAIRE CHRISTIAN\Bureau\RSIT.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\Documents and Settings\LEMAIRE CHRISTIAN\Bureau\LEMAIRE CHRISTIAN.exe

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
          O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
          O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
          O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
          O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
          O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
          O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
          O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
          O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
          O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
          O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
          O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
          O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
          O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
          O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/FR/install.cab
          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Securitoo Control Parental (OPTENET_FILTER) - Securitoo - C:\Program Files\Securitoo\Controle Parental\bin\optproxy.exe
          O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
          O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
          O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
        2. @SPV76Le 2è :

          info.txt logfile of random's system information tool 1.05 2008-12-27 01:07:07

          ======Uninstall list======

          -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
          -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205}
          -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
          -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382}
          -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629}
          -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
          ABBYY FineReader 5.0 Sprint Plus-->MsiExec.exe /X{D1696920-9794-4BBC-8A30-7A88763DE5A2}
          Actions MP3 Player Utilities-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F08CBDC-069F-4F87-A848-3EB2526C36D4}\Setup.exe"
          Adobe Acrobat 5.0-->C:\WINDOWS\ISUN040C.EXE -f"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Fichiers communs\Adobe\Acrobat 5.0\NT\Uninst.dll"
          Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
          Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
          Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
          Adobe Shockwave Player-->C:\WINDOWS\SYSTEM32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\SYSTEM32\Adobe\SHOCKW~1\Install.log
          Adobe® Photoshop® Album Edition Découverte 3.0-->MsiExec.exe /I{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}
          Apple Software Update-->MsiExec.exe /I{74EC78BC-B379-4E29-9006-8F161DCAABA6}
          ARTEuro-->MsiExec.exe /I{1D3C662A-F6C6-4767-A788-7AA43A9A1317}
          Avanquest update-->C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe -runfromtemp -l0x0009 -removeonly
          avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
          Barre d'outils MSN-->C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\mtbs.exe c
          Broadcom Management Programs-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2A6282FF-B75B-463F-90F5-0A43732F690D} /l1036
          CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
          Contrôle Parental-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{93094D10-9388-11D4-9886-0000B43F396D}\Setup.exe" -l0x40c
          Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
          Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
          Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
          Dell Driver Reset Tool-->MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
          Dell Media Experience Update-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CDE4CC8B-134B-421E-943C-90799E56F664}\setup.exe" -l0x40c -L0x40c /SMAINT
          Dell Media Experience-->MsiExec.exe /I{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}
          Dell Photo AIO Printer 922-->C:\WINDOWS\system32\spool\drivers\w32x86\3\DLBTUNST.EXE -NOLICENSE
          Dell Picture Studio v3.0-->MsiExec.exe /I{AF06CAE4-C134-44B1-B699-14FBDB63BD37}
          Disc2Phone-->MsiExec.exe /I{FFAB5ABB-8AAB-42E2-847F-1743E51E01E9}
          Ecran de veille AOL Photos-->C:\Program Files\Fichiers communs\AOL\Screensaver\uninst_ygpss.exe
          eMule-->"C:\Program Files\eMule\Uninstall.exe"
          Extension Système de Microsoft Money-->MsiExec.exe /I{02CA7E66-1AD1-4DE9-BA9E-86A0EEB019C7}
          G15A922FR-->MsiExec.exe /X{88A1EEBD-6A00-4AA2-9285-6028A36E443E}
          Google Earth-->MsiExec.exe /I{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}
          Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
          Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
          HijackThis 2.0.2-->"C:\Documents and Settings\LEMAIRE CHRISTIAN\Bureau\HijackThis.exe" /uninstall
          Hotel Solitaire Deluxe-->"C:\Program Files\Zylom Games\Hotel Solitaire Deluxe\GameInstaller.exe" --uninstall UnInstall.log
          Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
          Intel(R) Graphics Media Accelerator Driver-->RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx2ID PCI\VEN_8086&DEV_2782 PCI\VEN_8086&DEV_2582
          J'ai trouvé-Le manoir hanté-->C:\program files\GALLIMARD\Le manoir hanté\unwise.exe
          Jasc Paint Shop Photo Album 5-->MsiExec.exe /I{4192EAC0-6B36-4723-B216-D0E86E7757AC}
          Jasc Paint Shop Pro Studio, Dell Editon-->MsiExec.exe /I{78C496B9-5A6B-4692-8C2E-AFFFC34E4961}
          Java 2 Runtime Environment, SE v1.4.2_03-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142030}
          Learn2 Player (Uninstall Only)-->C:\Program Files\Learn2.com\StRunner\stuninst.exe
          Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
          livebox-->C:\Program Files\InstallShield Installation Information\{17342E3B-0818-4A6F-BFF8-99476605ADD6}\Setup.exe -runfromtemp -l0x040c -removeonly
          Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
          Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
          Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
          Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
          Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
          Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
          Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
          Microsoft Money-->MsiExec.exe /I{019210C1-32C8-423C-BEFD-763C8E7A188F}
          Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
          Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
          Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
          Microsoft Word 2002-->MsiExec.exe /I{911B040C-6000-11D3-8CFE-0050048383C9}
          Microsoft Works 7.0-->MsiExec.exe /I{64D114CE-4234-45C2-B60A-2B07D5A48F72}
          Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 9 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
          Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
          Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
          Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
          Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
          MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
          MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
          MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
          Orange - Logiciels Internet-->C:\Program Files\Orange\installation\core\Installgui.exe -u
          Outil de mise à jour Google-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
          PowerDVD 5.5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
          QuickTime-->MsiExec.exe /I{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}
          RealPlayer Basic-->C:\Program Files\Fichiers communs\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
          Security Update pour Microsoft .NET Framework 2.0 (KB928365)-->C:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {8056AC9E-49C5-4375-9ADE-B2F862C9DF51} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
          Sonic DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}
          Sonic RecordNow Audio-->MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}
          Sonic RecordNow Copy-->MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}
          Sonic RecordNow Data-->MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}
          Sonic Update Manager-->MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
          Sony Ericsson PC Suite 3.209.00-->C:\Program Files\InstallShield Installation Information\{2FFE93F0-BB72-4E52-8761-354D1AAA9387}\Setup.exe -runfromtemp -l0x040c -removeonly
          Spybot - Search & Destroy 1.4-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
          Spyware Doctor 6.0-->C:\Program Files\Spyware Doctor\unins000.exe /LOG
          TomTom HOME-->C:\Program Files\TomTom HOME 2\Uninstall TomTom HOME.exe
          Turbo Lister 2-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{69640730-B830-4C24-BB5C-222DA1260548}
          VC_MergeModuleToMSI-->MsiExec.exe /I{900A92BA-19EF-4A34-86CF-7B6C85BDD971}
          Viewpoint Media Player-->C:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u
          Wanadoo Photo-->"C:\Program Files\Wanadoo Photo\unins000.exe"
          Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
          Windows Live Sign-in Assistant-->MsiExec.exe /I{49672EC2-171B-47B4-8CE7-50D7806360D7}
          Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
          Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
          Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
          Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

          =====HijackThis Backups=====

          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

          ======Hosts File======

          127.0.0.1 localhost

          ======Security center information======

          AV: avast! antivirus 4.8.1296 [VPS 081226-0]

          System event log

          Computer Name: DC387P1J
          Event Code: 7036
          Message: Le service LiveUpdate est entré dans l'état : en cours d'exécution.

          Record Number: 85082
          Source Name: Service Control Manager
          Time Written: 20081203082809.000000+060
          Event Type: Informations
          User:

          Computer Name: DC387P1J
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service LiveUpdate.

          Record Number: 85081
          Source Name: Service Control Manager
          Time Written: 20081203082809.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: DC387P1J
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service aswRdr.

          Record Number: 85080
          Source Name: Service Control Manager
          Time Written: 20081203082717.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: DC387P1J
          Event Code: 7036
          Message: Le service avast! Web Scanner est entré dans l'état : en cours d'exécution.

          Record Number: 85079
          Source Name: Service Control Manager
          Time Written: 20081203082716.000000+060
          Event Type: Informations
          User:

          Computer Name: DC387P1J
          Event Code: 7035
          Message: Un contrôle Démarrer a correctement été envoyé au service avast! Web Scanner.

          Record Number: 85078
          Source Name: Service Control Manager
          Time Written: 20081203082716.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Application event log

          Computer Name: DC387P1J
          Event Code: 1800
          Message: Le service Centre de sécurité Windows a démarré.

          Record Number: 5
          Source Name: SecurityCenter
          Time Written: 20081129125940.000000+060
          Event Type: Informations
          User:

          Computer Name: DC387P1J
          Event Code: 101
          Message:
          Record Number: 4
          Source Name: Automatic LiveUpdate Scheduler
          Time Written: 20081129125928.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: DC387P1J
          Event Code: 101
          Message:
          Record Number: 3
          Source Name: Automatic LiveUpdate Scheduler
          Time Written: 20081129125928.000000+060
          Event Type: Informations
          User: AUTORITE NT\SYSTEM

          Computer Name: DC387P1J
          Event Code: 0
          Message:
          Record Number: 2
          Source Name: LiveUpdate Notice Service
          Time Written: 20081129125928.000000+060
          Event Type: Informations
          User:

          Computer Name: DC387P1J
          Event Code: 0
          Message:
          Record Number: 1
          Source Name: gusvc
          Time Written: 20081129125928.000000+060
          Event Type: Informations
          User:

          Security event log

          Computer Name: DC387P1J
          Event Code: 528
          Message: Ouverture de session réseau réussie :

          Utilisateur : SERVICE LOCAL

          Domaine : AUTORITE NT

          Id. de la session : (0x0,0x3E5)

          Type de session : 5

          Processus de session : Advapi

          Package d'authentification : Negotiate

          Station de travail :

          GUID d'ouv. de session : -

          Record Number: 200919
          Source Name: Security
          Time Written: 20081212080639.000000+060
          Event Type: Succès de l'audit
          User: AUTORITE NT\SERVICE LOCAL

          Computer Name: DC387P1J
          Event Code: 576
          Message: Privilèges spéciaux assignés à la nouvelle session :

          Utilisateur : SERVICE RÉSEAU

          Domaine : AUTORITE NT

          Id. de la session : (0x0,0x3E4)

          Privilèges : SeAuditPrivilege
          SeAssignPrimaryTokenPrivilege
          SeChangeNotifyPrivilege

          Record Number: 200918
          Source Name: Security
          Time Written: 20081212080628.000000+060
          Event Type: Succès de l'audit
          User: AUTORITE NT\SERVICE RÉSEAU

          Computer Name: DC387P1J
          Event Code: 528
          Message: Ouverture de session réseau réussie :

          Utilisateur : SERVICE RÉSEAU

          Domaine : AUTORITE NT

          Id. de la session : (0x0,0x3E4)

          Type de session : 5

          Processus de session : Advapi

          Package d'authentification : Negotiate

          Station de travail :

          GUID d'ouv. de session : -

          Record Number: 200917
          Source Name: Security
          Time Written: 20081212080628.000000+060
          Event Type: Succès de l'audit
          User: AUTORITE NT\SERVICE RÉSEAU

          Computer Name: DC387P1J
          Event Code: 576
          Message: Privilèges spéciaux assignés à la nouvelle session :

          Utilisateur : SERVICE RÉSEAU

          Domaine : AUTORITE NT

          Id. de la session : (0x0,0x3E4)

          Privilèges : SeAuditPrivilege
          SeAssignPrimaryTokenPrivilege
          SeChangeNotifyPrivilege

          Record Number: 200916
          Source Name: Security
          Time Written: 20081212080626.000000+060
          Event Type: Succès de l'audit
          User: AUTORITE NT\SERVICE RÉSEAU

          Computer Name: DC387P1J
          Event Code: 528
          Message: Ouverture de session réseau réussie :

          Utilisateur : SERVICE RÉSEAU

          Domaine : AUTORITE NT

          Id. de la session : (0x0,0x3E4)

          Type de session : 5

          Processus de session : Advapi

          Package d'authentification : Negotiate

          Station de travail :

          GUID d'ouv. de session : -

          Record Number: 200915
          Source Name: Security
          Time Written: 20081212080626.000000+060
          Event Type: Succès de l'audit
          User: AUTORITE NT\SERVICE RÉSEAU

          ======Environment variables======

          "ComSpec"=%SystemRoot%\system32\cmd.exe
          "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Fichiers communs\Sonic Shared;C:\Program Files\Fichiers communs\Teleca Shared;C:\Program Files\QuickTime\QTSystem
          "windir"=%SystemRoot%
          "FP_NO_HOST_CHECK"=NO
          "OS"=Windows_NT
          "PROCESSOR_ARCHITECTURE"=x86
          "PROCESSOR_LEVEL"=15
          "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
          "PROCESSOR_REVISION"=0401
          "NUMBER_OF_PROCESSORS"=2
          "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
          "TEMP"=%SystemRoot%\TEMP
          "TMP"=%SystemRoot%\TEMP
          "SonicCentral"=C:\Program Files\Fichiers communs\Sonic Shared\Sonic Central\
          "CLASSPATH"=.;C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zip
          "QTJAVA"=C:\Program Files\Java\j2re1.4.2_03\lib\ext\QTJava.zip

          -----------------EOF-----------------
      8. Modérateur
        Essaie de le retélécharger.
        Sinon, on le fera manuellement.
        1. C'est fait mais ça ne marche pas mieux...
      9. Modérateur
        - Non bien sûr tu n'as pas à réinstaller, bien entendu ;-).
        - Tu as installé le pare feu ? Si oui, peut être qu'il le bloque.
        Essaye de désactiver le pare feu et l'antivirus le temps de la recherche.
        1. J'ai réessayé sans le parefeu et en stoppant la protection résidente d'avaast mais c'est pareil.
      10. Modérateur
        Suis cette procédure pour supprimer toutes les traces de Norton :
        = = = =>>> En cliquant ici <<<= = = =

        **************************************************

        Pour supprimer les anciennes versions de Java et télécharger la nouvelle,
        Télécharge JavaRa.zip de Paul 'Prm753' McLain et Fred de Vries sur ton Bureau :
        = = = =>>> En cliquant ici <<<= = = =
        * Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
        * Double-clique sur le répertoire JavaRa
        * Puis double-clique sur le fichier JavaRa.exe (le .exe peut ne pas s'afficher).
        * Clique sur Search For Updates
        * Sélectionne Update Using jucheck.exe puis clique sur Search.
        * Autorise le processus à se connecter s'il le demande, clique sur Install et suis les instructions d'installation qui prennent quelques minutes
        * L'installation est terminée
        * Reviens à l'écran de JavaRa et clique sur Remove Older Versions.
        * Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur Ok, puis une deuxième fois sur Ok.
        * Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
        * Ferme l'application.
        Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.

        *************************************************

        Installe un pare feu car celui de Windows n’est pas suffisant.
        ZoneAlarm :
        = = = = >>> En cliquant ici <<< = = = =
        Un tutorial pour le configurer
        = = = = >>> En cliquant ici <<< = = = =
        1. Bonsoir Crapoulou,

          J'ai quelques petits soucis...
          - Tu m'as demander de refaire la maneuvre concernant la désinstallation de norton, je l'ai donc fait mais je souhaiterais savoir si vraiment je dois faire l'étape 3 étant donné que le but est de désinstaller et non de réinstaller norton?
          - J'ai installer JavaRa.zip etc.. mais le programme bloque lorsqu'il s'agit de rechercher les mises à jour en utilisant jucheck.exe... il ne recherche rien du tout... ça s'arrête là. Qu'en penses tu?
          Dans l'attente de ta réponse, je te souhaite une bonne soirée.

          @+
      11. Modérateur
        Il est complet ?
        Il t'a trouvé des infections ?
        Fais suivre d'un hijackthis stp.
        1. Normalement il est complet, pourquoi? Il ne me trouve plus d'infection avec le Win 32 trojan mais toujours 52 lignes avec des erreurs et je ne sais pas trop à quoi cela correspond.

          Voici le rapport Hijackthis:
          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 18:47:32, on 24/12/2008
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Unable to get Internet Explorer version!
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
          C:\Program Files\Securitoo\Controle Parental\bin\optproxy.exe
          C:\Program Files\Spyware Doctor\pctsAuxs.exe
          C:\Program Files\Spyware Doctor\pctsSvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Spyware Doctor\pctsTray.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\system32\hkcmd.exe
          C:\Program Files\Analog Devices\Core\smax4pnp.exe
          C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
          C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
          C:\Program Files\Dell\Media Experience\DMXLauncher.exe
          C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
          C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
          C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
          C:\WINDOWS\system32\dla\tfswctrl.exe
          C:\Program Files\Real\RealPlayer\RealPlay.exe
          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
          C:\Program Files\Orange\Systray\SystrayApp.exe
          C:\WINDOWS\System32\alg.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\TomTom HOME 2\HOMERunner.exe
          C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
          C:\Documents and Settings\LEMAIRE CHRISTIAN\Bureau\HiJackThis.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
          O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
          O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
          O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
          O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
          O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
          O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
          O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
          O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
          O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
          O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
          O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
          O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
          O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
          O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/FR/install.cab
          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Securitoo Control Parental (OPTENET_FILTER) - Securitoo - C:\Program Files\Securitoo\Controle Parental\bin\optproxy.exe
          O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
          O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
          O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
      12. Modérateur
        Poste le rapport Avast stp.
        Je vais me coucher.
        A demain.
        1. Bonjour Crapoulou,

          Voici le rapport avaast de cet après midi !

          *
          * Rapport avast!
          * Ce fichier est généré automatiquement
          *
          * Tâche utilisée 'Interface utilisateur simplifiée'
          * Débuté le mercredi 24 décembre 2008 15:31:36
          * VPS : 081223-0, 23/12/2008
          *

          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CometCursors.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CometCursors.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CometCursors1.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CometCursors1.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FraudXPAntivirus.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FraudXPAntivirus.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\IEDefender.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\IEDefender.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetGameBox2.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsActiveDesktop.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsActiveDesktop.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsExplorer.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsExplorer.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterAntiVirusDisableNotify.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterAntiVirusDisableNotify.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterdisabled.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterdisabled.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterFirewallDisableNotify.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterFirewallDisableNotify.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterFirewallOverride.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterFirewallOverride.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterRegistryTools.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterRegistryTools.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterRegistryTools1.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterRegistryTools1.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterTaskManager.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSystem.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSystem.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgp.zip\k.txt [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgp.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgp1.zip\c.ico [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudCgp1.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentgvu.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentgvu.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentgvu1.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRenos.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinRenos1.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSdBotaad.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSdBotaad.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSdBotaad1.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSdBotaad1.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSdBotaad2.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSdBotaad2.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WorldsecurityonlineFakeAlert.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WorldsecurityonlineFakeAlert.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZlobDNSChanger.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZlobDNSChanger.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZlobDNSChanger1.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZlobDNSChanger1.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZlobDNSChanger2.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ZlobDNSChanger2.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
          Fichiers infectés : 0
          Total des fichiers : 296636
          Total des dossiers : 6937
          Taille totale : 33,2 GB

          *
          * Tâche terminée : mercredi 24 décembre 2008 16:38:02
          * Programme était en exécution 1 heure(s), 6 minute(s), 26 seconde(s)
          *
      13. Modérateur
        Fais une analyse complète avec ton antivirus.
        Comment va l'ordi ?
        1. Bonsoir Crapoulou

          Légère amélioration par moment au niveau des changements de page, mais par moment à nouveau très lent.
          J'ai fait un scan minutieux avec avaast et il m'a retrouvé un "Win 32 : Trojan-gen (other)" je l'ai mis en quarantaine semble t-il mais 53 lignes ont présenté des erreurs impossibles à scanner ou à mettre en quarantaine. Que puis je faire? Qu'en penses tu?

          @+
      14. Modérateur
        Télécharge Malwarebytes’ Anti-Malware
        = = = = >>> En cliquant ici <<< = = = =

        - Sur la page cliques sur Télécharger Malwarebyte’s Anti-Malware
        - Enregistres le sur le bureau
        - Double cliques sur le fichier téléchargé pour lancer le processus d’installation
        - Lorsqu’il te le sera demandé, met à jour Malwarebytes anti malware
        - Si le pare-feu demande l’autorisation de se connecter pour malwarebytes, acceptes
        - Une fois la mise à jour terminée, ferme Malwarebytes
        - Double-cliques sur l’icône de malwarebytes pour le relancer
        - Dans l’onglet, Recherche, probablement ouvert par défaut,
        - Sélectionne Exécuter un examen complet
        - Clique sur Rechercher
        - Le scan démarre
        - A la fin de l’analyse, un message s’affiche : L’examen s’est terminé normalement. Cliquez sur ‘Afficher les résultats’ pour afficher tous les objets trouvés.
        - Cliques sur Ok pour poursuivre.
        - Si des malwares ont été détectés, cliques sur Afficher les résultats
        - Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
        - Malwarebytes va ouvrir le bloc-notes et y copier le rapport d’analyse.
        - Rends toi dans l’onglet rapport/log
        - Tu cliques dessus pour l’afficher une fois affiché
        - Tu cliques sur édition en haut du boc notes, et puis sur sélectionner tout
        - Tu recliques sur édition et puis sur copier et tu reviens sur le forum et dans ta réponse
        - Tu cliques droit dans le cadre de la réponse et coller

        Si tu as besoin d’aide regarde ce tutorial ICI
        1. Bonsoir

          Voici le rapport :

          Malwarebytes' Anti-Malware 1.31
          Version de la base de données: 1528
          Windows 5.1.2600 Service Pack 3

          22/12/2008 01:49:30
          mbam-log-2008-12-22 (01-49-30).txt

          Type de recherche: Examen complet (C:\|)
          Eléments examinés: 115002
          Temps écoulé: 28 minute(s), 18 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 0

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          (Aucun élément nuisible détecté)
      15. Modérateur
        Poste un nouveau rapport hijackthis.
        1. Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 21:19:27, on 21/12/2008
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Unable to get Internet Explorer version!
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
          C:\Program Files\Securitoo\Controle Parental\bin\optproxy.exe
          C:\Program Files\Spyware Doctor\pctsAuxs.exe
          C:\Program Files\Spyware Doctor\pctsSvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\hkcmd.exe
          C:\Program Files\Analog Devices\Core\smax4pnp.exe
          C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
          C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
          C:\Program Files\Dell\Media Experience\DMXLauncher.exe
          C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
          C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
          C:\WINDOWS\system32\dla\tfswctrl.exe
          C:\Program Files\Real\RealPlayer\RealPlay.exe
          C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
          C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
          C:\Program Files\Orange\Systray\SystrayApp.exe
          C:\Program Files\Spyware Doctor\pctsTray.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\TomTom HOME 2\HOMERunner.exe
          C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
          C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\WINDOWS\System32\alg.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Documents and Settings\LEMAIRE CHRISTIAN\Bureau\HiJackThis.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
          O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
          O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
          O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
          O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
          O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
          O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
          O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
          O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
          O4 - HKLM\..\Run: [DLBTCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16
          O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
          O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
          O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
          O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
          O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
          O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
          O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/FR/install.cab
          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Securitoo Control Parental (OPTENET_FILTER) - Securitoo - C:\Program Files\Securitoo\Controle Parental\bin\optproxy.exe
          O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
          O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
          O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
      16. Modérateur
        As tu bien supprimé les traces de Norton données sur mon message ??!
        1. Bonjour,
          Ca y est je viens de le faire.
      • 1
      • 2